Modify an order between iptables and conntrack when update firewall
When update a firewall, we should update the iptables firstly,
and then remove the conntrack record, just like the function
create_firewall() and create_firewall_group(). Otherwise, the
contrack record could be reproduced. It will be occurred more
easily in scenario of large flow, because removing conntrack
and updating firewall will take some time, and in this interval
the subsequent flow could be came to reproduced the same
conntrack record.
Reviewed: https:/ /review. openstack. org/471301 /git.openstack. org/cgit/ openstack/ neutron- fwaas/commit/ ?id=6a31bfbb340 0fb818e7b2f15fa 11337bafed80cd
Committed: https:/
Submitter: Jenkins
Branch: master
commit 6a31bfbb3400fb8 18e7b2f15fa1133 7bafed80cd
Author: wujun <email address hidden>
Date: Tue Jun 6 05:58:32 2017 -0400
Modify an order between iptables and conntrack when update firewall
When update a firewall, we should update the iptables firstly, firewall( ) and create_ firewall_ group() . Otherwise, the
and then remove the conntrack record, just like the function
create_
contrack record could be reproduced. It will be occurred more
easily in scenario of large flow, because removing conntrack
and updating firewall will take some time, and in this interval
the subsequent flow could be came to reproduced the same
conntrack record.
Change-Id: I7bd36964199c6c e7c146f3ef06a69 3e9c6fe5353
Closes-bug: #1696093