[FWaaS v2] L3 agent restart breaks firewall iptables configuration for router ports
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
neutron |
Fix Released
|
Undecided
|
Elena Ezhova |
Bug Description
*Seen on:* Pike and master devstack with FWaaS v2
*Scenario:*
1. Create deny_icmp rule, a policy, a fw group, security group with all allowed.
2. Create 1 router, 2 subnets, fw group assigned to router ports.
3. Boot a VM in each subnet
4. Check that iptables rules are applied and it is impossible to ping VMs by floating IP or from qrouter namespace
5. Restart L3 agent
*Expected result:*
After the restart iptables rules are reapplied in the same way and the traffic is still blocked.
*Actual result:*
In case when a firewall group contains several ports iptables rules get re-written for each port and in the result only the chains for the last port in a loop remain.
Example scenario: http://
Changed in neutron: | |
assignee: | nobody → Elena Ezhova (eezhova) |
tags: | added: fwaas |
Changed in neutron: | |
status: | New → In Progress |
Fix is in progress: https:/ /review. openstack. org/495657