Commits
Dmitry Mishin authored and Alexey Dobriyan committed 9acd0814e84
NETFILTER: fix SNAT, DNAT in CT if ip_conntrack_disable_ve0 is uset If ip_conntrack_disable_ve0 option is set, than it is impossible to use nat targets (DNAT, SNAT) inside Containers even if nat table is permitted for them and respective modules are loaded. This patch fixes above issue. Fixed and tested by Konstantin Khlebnikov <khlebnikov@openvz.org>.