xgerman | Thanks. No worries... | 00:36 |
---|---|---|
yushiro | However, FWaaS DB inherits common_db_mixin in neutron now. Is this module also migrated into neutron-lib? | 00:42 |
*** hoangcx has joined #openstack-fwaas | 00:47 | |
njohnston | I do not believe that this module has migrated, no | 01:16 |
yushiro | njohnston, OK. now, I created new PS into neutron-fwaas. | 01:17 |
yushiro | As you said, I could create the patch in neutron-fwaas. | 01:18 |
yushiro | As soon as I finished writing UTs, I'll upload. I hope you can take a look. | 01:18 |
*** lnicolas1 has quit IRC | 02:09 | |
reedip | When is the next meeting , today ??? | 02:27 |
reedip | Weekly meeting | 02:27 |
hoangcx | reedip: Weekly on Tuesday at 1400 UTC | 02:30 |
reedip | hoangcx : so today, right. Thanks :) | 02:36 |
hoangcx | reedip: Yes. | 02:37 |
*** yushiro has quit IRC | 03:29 | |
*** reedip has quit IRC | 03:34 | |
*** reedip has joined #openstack-fwaas | 03:46 | |
*** yushiro has joined #openstack-fwaas | 05:25 | |
*** padkrish has joined #openstack-fwaas | 06:25 | |
*** yamamoto has quit IRC | 07:33 | |
*** padkrish has quit IRC | 07:36 | |
*** amotoki has quit IRC | 08:24 | |
reedip | hi yushiro | 08:26 |
yushiro | hi | 08:26 |
reedip | have we considered Rate Limiting with Firewalls? | 08:26 |
yushiro | reedip, in V1? | 08:26 |
reedip | in V2 | 08:27 |
yushiro | I haevn't tested yet. | 08:29 |
reedip | do we have it ? | 08:30 |
reedip | I mean do we have rate limiting on Ingress and Egress for Firewalls ? | 08:30 |
yushiro | Ah, rate limit is not for REST API but a kind of filter for firewall_rule ? | 08:31 |
yushiro | firewall_group includes ports and firewall_policies(ingress, egress). | 08:32 |
*** amotoki has joined #openstack-fwaas | 08:33 | |
reedip | yushiro : yup | 08:35 |
*** yamamoto has joined #openstack-fwaas | 08:35 | |
reedip | ideally qos should work well with it, but was just thinking if that is possible? | 08:35 |
yushiro | I think qos is running on OVS, and current firewall_rule doesn't control rate limit. Therefore, I think fwaas doesn't interfere qos. | 08:43 |
yushiro | But I'm not expert of qos :( I'm sorry if I was wrong. | 08:44 |
yushiro | reedip, Sorry. I have to go dental clinic. Let's discuss later after fwaas IRC meeting. | 08:46 |
reedip | yushiro : no worries. I may not be able to catch up the meeting today though, but will come back on later to discuss the items on this channel | 08:47 |
yushiro | sure | 08:47 |
*** amotoki has quit IRC | 08:53 | |
*** mickeys has quit IRC | 09:01 | |
*** yushiro has quit IRC | 09:05 | |
*** Brenda has joined #openstack-fwaas | 09:06 | |
Brenda | https://bugs.launchpad.net/openstack-api-site/+bug/1656735 | 09:07 |
openstack | Launchpad bug 1656735 in neutron "Fwaas - insert_rule and remove_rule always set audited to False" [Undecided,Opinion] - Assigned to brenda (tian-mingming) | 09:07 |
Brenda | There are some different opinions about this bug. Can we have a discussion about it? | 09:08 |
reedip | Brenda : we have a meeting today at UTC 1400 | 09:09 |
reedip | where all ( or most ) FWaaS folks would be present | 09:09 |
Brenda | Ok | 09:10 |
Brenda | I am in China. | 09:10 |
Brenda | So it's at 10:00 PM | 09:10 |
reedip | its 8: 30 pm for me in India :) | 09:10 |
reedip | anyways, If I attend , I will try to put this query up | 09:11 |
Brenda | Great. Then you can go to bed earlier:) | 09:11 |
Brenda | OK, Thank you very much. | 09:13 |
*** yamamoto has quit IRC | 09:29 | |
*** amotoki has joined #openstack-fwaas | 09:57 | |
*** mickeys has joined #openstack-fwaas | 10:02 | |
*** mickeys has quit IRC | 10:06 | |
*** hoangcx has quit IRC | 10:06 | |
*** yamamoto has joined #openstack-fwaas | 10:20 | |
*** yamamoto has quit IRC | 10:21 | |
*** amotoki has quit IRC | 11:07 | |
*** amotoki has joined #openstack-fwaas | 11:30 | |
*** yamamoto has joined #openstack-fwaas | 12:20 | |
*** yamamoto has quit IRC | 13:04 | |
*** AlexeyAbashkin has joined #openstack-fwaas | 13:16 | |
*** yamamoto has joined #openstack-fwaas | 13:25 | |
*** yamamoto has quit IRC | 13:25 | |
*** hoangcx has joined #openstack-fwaas | 13:39 | |
*** yushiro has joined #openstack-fwaas | 13:57 | |
*** chandanc_ has joined #openstack-fwaas | 14:00 | |
*** reedip has quit IRC | 14:06 | |
*** brenda_ has joined #openstack-fwaas | 14:07 | |
brenda_ | Has the meeting started? | 14:09 |
njohnston | yes, on #openstack-meeting-4 | 14:09 |
*** brenda_ has left #openstack-fwaas | 14:12 | |
*** reedip has joined #openstack-fwaas | 14:20 | |
*** amotoki has quit IRC | 14:29 | |
*** amotoki has joined #openstack-fwaas | 14:35 | |
*** amotoki has quit IRC | 14:57 | |
*** brenda_ has joined #openstack-fwaas | 15:00 | |
yushiro | I'm home. | 15:00 |
*** SridarK has joined #openstack-fwaas | 15:01 | |
SridarK | yushiro: hi | 15:01 |
yushiro | SridarK, hi | 15:01 |
xgerman | hi | 15:01 |
brenda_ | hi | 15:01 |
SridarK | yushiro: on #link https://review.openstack.org/#/c/423229/ | 15:02 |
SridarK | i wanted to clarify None vs ANY | 15:02 |
yushiro | SridarK, yes. | 15:02 |
SridarK | I think it is fine - just wanted some clarifications | 15:02 |
SridarK | 1) If nothing is specified - we default to TCP | 15:03 |
SridarK | yushiro: that is correct ? | 15:04 |
yushiro | hmm, currently it's not. in OSC plugin, if nothing is specified for 'protocol', set None(equal to 'any') | 15:06 |
*** hoangcx has quit IRC | 15:06 | |
*** chandanc_ has quit IRC | 15:06 | |
yushiro | This behavior is same as v1 I think. | 15:06 |
SridarK | but we want the default to be TCP ? | 15:06 |
*** brenda_ has quit IRC | 15:06 | |
yushiro | SridarK, Yes | 15:07 |
SridarK | ok | 15:08 |
*** brenda_ has joined #openstack-fwaas | 15:08 | |
yushiro | SridarK, sorry. I was confused about 'default' behavior between server side and client side. | 15:09 |
SridarK | yushiro: no worries | 15:09 |
SridarK | u mentioned the fix on the Client too | 15:09 |
yushiro | Yes. However, python-neutronclient is hard to be merged from now you know. This is my TODO. Is it OK? | 15:11 |
*** brenda_ has quit IRC | 15:11 | |
SridarK | yushiro: ok that is fine, i wanted to see what would the best model that has no confusion | 15:11 |
SridarK | If the protocol is set to ANY | 15:12 |
SridarK | then providing port numbers is a bit questionable on the rul | 15:12 |
SridarK | *rule | 15:12 |
yushiro | Ok | 15:13 |
SridarK | it will be relevant for TCP or UDP | 15:13 |
SridarK | but for other things carried in an IP packet will not make sense | 15:13 |
yushiro | SridarK, I see. BTW, 'protocol' can specify 8 bit integer value, right? | 15:13 |
SridarK | we could have a rule that could say "I want to filter all packets going to destination 20.20.20.23 and i dont really care what protocol" | 15:14 |
SridarK | it could be TCP or UDP or something else | 15:15 |
SridarK | but if we add dest L4 port - now that is a bit confusing | 15:15 |
SridarK | yes the protocol can specify a 8 bit integer value | 15:15 |
SridarK | so i am wondering about our valdation logic | 15:16 |
yushiro | SridarK, Yes. and I found bugs... | 15:16 |
SridarK | or maybe we just map to what iptables supports | 15:16 |
yushiro | curl -X POST -d '{"firewall_rule":{"name":"test", "protocol": "10", "action": "deny"}}' : Invalid input for protocol. Reason: 10 is not in valid_values. | 15:17 |
yushiro | curl -X POST -d '{"firewall_rule":{"name":"test", "protocol": 10, "action": "deny"}}' : Request Failed: internal server error while processing your request. | 15:17 |
yushiro | AttributeError: 'int' object has no attribute 'isdigit' at neutron_fwaas/extensions/firewall.py +179 | 15:18 |
SridarK | what if u set it to 6 (TCP) | 15:18 |
yushiro | OK. Just a moment. | 15:18 |
SridarK | it will probab also fail like this | 15:18 |
SridarK | maybe we need to clean up more | 15:19 |
yushiro | SridarK, Yes. same error occurred. | 15:19 |
SridarK | so really if we said protocol = 6, then L4 ports should be valid | 15:19 |
yushiro | I see. | 15:20 |
SridarK | but i think we have a basic issue here in our validator | 15:20 |
SridarK | it seems we cannot specify an 8 bit integer value for protocol | 15:20 |
yushiro | yes. I'll file a bug-report. | 15:21 |
yushiro | only 'tcp', 'udp', 'icmp' or 'any' | 15:21 |
SridarK | or we can just state that we only support ICMP, TCP or UDP now | 15:21 |
SridarK | If nothing is specified it will default to TCP | 15:21 |
*** amotoki has joined #openstack-fwaas | 15:22 | |
yushiro | I think it is better and easy to understand for CLI users. | 15:22 |
SridarK | ok some more thinking is needed too | 15:22 |
SridarK | let me also look at the code | 15:22 |
yushiro | Yes. | 15:22 |
SridarK | also we can check on iptables | 15:23 |
yushiro | Yes also. | 15:23 |
SridarK | i agree that this is confusing | 15:23 |
SridarK | it is very late for u | 15:24 |
SridarK | we can discuss on email or i will ping u during ur morning | 15:24 |
*** brenda_ has joined #openstack-fwaas | 15:24 | |
yushiro | OK. Thank you for your kindness :) | 15:24 |
SridarK | oh pls no worries | 15:24 |
SridarK | we can also discuss more on the L2Agent with padkrish | 15:24 |
SridarK | tomorrow morning ur time | 15:25 |
SridarK | yushiro: anything else to discuss ? | 15:25 |
yushiro | SridarK, nothing. Maybe tomorrow, I'll ask you about default fwg. | 15:26 |
*** amotoki has quit IRC | 15:26 | |
SridarK | yushiro: ok then | 15:26 |
SridarK | Good Night | 15:26 |
yushiro | See you. | 15:26 |
*** yushiro has quit IRC | 15:26 | |
*** amotoki has joined #openstack-fwaas | 15:26 | |
*** amotoki has quit IRC | 15:27 | |
*** brenda_ has quit IRC | 15:27 | |
*** amotoki has joined #openstack-fwaas | 15:27 | |
*** brenda_ has joined #openstack-fwaas | 15:28 | |
brenda_ | Can we have a discussion about https://review.openstack.org/#/c/423161/ | 15:29 |
brenda_ | There are different opions about if we should set ‘audited’ to False automatically after insert rule or remove rule from a firewall policy. | 15:33 |
*** brenda_ has quit IRC | 15:35 | |
*** brenda_ has joined #openstack-fwaas | 15:36 | |
*** brenda_ has left #openstack-fwaas | 15:39 | |
*** amotoki has quit IRC | 15:41 | |
*** amotoki has joined #openstack-fwaas | 15:57 | |
*** reedip has quit IRC | 16:02 | |
*** reedip has joined #openstack-fwaas | 16:16 | |
*** reedip_ has joined #openstack-fwaas | 16:40 | |
reedip_ | hi | 16:41 |
reedip_ | sorry was out so couldnt attend the meeting today | 16:41 |
reedip_ | hi SridarK | 17:17 |
SridarK | reedip_: Hi | 17:18 |
reedip_ | SridarK : I was checking https://review.openstack.org/#/c/424534/1 | 17:18 |
reedip_ | It is related to demonstrating public resources to other projects | 17:19 |
SridarK | we were going to discuss this but it was late for Yushiro | 17:19 |
SridarK | i am quite confused on this too | 17:19 |
SridarK | perhaps ur morning time tomorrow we can continue this discussion | 17:20 |
reedip_ | SridarK : I get his intention, public firewalls must be visible to other tenants | 17:20 |
reedip_ | SridarK : I will be in office early tomorrow probably, so yes | 17:20 |
SridarK | yes that is correct seems we have some issues with public and shared | 17:20 |
reedip_ | my only objection is the overwritten function | 17:20 |
SridarK | reedip_: ok lets do that then - i think we need to understand this more | 17:20 |
SridarK | reedip_: ok - i will be heading in to work now so will go offline | 17:21 |
reedip_ | SridarK : ok, sure. Even if I am not there, you can continue and I will discuss with him as we have similar work time ( he is JST ) | 17:21 |
reedip_ | have a good day SridarK :) | 17:21 |
SridarK | reedip_: yes absolutely | 17:21 |
SridarK | reedip_: thx and Good evening/Night | 17:21 |
reedip_ | its 11 PM , so night would be a good call :) | 17:24 |
*** amotoki has quit IRC | 17:38 | |
*** mickeys has joined #openstack-fwaas | 17:38 | |
*** reedip_ has quit IRC | 17:59 | |
*** amotoki has joined #openstack-fwaas | 18:04 | |
*** amotoki has quit IRC | 18:06 | |
*** SridarK has quit IRC | 18:24 | |
*** SridarK_ has joined #openstack-fwaas | 19:21 | |
*** SridarK_ has quit IRC | 20:47 | |
*** yamamoto has joined #openstack-fwaas | 21:08 | |
*** yamamoto has quit IRC | 21:12 | |
*** amotoki has joined #openstack-fwaas | 22:02 | |
*** yamamoto has joined #openstack-fwaas | 22:17 | |
*** amotoki has quit IRC | 23:15 | |
*** amotoki has joined #openstack-fwaas | 23:22 | |
*** amotoki has quit IRC | 23:42 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!