From 05dc92c02c40344ee66f78b032b66116d3b67c18 Mon Sep 17 00:00:00 2001 From: anthony Date: Thu, 26 Jul 2012 14:06:58 -0700 Subject: [PATCH] VPC : remove all rules for a plugged nic device --- .../debian/config/opt/cloud/bin/cloud-nic.sh | 34 +++++++++++++++---- 1 file changed, 28 insertions(+), 6 deletions(-) diff --git a/patches/systemvm/debian/config/opt/cloud/bin/cloud-nic.sh b/patches/systemvm/debian/config/opt/cloud/bin/cloud-nic.sh index 3f80a4ca9b8..24596f794e2 100755 --- a/patches/systemvm/debian/config/opt/cloud/bin/cloud-nic.sh +++ b/patches/systemvm/debian/config/opt/cloud/bin/cloud-nic.sh @@ -2,9 +2,6 @@ plug_nic() { - sudo iptables -t mangle -A PREROUTING -i $dev -m state --state NEW -j MARK --set-mark $tableNo 2>/dev/null - sudo iptables -t mangle -A PREROUTING -i $dev -m state --state NEW -j CONNMARK --save-mark 2>/dev/null - sudo echo "$tableNo $tableName" >> /etc/iproute2/rt_tables 2>/dev/null sudo ip rule add fwmark $tableNo table $tableName 2>/dev/null sudo ip route flush table $tableName @@ -13,18 +10,43 @@ plug_nic() { unplug_nic() { - sudo iptables -t mangle -D PREROUTING -i $dev -m state --state NEW -j MARK --set-mark $tableNo 2>/dev/null - sudo iptables -t mangle -D PREROUTING -i $dev -m state --state NEW -j CONNMARK --save-mark 2>/dev/null + sudo iptables -t mangle -D PREROUTING -i $dev -m state --state NEW -j CONNMARK --set-mark $tableNo 2>/dev/null sudo ip rule del fwmark $tableNo 2>/dev/null sudo ip route flush table $tableName sudo sed -i /"$tableNo $tableName"/d /etc/iproute2/rt_tables 2>/dev/null sudo ip route flush cache + # remove network usage rules + sudo iptables -t mangle -F NETWORK_STATS_$dev 2>/dev/null + iptables-save -t mangle | grep NETWORK_STATS_$dev | grep "\-A" | while read rule + do + rule=$(echo $rule | sed 's/\-A/\-D/') + sudo iptables -t mangle $rule + done + sudo iptables -t mangle -X NETWORK_STATS_$dev 2>/dev/null + # remove rules on this dev + iptables-save -t mangle | grep $dev | grep "\-A" | while read rule + do + rule=$(echo $rule | sed 's/\-A/\-D/') + sudo iptables -t mangle $rule + done + iptables-save -t nat | grep $dev | grep "\-A" | while read rule + do + rule=$(echo $rule | sed 's/\-A/\-D/') + sudo iptables -t nat $rule + done + iptables-save | grep $dev | grep "\-A" | while read rule + do + rule=$(echo $rule | sed 's/\-A/\-D/') + sudo iptables $rule + done + # remove apache config for this eth + rm -f /etc/apache2/conf.d/vhost$dev.conf } action=$1 dev=$2 -tableNo=$(echo $dev | awk -F'eth' '{print $2}') +tableNo=${dev:3} tableName="Table_$dev" if [ $action == 'add' ]