diff options
author | Vishal Patil <vishal.patil@nuagenetworks.net> | 2016-11-15 21:04:20 -0500 |
---|---|---|
committer | Vishal Patil <vishal.patil@nuagenetworks.net> | 2016-11-15 21:04:20 -0500 |
commit | 769274f376ed189d74e9684e126c17f6ddd3d4ff (patch) | |
tree | 2b20aba321850a14c2b02f58f54b49cd0a876b95 /roles/nuage_node/tasks | |
parent | dedc8742acecf6775dcd29a128ef1f0800c917e4 (diff) | |
download | openshift-769274f376ed189d74e9684e126c17f6ddd3d4ff.tar.gz openshift-769274f376ed189d74e9684e126c17f6ddd3d4ff.tar.bz2 openshift-769274f376ed189d74e9684e126c17f6ddd3d4ff.tar.xz openshift-769274f376ed189d74e9684e126c17f6ddd3d4ff.zip |
Added ip forwarding for nuage
Diffstat (limited to 'roles/nuage_node/tasks')
-rw-r--r-- | roles/nuage_node/tasks/iptables.yml | 17 | ||||
-rw-r--r-- | roles/nuage_node/tasks/main.yaml | 2 |
2 files changed, 19 insertions, 0 deletions
diff --git a/roles/nuage_node/tasks/iptables.yml b/roles/nuage_node/tasks/iptables.yml new file mode 100644 index 000000000..52935f075 --- /dev/null +++ b/roles/nuage_node/tasks/iptables.yml @@ -0,0 +1,17 @@ +--- +- name: IPtables | Get iptables rules + command: iptables -L --wait + register: iptablesrules + always_run: yes + +- name: Allow traffic from overlay to underlay + command: /sbin/iptables --wait -I FORWARD 1 -s {{ hostvars[groups.oo_first_master.0].openshift.master.sdn_cluster_network_cidr }} -j ACCEPT -m comment --comment "nuage-overlay-underlay" + when: "'nuage-overlay-underlay' not in iptablesrules.stdout" + notify: + - save iptable rules + +- name: Allow traffic from underlay to overlay + command: /sbin/iptables --wait -I FORWARD 1 -d {{ hostvars[groups.oo_first_master.0].openshift.master.sdn_cluster_network_cidr }} -j ACCEPT -m comment --comment "nuage-underlay-overlay" + when: "'nuage-underlay-overlay' not in iptablesrules.stdout" + notify: + - save iptable rules diff --git a/roles/nuage_node/tasks/main.yaml b/roles/nuage_node/tasks/main.yaml index 1146573d3..2ec4be2c2 100644 --- a/roles/nuage_node/tasks/main.yaml +++ b/roles/nuage_node/tasks/main.yaml @@ -37,3 +37,5 @@ notify: - restart vrs - restart node + +- include: iptables.yml |