ipv6 prefix delegated subnets are not accessable external of the router they are attached.
Bug #1570122 reported by
Matthew Thode
This bug affects 9 people
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
Ubuntu Cloud Archive |
Fix Released
|
High
|
Unassigned | ||
neutron |
Fix Released
|
High
|
John Davidge | ||
neutron (Ubuntu) |
Fix Released
|
High
|
Unassigned |
Bug Description
currently ip6tables in the qrouter namespace has the following rule. This causes unmarked packets to drop.
-A neutron-
It seems that prefix delegated subnets don't get that mark set on incoming trafic from the gateway port, I had to add my own rule to do that.
ip6tables -t mangle -A neutron-
At the moment that is probably too permissive, it should likely be limited based on the prefix delegated. with a '-d dead:beef:
Changed in neutron: | |
importance: | Undecided → Medium |
Changed in neutron: | |
assignee: | nobody → John Davidge (john-davidge) |
assignee: | John Davidge (john-davidge) → nobody |
Changed in neutron: | |
assignee: | nobody → John Davidge (john-davidge) |
Changed in neutron: | |
assignee: | John Davidge (john-davidge) → Brian Haley (brian-haley) |
Changed in neutron: | |
assignee: | Brian Haley (brian-haley) → John Davidge (john-davidge) |
tags: | added: newton-backport-potential |
tags: | added: ocata-rc-potential |
Changed in neutron: | |
milestone: | none → ocata-rc1 |
tags: | added: neutron-proactive-backport-potential |
To post a comment you must log in.
I guess the work done as part of the address-scopes blueprint broke this.