@@ -382,7 +382,7 @@ def fw_router(self):
382382 "-A FIREWALL_%s " % self .address ['public_ip' ] +
383383 "-m state --state RELATED,ESTABLISHED -j ACCEPT" ])
384384 self .fw .append (["mangle" , "" ,
385- "-A FIREWALL_%s DROP" % self .address ['public_ip' ]])
385+ "-A FIREWALL_%s -j DROP" % self .address ['public_ip' ]])
386386 self .fw .append (["mangle" , "" ,
387387 "-A VPN_%s -m state --state RELATED,ESTABLISHED -j ACCEPT" % self .address ['public_ip' ]])
388388 self .fw .append (["mangle" , "" ,
@@ -392,8 +392,6 @@ def fw_router(self):
392392 self .fw .append (["mangle" , "" ,
393393 "-A PREROUTING -i %s -m state --state NEW " % self .dev +
394394 "-j CONNMARK --set-xmark %s/0xffffffff" % self .dnum ])
395- self .fw .append (
396- ["mangle" , "" , "-A FIREWALL_%s -j DROP" % self .address ['public_ip' ]])
397395 self .fw .append (["filter" , "" ,
398396 "-A FORWARD -i %s -o eth0 -m state --state RELATED,ESTABLISHED -j ACCEPT" % self .dev ])
399397 self .fw .append (["filter" , "" ,
@@ -484,10 +482,6 @@ def fw_vpcrouter(self):
484482 (guestNetworkCidr , self .dev , self .address ['public_ip' ])])
485483
486484 if self .get_type () in ["public" ]:
487- self .fw .append (["" , "front" ,
488- "-A FORWARD -o %s -d %s -j ACL_INBOUND_%s" % (
489- self .dev , self .address ['network' ], self .dev )
490- ])
491485 self .fw .append (
492486 ["mangle" , "" , "-A FORWARD -j VPN_STATS_%s" % self .dev ])
493487 self .fw .append (
0 commit comments