apache / apache/cloudstack

Clarify ACL-Rule Behaviour for TCP/UDP-Protocol without start- and endport

Offen
#13,122 0 Kommentare 0 Reaktionen 0 zugewiesene Personen Auf GitHub ansehen
type:question
Vorherrschende Sprache
Java
Sterne
3.1k
Forks
1.4k
Ø Merge
6 T. 19 Std.
Gemergte PRs (30 T.)
32

Beschreibung

### Discussed in https://github.com/apache/cloudstack/discussions/13113

Originally posted by **mwaag** May 7, 2026
Hi,

we noticed cloudstack let you successfully define ACL-Ingress-Rules for TCP (and UDP) without setting a start- and endport.
Many of our users (even we) assumed, that it stands for 'all ports'. But instead the router keeps on blocking traffic.
(We didn't test this on UDP explicitly)

We know, we can workaround this with just setting start- and endports or use protocol: All

Is this expected behaviour or should this be handled as a bug?
(We probably would suggest to either restrict defining rules without setting start- and endports at all or treat this kind of rules as "all ports" - rule)

Tested Versions are:
4.18.2.4
4.20.3.0

10_03_08-000372
10_04_13-000374

Beitragsleitfaden

Beitragsleitfaden öffnen

Rechercherichtung

Beginne mit der verlinkten Diskussion unter https://github.com/apache/cloudstack/discussions/13113, einschließlich des gemeldeten Verhaltens unter CloudStack 4.18.2.4 und 4.20.3.0. Es wird keine Quelldatei oder kein Test genannt, daher ermittle die ACL-Ingress-Behandlung für TCP- und UDP-Regeln ohne Start- oder Endports. Als abgeschlossen gilt die Aufgabe, wenn das Verhalten explizit definiert ist und entweder eingeschränkt oder konsistent als Regel für alle Ports behandelt wird, mit Abdeckung für beide Protokolle.

Vom Indexierungsmodell aus dem Issue-Text verfasst.

Bewertung

Tech-Stack
java
Bereich
networking
Issue-Typ
Bug
Schwierigkeit
4/5
Geschätzter Aufwand
3-5 Tage
Aktivitätsstatus
Ruhig
Klarheit
Größtenteils klar
Anfängerfreundlichkeit
45/100

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.