mark vpn traffic as exemption for return routes - #14280
DaanHoogland wants to merge 1 commit into
Conversation
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## 4.22 #14280 +/- ##
============================================
- Coverage 18.00% 18.00% -0.01%
+ Complexity 16219 16218 -1
============================================
Files 5936 5936
Lines 535716 535716
Branches 65596 65596
============================================
- Hits 96459 96456 -3
Misses 428268 428268
- Partials 10989 10992 +3
Flags with carried forward coverage won't be shown. Click here to find out more. ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
|
|
Tested the change on 4.22.1.1 and it fixes #14184. Environment and evidence below. Environment
Before (unpatched router),
The static-NAT VM reaches the far side with its public address. After (patched router, static NAT re-applied) Same capture on vpcb's VR: Private source preserved across the tunnel, with the SNAT rule still ahead of the exemption, so the ordering no longer matters. Non-tunnel traffic still uses the static NAT. Counters zeroed, then from vm-a: one ping across the tunnel and two HTTPS requests to the internet ( The two internet connections took the static-NAT SNAT; the tunnel flow took the 0x525 exemption. The VPN connections stayed |
|
@DaanHoogland nowadays, most PRs use the |



Description
This PR...
Fixes: #14184
Types of changes
Feature/Enhancement Scale or Bug Severity
Feature/Enhancement Scale
Bug Severity
Screenshots (if appropriate):
How Has This Been Tested?
How did you try to break this feature and the system with this change?