Friday, 2018-01-05

*** hoangcx has quit IRC01:55
*** hoangcx has joined #openstack-fwaas01:55
*** threestrands_ has joined #openstack-fwaas02:14
*** threestrands_ has quit IRC02:14
*** threestrands_ has joined #openstack-fwaas02:14
*** threestrands has quit IRC02:16
*** yamamoto has joined #openstack-fwaas03:28
*** reedip has joined #openstack-fwaas03:34
*** annp has joined #openstack-fwaas03:56
openstackgerritCao Xuan Hoang proposed openstack/neutron-fwaas master: [log]: Add rpc stuff for logging  https://review.openstack.org/53071504:13
openstackgerritCao Xuan Hoang proposed openstack/neutron-fwaas master: [log]: Add rpc stuff for logging  https://review.openstack.org/53071504:42
*** threestrands_ has quit IRC06:13
*** chandanc has joined #openstack-fwaas06:36
*** chandanc has quit IRC07:05
*** chandanc has joined #openstack-fwaas07:40
chandancxgerman_: does https://www.irccloud.com/pastebin/U9cW9o1H/  happen for even OVS based SG07:42
*** chandanc has quit IRC08:01
*** chandanc has joined #openstack-fwaas08:02
*** chandanc has quit IRC08:09
*** chandanc has joined #openstack-fwaas08:57
*** chandanc_ has joined #openstack-fwaas09:04
*** chandanc has quit IRC09:06
*** chandanc_ is now known as chandanc09:06
*** hoangcx has quit IRC10:15
*** jafeha has quit IRC10:17
*** reedip has quit IRC10:39
*** chandanc has quit IRC10:48
*** reedip has joined #openstack-fwaas10:52
*** jafeha has joined #openstack-fwaas11:17
*** annp has quit IRC12:00
xgerman_Yes, that’s the scenario I tested15:14
xgerman_co-exiatnce15:14
*** jafeha has quit IRC15:37
*** jafeha has joined #openstack-fwaas15:39
*** yamamoto has quit IRC16:26
*** openstackstatus has quit IRC16:40
*** openstackstatus has joined #openstack-fwaas16:41
*** ChanServ sets mode: +v openstackstatus16:41
*** yamamoto has joined #openstack-fwaas16:50
*** jafeha__ has joined #openstack-fwaas17:14
*** jafeha has quit IRC17:16
*** chandanc has joined #openstack-fwaas17:18
chandancHello xgerman_ : i think the issue is that we handle both allow and deny rules while sg handles only allow rules17:18
chandanchere is the part that differs for FWaaS v217:19
chandanchttps://github.com/openstack/neutron-fwaas/blob/master/neutron_fwaas/services/firewall/drivers/linux/l2/openvswitch_firewall/firewall.py#L90217:19
chandanchttps://github.com/openstack/neutron/blob/master/neutron/agent/linux/openvswitch_firewall/firewall.py#L107817:19
*** jafeha__ has quit IRC17:20
xgerman_yeah, this is what yushiro said. I think what we do is better because more explicit + I am not sure if you enable co-existance we should behave like SG until someone adds rules17:24
chandanchmm, i agree we do better, :)17:27
chandancwe can disable handling deny if needed17:29
chandanci think SG doesnot expect rules with deny action17:29
*** yamamoto has quit IRC17:47
xgerman_this is a difficult topic since on the one hand we don’t want to break SG if you add FWaaS but also not change our behavior drastically when you run us stand-alone as opposed to co-existance + SG might behave wrong (I found at least 1 regression error in Pike+)17:50
xgerman_ok, I made up my mind: we should be strict and people should fix their SG. Having implicit allows is dangerous for security17:59
chandancxgerman_: i agree lets keep our behaviour18:02
xgerman_we definitely need to give a talk/record a video/write doc18:02
*** yamamoto has joined #openstack-fwaas18:03
chandancsure, we should have a demo recorded. i can take a shot18:04
*** yamamoto has quit IRC18:07
xgerman_+118:10
*** chandanc has quit IRC18:23
openstackgerritboden proposed openstack/neutron-fwaas master: use EGRESS_DIRECTION and INGRESS_DIRECTION from neutron-lib  https://review.openstack.org/53146718:46
*** yamamoto has joined #openstack-fwaas18:48
*** yamamoto has quit IRC18:52
*** openstack has joined #openstack-fwaas21:15
*** ChanServ sets mode: +o openstack21:15
*** yamamoto has joined #openstack-fwaas22:04
*** lnicolas has quit IRC22:10
*** yamamoto has quit IRC22:17
*** vishwanathj_ has joined #openstack-fwaas22:21
*** vishwanathj has quit IRC22:59
*** vishwanathj has joined #openstack-fwaas23:31

Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!