OVS firewall should drop iptables rules if it detects a bridge
Bug #1721895 reported by
Kevin Benton
This bug affects 1 person
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
neutron |
Fix Released
|
Undecided
|
Jakub Libosvar |
Bug Description
When a user switches from the hybrid firewall to the OVS native firewall the iptables rules will be left behind on the filtering bridge. Since removing the bridge would require difficult coordination with Nova and it would be disruptive to traffic, that is currently not a viable approach.
To make the transition easier, the OVS firewall should at least detect when one of its VM ports contains a filtering bridge and drop all of the iptables rules on it so we don't have stale rules interfering with the traffic.
Changed in neutron: | |
assignee: | nobody → Jakub Libosvar (libosvar) |
To post a comment you must log in.
Fix proposed to branch: master /review. openstack. org/510628
Review: https:/