summaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorMatus Fabian <matfabia@cisco.com>2018-08-27 07:21:38 -0700
committerDamjan Marion <dmarion@me.com>2018-09-02 11:37:15 +0000
commite0fe0fd0902beb393566f6a7ad7d4e5b285fcda9 (patch)
tree1950583983752d5ddae401fb21d32f99ae74a2c5
parent86f6d3e291197e136339a21f5d505fb25e996796 (diff)
NAT44: fix nat44_ed_not_translate_output_feature for multiple VRF (VPP-1404)
Change-Id: I44acc5aeff59dc25d18369e29618bbe39d30a1b3 Signed-off-by: Matus Fabian <matfabia@cisco.com> (cherry picked from commit f96d0a105d357a6b7bb4252b271fbcbab45bc9bd)
-rwxr-xr-xsrc/plugins/nat/in2out.c24
1 files changed, 15 insertions, 9 deletions
diff --git a/src/plugins/nat/in2out.c b/src/plugins/nat/in2out.c
index be1ddb3db7e..c3ef6ce1996 100755
--- a/src/plugins/nat/in2out.c
+++ b/src/plugins/nat/in2out.c
@@ -2603,22 +2603,24 @@ nat_not_translate_output_feature_fwd (snat_main_t * sm, ip4_header_t * ip,
static_always_inline int
nat44_ed_not_translate_output_feature (snat_main_t * sm, ip4_header_t * ip,
u8 proto, u16 src_port, u16 dst_port,
- u32 thread_index, u32 sw_if_index)
+ u32 thread_index, u32 rx_sw_if_index,
+ u32 tx_sw_if_index)
{
clib_bihash_kv_16_8_t kv, value;
snat_main_per_thread_data_t *tsm = &sm->per_thread_data[thread_index];
snat_interface_t *i;
snat_session_t *s;
- u32 fib_index = ip4_fib_table_get_index_for_sw_if_index (sw_if_index);
+ u32 rx_fib_index = ip4_fib_table_get_index_for_sw_if_index (rx_sw_if_index);
+ u32 tx_fib_index = ip4_fib_table_get_index_for_sw_if_index (tx_sw_if_index);
/* src NAT check */
- make_ed_kv (&kv, &ip->src_address, &ip->dst_address, proto, fib_index,
+ make_ed_kv (&kv, &ip->src_address, &ip->dst_address, proto, tx_fib_index,
src_port, dst_port);
if (!clib_bihash_search_16_8 (&tsm->out2in_ed, &kv, &value))
return 1;
/* dst NAT check */
- make_ed_kv (&kv, &ip->dst_address, &ip->src_address, proto, fib_index,
+ make_ed_kv (&kv, &ip->dst_address, &ip->src_address, proto, rx_fib_index,
dst_port, src_port);
if (!clib_bihash_search_16_8 (&tsm->in2out_ed, &kv, &value))
{
@@ -2629,7 +2631,7 @@ nat44_ed_not_translate_output_feature (snat_main_t * sm, ip4_header_t * ip,
/* hairpinning */
pool_foreach (i, sm->output_feature_interfaces,
({
- if ((nat_interface_is_inside(i)) && (sw_if_index == i->sw_if_index))
+ if ((nat_interface_is_inside(i)) && (rx_sw_if_index == i->sw_if_index))
return 0;
}));
return 1;
@@ -2677,7 +2679,8 @@ icmp_match_in2out_ed(snat_main_t *sm, vlib_node_runtime_t *node,
if (vnet_buffer(b)->sw_if_index[VLIB_TX] != ~0)
{
if (PREDICT_FALSE(nat44_ed_not_translate_output_feature(sm, ip,
- key.proto, key.l_port, key.r_port, thread_index, sw_if_index)))
+ key.proto, key.l_port, key.r_port, thread_index, sw_if_index,
+ vnet_buffer(b)->sw_if_index[VLIB_TX])))
{
dont_translate = 1;
goto out;
@@ -3125,7 +3128,8 @@ nat44_ed_in2out_node_fn_inline (vlib_main_t * vm,
{
if (PREDICT_FALSE(nat44_ed_not_translate_output_feature(
sm, ip0, ip0->protocol, udp0->src_port,
- udp0->dst_port, thread_index, sw_if_index0)))
+ udp0->dst_port, thread_index, sw_if_index0,
+ vnet_buffer(b0)->sw_if_index[VLIB_TX])))
goto trace00;
}
else
@@ -3310,7 +3314,8 @@ nat44_ed_in2out_node_fn_inline (vlib_main_t * vm,
{
if (PREDICT_FALSE(nat44_ed_not_translate_output_feature(
sm, ip1, ip1->protocol, udp1->src_port,
- udp1->dst_port, thread_index, sw_if_index1)))
+ udp1->dst_port, thread_index, sw_if_index1,
+ vnet_buffer(b1)->sw_if_index[VLIB_TX])))
goto trace01;
}
else
@@ -3524,7 +3529,8 @@ nat44_ed_in2out_node_fn_inline (vlib_main_t * vm,
{
if (PREDICT_FALSE(nat44_ed_not_translate_output_feature(
sm, ip0, ip0->protocol, udp0->src_port,
- udp0->dst_port, thread_index, sw_if_index0)))
+ udp0->dst_port, thread_index, sw_if_index0,
+ vnet_buffer(b0)->sw_if_index[VLIB_TX])))
goto trace0;
}
else