From a551b2ebd7b267188685e3f8e3d5a1743650c53a Mon Sep 17 00:00:00 2001 From: Daan Hoogland Date: Thu, 1 Oct 2026 11:05:22 +0200 Subject: [PATCH] mark vpn traffic as exemption for return routes --- systemvm/debian/opt/cloud/bin/configure.py | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/systemvm/debian/opt/cloud/bin/configure.py b/systemvm/debian/opt/cloud/bin/configure.py index bf48be66694c..c484ca444eea 100755 --- a/systemvm/debian/opt/cloud/bin/configure.py +++ b/systemvm/debian/opt/cloud/bin/configure.py @@ -1530,7 +1530,6 @@ def forward_vpc(self, rule): self.fw.append(["nat", "", fw_output_rule]) def processStaticNatRule(self, rule): - # FIXME this needs ordering with the VPN no nat rule device = self.getDeviceByIp(rule["public_ip"]) if device is None: raise Exception("Ip address %s has no device in the ips databag" % rule["public_ip"]) @@ -1556,8 +1555,9 @@ def processStaticNatRule(self, rule): self.fw.append(["nat", "front", "-A PREROUTING -d %s/32 -j DNAT --to-destination %s" % (rule["public_ip"], rule["internal_ip"])]) + # Skip VPN-marked traffic so chain order vs the site-to-site VPN exemption doesn't matter. self.fw.append(["nat", "front", - "-A POSTROUTING -o %s -s %s/32 -j SNAT --to-source %s" % (device, rule["internal_ip"], rule["public_ip"])]) + "-A POSTROUTING -o %s -s %s/32 -m mark ! --mark 0x525 -j SNAT --to-source %s" % (device, rule["internal_ip"], rule["public_ip"])]) self.fw.append(["nat", "front", "-A OUTPUT -d %s/32 -j DNAT --to-destination %s" % (rule["public_ip"], rule["internal_ip"])]) self.fw.append(["filter", "",