DESCRIPTION:
Firewal is not working when setting the destination-ip-address as VM's floating ip
Steps to Reproduce:
1. create one network and attached it to the newly created router
2. Create VMs on the above network
3. create security group rule for icmp
4. create an external network and attach it to the router as gateway
5. create floating ip and associate it to the VMs
6. create a first firewall rule as protocol=icmp , action =deny and desitination-ip-address as floatingip
7. create second firewall rule as protocol=any action=allow
8. attach the rule to the policy and the policy to the firewall
9. ping the VMs floating ip from network node which is having the external network configured.
Actual Results:
Ping succeeds
Expected Results:
Ping should fail as per the firewall rule
Can you please confirm if you are using only security groups or FWaaS as well? If you are using FWaaS please indicate the steps you followed to create the firewall_policy, firewall, etc.