Merge pull request #2460 from moby/revert-2450-iptables-policy
Revert "Always configure iptables forward policy"
This commit is contained in:
commit
e49ee8266d
1 changed files with 5 additions and 5 deletions
|
@ -34,11 +34,11 @@ func setupIPForwarding(enableIPTables bool) error {
|
|||
if err := configureIPForwarding(true); err != nil {
|
||||
return fmt.Errorf("Enabling IP forwarding failed: %v", err)
|
||||
}
|
||||
}
|
||||
|
||||
// Set the default policy on forward chain to drop only if the
|
||||
// daemon option iptables is not set to false.
|
||||
if enableIPTables {
|
||||
// When enabling ip_forward set the default policy on forward chain to
|
||||
// drop only if the daemon option iptables is not set to false.
|
||||
if !enableIPTables {
|
||||
return nil
|
||||
}
|
||||
if err := iptables.SetDefaultPolicy(iptables.Filter, "FORWARD", iptables.Drop); err != nil {
|
||||
if err := configureIPForwarding(false); err != nil {
|
||||
logrus.Errorf("Disabling IP forwarding failed, %v", err)
|
||||
|
|
Loading…
Add table
Reference in a new issue