*** yamamoto has joined #openstack-fwaas | 00:02 | |
*** threestrands has quit IRC | 00:21 | |
*** yamamoto has quit IRC | 00:45 | |
*** yamamoto has joined #openstack-fwaas | 01:24 | |
*** annp has joined #openstack-fwaas | 01:56 | |
*** yamamoto has quit IRC | 02:22 | |
*** yamamoto has joined #openstack-fwaas | 02:24 | |
*** vks1 has joined #openstack-fwaas | 02:26 | |
*** yamamoto has quit IRC | 02:40 | |
*** yamamoto has joined #openstack-fwaas | 02:54 | |
*** threestrands has joined #openstack-fwaas | 02:55 | |
*** yamamoto has quit IRC | 03:05 | |
*** AlexeyAbashkin has joined #openstack-fwaas | 04:15 | |
*** AlexeyAbashkin has quit IRC | 04:20 | |
*** yamamoto has joined #openstack-fwaas | 05:39 | |
*** yamamoto has quit IRC | 05:43 | |
*** yamamoto has joined #openstack-fwaas | 05:53 | |
*** yamamoto has quit IRC | 05:57 | |
*** vks1 has quit IRC | 06:10 | |
*** eN_Guruprasad_Rn has joined #openstack-fwaas | 06:16 | |
*** vks1 has joined #openstack-fwaas | 06:25 | |
*** yamamoto has joined #openstack-fwaas | 06:31 | |
*** yamamoto has quit IRC | 06:43 | |
*** threestrands has quit IRC | 06:50 | |
*** yamamoto has joined #openstack-fwaas | 06:59 | |
*** yamamoto has quit IRC | 07:06 | |
*** yamamoto has joined #openstack-fwaas | 07:49 | |
*** yamamoto has quit IRC | 07:51 | |
*** yamamoto has joined #openstack-fwaas | 07:57 | |
*** AlexeyAbashkin has joined #openstack-fwaas | 08:06 | |
*** yamamoto has quit IRC | 08:33 | |
*** yamamoto has joined #openstack-fwaas | 08:40 | |
*** AlexeyAbashkin has quit IRC | 08:41 | |
*** AlexeyAbashkin has joined #openstack-fwaas | 08:42 | |
*** yamamoto has quit IRC | 08:44 | |
*** yamamoto has joined #openstack-fwaas | 09:04 | |
*** yamamoto has quit IRC | 09:19 | |
*** eN_Guruprasad_Rn has quit IRC | 09:19 | |
*** eN_Guruprasad_Rn has joined #openstack-fwaas | 09:19 | |
*** xgerman_ has quit IRC | 10:09 | |
*** fyxim has quit IRC | 10:09 | |
*** xgerman_ has joined #openstack-fwaas | 10:15 | |
*** fyxim has joined #openstack-fwaas | 10:15 | |
*** annp has quit IRC | 10:23 | |
openstackgerrit | Akihiro Motoki proposed openstack/neutron-fwaas-dashboard master: Some more cleanup around tox_install.sh https://review.openstack.org/524132 | 10:39 |
---|---|---|
*** hoangcx has quit IRC | 10:43 | |
*** hoangcx has joined #openstack-fwaas | 10:44 | |
*** yamamoto has joined #openstack-fwaas | 12:37 | |
*** yamamoto has quit IRC | 13:04 | |
*** yamamoto has joined #openstack-fwaas | 13:05 | |
*** vks1 has quit IRC | 13:26 | |
*** vks1 has joined #openstack-fwaas | 13:34 | |
*** hoangcx_ has joined #openstack-fwaas | 13:54 | |
*** annp has joined #openstack-fwaas | 13:55 | |
*** chandanc has joined #openstack-fwaas | 13:57 | |
*** yushiro has joined #openstack-fwaas | 13:58 | |
yushiro | Hi fwaas folks | 14:00 |
annp | hi yushiro and all | 14:01 |
yushiro | xgerman_, I was absent for last meeting. So, I'll chair today. | 14:01 |
yushiro | #startmeeting fwaas | 14:01 |
openstack | Meeting started Thu Nov 30 14:01:45 2017 UTC and is due to finish in 60 minutes. The chair is yushiro. Information about MeetBot at http://wiki.debian.org/MeetBot. | 14:01 |
openstack | Useful Commands: #action #agreed #help #info #idea #link #topic #startvote. | 14:01 |
*** openstack changes topic to " (Meeting topic: fwaas)" | 14:01 | |
openstack | The meeting name has been set to 'fwaas' | 14:01 |
chandanc | Hello | 14:01 |
yushiro | #chair xgerman_ yushiro | 14:02 |
openstack | Current chairs: xgerman_ yushiro | 14:02 |
yushiro | chandanc, hi, long time no see :) | 14:02 |
chandanc | Hello yushiro | 14:02 |
*** SridarK has joined #openstack-fwaas | 14:02 | |
yushiro | SridarK, Hi! | 14:02 |
SridarK | Hi All | 14:02 |
yushiro | #chair SridarK | 14:02 |
openstack | Current chairs: SridarK xgerman_ yushiro | 14:02 |
yushiro | OK, we just started now. Good timing :) | 14:03 |
SridarK | I think according to our etherpad - today is my turn | 14:03 |
yushiro | Ah, OK SridarK and sorry I was absent last meeting. | 14:03 |
SridarK | but yushiro if u have started running already | 14:03 |
SridarK | pls go ahead | 14:04 |
yushiro | Sure | 14:04 |
yushiro | #topic Queens | 14:04 |
*** openstack changes topic to "Queens (Meeting topic: fwaas)" | 14:04 | |
SridarK | yushiro: yes no worries | 14:04 |
yushiro | 1. l2-agent | 14:04 |
yushiro | oops, 1. l2-agent 2.OVS firewall 3. co-existing Now we are talking about '1.' | 14:05 |
yushiro | #link https://review.openstack.org/#/c/323971/ | 14:05 |
SridarK | annp: i think ur last update on PS77 | 14:05 |
annp | SridarK, yes. | 14:06 |
yushiro | Now, this patch is independent and annp added 'sg_enabled' flag on it. | 14:06 |
SridarK | took care of checking the enable flag | 14:06 |
SridarK | yes | 14:06 |
SridarK | I am checking that and can do a +2 soon | 14:07 |
yushiro | SridarK, Good. In my point of view, there is no issue now. | 14:07 |
SridarK | yushiro: +1 | 14:07 |
annp | +1 yushiro | 14:07 |
yushiro | annp, if you feel there is no issue, plz put +1 :) | 14:07 |
annp | yushiro Sure. :) | 14:08 |
yushiro | hoangcx, I'd like to ask you to check this patch either. | 14:08 |
annp | yushiro, Done. | 14:08 |
yushiro | OK, I'll check it again and start updating 'auto-association default fwg patch'. | 14:09 |
SridarK | yushiro: sounds good | 14:09 |
yushiro | OK, let's move next patch. | 14:09 |
yushiro | [1. l2-agent **2.OVS firewall 3. co-existing] | 14:10 |
yushiro | #link https://review.openstack.org/#/c/447251/54 | 14:10 |
yushiro | chandanc, and annp has updated. Could you tell me some updates? | 14:10 |
yushiro | s/me/us | 14:11 |
annp | regarding to ovs firewall driver patch: i added handling for port no security group in standalone mode of fwg | 14:11 |
chandanc | annp did most of the update on OVS patch, the only change i proposed was to move the sg_enabled detection logic to the agent | 14:11 |
annp | chandanc, yes. | 14:12 |
yushiro | chandanc, annp OK, I see. Thanks for your update :) | 14:12 |
annp | I also added explicit drop flows for deny and reject rules | 14:12 |
annp | finally, I added generating flow's priority for each fwg rule to respect rule ordering. | 14:13 |
SridarK | annp: so on a FWaaS deny we will drop at this table | 14:14 |
SridarK | and on FWaaS permit - if SG is enabled then we will punt to SG | 14:15 |
annp | SridarK: yes. | 14:15 |
*** chandanc_ has joined #openstack-fwaas | 14:16 | |
yushiro | annp, In order to transit fwg to sg, we need https://review.openstack.org/#/c/515368/12 ? | 14:16 |
SridarK | annp: on drops there is only one caveat that SG logging will miss it | 14:16 |
annp | yushiro, yes. we need co-existence patch for co-existence mode. | 14:17 |
SridarK | if SG was also enabled once we have SG logging | 14:17 |
*** chandanc has quit IRC | 14:18 | |
annp | SridarK: yes, security group logging will miss drop packets. I think it should be documented in case co-existence | 14:18 |
yushiro | SridarK, ah, yes. | 14:18 |
*** chandanc_ has quit IRC | 14:18 | |
SridarK | annp: yushiro: yes that is a caveat we can fix with documentation | 14:18 |
*** chandanc has joined #openstack-fwaas | 14:18 | |
SridarK | ok we are on the same page | 14:19 |
chandanc | sorry facing connection issue | 14:19 |
hoangcx_ | Or can we add more validation to handle it? | 14:19 |
yushiro | chandanc, NP. I hope your connection become stable :) | 14:19 |
annp | hoangcx_: what do you mean? validation? | 14:20 |
SridarK | hoangcx_: are u asking on the logging issue ? | 14:20 |
chandanc | thanks yushiro :) | 14:20 |
hoangcx_ | Sorry, it will not work. I think documentation is better. | 14:20 |
annp | hoangcx_: +1 | 14:20 |
SridarK | if so we want the logging stats to reflect - we will incur a performance penalty too | 14:21 |
SridarK | yes doc is better | 14:21 |
hoangcx_ | SridarK: +1 | 14:21 |
SridarK | anyways we will support Logging on FWaaS too once SG is done | 14:21 |
yushiro | So, we should implement fwaas logging ASAP :) | 14:22 |
SridarK | :-) | 14:22 |
yushiro | Aha, SridarK +1 | 14:22 |
annp | SridarK: yeah. +1 | 14:22 |
chandanc | sure | 14:22 |
yushiro | annp, Your co-existing patch is 'PoC'. I haven't tested this patch yet. Is it work now? | 14:23 |
annp | yushiro, yes, It work fine now. | 14:23 |
chandanc | yes i could do some tests | 14:23 |
yushiro | annp, If it works correctly, could you remove 'PoC' from commit msg? | 14:23 |
yushiro | chandanc, OK, sounds good. | 14:24 |
annp | Regarding to co-existing patch, chandanc: do you want to update? | 14:24 |
chandanc | annp: i dont think i will be updating it for now | 14:24 |
annp | yushiro, Sure, I will remove that. | 14:24 |
chandanc | will have to wait for feedback | 14:24 |
chandanc | I have update the ppt to the latest implementation | 14:25 |
chandanc | https://docs.google.com/presentation/d/1tRf-JQQiF0v_BdJahDjraxSEgz3c41YGdzHj3ui1C0Q/edit#slide=id.g29cfa03b8a_0_56 | 14:25 |
yushiro | 1 feedback for this patch. Please write releasenote about an effect for logging feature. | 14:25 |
annp | chandanc, I think so too. We are waiting feedback from yushiro, SridarK, xgerman_, ... for that | 14:25 |
yushiro | I'll comment on it. | 14:26 |
yushiro | after this meeting. | 14:26 |
xgerman_ | o/ | 14:26 |
SridarK | annp: will do | 14:26 |
annp | SridarK, Yushiro, xgerman_: Thanks :) | 14:26 |
yushiro | OK, Q-2 is only 4 days or ... We'll do our best. | 14:27 |
yushiro | Anything else for this topic? | 14:27 |
annp | that's all from me | 14:28 |
yushiro | OK, let's move on next topic. | 14:28 |
*** chandanc_ has joined #openstack-fwaas | 14:28 | |
yushiro | #topic Horizon support | 14:28 |
*** openstack changes topic to "Horizon support (Meeting topic: fwaas)" | 14:28 | |
yushiro | chandanc, Do you know Sarath today? | 14:29 |
yushiro | #link https://bugs.launchpad.net/neutron-fwaas-dashboard | 14:29 |
*** chandanc has quit IRC | 14:30 | |
*** chandanc_ is now known as chandanc | 14:30 | |
yushiro | All of bugs or backlog were listed on launchpad now. | 14:30 |
chandanc | not sure about him, he got into some office work | 14:30 |
yushiro | chandanc, OK, thank you. | 14:30 |
SridarK | I think we had a few minor issues and will be good to be ready with L2 support | 14:31 |
xgerman_ | yes, I think it was mostly good | 14:31 |
yushiro | Yeah. I think this is worth to fix it: 'ip_version' doesn't exist in detail firewall rule view' - https://bugs.launchpad.net/neutron-fwaas-dashboard/+bug/1728838 | 14:32 |
openstack | Launchpad bug 1728838 in Neutron FWaaS dashboard "'ip_version' doesn't exist in detail firewall rule view" [Undecided,New] | 14:32 |
amotoki | if you need to be a bug supervisor, feel free to request to join a team. | 14:33 |
amotoki | we need to expand the bug team | 14:33 |
yushiro | amotoki, Thanks. | 14:34 |
SridarK | +1 | 14:34 |
yushiro | amotoki, you mean $B!H(BNeutron FWaaS dashboard Driver Team$B!I(B team ? | 14:35 |
yushiro | ah, duplicated 'team' :) | 14:35 |
amotoki | some japanese chars are included???? | 14:35 |
amotoki | yushiro: yes, neutron-fwaas-dashboard is a separate launchpad project, so it has a separate team. | 14:36 |
amotoki | if you are okay, I can add neutron-bugs team to the neutron-fwaas-dashboard bug team in launchpad | 14:36 |
amotoki | it might be more reasonable solution | 14:37 |
yushiro | Ah, I think it's OK. How about you, SridarK and xgerman_ ? | 14:37 |
xgerman_ | +1 | 14:37 |
SridarK | yes i think tht works | 14:37 |
xgerman_ | we are part of the community | 14:37 |
amotoki | thanks. I will update it soon | 14:38 |
yushiro | Yes (^_^)v | 14:38 |
amotoki | ah, i noticed a better approach. I can set neutron-bugs team as the bug supervisor of neutron-fwaas-dashboard :) | 14:38 |
*** chandanc has quit IRC | 14:38 | |
amotoki | done | 14:39 |
yushiro | amotoki, Thanks for your quick update | 14:39 |
xgerman_ | +1 | 14:39 |
SridarK | yes thx amotoki | 14:39 |
yushiro | OK, let's move next topic. | 14:40 |
*** chandanc has joined #openstack-fwaas | 14:40 | |
yushiro | #topic Stadium Compliance | 14:40 |
*** openstack changes topic to "Stadium Compliance (Meeting topic: fwaas)" | 14:40 | |
yushiro | Is reedip here? | 14:40 |
yushiro | OK, maybe today he is off I think. | 14:41 |
yushiro | OK, let's move on next topic. | 14:42 |
yushiro | #topic bugs | 14:42 |
*** openstack changes topic to "bugs (Meeting topic: fwaas)" | 14:42 | |
yushiro | #link http://urx2.nu/C7UI | 14:42 |
xgerman_ | we need to classify the undecided ones | 14:44 |
yushiro | yes. | 14:45 |
yushiro | I'll check it after this meeting. | 14:45 |
xgerman_ | thanks — I can go through them as well | 14:46 |
yushiro | xgerman_, NP :) | 14:46 |
SridarK | lets maybe meet for 30 mins on Mon or Tue and run thru them ? | 14:46 |
xgerman_ | ok, works for me | 14:46 |
yushiro | Sure. | 14:46 |
SridarK | We can look thru and decide amongst us quickly | 14:46 |
xgerman_ | +1 | 14:46 |
yushiro | +1+1 | 14:46 |
SridarK | We can meet during yushiro's day time | 14:47 |
SridarK | will make it easier on xgerman_ and myself | 14:47 |
SridarK | as well | 14:47 |
SridarK | will be our evening | 14:47 |
yushiro | Wow, thanks :) I think it's ok for same time for this meeting. | 14:47 |
yushiro | #topic Open Discussion | 14:48 |
*** openstack changes topic to "Open Discussion (Meeting topic: fwaas)" | 14:48 | |
SridarK | doude: i have not got to ur changes yes | 14:48 |
SridarK | *yet | 14:48 |
SridarK | as soon as L2 is done i can start looking | 14:48 |
doude | Hi | 14:48 |
doude | ok I'm waiting lé merge | 14:48 |
doude | s/lé/l2 | 14:49 |
SridarK | doude: yes | 14:49 |
yushiro | doude, Hi. since Sydney :) | 14:49 |
doude | I"m in starting blocks | 14:49 |
doude | Hi yushiro | 14:49 |
yushiro | Just an announcement: PTG will be held in Dublin at Feb. https://www.openstack.org/ptg/ | 14:49 |
yushiro | Also there is Travel Support Program here: https://www.openstack.org/ptg/#tab_travel | 14:50 |
xgerman_ | ok, I have plane tickets ;-) | 14:51 |
yushiro | January 4, 2018: Deadline to submit applications for Round One approvals | 14:51 |
xgerman_ | k | 14:51 |
yushiro | January 25, 2018: Deadline to submit applications for Round Two approvals | 14:51 |
yushiro | I strongly hope to meet members in Dublin :) Of course, I'll register TSP! | 14:52 |
SridarK | i am not sure yet | 14:52 |
doude | not sure yet also | 14:52 |
yushiro | haha, me too :) I'll try it. | 14:53 |
yushiro | Q-2 is Dec 04 - Dec 08. | 14:55 |
yushiro | FWaaS team can help each other and I believe we can do it :) | 14:56 |
xgerman_ | yeah, we *really* need to get L2 in by then | 14:56 |
yushiro | +1 | 14:56 |
SridarK | +1 | 14:56 |
xgerman_ | yushiro do you recall if we ever officially release the V2 API? | 14:56 |
yushiro | xgerman_, let me see.. I think no need to do that because we don't change V2 API. | 14:58 |
xgerman_ | I want to change V2 ;-) | 14:58 |
xgerman_ | I am adding remote fwg | 14:59 |
hoangcx_ | with remote fgw? | 14:59 |
xgerman_ | yes | 14:59 |
yushiro | Ah, like SG 'remote_group_id'. | 14:59 |
xgerman_ | yep, was in our spec | 14:59 |
xgerman_ | now I am wondering if I need an Extension or not | 14:59 |
xgerman_ | if we never released Not… | 15:00 |
yushiro | I think it's OK to add with reno. | 15:01 |
yushiro | Oh, it's over time :) | 15:01 |
yushiro | #endmeeting | 15:01 |
*** openstack changes topic to "#openstack-fwaas" | 15:01 | |
xgerman_ | k | 15:01 |
openstack | Meeting ended Thu Nov 30 15:01:13 2017 UTC. Information about MeetBot at http://wiki.debian.org/MeetBot . (v 0.1.4) | 15:01 |
openstack | Minutes: http://eavesdrop.openstack.org/meetings/fwaas/2017/fwaas.2017-11-30-14.01.html | 15:01 |
openstack | Minutes (text): http://eavesdrop.openstack.org/meetings/fwaas/2017/fwaas.2017-11-30-14.01.txt | 15:01 |
openstack | Log: http://eavesdrop.openstack.org/meetings/fwaas/2017/fwaas.2017-11-30-14.01.log.html | 15:01 |
xgerman_ | o/ | 15:01 |
yushiro | SridarK, How do you think about adding an attribute into v2 API like 'remote_group_id'? | 15:02 |
SridarK | yushiro: i think it is ok - worst case we will need an extension | 15:03 |
yushiro | SridarK, OK, so we're on same page now. | 15:03 |
annp | xgerman_ do you want remote_group_id on L3 side or l2 side or both of them? | 15:03 |
*** hoangcx_ has quit IRC | 15:05 | |
annp | xgerman_: Just a question :) | 15:05 |
yushiro | Good point. In L3, we need to translate from fwg to IP addresses and insert into iptables by using ipset or some command I think. | 15:07 |
*** eN_Guruprasad_Rn has quit IRC | 15:07 | |
annp | In l2 we can use conjunct flows to do that. | 15:09 |
yushiro | annp, yeah, we have feasibility for both I think. | 15:10 |
annp | But conjunct flows are quite complicated. It will take our time. | 15:10 |
yushiro | OK. | 15:11 |
yushiro | I'll leave it now... good night. | 15:11 |
*** yushiro has quit IRC | 15:11 | |
annp | good night! | 15:11 |
annp | see you guys, thank you. | 15:12 |
*** annp has quit IRC | 15:12 | |
*** chandanc has quit IRC | 15:29 | |
-openstackstatus- NOTICE: if you receieved a result of "RETRY_LIMIT" after 14:15 UTC, it was likely due to an error since corrected. please "recheck" | 15:37 | |
*** yamamoto has quit IRC | 15:49 | |
*** yamamoto has joined #openstack-fwaas | 15:50 | |
xgerman_ | annp I can see it for both L2 and L3 — | 15:51 |
*** eN_Guruprasad_Rn has joined #openstack-fwaas | 15:52 | |
*** eN_Guruprasad_Rn has quit IRC | 16:08 | |
*** AlexeyAbashkin has quit IRC | 17:01 | |
*** SumitNaiksatam has joined #openstack-fwaas | 17:53 | |
*** vks1 has quit IRC | 18:10 | |
*** SridarK has quit IRC | 18:14 | |
*** openstackgerrit has quit IRC | 18:48 | |
*** AlexeyAbashkin has joined #openstack-fwaas | 19:52 | |
*** AlexeyAbashkin has quit IRC | 19:59 | |
*** SumitNaiksatam has quit IRC | 20:00 | |
*** AlexeyAbashkin has joined #openstack-fwaas | 20:12 | |
*** AlexeyAbashkin has quit IRC | 20:17 | |
*** threestrands has joined #openstack-fwaas | 21:12 | |
*** openstackgerrit has joined #openstack-fwaas | 22:52 | |
openstackgerrit | German Eichberger proposed openstack/neutron-fwaas master: [WIP] Adds remote firewall group https://review.openstack.org/521207 | 22:52 |
*** AlexeyAbashkin has joined #openstack-fwaas | 23:12 | |
*** AlexeyAbashkin has quit IRC | 23:16 |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!