Skip to content

Commit a2d51ee

Browse files
author
Rene Diepstraten
committed
Add ipv6 addresses to ipset after creating
1 parent b8303bc commit a2d51ee

File tree

1 file changed

+4
-2
lines changed

1 file changed

+4
-2
lines changed

scripts/vm/network/security_group.py

Lines changed: 4 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -515,11 +515,10 @@ def default_network_rules(vm_name, vm_id, vm_ip, vm_ip6, vm_mac, vif, brname, se
515515
secIpSet = "0";
516516

517517
if secIpSet == "1":
518-
logging.debug("Adding ipset for secondary ips")
518+
logging.debug("Adding ipset for secondary ipv4 addresses")
519519
ip4s, ip6s = split_ips_by_family(ips)
520520

521521
add_to_ipset(vmipsetName, ip4s, action)
522-
add_to_ipset(vmipsetName6, ip6s, action)
523522

524523
if write_secip_log_for_vm(vm_name, sec_ips, vm_id) == False:
525524
logging.debug("Failed to log default network rules, ignoring")
@@ -565,6 +564,9 @@ def default_network_rules(vm_name, vm_id, vm_ip, vm_ip6, vm_mac, vif, brname, se
565564
pass
566565

567566
add_to_ipset(vmipsetName6, vm_ip6_addr, action)
567+
if secIpSet == "1":
568+
logging.debug("Adding ipset for secondary ipv6 addresses")
569+
add_to_ipset(vmipsetName6, ip6s, action)
568570

569571
try:
570572
execute('ip6tables -A ' + brfw + '-OUT' + ' -m physdev --physdev-is-bridged --physdev-out ' + vif + ' -j ' + vmchain_default)

0 commit comments

Comments
 (0)