Clarify ACL-Rule Behaviour for TCP/UDP-Protocol without start- and endport
- 主要語言
- Java
- 星號
- 3.1k
- 分支
- 1.4k
- 平均合併
- 7 天 14 小時
- 30 天內合併 PR
- 31
描述
### Discussed in https://github.com/apache/cloudstack/discussions/13113
Originally posted by **mwaag** May 7, 2026
Hi,
we noticed cloudstack let you successfully define ACL-Ingress-Rules for TCP (and UDP) without setting a start- and endport.
Many of our users (even we) assumed, that it stands for 'all ports'. But instead the router keeps on blocking traffic.
(We didn't test this on UDP explicitly)
We know, we can workaround this with just setting start- and endports or use protocol: All
Is this expected behaviour or should this be handled as a bug?
(We probably would suggest to either restrict defining rules without setting start- and endports at all or treat this kind of rules as "all ports" - rule)
Tested Versions are:
4.18.2.4
4.20.3.0
貢獻指南
研究方向
從連結的討論開始:https://github.com/apache/cloudstack/discussions/13113,包括 CloudStack 4.18.2.4 和 4.20.3.0 中回報的行為。沒有指定原始檔案或測試,因此請找出沒有起始連接埠或結束連接埠的 TCP 和 UDP 規則之 ACL ingress 處理方式。完成表示該行為已明確定義,並且受到限制,或一致地作為涵蓋所有連接埠的規則來處理,同時涵蓋兩種通訊協定。
由索引模型根據 Issue 內容生成。
評估
- 技術堆疊
- java
- 領域
- networking
- Issue 類型
- 缺陷
- 難度
- 4/5
- 預估耗時
- 3-5 天
- 活躍度
- 冷清
- 描述清晰度
- 基本清楚
- 新手友好度
- 45/100