apache / apache/cloudstack

Clarify ACL-Rule Behaviour for TCP/UDP-Protocol without start- and endport

未關閉
#13,122 0 則留言 0 個 reaction 已指派 0 人 在 GitHub 檢視
type:question
主要語言
Java
星號
3.1k
分支
1.4k
平均合併
7 天 14 小時
30 天內合併 PR
31

描述

### Discussed in https://github.com/apache/cloudstack/discussions/13113

Originally posted by **mwaag** May 7, 2026
Hi,

we noticed cloudstack let you successfully define ACL-Ingress-Rules for TCP (and UDP) without setting a start- and endport.
Many of our users (even we) assumed, that it stands for 'all ports'. But instead the router keeps on blocking traffic.
(We didn't test this on UDP explicitly)

We know, we can workaround this with just setting start- and endports or use protocol: All

Is this expected behaviour or should this be handled as a bug?
(We probably would suggest to either restrict defining rules without setting start- and endports at all or treat this kind of rules as "all ports" - rule)

Tested Versions are:
4.18.2.4
4.20.3.0

10_03_08-000372
10_04_13-000374

貢獻指南

開啟貢獻指南

研究方向

從連結的討論開始:https://github.com/apache/cloudstack/discussions/13113,包括 CloudStack 4.18.2.4 和 4.20.3.0 中回報的行為。沒有指定原始檔案或測試,因此請找出沒有起始連接埠或結束連接埠的 TCP 和 UDP 規則之 ACL ingress 處理方式。完成表示該行為已明確定義,並且受到限制,或一致地作為涵蓋所有連接埠的規則來處理,同時涵蓋兩種通訊協定。

由索引模型根據 Issue 內容生成。

評估

技術堆疊
java
領域
networking
Issue 類型
缺陷
難度
4/5
預估耗時
3-5 天
活躍度
冷清
描述清晰度
基本清楚
新手友好度
45/100

把新 issue 寄到你的電子郵件信箱

精選適合新手參與的 GitHub issue 摘要。