From 769274f376ed189d74e9684e126c17f6ddd3d4ff Mon Sep 17 00:00:00 2001 From: Vishal Patil Date: Tue, 15 Nov 2016 21:04:20 -0500 Subject: Added ip forwarding for nuage --- roles/nuage_node/tasks/iptables.yml | 17 +++++++++++++++++ 1 file changed, 17 insertions(+) create mode 100644 roles/nuage_node/tasks/iptables.yml (limited to 'roles/nuage_node/tasks/iptables.yml') diff --git a/roles/nuage_node/tasks/iptables.yml b/roles/nuage_node/tasks/iptables.yml new file mode 100644 index 000000000..52935f075 --- /dev/null +++ b/roles/nuage_node/tasks/iptables.yml @@ -0,0 +1,17 @@ +--- +- name: IPtables | Get iptables rules + command: iptables -L --wait + register: iptablesrules + always_run: yes + +- name: Allow traffic from overlay to underlay + command: /sbin/iptables --wait -I FORWARD 1 -s {{ hostvars[groups.oo_first_master.0].openshift.master.sdn_cluster_network_cidr }} -j ACCEPT -m comment --comment "nuage-overlay-underlay" + when: "'nuage-overlay-underlay' not in iptablesrules.stdout" + notify: + - save iptable rules + +- name: Allow traffic from underlay to overlay + command: /sbin/iptables --wait -I FORWARD 1 -d {{ hostvars[groups.oo_first_master.0].openshift.master.sdn_cluster_network_cidr }} -j ACCEPT -m comment --comment "nuage-underlay-overlay" + when: "'nuage-underlay-overlay' not in iptablesrules.stdout" + notify: + - save iptable rules -- cgit v1.2.3