Comment 4 for bug 1372882

Revision history for this message
Sean M. Collins (scollins) wrote :

Moving this to confirmed - yes we have logic that filters RAs inbound on VM ports to only allow RAs from the subnet's gateway IP, but in the case of provider networks where VMs are attached to a network that also contains bare metal hosts, the bare metal hosts are not protected.