CS4.22.0 vROUTER ACLs Feature is non RFC compliant applied to Internal Interface
- 主要言語
- Java
- スター
- 3.1k
- フォーク
- 1.4k
- 平均マージ
- 6日 19時間
- マージ済み PR(30日)
- 32
説明
### problem
CS 4.22.0
Host Ubuntu 22.4 KVM
vRouter on VPC ACLs
This VPC ACL feature is beyond good, it's awesome. However @weizhouapache with all the love I have for the team. That's not right, ACL should be applied to the edge - and we know that should not be to interpretation, and many think are just Cisco best practices - we should have a feature to select WAN-side, LAN-side or named Edge-side, Internal-Side which seems are more contemporary names.
- RFC 2827
- RFC 3704
Suggestion: if decided to make it RF-ish. To make easy the transition for existing systems, the updated feature will apply to LAN-side (internal-side) by default.
### versions
CS 4.22.0
Host Ubuntu 22.4 KVM
running vRouter with 8CPUs and 8GRAM, oversubscription is 1:1 for all systems.
### The steps to reproduce the bug
1. Create a VPC
2. Add the custom ACL with ingress only
3. the ACL does not filter the traffic, as is applied to the vRouter LAN AKA Internal interface.
### What to do about it?
_No response_
コントリビューションガイド
評価
この issue はまだ評価されていません。