oh silly me.. {{}} matter

This commit is contained in:
Stephen Smoogen 2015-02-18 20:59:14 +00:00
parent 7f0ba20638
commit f77a4809d3

View file

@ -5,8 +5,8 @@
:OUTPUT ACCEPT [3:224]
:POSTROUTING ACCEPT [428:23328]
# dnat and snat everything to the internal virt host
#-A PREROUTING -d {{guest_ip}}/32 -j DNAT --to-destination 192.168.122.2
#-A POSTROUTING -s 192.168.122.2/32 -j SNAT --to-source {{guest_ip}}
#-A PREROUTING -d guest_ip/32 -j DNAT --to-destination 192.168.122.2
#-A POSTROUTING -s 192.168.122.2/32 -j SNAT --to-source guest_ip
-A POSTROUTING -s 192.168.122.0/24 ! -d 192.168.122.0/24 -p tcp -j MASQUERADE --to-ports 1024-65535
-A POSTROUTING -s 192.168.122.0/24 ! -d 192.168.122.0/24 -p udp -j MASQUERADE --to-ports 1024-65535
-A POSTROUTING -s 192.168.122.0/24 ! -d 192.168.122.0/24 -j MASQUERADE
@ -77,7 +77,7 @@ COMMIT
-A INPUT -j REJECT --reject-with icmp-host-prohibited
# source and dest of the guest ip we forward into the guest
#-A FORWARD -d {{guest_ip}}/32 -j ACCEPT
#-A FORWARD -s {{guest_ip}}/32 -j ACCEPT
#-A FORWARD -d guest_ip/32 -j ACCEPT
#-A FORWARD -s guest_ip/32 -j ACCEPT
-A FORWARD -j REJECT --reject-with icmp-host-prohibited
COMMIT