Friday, 2019-06-21

mlavalle#startmeeting neutron_drivers14:00
openstackMeeting started Fri Jun 21 14:00:13 2019 UTC and is due to finish in 60 minutes.  The chair is mlavalle. Information about MeetBot at
openstackUseful Commands: #action #agreed #help #info #idea #link #topic #startvote.14:00
*** openstack changes topic to " (Meeting topic: neutron_drivers)"14:00
openstackThe meeting name has been set to 'neutron_drivers'14:00
mlavallegood evening / afternoon / morning to everybody14:03
mlavallelet's get going14:03
mlavalle#topic RFEs14:03
*** openstack changes topic to "RFEs (Meeting topic: neutron_drivers)"14:03
mlavalleToday we have 1 RFE to discuss:
openstackLaunchpad bug 1832758 in neutron "[RFE] Allow/deny custom ethertypes in security groups" [Wishlist,New]14:03
slaweqthat is interesting one :)14:04
amotokiI haven't followed comments so far, but as a quick look it looks okay to accept ether types other than IPv4/IPv6.14:06
amotokiovs flow allows us to do it.14:07
slaweqamotoki: yes, but the problem here is that in case of iptables fw driver all such custom ethertypes are allows already14:08
slaweqand there is no way to block them currently14:08
slaweqso we have totally different behaviour depends on what driver is used14:08
haleybyes, with iptables_hybrid we might be able to do it using ebtables, right now it's almost a bug in the iptables_hybrid code imho14:08
amotokislaweq: ah.... the fallback default rule allows all traffic?14:08
slaweqat least IIUC this bug report and what njohnston explained us recently, it is like that14:09
mlavalleso that tells me that we should strive for consistency, right?14:09
slaweqso IMO first question here is:14:09
slaweqwhich behaviour is correct14:10
slaweq1. iptables_hybrid driver which allows custom ethertypes14:10
slaweq2. ovs driver which blocks it14:10
mlavalleanother way to pose the question is:14:10
mlavalledo we believe that there are already users with this use case going on with iptables_hybrid14:11
mlavalleif yes, that kind of tells us that is the right behavior14:11
haleybyes, there are, but it might have been an oversight since we're allowing traffic that wasn't allowed by an SG rule14:12
mlavalleI know14:12
slaweqmlavalle: as njohnston wrote in comment, we had customers using e.g. InfiniBand which require such traffic14:12
