Bug #1520

Firewall not working with Open vSwitch

Added by OpenNebula Systems Support Team almost 9 years ago. Updated over 8 years ago.

Status:ClosedStart date:09/27/2012
Priority:NormalDue date:
Assignee:Jaime Melis% Done:

0%

Category:Drivers - Auth
Target version:Release 3.8
Resolution:fixed Pull request:
Affected Versions:OpenNebula 3.6

Description

No traffic is being blocked to the VM. Additionally this error message appears:

xt_physdev: using --physdev-out in the OUTPUT, FORWARD and POSTROUTING chains for non-bridged traffic is not supported anymore.

Associated revisions

Revision 0e1729e8
Added by Jaime Melis almost 9 years ago

bug #1520: Firewall not working with Open vSwitch

Switch from the iptables firewall scripts, which aren't compatible anymore,
with scripts that create openvswitch flows.

Port whitelisting functionality can't be implemented with this model.

Revision dcc10218
Added by Jaime Melis almost 9 years ago

bug #1520: Remove unsupported white_ports, and apply the mac_spoofing filter on all interfaces.

History

#1 Updated by Ruben S. Montero almost 9 years ago

  • Target version set to Release 3.8

#2 Updated by Ruben S. Montero over 8 years ago

  • Status changed from New to Assigned
  • Assignee set to Jaime Melis

#3 Updated by Jaime Melis over 8 years ago

  • Status changed from Assigned to Closed
  • Resolution set to fixed

Documentation updated.

Also available in: Atom PDF