Comment 6 for bug 1223472

Revision history for this message
Akihiro Motoki (amotoki) wrote :

Sridar, Sumit, thanks for the clarification.
It looks reasonable that a router and a firewall can be created in any order.

It raises new questions to me. Let me clarify the expected behavior of FWaaS in **Havana**.

(1) It seems we assume only one firewall instance per tenant, but actually we can create multiple firewall instances per tenant. Is it better to reject multiple firewall instances per tenant to avoid unnecessary confusion?

(2) When a tenant has multiple routers, is a firewall instance mapped onto both routers?

(3) how a router and a firewall are associated with each other. Assume that we have multiple routers (router1, router2) and multiple firewalls (fw1, fw2) in a tenant. Are both fw1 and fw2 inserted onto both routers? If we assume one firewall instance per tenant, this question is not valid.

Although it may be out of scope of this bug, I believe it needs to be clarified.
I just would like to clarify the limitation of Havana release and the future action items for Icehouse.
It helps us document FWaaS expected behavior and the limitations in the next release.