Skip to content

Navigation Menu

Sign in
Appearance settings

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Appearance settings

Network ACL check is bypassed on Load balancing rules in VPC #9054

Copy link
Copy link
@weizhouapache

Description

@weizhouapache
Issue body actions

This issue was found duing the investigation on #9053 .
This sounds like a critical/major issue.

steps the reproduce the issue

  • create a VPC
  • create a VPC tier with ACL "default_deny"
  • create a VM in the VPC tier
  • acquire the public IP
  • create load balancing rule with public port=2222 and private port=22
  • acquire another public IP (it may be not needed in 4.19/4.20 as vpc supports conserved mode)
  • create port forwarding rule with public port=2223 and private port=22

Expected result

  • both LB and PF ports (2222/2223) are unreachable as the ACL is "default_deny"

Actual result

  • PF port (2223) is unreachable (as expected)
  • LB port (2222) is reachable (bug/unexpected behavior)
ISSUE TYPE
  • Bug Report
COMPONENT NAME

CLOUDSTACK VERSION
4.19/4.20, it impacts probably other versions as well
CONFIGURATION
OS / ENVIRONMENT
SUMMARY
STEPS TO REPRODUCE

EXPECTED RESULTS

ACTUAL RESULTS

Reactions are currently unavailable

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

No type

Projects

No projects

Milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions

    Morty Proxy This is a proxified and sanitized view of the page, visit original site.