Details
-
Bug
-
Status: Closed
-
Blocker
-
Resolution: Fixed
-
4.9.2.0
-
Security Level: Public (Anyone can view this level - this is the default.)
-
None
-
Cloudstack 4.9.2.0
XenServer 6.5SP1
Zone with Advanced Network
-
Important
Description
The Network Offering of the VPC Tier has a Default Egress Policy = Deny.
Some Allow Rules exist in the ACL, but ALL egress connections are possible.
Creating a Deny All rule explicit at the end of the rules is actually blocking ALL traffic (should not, because of the Allow rules).
The Iptables in the VR are wrong:
1) the allow & deny rules are in wrong order.
2) some rules are in mangle table instead of filter
Do you know how to fix this?
Thank you for your help.
Francois Scheurer
Attachments
Issue Links
- links to