mirror of
https://github.com/moby/moby.git
synced 2026-08-08 00:52:17 +00:00
Check for advertise IP when deriving ipsec nodes
- We need to compare the node notification IP with the advertise address otherwise when the advertise address is different from the local address (this is for the public address outside of the host that maps 1-to-1 to the local private address) the local IP will be acocunted as an ipsec host and extra states will be programmed for it. Signed-off-by: Alessandro Boch <aboch@docker.com>
This commit is contained in:
@@ -95,7 +95,7 @@ func (d *driver) checkEncryption(nid string, rIP net.IP, vxlanID uint32, isLocal
|
||||
switch {
|
||||
case isLocal:
|
||||
if err := d.peerDbNetworkWalk(nid, func(pKey *peerKey, pEntry *peerEntry) bool {
|
||||
if !lIP.Equal(pEntry.vtep) {
|
||||
if !aIP.Equal(pEntry.vtep) {
|
||||
nodes[pEntry.vtep.String()] = pEntry.vtep
|
||||
}
|
||||
return false
|
||||
|
||||
Reference in New Issue
Block a user