diff --git a/src/vnm_mad/remotes/lib/security_groups_iptables.rb b/src/vnm_mad/remotes/lib/security_groups_iptables.rb index 0798802c7a..1d5bfc9d42 100644 --- a/src/vnm_mad/remotes/lib/security_groups_iptables.rb +++ b/src/vnm_mad/remotes/lib/security_groups_iptables.rb @@ -388,6 +388,10 @@ module SGIPTables commands.add :ip6tables, "-A #{chain_in} -p icmpv6 --icmpv6-type 135 "\ "-j ACCEPT" + ## Allow neighbor solicitations replies to reach the host + commands.add :ip6tables, "-A #{chain_in} -p icmpv6 --icmpv6-type 136 "\ + "-j ACCEPT" + ## Allow routers to send Redirect messages commands.add :ip6tables, "-A #{chain_in} -p icmpv6 --icmpv6-type 137 "\ "-j ACCEPT" @@ -396,6 +400,10 @@ module SGIPTables commands.add :ip6tables, "-A #{chain_out} -p icmpv6 --icmpv6-type 133 "\ "-j ACCEPT" + ## Allow the host to send neighbor solicitation requests + commands.add :ip6tables, "-A #{chain_out} -p icmpv6 --icmpv6-type 135 "\ + "-j ACCEPT" + ## Allow the host to send neighbor solicitation replies commands.add :ip6tables, "-A #{chain_out} -p icmpv6 --icmpv6-type 136 "\ "-j ACCEPT"