瀏覽代碼

vm/iptables: do not MASQUERADE packets on lo (#416)

Masquerading packets on lo actually drops them when there is no default route.
This causes problems with commutication between ntpd processes (ntp main
daemon and resolver). And perhaps many more...
Marek Marczykowski 12 年之前
父節點
當前提交
b5fff2564f
共有 1 個文件被更改,包括 1 次插入0 次删除
  1. 1 0
      network/iptables

+ 1 - 0
network/iptables

@@ -6,6 +6,7 @@
 :PR-QBS - [0:0]
 -A PREROUTING -j PR-QBS
 -A POSTROUTING -o vif+ -j ACCEPT
+-A POSTROUTING -o lo -j ACCEPT
 -A POSTROUTING -j MASQUERADE
 COMMIT
 # Completed on Mon Sep  6 08:57:46 2010