You are viewing an old version of this page. View the current version.

Compare with Current View Page History

« Previous Version 10 Next »

Introduction:

Currently on the private gateway there is no way to configure the Source NAT.

With this feature we can enable the source NAT service  on the VPC private gateway.

Use Case:

Users might want to deploy multiple VPCs (with the same super CIDR) and/or guest Tier CIDR. So, there could be a possibility that multiple guest VM (from different VPCs) having the same IP need to reach a enterprise DC via the Private GW.

In these cases, NAT service is needed on the private GW.

Bug Reference: CLOUDSTACK-1828

Design:

After enabling source NAT on private gateway interface guest, VMs in VPC reaches to enterprise network via private gateway ip address by NATing.

Source NAT private gateway can be disabled. On disable the the guest VM traffic will not be NATed.

On deletion of private gateway NAT rules specific to private gateway get deleted.

APIs

API Name

Parameters

Response

enableSourceNatOnPrivateGw

privategatewayid

True/False

disableSourceNatOnPrivateGw

privategatewayid

True/False

Existing API changes:

API Name

New parameter

Value

createPrivateGateway

sourcenat (optional)

true/false

DB Changes:

Table:

vpc_gateway

new column:   type           default value

Source_nat     boolean       0

Back end script changes:

When user enables source NAT on the private gateway the below iptables rules get configured on the VR.

Example SNAT rule on VR for private gateway.

 - eth3 Private gateway interface

- 10.147.52.108 - private gateway ip address.

iptables -t NAT -A POSTROUTING -o eth3  -j SNAT --to-source 10.147.52.108

UI Changes:

The current private gateway configuration page needs a check box 'Set Source NAT' to enable/disable source NAT on private gateway

Upgrade Changes:

No upgrade changes are needed.

  • No labels