as title
Steps to reproduce the issue
- create a VM with two NICs (the 2nd NIC is on an isolated network)
- acquire public IPs for the isolated network
- Enable Static NAT to the VM, add firewall rules. The IP is unreachable
- Create port forwarding rule to the vm, add firewall rules. The IP is unreachable as well
Workaround
- Use load balancing rule instead of static NAT and port forwarding.
- configure ip rule/tables inside the VM
Idea: when enable static nat or create firewall rules, specify if the public IP is transparent or not.
- If transparent, the source IP of packets which are forwarded from cloudstack VR to the VM, will not be changed
- If not transparent, the source IP of packets which are forwarded from cloudstack VR to the VM, will be the VR IP.
ISSUE TYPE
- Bug Report
- Improvement Request
COMPONENT NAME
CLOUDSTACK VERSION
CONFIGURATION
OS / ENVIRONMENT
SUMMARY
STEPS TO REPRODUCE
EXPECTED RESULTS
ACTUAL RESULTS
as title
Steps to reproduce the issue
Workaround
Idea: when enable static nat or create firewall rules, specify if the public IP is transparent or not.
ISSUE TYPE
COMPONENT NAME
CLOUDSTACK VERSION
CONFIGURATION
OS / ENVIRONMENT
SUMMARY
STEPS TO REPRODUCE
EXPECTED RESULTS
ACTUAL RESULTS