apache / apache/cloudstack

CS4.22.0 vROUTER ACLs Feature is non RFC compliant applied to Internal Interface

未關閉
#13,266 10 則留言 0 個 reaction 已指派 1 人 已被 @weizhouapache 認領 在 GitHub 檢視
component:networking component:virtual-router type:enhancement
主要語言
Java
星號
3.1k
分支
1.4k
平均合併
7 天 14 小時
30 天內合併 PR
31

描述

### problem

CS 4.22.0
Host Ubuntu 22.4 KVM
vRouter on VPC ACLs

This VPC ACL feature is beyond good, it's awesome. However @weizhouapache with all the love I have for the team. That's not right, ACL should be applied to the edge - and we know that should not be to interpretation, and many think are just Cisco best practices - we should have a feature to select WAN-side, LAN-side or named Edge-side, Internal-Side which seems are more contemporary names.

- RFC 2827
- RFC 3704

Suggestion: if decided to make it RF-ish. To make easy the transition for existing systems, the updated feature will apply to LAN-side (internal-side) by default.

### versions

CS 4.22.0
Host Ubuntu 22.4 KVM
running vRouter with 8CPUs and 8GRAM, oversubscription is 1:1 for all systems.

### The steps to reproduce the bug

1. Create a VPC
2. Add the custom ACL with ingress only
3. the ACL does not filter the traffic, as is applied to the vRouter LAN AKA Internal interface.

### What to do about it?

_No response_

貢獻指南

開啟貢獻指南

評估

這個 Issue 還沒有評估資料。

把新 issue 寄到你的電子郵件信箱

精選適合新手參與的 GitHub issue 摘要。