| xgerman | Thanks. No worries... | 00:36 |
|---|---|---|
| yushiro | However, FWaaS DB inherits common_db_mixin in neutron now. Is this module also migrated into neutron-lib? | 00:42 |
| *** hoangcx has joined #openstack-fwaas | 00:47 | |
| njohnston | I do not believe that this module has migrated, no | 01:16 |
| yushiro | njohnston, OK. now, I created new PS into neutron-fwaas. | 01:17 |
| yushiro | As you said, I could create the patch in neutron-fwaas. | 01:18 |
| yushiro | As soon as I finished writing UTs, I'll upload. I hope you can take a look. | 01:18 |
| *** lnicolas1 has quit IRC | 02:09 | |
| reedip | When is the next meeting , today ??? | 02:27 |
| reedip | Weekly meeting | 02:27 |
| hoangcx | reedip: Weekly on Tuesday at 1400 UTC | 02:30 |
| reedip | hoangcx : so today, right. Thanks :) | 02:36 |
| hoangcx | reedip: Yes. | 02:37 |
| *** yushiro has quit IRC | 03:29 | |
| *** reedip has quit IRC | 03:34 | |
| *** reedip has joined #openstack-fwaas | 03:46 | |
| *** yushiro has joined #openstack-fwaas | 05:25 | |
| *** padkrish has joined #openstack-fwaas | 06:25 | |
| *** yamamoto has quit IRC | 07:33 | |
| *** padkrish has quit IRC | 07:36 | |
| *** amotoki has quit IRC | 08:24 | |
| reedip | hi yushiro | 08:26 |
| yushiro | hi | 08:26 |
| reedip | have we considered Rate Limiting with Firewalls? | 08:26 |
| yushiro | reedip, in V1? | 08:26 |
| reedip | in V2 | 08:27 |
| yushiro | I haevn't tested yet. | 08:29 |
| reedip | do we have it ? | 08:30 |
| reedip | I mean do we have rate limiting on Ingress and Egress for Firewalls ? | 08:30 |
| yushiro | Ah, rate limit is not for REST API but a kind of filter for firewall_rule ? | 08:31 |
| yushiro | firewall_group includes ports and firewall_policies(ingress, egress). | 08:32 |
| *** amotoki has joined #openstack-fwaas | 08:33 | |
| reedip | yushiro : yup | 08:35 |
| *** yamamoto has joined #openstack-fwaas | 08:35 | |
| reedip | ideally qos should work well with it, but was just thinking if that is possible? | 08:35 |
| yushiro | I think qos is running on OVS, and current firewall_rule doesn't control rate limit. Therefore, I think fwaas doesn't interfere qos. | 08:43 |
| yushiro | But I'm not expert of qos :( I'm sorry if I was wrong. | 08:44 |
| yushiro | reedip, Sorry. I have to go dental clinic. Let's discuss later after fwaas IRC meeting. | 08:46 |
| reedip | yushiro : no worries. I may not be able to catch up the meeting today though, but will come back on later to discuss the items on this channel | 08:47 |
| yushiro | sure | 08:47 |
| *** amotoki has quit IRC | 08:53 | |
| *** mickeys has quit IRC | 09:01 | |
| *** yushiro has quit IRC | 09:05 | |
| *** Brenda has joined #openstack-fwaas | 09:06 | |
| Brenda | https://bugs.launchpad.net/openstack-api-site/+bug/1656735 | 09:07 |
| openstack | Launchpad bug 1656735 in neutron "Fwaas - insert_rule and remove_rule always set audited to False" [Undecided,Opinion] - Assigned to brenda (tian-mingming) | 09:07 |
| Brenda | There are some different opinions about this bug. Can we have a discussion about it? | 09:08 |
| reedip | Brenda : we have a meeting today at UTC 1400 | 09:09 |
| reedip | where all ( or most ) FWaaS folks would be present | 09:09 |
| Brenda | Ok | 09:10 |
| Brenda | I am in China. | 09:10 |
| Brenda | So it's at 10:00 PM | 09:10 |
| reedip | its 8: 30 pm for me in India :) | 09:10 |
| reedip | anyways, If I attend , I will try to put this query up | 09:11 |
| Brenda | Great. Then you can go to bed earlier:) | 09:11 |
| Brenda | OK, Thank you very much. | 09:13 |
| *** yamamoto has quit IRC | 09:29 | |
| *** amotoki has joined #openstack-fwaas | 09:57 | |
| *** mickeys has joined #openstack-fwaas | 10:02 | |
| *** mickeys has quit IRC | 10:06 | |
| *** hoangcx has quit IRC | 10:06 | |
| *** yamamoto has joined #openstack-fwaas | 10:20 | |
| *** yamamoto has quit IRC | 10:21 | |
| *** amotoki has quit IRC | 11:07 | |
| *** amotoki has joined #openstack-fwaas | 11:30 | |
| *** yamamoto has joined #openstack-fwaas | 12:20 | |
| *** yamamoto has quit IRC | 13:04 | |
| *** AlexeyAbashkin has joined #openstack-fwaas | 13:16 | |
| *** yamamoto has joined #openstack-fwaas | 13:25 | |
| *** yamamoto has quit IRC | 13:25 | |
| *** hoangcx has joined #openstack-fwaas | 13:39 | |
| *** yushiro has joined #openstack-fwaas | 13:57 | |
| *** chandanc_ has joined #openstack-fwaas | 14:00 | |
| *** reedip has quit IRC | 14:06 | |
| *** brenda_ has joined #openstack-fwaas | 14:07 | |
| brenda_ | Has the meeting started? | 14:09 |
| njohnston | yes, on #openstack-meeting-4 | 14:09 |
| *** brenda_ has left #openstack-fwaas | 14:12 | |
| *** reedip has joined #openstack-fwaas | 14:20 | |
| *** amotoki has quit IRC | 14:29 | |
| *** amotoki has joined #openstack-fwaas | 14:35 | |
| *** amotoki has quit IRC | 14:57 | |
| *** brenda_ has joined #openstack-fwaas | 15:00 | |
| yushiro | I'm home. | 15:00 |
| *** SridarK has joined #openstack-fwaas | 15:01 | |
| SridarK | yushiro: hi | 15:01 |
| yushiro | SridarK, hi | 15:01 |
| xgerman | hi | 15:01 |
| brenda_ | hi | 15:01 |
| SridarK | yushiro: on #link https://review.openstack.org/#/c/423229/ | 15:02 |
| SridarK | i wanted to clarify None vs ANY | 15:02 |
| yushiro | SridarK, yes. | 15:02 |
| SridarK | I think it is fine - just wanted some clarifications | 15:02 |
| SridarK | 1) If nothing is specified - we default to TCP | 15:03 |
| SridarK | yushiro: that is correct ? | 15:04 |
| yushiro | hmm, currently it's not. in OSC plugin, if nothing is specified for 'protocol', set None(equal to 'any') | 15:06 |
| *** hoangcx has quit IRC | 15:06 | |
| *** chandanc_ has quit IRC | 15:06 | |
| yushiro | This behavior is same as v1 I think. | 15:06 |
| SridarK | but we want the default to be TCP ? | 15:06 |
| *** brenda_ has quit IRC | 15:06 | |
| yushiro | SridarK, Yes | 15:07 |
| SridarK | ok | 15:08 |
| *** brenda_ has joined #openstack-fwaas | 15:08 | |
| yushiro | SridarK, sorry. I was confused about 'default' behavior between server side and client side. | 15:09 |
| SridarK | yushiro: no worries | 15:09 |
| SridarK | u mentioned the fix on the Client too | 15:09 |
| yushiro | Yes. However, python-neutronclient is hard to be merged from now you know. This is my TODO. Is it OK? | 15:11 |
| *** brenda_ has quit IRC | 15:11 | |
| SridarK | yushiro: ok that is fine, i wanted to see what would the best model that has no confusion | 15:11 |
| SridarK | If the protocol is set to ANY | 15:12 |
| SridarK | then providing port numbers is a bit questionable on the rul | 15:12 |
| SridarK | *rule | 15:12 |
| yushiro | Ok | 15:13 |
| SridarK | it will be relevant for TCP or UDP | 15:13 |
| SridarK | but for other things carried in an IP packet will not make sense | 15:13 |
| yushiro | SridarK, I see. BTW, 'protocol' can specify 8 bit integer value, right? | 15:13 |
| SridarK | we could have a rule that could say "I want to filter all packets going to destination 20.20.20.23 and i dont really care what protocol" | 15:14 |
| SridarK | it could be TCP or UDP or something else | 15:15 |
| SridarK | but if we add dest L4 port - now that is a bit confusing | 15:15 |
| SridarK | yes the protocol can specify a 8 bit integer value | 15:15 |
| SridarK | so i am wondering about our valdation logic | 15:16 |
| yushiro | SridarK, Yes. and I found bugs... | 15:16 |
| SridarK | or maybe we just map to what iptables supports | 15:16 |
| yushiro | curl -X POST -d '{"firewall_rule":{"name":"test", "protocol": "10", "action": "deny"}}' : Invalid input for protocol. Reason: 10 is not in valid_values. | 15:17 |
| yushiro | curl -X POST -d '{"firewall_rule":{"name":"test", "protocol": 10, "action": "deny"}}' : Request Failed: internal server error while processing your request. | 15:17 |
| yushiro | AttributeError: 'int' object has no attribute 'isdigit' at neutron_fwaas/extensions/firewall.py +179 | 15:18 |
| SridarK | what if u set it to 6 (TCP) | 15:18 |
| yushiro | OK. Just a moment. | 15:18 |
| SridarK | it will probab also fail like this | 15:18 |
| SridarK | maybe we need to clean up more | 15:19 |
| yushiro | SridarK, Yes. same error occurred. | 15:19 |
| SridarK | so really if we said protocol = 6, then L4 ports should be valid | 15:19 |
| yushiro | I see. | 15:20 |
| SridarK | but i think we have a basic issue here in our validator | 15:20 |
| SridarK | it seems we cannot specify an 8 bit integer value for protocol | 15:20 |
| yushiro | yes. I'll file a bug-report. | 15:21 |
| yushiro | only 'tcp', 'udp', 'icmp' or 'any' | 15:21 |
| SridarK | or we can just state that we only support ICMP, TCP or UDP now | 15:21 |
| SridarK | If nothing is specified it will default to TCP | 15:21 |
| *** amotoki has joined #openstack-fwaas | 15:22 | |
| yushiro | I think it is better and easy to understand for CLI users. | 15:22 |
| SridarK | ok some more thinking is needed too | 15:22 |
| SridarK | let me also look at the code | 15:22 |
| yushiro | Yes. | 15:22 |
| SridarK | also we can check on iptables | 15:23 |
| yushiro | Yes also. | 15:23 |
| SridarK | i agree that this is confusing | 15:23 |
| SridarK | it is very late for u | 15:24 |
| SridarK | we can discuss on email or i will ping u during ur morning | 15:24 |
| *** brenda_ has joined #openstack-fwaas | 15:24 | |
| yushiro | OK. Thank you for your kindness :) | 15:24 |
| SridarK | oh pls no worries | 15:24 |
| SridarK | we can also discuss more on the L2Agent with padkrish | 15:24 |
| SridarK | tomorrow morning ur time | 15:25 |
| SridarK | yushiro: anything else to discuss ? | 15:25 |
| yushiro | SridarK, nothing. Maybe tomorrow, I'll ask you about default fwg. | 15:26 |
| *** amotoki has quit IRC | 15:26 | |
| SridarK | yushiro: ok then | 15:26 |
| SridarK | Good Night | 15:26 |
| yushiro | See you. | 15:26 |
| *** yushiro has quit IRC | 15:26 | |
| *** amotoki has joined #openstack-fwaas | 15:26 | |
| *** amotoki has quit IRC | 15:27 | |
| *** brenda_ has quit IRC | 15:27 | |
| *** amotoki has joined #openstack-fwaas | 15:27 | |
| *** brenda_ has joined #openstack-fwaas | 15:28 | |
| brenda_ | Can we have a discussion about https://review.openstack.org/#/c/423161/ | 15:29 |
| brenda_ | There are different opions about if we should set ‘audited’ to False automatically after insert rule or remove rule from a firewall policy. | 15:33 |
| *** brenda_ has quit IRC | 15:35 | |
| *** brenda_ has joined #openstack-fwaas | 15:36 | |
| *** brenda_ has left #openstack-fwaas | 15:39 | |
| *** amotoki has quit IRC | 15:41 | |
| *** amotoki has joined #openstack-fwaas | 15:57 | |
| *** reedip has quit IRC | 16:02 | |
| *** reedip has joined #openstack-fwaas | 16:16 | |
| *** reedip_ has joined #openstack-fwaas | 16:40 | |
| reedip_ | hi | 16:41 |
| reedip_ | sorry was out so couldnt attend the meeting today | 16:41 |
| reedip_ | hi SridarK | 17:17 |
| SridarK | reedip_: Hi | 17:18 |
| reedip_ | SridarK : I was checking https://review.openstack.org/#/c/424534/1 | 17:18 |
| reedip_ | It is related to demonstrating public resources to other projects | 17:19 |
| SridarK | we were going to discuss this but it was late for Yushiro | 17:19 |
| SridarK | i am quite confused on this too | 17:19 |
| SridarK | perhaps ur morning time tomorrow we can continue this discussion | 17:20 |
| reedip_ | SridarK : I get his intention, public firewalls must be visible to other tenants | 17:20 |
| reedip_ | SridarK : I will be in office early tomorrow probably, so yes | 17:20 |
| SridarK | yes that is correct seems we have some issues with public and shared | 17:20 |
| reedip_ | my only objection is the overwritten function | 17:20 |
| SridarK | reedip_: ok lets do that then - i think we need to understand this more | 17:20 |
| SridarK | reedip_: ok - i will be heading in to work now so will go offline | 17:21 |
| reedip_ | SridarK : ok, sure. Even if I am not there, you can continue and I will discuss with him as we have similar work time ( he is JST ) | 17:21 |
| reedip_ | have a good day SridarK :) | 17:21 |
| SridarK | reedip_: yes absolutely | 17:21 |
| SridarK | reedip_: thx and Good evening/Night | 17:21 |
| reedip_ | its 11 PM , so night would be a good call :) | 17:24 |
| *** amotoki has quit IRC | 17:38 | |
| *** mickeys has joined #openstack-fwaas | 17:38 | |
| *** reedip_ has quit IRC | 17:59 | |
| *** amotoki has joined #openstack-fwaas | 18:04 | |
| *** amotoki has quit IRC | 18:06 | |
| *** SridarK has quit IRC | 18:24 | |
| *** SridarK_ has joined #openstack-fwaas | 19:21 | |
| *** SridarK_ has quit IRC | 20:47 | |
| *** yamamoto has joined #openstack-fwaas | 21:08 | |
| *** yamamoto has quit IRC | 21:12 | |
| *** amotoki has joined #openstack-fwaas | 22:02 | |
| *** yamamoto has joined #openstack-fwaas | 22:17 | |
| *** amotoki has quit IRC | 23:15 | |
| *** amotoki has joined #openstack-fwaas | 23:22 | |
| *** amotoki has quit IRC | 23:42 | |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!