Skip to content

Navigation Menu

Sign in
Appearance settings

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Appearance settings

CLOUDSTACK-10043: fix restore default drop for egress rules in ACL#2323

Closed
resmo wants to merge 1 commit intoapache:masterapache/cloudstack:masterfrom
resmo:fix/vpc_acl_egress_default_dropCopy head branch name to clipboard
Closed

CLOUDSTACK-10043: fix restore default drop for egress rules in ACL#2323
resmo wants to merge 1 commit intoapache:masterapache/cloudstack:masterfrom
resmo:fix/vpc_acl_egress_default_dropCopy head branch name to clipboard

Conversation

@resmo
Copy link
Member

@resmo resmo commented Nov 13, 2017

While verifying the fix for CLOUDSTACK-10135 in #2313 we found a regression.

At least to version 4.5.x (verified in 4.5.3) every ACL hat a default drop for egress (ACL_OUTBOUND). This commit restores this behavior (regression fix)

Ok, after some more investigation and help of @fmaximus it seems the 4.5 implementation is wrong as well. It does not add a deny egress all but a deny egress all if there is any egress rule (even a deny), but anyway.

This is a not a bug fix anymore but a default deny.

/cc @rhtyd @yvsubhash

@yadvr
Copy link
Member

yadvr commented Nov 14, 2017

@blueorangutan package

@blueorangutan
Copy link

@rhtyd a Jenkins job has been kicked to build packages. I'll keep you posted as I make progress.

@blueorangutan
Copy link

Packaging result: ✔centos6 ✔centos7 ✔debian. JID-1252

@yadvr
Copy link
Member

yadvr commented Nov 22, 2017

@resmo are you planning to work on option 3 (from dev@ ML) or go with this change (drop by default) ?

@resmo
Copy link
Member Author

resmo commented Nov 22, 2017

I would say, close this PR and I am going for the option 3.

@resmo resmo closed this Nov 22, 2017
@resmo resmo deleted the fix/vpc_acl_egress_default_drop branch November 22, 2017 13:14
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

Morty Proxy This is a proxified and sanitized view of the page, visit original site.