Comment 5 for bug 1460741

Revision history for this message
Kevin Benton (kevinbenton) wrote :

Hi Mike,

Can you do me a favor and try out https://review.openstack.org/218517 ?

It moves the INVALID drop below the user-defined rules. With that patch applied, you should be able to add explicit allow rules that match the headers of the bad packets so they are permitted before the INVALID drop.