apache / apache/cloudstack

Clarify ACL-Rule Behaviour for TCP/UDP-Protocol without start- and endport

オープン
#13,122 コメント 0 件 リアクション 0 件 担当者 0 名 GitHub で見る
type:question
主要言語
Java
スター
3.1k
フォーク
1.4k
平均マージ
6日 19時間
マージ済み PR(30日)
32

説明

### Discussed in https://github.com/apache/cloudstack/discussions/13113

Originally posted by **mwaag** May 7, 2026
Hi,

we noticed cloudstack let you successfully define ACL-Ingress-Rules for TCP (and UDP) without setting a start- and endport.
Many of our users (even we) assumed, that it stands for 'all ports'. But instead the router keeps on blocking traffic.
(We didn't test this on UDP explicitly)

We know, we can workaround this with just setting start- and endports or use protocol: All

Is this expected behaviour or should this be handled as a bug?
(We probably would suggest to either restrict defining rules without setting start- and endports at all or treat this kind of rules as "all ports" - rule)

Tested Versions are:
4.18.2.4
4.20.3.0

10_03_08-000372
10_04_13-000374

コントリビューションガイド

コントリビューションガイドを開く

調査の方向性

https://github.com/apache/cloudstack/discussions/13113 のリンク先の議論から始め、CloudStack 4.18.2.4 および 4.20.3.0 で報告されている挙動も確認してください。ソースファイルやテストは指定されていないため、開始ポートまたは終了ポートのない TCP および UDP ルールに対する ACL ingress の処理を特定してください。完了条件は、その挙動が明示的に定義され、制限されるか、すべてのポートを対象とするルールとして一貫して処理され、両方のプロトコルがカバーされていることです。

索引モデルが issue の本文から書いたものです。

評価

技術スタック
java
領域
networking
issue の種類
バグ
難易度
4/5
見積もり時間
3〜5日
活発さ
静か
明瞭さ
おおむね明確
初心者へのやさしさ
45/100

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。