From 73fcc70c718155dd91c592e09946ee4e15630e85 Mon Sep 17 00:00:00 2001 From: John Anderson Date: Mon, 28 Dec 2015 15:10:29 +0800 Subject: remove the forward reject rule of iptables * Functest's testcase running in the docker, and need access openstack's network. But the libvirt nat networks will create forward iptable rules, which reject the connection from the docker. Change-Id: Id0122879aa133ccb81a0bba1ea8d06ac36a65290 Author: carey.xu Signed-off-by: carey.xu --- deploy/network.sh | 6 ++++++ 1 file changed, 6 insertions(+) (limited to 'deploy/network.sh') diff --git a/deploy/network.sh b/deploy/network.sh index 836af0f9..c6d0df5d 100755 --- a/deploy/network.sh +++ b/deploy/network.sh @@ -1,4 +1,9 @@ +function clear_forward_rejct_rules() +{ + while sudo iptables -nL FORWARD --line-number|grep -E 'REJECT +all +-- +0.0.0.0/0 +0.0.0.0/0 +reject-with icmp-port-unreachable'|head -1|awk '{print $1}'|xargs sudo iptables -D FORWARD; do :; done +} + function setup_bridge_net() { net_name=$1 @@ -89,4 +94,5 @@ function create_nets() { # create external network setup_bridge_external + clear_forward_rejct_rules } -- cgit 1.2.3-korg