Open JSilent opened 4 years ago
Indeed, my solution is to turn off calico's natoutgoing :smile:
so it not possible to have a mixed setup ?
@kifeo Maybe you can modify the following parameters for a mixed setup.
Configuration parameter | Environment variable | Description | Schema |
---|---|---|---|
ChainInsertMode | FELIX_CHAININSERTMODE | Controls whether Felix hooks the kernel’s top-level iptables chains by inserting a rule at the top of the chain or by appending a rule at the bottom. Insert is the safe default since it prevents Calico’s rules from being bypassed. If you switch to Append mode, be sure that the other rules in the chains signal acceptance by falling through to the Calico rules, otherwise the Calico policy will be bypassed. [Default: Insert] | Insert, Append |
Hi, the messages to the specified destination can be routed to the gateway. However the SNAT doesn't take effect, since Calico ensures it's always the first rule in POSTROUTING, even though I manually move STATIC-EGRESS-NAT-CHAIN before MASQUERADE.
By the way, the ipipEnabled is true in calico's configuration.