*** sterdnotshaken has quit IRC | 00:24 | |
openstackgerrit | Ihar Hrachyshka proposed openstack/neutron-fwaas master: Fix mismatch in error messages https://review.openstack.org/503830 | 03:04 |
---|---|---|
openstackgerrit | Merged openstack/neutron-fwaas master: Use shim tool for ostestr https://review.openstack.org/503815 | 03:59 |
openstackgerrit | Reedip proposed openstack/neutron-fwaas master: Introduce default firewall groups https://review.openstack.org/425769 | 04:01 |
*** reedip_afk is now known as reedip | 04:15 | |
*** SarathMekala has joined #openstack-fwaas | 04:40 | |
*** yamamoto_ has quit IRC | 05:21 | |
*** openstack has joined #openstack-fwaas | 05:30 | |
openstackgerrit | Merged openstack/neutron-fwaas master: Fix mismatch in error messages https://review.openstack.org/503830 | 05:48 |
*** ivasilevskaya has joined #openstack-fwaas | 11:03 | |
*** SarathMekala has quit IRC | 11:03 | |
ivasilevskaya | reedip, didn't know this channel existed :) | 11:04 |
ivasilevskaya | reedip, I wonder if we can go with a blunt 'create_default_firewall_group' method. If I understood your suggestion correctly you advise to move default fwg creation to l2 extension patch and I'd rather get the things done and throughly tested in original patch | 11:06 |
*** ivasilevskaya has quit IRC | 12:08 | |
openstackgerrit | Akihiro Motoki proposed openstack/neutron-fwaas-dashboard master: FWaaS v1 dashboard: Clean up admin_state logic https://review.openstack.org/500805 | 14:07 |
openstackgerrit | Merged openstack/neutron-fwaas-dashboard master: FWaaS v1 dashboard: Clean up admin_state logic https://review.openstack.org/500805 | 14:19 |
*** yamamoto has joined #openstack-fwaas | 14:35 | |
*** yamamoto has quit IRC | 14:46 | |
*** yamamoto has joined #openstack-fwaas | 15:00 | |
*** reedip_ has joined #openstack-fwaas | 15:12 | |
*** bbbbzhao_ has joined #openstack-fwaas | 15:13 | |
reedip_ | xgerman_ when will we have our meeting tomorrow ? Can you discuss the timing once with SridarK and yushiro ? I would like to join in :) | 15:14 |
xgerman_ | Will be 9-12 Mountain time ;-) Maybe longer… | 15:15 |
xgerman_ | That’s what the Neutron schedule says | 15:16 |
reedip_ | hmm ... | 15:22 |
reedip_ | Let me see what it is in my TZ | 15:22 |
reedip_ | :P | 15:22 |
*** sterdnotshaken has joined #openstack-fwaas | 15:27 | |
reedip_ | sterdnotshaken : the fwaas_dashboard is only for FWaaS v2 | 15:31 |
reedip_ | sorry, I saw your message but couldnt respond back ( couldnt find you online ) | 15:31 |
*** SridarK has joined #openstack-fwaas | 15:37 | |
sterdnotshaken | reedip_ Thanks for responding! Ok, so there now is a fwaas dashboard fir fwaas v2 then? For a while there, it was only for v1 right? | 15:38 |
reedip_ | sterdnotshaken : yes, earlier there was only for V1 but the new dashboard serves V2 | 15:38 |
reedip_ | SridarK : hi, seems there is some work to be done for the Default FWG | 15:39 |
reedip_ | couldnt find yushiro online | 15:39 |
SridarK | reedip_: hi | 15:39 |
reedip_ | need to discuss this tomorrow in our team meeting for PTG . | 15:39 |
SridarK | yes default fwg will need some work | 15:40 |
reedip_ | I couldnt find the etherpad for FWaaS PTG | 15:40 |
reedip_ | I would like to update it so that atleast we have the topics to discuss | 15:40 |
reedip_ | SridarK : we would have out meeting around 24 hours from now, right ? | 15:40 |
SridarK | the etherpad got reconstituted into the neutron ptg etherpd | 15:40 |
SridarK | the format here it seems is to give a quick update on where things stand | 15:41 |
SridarK | and bring up any blocking issues | 15:41 |
reedip_ | SridarK : ok , actually there have been some issues in DVR | 15:42 |
reedip_ | with FWaaS. | 15:42 |
SridarK | reedip_: yes i spoke with Swami | 15:42 |
reedip_ | I am trying to set up a system with DVR , so I would need some help of Swami on this ... | 15:42 |
SridarK | u have some bugs filed ? | 15:42 |
reedip_ | 2 actually.... | 15:42 |
reedip_ | one by me one by another person.... | 15:42 |
SridarK | can u pls paste them here | 15:42 |
reedip_ | umm, wait | 15:43 |
SridarK | there have been some changes on DVR side | 15:43 |
reedip_ | a lot , actually | 15:43 |
reedip_ | I have been trying to read some of the recent code changes... and I am lost, simply.. | 15:43 |
SridarK | no in terms of the issue with FIP | 15:43 |
reedip_ | https://bugs.launchpad.net/neutron/+bug/1715395 | 15:43 |
openstack | Launchpad bug 1715395 in neutron "FWaaS: Firewall creation fails in case of distributed routers (Pike)" [High,In progress] - Assigned to Reedip (reedip-banerjee) | 15:43 |
reedip_ | https://bugs.launchpad.net/neutron/+bug/1716401 | 15:44 |
openstack | Launchpad bug 1716401 in neutron "FWaaS: Ip tables rules do not get updated in case of distributed virtual routers (DVR)" [Undecided,New] - Assigned to Reedip (reedip-banerjee) | 15:44 |
SridarK | but yes the DVR code has changed significantly | 15:44 |
SridarK | ok good thx for the links | 15:44 |
SridarK | we can work with Swami to resolve this | 15:44 |
reedip_ | SridarK , can you get an idea of the changes in DVR | 15:44 |
reedip_ | so that we can sync up with the code? | 15:45 |
*** yushiro2 has joined #openstack-fwaas | 15:45 | |
SridarK | but the agent side of the code has changed a lot - since i added the widgets for us to coexist with dvr | 15:45 |
SridarK | it is unrecognizable to me too | 15:45 |
reedip_ | widgets ? | 15:45 |
SridarK | code :-) | 15:45 |
reedip_ | oh ... :) | 15:46 |
reedip_ | oh , got it... | 15:46 |
reedip_ | maybe you can get Swami in tomorrow's meeting as well for 30 min or so ? | 15:46 |
SridarK | ok spoke to Swami a bit yday - will try to sit with him today | 15:46 |
reedip_ | ok SridarK , and it would be great if you can share the points .. I would like to work on the DVR part | 15:48 |
SridarK | reedip_: sure will do thx | 15:51 |
reedip_ | +1 :) | 15:51 |
*** reedip_ is now known as outofmemory | 16:28 | |
*** outofmemory has quit IRC | 16:32 | |
doude | Hi reedip | 16:34 |
sterdnotshaken | So is the FWaaS Horizon dashboard plugin available for Ocata or is it new for Pike only? | 16:48 |
*** sterdnotshaken1 has joined #openstack-fwaas | 16:58 | |
*** sterdnotshaken has quit IRC | 17:01 | |
yushiro2 | sterdnotshaken1, Hi. You mean FWaaS v1? | 17:04 |
sterdnotshaken1 | yushiro2, FWaas v2 | 17:05 |
yushiro2 | sterdnotshaken1, OK. v2 dashboard cannot use in Pike. This is for Queens. (Now, under development) | 17:06 |
sterdnotshaken1 | yushiro2, Oh, ok. so there is no FWaaS Horizon Dashboard for Ocata nor Pike… Good to know. Queens is slated for release in 6 months or so correct? | 17:09 |
yushiro2 | sterdnotshaken1, yes.. You're right. Queens is slated for 6month. You can check following link: https://releases.openstack.org/queens/schedule.html | 17:11 |
yushiro2 | We're planning to complete fwaas v2 (including dashboard) in early queens. | 17:12 |
sterdnotshaken1 | Also, if we are using Linux Bridge based SG, but our Ocata implementation uses OVS, can we use FWaaS v2 (which deploys security rules in the form of OVS flows) or do we need to change our SG to use OVS as well? | 17:14 |
sterdnotshaken1 | Hopefully that question makes sense... | 17:15 |
sterdnotshaken1 | I guess my question is, if we have Linux Bridge set as our firewall driver, but are running OVS as our mechanism driver, does FWaaS v2 work with that? | 17:17 |
SridarK | sterdnotshaken1: in theory this could work - but some clarifications: | 17:19 |
SridarK | 1) FWaaS v2 on L3 ports - will have no issues on what u are doing with SG | 17:20 |
SridarK | 2) FWaaS v2 on VM ports - will use ovs as u point out. This code is in the last stages of review so should merge hopefully in a few weeks. | 17:21 |
SridarK | 3) As a first step - we will spend more time on testing out FWaaS v2 on VM ports standalone (ie no SG) | 17:21 |
SridarK | 4) We were hoping that the deployment for SG and FWaaS v2 will start will all ovs | 17:22 |
yushiro2 | Aha, thanks for your explanation, SridarK | 17:23 |
SridarK | 5) Then we get to the stage where we could have SG on iptables and and FWaaS v2 on ovs - this will require some validation - | 17:23 |
SridarK | sterdnotshaken1: that is the basic plan as we were thinking - pls go ahead if u have more questions or suggestions | 17:24 |
SridarK | one of the things i am not entirely sure abt is when SG on ovs is ready for consumption or what state it is in | 17:25 |
sterdnotshaken1 | We've ran it in the past and it worked great for us. We end up switching back to Linux Bridge per some concerns regarding flow table size on br-int with we got up to 1000's of customers... | 17:26 |
SridarK | sterdnotshaken1: ok | 17:27 |
sterdnotshaken1 | SridarK, Excellent, very good explanation! That clarifies it. Thank you very much. So it sound like Queens is going to be a very significant release for FWaaS then. | 17:27 |
SridarK | sterdnotshaken1: yes with respect L2 support | 17:27 |
sterdnotshaken1 | excellent! | 17:27 |
SridarK | sterdnotshaken1: perhaps if u have time u can drop in to some of our weekly IRC mtgs | 17:28 |
SridarK | we would love to get some feedback from users | 17:28 |
yushiro2 | SridarK, sterdnotshaken1 yes, it sounds good ;) | 17:28 |
sterdnotshaken1 | Thank you for your help as well Yushiro2 | 17:29 |
yushiro2 | sterdnotshaken1, quick question. I found a person in Wiki:https://en.wikipedia.org/wiki/Steven_Davis Is it you?? ;) | 17:31 |
sterdnotshaken1 | ha ha! I wish! Naw, not me :) | 17:32 |
SridarK | :-) | 17:32 |
SridarK | sterdnotshaken1: by any chance are u at the PTG gathering at Denver ? | 17:33 |
sterdnotshaken1 | I'm located in Utah, which is next to Colorado, alas, I don't think I'll be able to make it. :( | 17:34 |
*** yamamoto has quit IRC | 17:34 | |
yushiro2 | sterdnotshaken1, hahaha :) OK, just joking. | 17:34 |
*** SumitNaiksatam has joined #openstack-fwaas | 17:40 | |
SridarK | sterdnotshaken1: ok cool - lets stay in touch here and possibly on the weekly mtgs | 17:47 |
sterdnotshaken1 | Sounds great! | 17:47 |
*** yushiro2 has quit IRC | 17:57 | |
*** SridarK has quit IRC | 17:58 | |
*** yamamoto has joined #openstack-fwaas | 18:12 | |
*** yamamoto_ has joined #openstack-fwaas | 18:14 | |
*** yamamoto has quit IRC | 18:18 | |
*** yamamoto_ has quit IRC | 19:00 | |
*** yamamoto has joined #openstack-fwaas | 19:06 | |
*** SumitNaiksatam has quit IRC | 19:10 | |
*** yushiro has joined #openstack-fwaas | 19:19 | |
*** yushiro has quit IRC | 19:59 | |
*** yamamoto has quit IRC | 20:02 | |
*** yamamoto has joined #openstack-fwaas | 20:55 | |
*** sterdnotshaken has joined #openstack-fwaas | 21:05 | |
*** sterdnotshaken1 has quit IRC | 21:05 | |
*** yamamoto has quit IRC | 22:19 | |
*** yamamoto has joined #openstack-fwaas | 22:21 | |
*** yamamoto has quit IRC | 22:24 | |
*** yamamoto has joined #openstack-fwaas | 22:46 | |
*** yamamoto has quit IRC | 22:47 | |
*** openstackstatus has joined #openstack-fwaas | 23:10 | |
*** ChanServ sets mode: +v openstackstatus | 23:10 |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!