apache / apache/cloudstack

Static NAT and Port forwarding do not work if the VM NIC is not default

Open
#8,366 0 comments 0 reactions 1 assignee Claimed by @weizhouapache View on GitHub
component:advanced-networking component:networking
Dominant language
Java
Stars
3.1k
Forks
1.4k
Avg merge
6d 19h
Merged PRs (30d)
32

Description

as title

Steps to reproduce the issue
- create a VM with two NICs (the 2nd NIC is on an isolated network)
- acquire public IPs for the isolated network
- Enable Static NAT to the VM, add firewall rules. The IP is unreachable
- Create port forwarding rule to the vm, add firewall rules. The IP is unreachable as well

Workaround
- Use load balancing rule instead of static NAT and port forwarding.
- configure ip rule/tables inside the VM

Idea: when enable static nat or create firewall rules, specify if the public IP is transparent or not.
- If transparent, the source IP of packets which are forwarded from cloudstack VR to the VM, will not be changed
- If not transparent, the source IP of packets which are forwarded from cloudstack VR to the VM, will be the VR IP.

##### ISSUE TYPE

* Bug Report
* Improvement Request

##### COMPONENT NAME

~~~
VR
~~~

##### CLOUDSTACK VERSION

~~~
4.18/4.19
~~~

##### CONFIGURATION

##### OS / ENVIRONMENT

##### SUMMARY

##### STEPS TO REPRODUCE

~~~

~~~

##### EXPECTED RESULTS

~~~

~~~

##### ACTUAL RESULTS

~~~

~~~

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.