base / iptables / staging: drop nat section in iptables

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
This commit is contained in:
Kevin Fenzi 2020-07-18 16:25:45 -07:00
parent 3c340cf69b
commit e1d77f58d6

View file

@ -1,18 +1,4 @@
# {{ ansible_managed }}
*nat
:PREROUTING ACCEPT []
:POSTROUTING ACCEPT []
:OUTPUT ACCEPT []
# Redirect staging attempts to talk to the external proxy to an internal ip.
# This is primarily for openid in staging which needs to get around proxy
# redirects.
{% if 'cloud.' not in inventory_hostname and 'aws.fedoraproject.org' not in inventory_hostname %}
-A OUTPUT -d 209.132.181.5 -j DNAT --to-destination 10.5.128.177
{% endif %}
COMMIT
*filter
:INPUT ACCEPT [0:0]
:FORWARD ACCEPT [0:0]