mirror of
https://github.com/apache/cloudstack.git
synced 2025-12-17 11:04:00 +01:00
VPC : remove all rules for a plugged nic device
This commit is contained in:
parent
599dcb49d5
commit
05dc92c02c
@ -2,9 +2,6 @@
|
|||||||
|
|
||||||
|
|
||||||
plug_nic() {
|
plug_nic() {
|
||||||
sudo iptables -t mangle -A PREROUTING -i $dev -m state --state NEW -j MARK --set-mark $tableNo 2>/dev/null
|
|
||||||
sudo iptables -t mangle -A PREROUTING -i $dev -m state --state NEW -j CONNMARK --save-mark 2>/dev/null
|
|
||||||
|
|
||||||
sudo echo "$tableNo $tableName" >> /etc/iproute2/rt_tables 2>/dev/null
|
sudo echo "$tableNo $tableName" >> /etc/iproute2/rt_tables 2>/dev/null
|
||||||
sudo ip rule add fwmark $tableNo table $tableName 2>/dev/null
|
sudo ip rule add fwmark $tableNo table $tableName 2>/dev/null
|
||||||
sudo ip route flush table $tableName
|
sudo ip route flush table $tableName
|
||||||
@ -13,18 +10,43 @@ plug_nic() {
|
|||||||
|
|
||||||
|
|
||||||
unplug_nic() {
|
unplug_nic() {
|
||||||
sudo iptables -t mangle -D PREROUTING -i $dev -m state --state NEW -j MARK --set-mark $tableNo 2>/dev/null
|
sudo iptables -t mangle -D PREROUTING -i $dev -m state --state NEW -j CONNMARK --set-mark $tableNo 2>/dev/null
|
||||||
sudo iptables -t mangle -D PREROUTING -i $dev -m state --state NEW -j CONNMARK --save-mark 2>/dev/null
|
|
||||||
|
|
||||||
sudo ip rule del fwmark $tableNo 2>/dev/null
|
sudo ip rule del fwmark $tableNo 2>/dev/null
|
||||||
sudo ip route flush table $tableName
|
sudo ip route flush table $tableName
|
||||||
sudo sed -i /"$tableNo $tableName"/d /etc/iproute2/rt_tables 2>/dev/null
|
sudo sed -i /"$tableNo $tableName"/d /etc/iproute2/rt_tables 2>/dev/null
|
||||||
sudo ip route flush cache
|
sudo ip route flush cache
|
||||||
|
# remove network usage rules
|
||||||
|
sudo iptables -t mangle -F NETWORK_STATS_$dev 2>/dev/null
|
||||||
|
iptables-save -t mangle | grep NETWORK_STATS_$dev | grep "\-A" | while read rule
|
||||||
|
do
|
||||||
|
rule=$(echo $rule | sed 's/\-A/\-D/')
|
||||||
|
sudo iptables -t mangle $rule
|
||||||
|
done
|
||||||
|
sudo iptables -t mangle -X NETWORK_STATS_$dev 2>/dev/null
|
||||||
|
# remove rules on this dev
|
||||||
|
iptables-save -t mangle | grep $dev | grep "\-A" | while read rule
|
||||||
|
do
|
||||||
|
rule=$(echo $rule | sed 's/\-A/\-D/')
|
||||||
|
sudo iptables -t mangle $rule
|
||||||
|
done
|
||||||
|
iptables-save -t nat | grep $dev | grep "\-A" | while read rule
|
||||||
|
do
|
||||||
|
rule=$(echo $rule | sed 's/\-A/\-D/')
|
||||||
|
sudo iptables -t nat $rule
|
||||||
|
done
|
||||||
|
iptables-save | grep $dev | grep "\-A" | while read rule
|
||||||
|
do
|
||||||
|
rule=$(echo $rule | sed 's/\-A/\-D/')
|
||||||
|
sudo iptables $rule
|
||||||
|
done
|
||||||
|
# remove apache config for this eth
|
||||||
|
rm -f /etc/apache2/conf.d/vhost$dev.conf
|
||||||
}
|
}
|
||||||
|
|
||||||
action=$1
|
action=$1
|
||||||
dev=$2
|
dev=$2
|
||||||
tableNo=$(echo $dev | awk -F'eth' '{print $2}')
|
tableNo=${dev:3}
|
||||||
tableName="Table_$dev"
|
tableName="Table_$dev"
|
||||||
|
|
||||||
if [ $action == 'add' ]
|
if [ $action == 'add' ]
|
||||||
|
|||||||
Loading…
x
Reference in New Issue
Block a user