yahoo-eng-team team mailing list archive
-
yahoo-eng-team team
-
Mailing list archive
-
Message #64375
[Bug 1633280] Re: [RFE]need a way to disable anti-spoofing rules and yet keep security groups
[Expired for neutron because there has been no activity for 60 days.]
** Changed in: neutron
Status: Incomplete => Expired
--
You received this bug notification because you are a member of Yahoo!
Engineering Team, which is subscribed to neutron.
https://bugs.launchpad.net/bugs/1633280
Title:
[RFE]need a way to disable anti-spoofing rules and yet keep security
groups
Status in neutron:
Expired
Bug description:
Basically all NFV use-cases would require this split. The current
approach for NFV is to turn things off and have the VNFs protect
themselves rather than the infra-structure supports security. Even in
simple deployments, like cloud bursting, you'll need to be able to
allow the customer to control his addressing. The customer might want
to do so by having the router (which does the IPSEC tunnel
termination) either use ICMP RA (in case of v6/SLAAC) or DHCP (v4/v6)
to control addressing - as opposed to have openstack control the
addressing. In this case, the VNF only deals with addressing but it
has to protect itself without security groups.
To manage notifications about this bug go to:
https://bugs.launchpad.net/neutron/+bug/1633280/+subscriptions
References