From f77a4809d305e4bf8b343fdd67b561256860d850 Mon Sep 17 00:00:00 2001 From: Stephen Smoogen Date: Wed, 18 Feb 2015 20:59:14 +0000 Subject: [PATCH] oh silly me.. {{}} matter --- .../iptables/iptables.serverbeach06.fedoraproject.org | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/roles/base/templates/iptables/iptables.serverbeach06.fedoraproject.org b/roles/base/templates/iptables/iptables.serverbeach06.fedoraproject.org index 170b90d358..c7542a13e9 100644 --- a/roles/base/templates/iptables/iptables.serverbeach06.fedoraproject.org +++ b/roles/base/templates/iptables/iptables.serverbeach06.fedoraproject.org @@ -5,8 +5,8 @@ :OUTPUT ACCEPT [3:224] :POSTROUTING ACCEPT [428:23328] # dnat and snat everything to the internal virt host -#-A PREROUTING -d {{guest_ip}}/32 -j DNAT --to-destination 192.168.122.2 -#-A POSTROUTING -s 192.168.122.2/32 -j SNAT --to-source {{guest_ip}} +#-A PREROUTING -d guest_ip/32 -j DNAT --to-destination 192.168.122.2 +#-A POSTROUTING -s 192.168.122.2/32 -j SNAT --to-source guest_ip -A POSTROUTING -s 192.168.122.0/24 ! -d 192.168.122.0/24 -p tcp -j MASQUERADE --to-ports 1024-65535 -A POSTROUTING -s 192.168.122.0/24 ! -d 192.168.122.0/24 -p udp -j MASQUERADE --to-ports 1024-65535 -A POSTROUTING -s 192.168.122.0/24 ! -d 192.168.122.0/24 -j MASQUERADE @@ -77,7 +77,7 @@ COMMIT -A INPUT -j REJECT --reject-with icmp-host-prohibited # source and dest of the guest ip we forward into the guest -#-A FORWARD -d {{guest_ip}}/32 -j ACCEPT -#-A FORWARD -s {{guest_ip}}/32 -j ACCEPT +#-A FORWARD -d guest_ip/32 -j ACCEPT +#-A FORWARD -s guest_ip/32 -j ACCEPT -A FORWARD -j REJECT --reject-with icmp-host-prohibited COMMIT