Established connection don't stops when rule is removed
Bug #1657260 reported by
Slawek Kaplonski
This bug affects 2 people
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
neutron |
Fix Released
|
Critical
|
Kevin Benton |
Bug Description
If iptables driver is used for Security groups (e.g. in Linuxbridge L2 agent) there is an issue with update rules. When You have rule which allows some kind of traffic (like ssh for example from some src IP address) and You have established, active connection which match this rule, connection will be still active even if rule will be removed/changed.
It is because in iptables in chain for each SG as first there is rule to accept packets with "state RELATED,
I'm not sure if it is in fact bug or maybe it's just design decision to have better performance of iptables.
Changed in neutron: | |
milestone: | none → ocata-rc1 |
Changed in neutron: | |
importance: | Undecided → Critical |
Changed in neutron: | |
assignee: | Slawek Kaplonski (slaweq) → Jakub Libosvar (libosvar) |
Changed in neutron: | |
assignee: | Jakub Libosvar (libosvar) → Kevin Benton (kevinbenton) |
To post a comment you must log in.
When a SG rule is removed, conntrack -D is run to drop all the connections that might be using the old rule. Did you see that happen in the logs?