commit f32b4d5b78c00f323b240126f8f9487408476f1e
Author: Nagendra E S <email address hidden>
Date: Fri Aug 3 18:46:37 2018 +0530
If I install a software simple gateway (vgw) on a compute
node and create in one virtual network 2 virtual machines,
each of them with default security group and attach a
floating IP to each of those 2 VMs I can ping by default
the VM which runs on the compute node where the vgw was
installed but cannot ping the VM which is runing on the
second compute node.
The normal behavior should be that by default (as long
as in the security default rule the ingress rule uses
the default security group as "Address" instead of
0.0.0.0/0 the ping on floating IPs should not work.
Code needs to be added to treat the special case of the
vgw interface - which is an interface of type INET and
sub-type SIMPLE_GATEWAY. After these changes the security
group rules will be respected for floating IPs on both
compute nodes.
Reviewed: https:/ /review. opencontrail. org/45521 github. com/Juniper/ contrail- controller/ commit/ f32b4d5b78c00f3 23b240126f8f948 7408476f1e
Committed: http://
Submitter: Zuul (<email address hidden>)
Branch: R4.1
commit f32b4d5b78c00f3 23b240126f8f948 7408476f1e
Author: Nagendra E S <email address hidden>
Date: Fri Aug 3 18:46:37 2018 +0530
If I install a software simple gateway (vgw) on a compute
node and create in one virtual network 2 virtual machines,
each of them with default security group and attach a
floating IP to each of those 2 VMs I can ping by default
the VM which runs on the compute node where the vgw was
installed but cannot ping the VM which is runing on the
second compute node.
The normal behavior should be that by default (as long
as in the security default rule the ingress rule uses
the default security group as "Address" instead of
0.0.0.0/0 the ping on floating IPs should not work.
Code needs to be added to treat the special case of the
vgw interface - which is an interface of type INET and
sub-type SIMPLE_GATEWAY. After these changes the security
group rules will be respected for floating IPs on both
compute nodes.
Cherry-Pick from review: /review. opencontrail. org/#/c/ 38460/
https:/
Change-Id: I417897106f2bad 039f74826200bb8 c877c89b1a7
Partial-Bug: #1736972