Created
December 17, 2015 13:22
-
-
Save anamorph/6aa305fd6850272c1bc6 to your computer and use it in GitHub Desktop.
Standard NAT enablement for AWS EC2 Instances
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
#!/bin/bash | |
# Configure the instance to run as a Port Address Translator (PAT) to provide | |
# Internet connectivity to private instances. | |
function log { logger -t "vpc" -- $1; } | |
function die { | |
[ -n "$1" ] && log "$1" | |
log "Configuration of PAT failed!" | |
exit 1 | |
} | |
# Sanitize PATH | |
PATH="/usr/sbin:/sbin:/usr/bin:/bin" | |
log "Determining the MAC address on eth0..." | |
ETH0_MAC=$(cat /sys/class/net/eth0/address) || | |
die "Unable to determine MAC address on eth0." | |
log "Found MAC ${ETH0_MAC} for eth0." | |
VPC_CIDR_URI="http://169.254.169.254/latest/meta-data/network/interfaces/macs/${ETH0_MAC}/vpc-ipv4-cidr-block" | |
log "Metadata location for vpc ipv4 range: ${VPC_CIDR_URI}" | |
VPC_CIDR_RANGE=$(curl --retry 3 --silent --fail ${VPC_CIDR_URI}) | |
if [ $? -ne 0 ]; then | |
log "Unable to retrive VPC CIDR range from meta-data, using 0.0.0.0/0 instead. PAT may be insecure!" | |
VPC_CIDR_RANGE="0.0.0.0/0" | |
else | |
log "Retrieved VPC CIDR range ${VPC_CIDR_RANGE} from meta-data." | |
fi | |
log "Enabling PAT..." | |
sysctl -q -w net.ipv4.ip_forward=1 net.ipv4.conf.eth0.send_redirects=0 && ( | |
iptables -t nat -C POSTROUTING -o eth0 -s ${VPC_CIDR_RANGE} -j MASQUERADE 2> /dev/null || | |
iptables -t nat -A POSTROUTING -o eth0 -s ${VPC_CIDR_RANGE} -j MASQUERADE ) || | |
die | |
sysctl net.ipv4.ip_forward net.ipv4.conf.eth0.send_redirects | log | |
iptables -n -t nat -L POSTROUTING | log | |
log "Configuration of PAT complete." | |
exit 0 |
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
running this is then a breeze:
bash <(curl -s hhttps://gist.github.com/anamorph/6aa305fd6850272c1bc6/raw/c9dee8a388bd667951fc29606d71f353e9486f6e/aws_enable_NAT.sh)