[fwaas]Support fwaas to control east-west traffic in dvr router

Bug #1476097 reported by lee jian
18
This bug affects 3 people
Affects Status Importance Assigned to Milestone
neutron
Expired
Wishlist
Unassigned

Bug Description

when fwaas is enabled with dvr router, the firewall rules will only be added to snat-ROUTER_ID on controller and floating ip namespaces on compute, this will result that, only south-north traffic can be controlled by fwaas, and the east-west traffic,which produced from one subnet to another is out of fwaas' control.

Revision history for this message
OpenStack Infra (hudson-openstack) wrote : Fix proposed to neutron-fwaas (master)

Fix proposed to branch: master
Review: https://review.openstack.org/203493

Changed in neutron:
assignee: nobody → lee jian (leejian0612)
status: New → In Progress
Revision history for this message
OpenStack Infra (hudson-openstack) wrote : Change abandoned on neutron-fwaas (master)

Change abandoned by Jian LI (<email address hidden>) on branch: master
Review: https://review.openstack.org/203493
Reason: Not a good solution and needed more discussion to fix it.

Changed in neutron:
importance: Undecided → Critical
tags: added: rfe
tags: added: l3-dvr-backlog rfe-approved
removed: rfe
Changed in neutron:
importance: Critical → High
status: In Progress → Triaged
Revision history for this message
Miguel Lavalle (minsel) wrote :

swami, mickey and sridhar working on a fix proposal

Revision history for this message
Swaminathan Vasudevan (swaminathan-vasudevan) wrote :

Based on the direction the FWaaS is taking on applying the firewall rules to the VM port, there might not be any change required for DVR, except for some documentation on advocating not to apply the firewall rules for the router ports in the case of DVR.

Changed in neutron:
importance: High → Wishlist
Revision history for this message
Armando Migliaccio (armando-migliaccio) wrote :

I'd say that DVR should be a requirement being tracked here:

https://review.openstack.org/#/c/237687/5/specs/mitaka/approved/libvirt-vif-vhostuser-fp.rst

To this aim, this RFE is most likely to be superseded.

Changed in neutron:
status: Triaged → Incomplete
assignee: lee jian (leejian0612) → nobody
tags: removed: rfe-approved
Revision history for this message
Armando Migliaccio (armando-migliaccio) wrote :

I'd say that DVR should be a requirement being tracked here:

https://review.openstack.org/#/c/243873/

To this aim, this RFE is most likely to be superseded.

Revision history for this message
Launchpad Janitor (janitor) wrote :

[Expired for neutron because there has been no activity for 60 days.]

Changed in neutron:
status: Incomplete → Expired
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Duplicates of this bug

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.