*** hoangcx has quit IRC | 00:01 | |
*** hoangcx_ is now known as hoangcx | 00:03 | |
*** yamamoto has joined #openstack-fwaas | 00:36 | |
*** yamamoto has quit IRC | 00:41 | |
*** hoangcx has quit IRC | 00:42 | |
*** hoangcx has joined #openstack-fwaas | 00:43 | |
*** threestrands has joined #openstack-fwaas | 01:05 | |
*** longkb has joined #openstack-fwaas | 01:15 | |
*** longkb2 has joined #openstack-fwaas | 01:21 | |
*** longkb has quit IRC | 01:22 | |
*** longkb has joined #openstack-fwaas | 01:27 | |
*** longkb2 has quit IRC | 01:28 | |
*** yamamoto has joined #openstack-fwaas | 01:38 | |
*** yamamoto has quit IRC | 01:44 | |
*** yamamoto has joined #openstack-fwaas | 01:50 | |
*** annp has joined #openstack-fwaas | 02:12 | |
*** longkb2 has joined #openstack-fwaas | 02:16 | |
*** longkb has quit IRC | 02:18 | |
*** longkb2 has quit IRC | 03:48 | |
*** longkb has joined #openstack-fwaas | 03:55 | |
*** longkb has quit IRC | 05:48 | |
*** longkb has joined #openstack-fwaas | 05:59 | |
bzhao__ | Hi guys, could u please describe the relationship between the fw v2 and neutron SG? | 06:55 |
---|---|---|
bzhao__ | I'm not sure whether we support both sg and fw apply on a single port for a long time? | 06:55 |
openstackgerrit | OpenStack Proposal Bot proposed openstack/neutron-fwaas-dashboard master: Imported Translations from Zanata https://review.openstack.org/565653 | 06:58 |
*** threestrands has quit IRC | 06:58 | |
openstackgerrit | Akihiro Motoki proposed openstack/neutron-fwaas-dashboard master: FWaaS v2 dashbaord: clean up unnecessary get_dict() methods https://review.openstack.org/565978 | 07:03 |
*** yamamoto has quit IRC | 10:21 | |
*** hoangcx has quit IRC | 10:21 | |
*** longkb has quit IRC | 10:37 | |
*** yamamoto has joined #openstack-fwaas | 10:37 | |
*** annp has quit IRC | 10:40 | |
*** yamamoto has quit IRC | 11:48 | |
*** yamamoto has joined #openstack-fwaas | 11:55 | |
*** yamamoto_ has joined #openstack-fwaas | 11:56 | |
*** yamamoto_ has quit IRC | 11:57 | |
*** yamamoto_ has joined #openstack-fwaas | 11:59 | |
*** yamamoto has quit IRC | 12:00 | |
*** yamamoto_ has quit IRC | 12:02 | |
*** yamamoto has joined #openstack-fwaas | 12:13 | |
*** yamamoto has quit IRC | 12:20 | |
*** yamamoto has joined #openstack-fwaas | 12:21 | |
*** yamamoto has quit IRC | 12:26 | |
*** njohnston has quit IRC | 12:29 | |
*** njohnston has joined #openstack-fwaas | 12:31 | |
*** hoangcx has joined #openstack-fwaas | 12:47 | |
*** hoangcx has quit IRC | 13:01 | |
*** hoangcx has joined #openstack-fwaas | 13:02 | |
*** yamamoto has joined #openstack-fwaas | 13:11 | |
*** yamamoto has quit IRC | 13:17 | |
*** yamamoto has joined #openstack-fwaas | 13:17 | |
*** yamamoto has quit IRC | 13:22 | |
*** wkite has joined #openstack-fwaas | 13:56 | |
*** wkite has quit IRC | 13:57 | |
*** wkite has joined #openstack-fwaas | 13:57 | |
*** SridarK has joined #openstack-fwaas | 13:58 | |
SridarK | Hi FWaaS folks | 14:00 |
wkite | hi | 14:00 |
SridarK | #startmeeting fwaas | 14:00 |
openstack | Meeting started Thu May 3 14:00:40 2018 UTC and is due to finish in 60 minutes. The chair is SridarK. Information about MeetBot at http://wiki.debian.org/MeetBot. | 14:00 |
openstack | Useful Commands: #action #agreed #help #info #idea #link #topic #startvote. | 14:00 |
*** openstack changes topic to " (Meeting topic: fwaas)" | 14:00 | |
openstack | The meeting name has been set to 'fwaas' | 14:00 |
SridarK | #chair xgerman_ | 14:00 |
openstack | Current chairs: SridarK xgerman_ | 14:00 |
*** reedip_ has joined #openstack-fwaas | 14:00 | |
SridarK | yushiro is out this week on time off | 14:01 |
reedip_ | o/ | 14:01 |
doude | hi | 14:02 |
SridarK | #topic announcements | 14:02 |
*** openstack changes topic to "announcements (Meeting topic: fwaas)" | 14:02 | |
*** ndefigueiredo has joined #openstack-fwaas | 14:02 | |
*** annp has joined #openstack-fwaas | 14:03 | |
xgerman_ | o/ | 14:03 |
annp | hi | 14:03 |
xgerman_ | So the new TC got lected | 14:03 |
SridarK | PTG announcement - it will be in Denver in Sep - if folks want to plan for it | 14:04 |
xgerman_ | #link https://governance.openstack.org/election/results/rocky/tc.html | 14:04 |
xgerman_ | yesh, train 2.0 | 14:04 |
SridarK | xgerman_: :-) | 14:05 |
SridarK | although i saw email that it will be better this time | 14:05 |
SridarK | any other announcements from folks ? | 14:05 |
SridarK | xgerman_: | 14:05 |
reedip_ | I might miss it :( | 14:05 |
SridarK | reedip_: I am not sure either it is a bit early to decide | 14:06 |
SridarK | ok lets move on | 14:07 |
SridarK | #topic Rocky Pluggable backend driver | 14:07 |
*** openstack changes topic to "Rocky Pluggable backend driver (Meeting topic: fwaas)" | 14:07 | |
SridarK | doude: pls go ahead | 14:07 |
doude | I fixed the issue raised in reviews | 14:09 |
doude | and pushed a new patch set #20 last week | 14:09 |
doude | I also send a answer to NSX developper today | 14:09 |
SridarK | annp: thx for the tests | 14:10 |
xgerman_ | +1 | 14:10 |
annp | doude, SridarK, I tried to tested with latest patch, It worked fine in my environment. | 14:10 |
SridarK | annp: great | 14:10 |
annp | SridarK, Have you tested with latest patch? | 14:10 |
doude | thanks for your feedback annp | 14:10 |
SridarK | doude: sounds good - i think we can confirm with the NSX folks | 14:11 |
annp | doube, you're welcome | 14:11 |
SridarK | then we should be good | 14:11 |
annp | SridarK, +1 | 14:11 |
SridarK | annp: no i have not yet - will do so tomorrow | 14:11 |
annp | +1 | 14:11 |
doude | yes SridarK I also invite her to reach me on IRC to discuss it if needed | 14:11 |
SridarK | doude: perfect | 14:12 |
SridarK | and annp u have verfied on a multinode setup ? | 14:12 |
annp | SridarK, I haven't verfied on multiple node environment yet. | 14:13 |
annp | SridarK, I'm planing do this in tomorrow. | 14:13 |
SridarK | annp: ok, i recalled yushiro mentioning that | 14:13 |
SridarK | annp: oh ok good | 14:13 |
SridarK | doude: anything else u would like to discuss ? | 14:13 |
annp | I will comment on gerrit when i finish testing | 14:13 |
doude | no I'm good | 14:14 |
annp | doube, +1 :) | 14:15 |
SridarK | #topic Rocky Remote FWG | 14:15 |
*** openstack changes topic to "Rocky Remote FWG (Meeting topic: fwaas)" | 14:15 | |
SridarK | xgerman_: pls go ahead | 14:15 |
xgerman_ | ok, I am battling sql alchemy — somehow my model doesn’t align with the update scripts | 14:15 |
xgerman_ | I also started with the ovs conjecture stuff | 14:16 |
SridarK | xgerman_: i saw the other patch | 14:16 |
xgerman_ | yes, the conjecture is super interesting… and I also will need to do the router port stuff | 14:17 |
xgerman_ | if anyone wants to help I am happy to split accordingly | 14:17 |
annp | xgerman_, I can help you :) | 14:18 |
reedip_ | share the sql alchemy patch please :) | 14:18 |
xgerman_ | #link https://review.openstack.org/#/c/521207/ | 14:18 |
SridarK | xgerman_: as a usecase would the Router port be just as important as the L2 port as well ? | 14:18 |
xgerman_ | the remote fwg resolve to the ip addresses on the ports. So you would drop/deny/accept traffic if those ips are in src/dst | 14:19 |
xgerman_ | that looked like a router port application | 14:19 |
SridarK | yes agree | 14:20 |
*** yamamoto has joined #openstack-fwaas | 14:20 | |
xgerman_ | though if you have L2 that might be redundant | 14:20 |
annp | xgerman_, +1 | 14:22 |
SridarK | sounds good, i have to understand the mapping on the driver side | 14:23 |
*** ndefigueiredo has quit IRC | 14:24 | |
SridarK | xgerman_: anything else u would like to discuss | 14:24 |
xgerman_ | no, that’s all | 14:24 |
SridarK | ok lets move on | 14:24 |
SridarK | #topic Rocky FWaaS Logging Spec | 14:24 |
*** openstack changes topic to "Rocky FWaaS Logging Spec (Meeting topic: fwaas)" | 14:24 | |
SridarK | annp: pls go ahead | 14:24 |
annp | There is one question from amotoki | 14:25 |
annp | I'm not sure whether we need a L3 logging extension same fwaas v2 or not. | 14:26 |
amotoki | in my understanding, ovs flows for logging are installed by l2-agent, but iptables rule in l3 netns will be installed by l3-agent. | 14:26 |
amotoki | this is the reason of my question | 14:27 |
annp | amotoki, So we need a l3 logging extension, right? | 14:27 |
amotoki | annp: I am not sure on the point honestly | 14:28 |
amotoki | at least it sounds odd to me that l2-agent extension manages l3 iptable rules. | 14:28 |
xgerman_ | yeah, l2 will only see packets l3 passed | 14:28 |
amotoki | I believe iptables in router netns should be managed by l3-agent | 14:29 |
xgerman_ | +1 | 14:29 |
annp | amotoki, yes. So it's better to follow fwaas v2 worked | 14:29 |
amotoki | annp: what do mean by "follow fwaas v2 worked" ? | 14:29 |
annp | amotoki, I mean we will have l3 logging extension | 14:30 |
amotoki | okay | 14:30 |
annp | amotoki, Do we need to mention this point on spec? | 14:31 |
amotoki | annp: I believe so. | 14:31 |
annp | amotoki, Agree! | 14:31 |
amotoki | this is related to what agent extension we need to implement it. | 14:31 |
annp | amotoki, I will update spec. Thanks | 14:32 |
amotoki | apart from that, I see no other blocking issue in the spec. | 14:32 |
annp | amotoki, +1 | 14:32 |
SridarK | annp: i think u are clear on the driver aspect but perhaps u just need to clear up on the agent ext | 14:32 |
annp | SridarK, yeah. It should be clearly. | 14:33 |
annp | SridarK, that's all for fwaas logging spec | 14:34 |
amotoki | I just concerned l3 stuff is managed by l2 agent ext when I read the spec. I believe we are in the same page. | 14:34 |
annp | amotoki, yes, we're same page now :) Thanks. | 14:34 |
SridarK | +1 | 14:34 |
SridarK | ok sounds good - | 14:34 |
amotoki | :) | 14:35 |
annp | :) | 14:35 |
annp | SridarK, please move on | 14:35 |
SridarK | #topic Rocky Address Group Spec | 14:35 |
*** openstack changes topic to "Rocky Address Group Spec (Meeting topic: fwaas)" | 14:35 | |
SridarK | wkite: pls go ahead | 14:35 |
SridarK | #link https://review.openstack.org/557137 | 14:35 |
SridarK | request folks to take a look as well | 14:36 |
*** ndefigueiredo has joined #openstack-fwaas | 14:36 | |
SridarK | wkite: would u like to discuss something here | 14:37 |
SridarK | wkite: thx for addressing the comments from before | 14:37 |
SridarK | ok if nothing lets move on | 14:38 |
SridarK | #topic Stateless Firewall | 14:38 |
*** openstack changes topic to "Stateless Firewall (Meeting topic: fwaas)" | 14:38 | |
SridarK | ndefigueiredo: hi | 14:38 |
SridarK | ndefigueiredo: would u like to update on any recent activity | 14:39 |
ndefigueiredo | Hi all, unfortunately I have not been able to work on the stateless firewall. I have been engaged with setting up our third party CI. | 14:40 |
SridarK | ndefigueiredo: ok keep us updated on when things pick up and we can discuss | 14:40 |
SridarK | #topic Open Discussion | 14:41 |
*** openstack changes topic to "Open Discussion (Meeting topic: fwaas)" | 14:41 | |
ndefigueiredo | yes, will do, once the CI is up and running I will be able to move on to actual Neutron development. | 14:41 |
amotoki | back to the past topic. just a maintenance question: I see a blueprint but do we have a RFE on the address group? | 14:42 |
SridarK | We have an action to triage bugs - we will get it done and then discuss | 14:42 |
reedip_ | We need to discuss the bugs | 14:42 |
reedip_ | which are open/in progress | 14:42 |
SridarK | wkite: ^^^ i think u were going to file an RFE | 14:42 |
SridarK | for Address Groups | 14:42 |
SridarK | reedip_: lets do some triage offline and bring it up in next mtg | 14:43 |
annp | xgerman, SridarK, Can you do me a favor? | 14:43 |
xgerman_ | sure | 14:43 |
SridarK | annp: sure | 14:43 |
amotoki | wkite: SridarK: it would be appreciated if you add a link to an RFE to the spec of address group. I just could not identify it. | 14:44 |
annp | xgerman, SridarK, yeah. Can you become moderator for topic https://etherpad.openstack.org/p/fwaas-v2-L7-filtering at vancouver's forum? | 14:44 |
SridarK | annp: sure | 14:44 |
SridarK | annp: is there some procedure to be followed or u can just add us ? | 14:45 |
annp | xgerman, SridarK, I'm afraid my english not enough to discussion :( | 14:45 |
SridarK | amotoki: agreed, not sure if wkite stepped away | 14:45 |
SridarK | annp: i think ur English is good but we can help | 14:46 |
amotoki | SridarK: no problem. if needed, let's file it. | 14:46 |
*** yamamoto has quit IRC | 14:46 | |
annp | SridarK, I guess I just add u and xgerman_ but let me find out | 14:46 |
amotoki | annp: no worries on english. | 14:46 |
xgerman_ | annp: we will be there if added or not | 14:47 |
SridarK | annp: ok sounds good | 14:47 |
SridarK | xgerman_: +1 | 14:47 |
amotoki | regarding the forum topic, we can add questions in advance if we have. | 14:47 |
annp | amotoki, thank you. actually, I'm not confident about english skill and technical also :) | 14:48 |
reedip_ | sorry guys, but got to go... would be back next week ... thanks :) @SridarK: will do some more triaging offline | 14:48 |
amotoki | I wonder how the reference implement of L7 firewall would be. | 14:48 |
SridarK | reedip_: sounds good | 14:48 |
annp | amotoki, how about bpf? | 14:48 |
xgerman_ | +1 bpf | 14:49 |
SridarK | annp: we should also meet up earlier in Vancouver and have a discussion on some thoughts, usecase, potential implementation approaches | 14:49 |
xgerman_ | yes, being prepared is always good | 14:49 |
amotoki | annp: it is a good candidate. I am not sure at now what level of filtering bpf supports. | 14:49 |
annp | SridarK, sure. When will you reach out vancouver? | 14:49 |
SridarK | annp: I get there on Sun afternoon | 14:50 |
xgerman_ | I et there Sunday night and Monday are all the LBaaS talks | 14:50 |
annp | SridarK, I will get ther on Sun evening. | 14:50 |
SridarK | Ok we should set some time and location so we can meet | 14:51 |
amotoki | I think we can add more breakdown sub-topics to the etherpad :) | 14:51 |
annp | amotoki, let's me find out your question. | 14:51 |
*** reedip_ has quit IRC | 14:51 | |
amotoki | when is the session scheduled? | 14:51 |
SridarK | amotoki: yes we shd do that | 14:52 |
annp | amotoki, Thursday morning | 14:52 |
amotoki | nice, we have enough time at YVR :) | 14:52 |
SridarK | amotoki: would u also be available for some initial discussions ? | 14:52 |
amotoki | SridarK: I hope so. I can be there with 99% though I haven't got the final approval. | 14:53 |
SridarK | amotoki: oh ok - we will keep u in the loop | 14:53 |
amotoki | thanks | 14:53 |
annp | SridarK, amotoki, xgerman, How about Tuesday morning? | 14:55 |
SridarK | annp: yes that works | 14:55 |
SridarK | we can continue discussion in etherpad (may be a separate one we can use for coordination) | 14:56 |
amotoki | +1 | 14:56 |
annp | SridarK, +1 | 14:56 |
SridarK | annp: sounds good and we can discuss on the channel as well - if u want to a fix a time - pls send us an email | 14:58 |
SridarK | ok i think we are almost at time | 14:58 |
annp | SridarK, Sure. | 14:59 |
SridarK | thanks all for joining | 14:59 |
SridarK | #endmeeting | 14:59 |
*** openstack changes topic to "Queens (Meeting topic: fwaas)" | 14:59 | |
amotoki | annp: I added some rough topics at the top of the etherpad. | 14:59 |
openstack | Meeting ended Thu May 3 14:59:18 2018 UTC. Information about MeetBot at http://wiki.debian.org/MeetBot . (v 0.1.4) | 14:59 |
openstack | Minutes: http://eavesdrop.openstack.org/meetings/fwaas/2018/fwaas.2018-05-03-14.00.html | 14:59 |
openstack | Minutes (text): http://eavesdrop.openstack.org/meetings/fwaas/2018/fwaas.2018-05-03-14.00.txt | 14:59 |
openstack | Log: http://eavesdrop.openstack.org/meetings/fwaas/2018/fwaas.2018-05-03-14.00.log.html | 14:59 |
annp | amotoki, amazing, I just saw that. Thanks. | 14:59 |
*** AlexeyAbashkin has joined #openstack-fwaas | 15:00 | |
amotoki | annp: I believe that kind of categories would inspire more discussions | 15:00 |
annp | amotoki, SridarK, xgerman_, Thanks for your great help. shall we discuss on etherpad? | 15:00 |
xgerman_ | +1 | 15:01 |
amotoki | +1 | 15:01 |
SridarK | annp: no worries at all - we can continue refining on the etherpad | 15:01 |
annp | +1 :) | 15:01 |
SridarK | we can also discuss in the coming weeks before we get to vancouver | 15:02 |
*** hoangcx has quit IRC | 15:02 | |
*** AlexeyAbashkin has quit IRC | 15:03 | |
annp | SridarK, +1 | 15:03 |
xgerman_ | +1 | 15:04 |
*** wkite has quit IRC | 15:08 | |
annp | amotoki, you're superman :) Thanks for updating in the etherpad. | 15:10 |
amotoki | annp: super random topics :) | 15:10 |
annp | amotoki, Actually, I learned a lot from you with logging api and now l7 filtering :) | 15:12 |
amotoki | annp: three? year ago, my company abandoned fwaas support due to immaturity of fwaas v1 and varieties of vendor FW features... they are from my experiences. | 15:12 |
amotoki | differentiations of fw features are benefits of firewall vendors and it usually conflicts with common API. that's usual. | 15:13 |
annp | amotoki, yeah :) | 15:16 |
annp | amotoki, SridarK, xgerman: I have to go out now. See you | 15:18 |
annp | amotoki, Good night! | 15:19 |
annp | xgerman_, SridarK, Have a great day ahead. :) | 15:19 |
*** wkite has joined #openstack-fwaas | 15:19 | |
xgerman_ | o/ | 15:20 |
SridarK | bye | 15:20 |
*** annp has quit IRC | 15:20 | |
*** wkite has quit IRC | 15:22 | |
amotoki | o/ | 15:28 |
*** ndefigueiredo has quit IRC | 15:32 | |
*** yamamoto has joined #openstack-fwaas | 15:44 | |
*** yamamoto has quit IRC | 15:55 | |
*** lnicolas has joined #openstack-fwaas | 16:17 | |
*** SridarK has quit IRC | 17:28 | |
*** SumitNaiksatam has joined #openstack-fwaas | 18:08 | |
*** SumitNaiksatam has quit IRC | 18:18 | |
*** openstackgerrit has quit IRC | 19:05 | |
*** yamamoto has joined #openstack-fwaas | 21:53 | |
*** yamamoto has quit IRC | 21:57 | |
*** threestrands has joined #openstack-fwaas | 22:59 | |
*** yamamoto has joined #openstack-fwaas | 23:59 |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!