[jira] [Comment Edited] (CLOUDSTACK-299) Egress firewall rules for guest network

2013-02-11 Thread Jayapal Reddy (JIRA)
. Egress firewall rules for guest network --- Key: CLOUDSTACK-299 URL: https://issues.apache.org/jira/browse/CLOUDSTACK-299 Project: CloudStack Issue Type: New Feature Security Level: Public

[jira] [Comment Edited] (CLOUDSTACK-299) Egress firewall rules for guest network

2013-02-11 Thread Jayapal Reddy (JIRA)
: --- Egress feature for external device SRX (CLOUDSACK-779), for 4.1 the priority decreased. was (Author: jayapal): Egress feature for external device SRX, for 4.1 the priority decreased. Egress firewall rules for guest network

[jira] [Commented] (CLOUDSTACK-299) Egress firewall rules for guest network

2013-02-11 Thread Jayapal Reddy (JIRA)
changes for Virtual Router are pushed to master. Egress firewall rules for guest network --- Key: CLOUDSTACK-299 URL: https://issues.apache.org/jira/browse/CLOUDSTACK-299 Project: CloudStack

[jira] [Commented] (CLOUDSTACK-299) Egress firewall rules for guest network

2013-02-11 Thread Animesh Chaturvedi (JIRA)
or in master? Please update the status it still says open Egress firewall rules for guest network --- Key: CLOUDSTACK-299 URL: https://issues.apache.org/jira/browse/CLOUDSTACK-299 Project: CloudStack

[jira] [Updated] (CLOUDSTACK-299) Egress firewall rules for guest network

2013-01-28 Thread Jayapal Reddy (JIRA)
- this is the default.) Components: Network Controller, Network Devices Affects Versions: 4.0.0 Reporter: Jayapal Reddy Assignee: Jayapal Reddy Fix For: 4.1.0 Support adding Egress firewall rules functionality for guest network in VR and external

[jira] [Updated] (CLOUDSTACK-299) Egress firewall rules for guest network

2013-01-27 Thread Jayapal Reddy (JIRA)
- this is the default.) Components: Network Controller, Network Devices Affects Versions: 4.0.0 Reporter: Jayapal Reddy Assignee: Jayapal Reddy Fix For: 4.2.0 Support adding Egress firewall rules functionality for guest network in VR and external

[jira] [Commented] (CLOUDSTACK-299) Egress firewall rules for guest network

2013-01-21 Thread Animesh Chaturvedi (JIRA)
Proceeding with IP Clearance process. Egress firewall rules for guest network --- Key: CLOUDSTACK-299 URL: https://issues.apache.org/jira/browse/CLOUDSTACK-299 Project: CloudStack Issue Type: New

RE: [IP Clearance: CLOUDSTACK-299] Egress firewall rules for guest network

2013-01-16 Thread Animesh Chaturvedi
Subject: [IP Clearance: CLOUDSTACK-299] Egress firewall rules for guest network Hi, I am starting the IP clearance process for the Citrix Egress firewall rules feature. https://issues.apache.org/jira/browse/CLOUDSTACK-299 Citrix would like to donate the egress firewall rules feature to Apache

RE: [IP Clearance: CLOUDSTACK-299] Egress firewall rules for guest network

2013-01-16 Thread Jayapal Reddy Uradi
-Original Message- From: Animesh Chaturvedi [mailto:animesh.chaturv...@citrix.com] Sent: Wednesday, January 16, 2013 10:38 PM To: cloudstack-dev@incubator.apache.org Subject: RE: [IP Clearance: CLOUDSTACK-299] Egress firewall rules for guest network Jayapal You need to post the markmail

[jira] [Updated] (CLOUDSTACK-984) QA: Egress firewall rules for guest network

2013-01-15 Thread Sudha Ponnaganti (JIRA)
[ https://issues.apache.org/jira/browse/CLOUDSTACK-984?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Sudha Ponnaganti updated CLOUDSTACK-984: Summary: QA: Egress firewall rules for guest network (was: QA: Egress

[IP Clearance: CLOUDSTACK-299] Egress firewall rules for guest network

2013-01-15 Thread Jayapal Reddy Uradi
in the isolated networks is allowed to public network. This feature is about controlling the guest network traffic to public network. Using this feature user can configure egress firewall rules on the guest network to allow specific traffic. Citrix egress firewall rules implementation by default all

[jira] [Updated] (CLOUDSTACK-299) Egress firewall rules for guest network

2013-01-11 Thread Chip Childers (JIRA)
[ https://issues.apache.org/jira/browse/CLOUDSTACK-299?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Chip Childers updated CLOUDSTACK-299: - Description: Support adding Egress firewall rules functionality for guest network

[jira] [Commented] (CLOUDSTACK-299) Egress firewall rules for guest network

2013-01-11 Thread Chip Childers (JIRA)
on this feature, and it has IP ownership issues to resolve before being accepted for inclusion. Please do not commit either the documentation or the code until those issues have been addressed. Egress firewall rules for guest network

[jira] [Updated] (CLOUDSTACK-299) Egress firewall rules for guest network

2013-01-11 Thread Animesh Chaturvedi (JIRA)
/display/CLOUDSTACK/Egress+firewall+rules+for+guest+network Feature Branch: unknown Documentation: https://reviews.apache.org/r/8813/ was: Support adding Egress firewall rules functionality for guest network in VR and external firewall device SRX. Release Planning: Dev List Discussion: unknown

[jira] [Updated] (CLOUDSTACK-299) Egress firewall rules for guest network

2013-01-09 Thread Chip Childers (JIRA)
[ https://issues.apache.org/jira/browse/CLOUDSTACK-299?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Chip Childers updated CLOUDSTACK-299: - Issue Type: New Feature (was: Bug) Egress firewall rules for guest network

[jira] [Commented] (CLOUDSTACK-299) Egress firewall rules for guest network

2013-01-06 Thread Jayapal Reddy (JIRA)
://issues.apache.org/jira/browse/CLOUDSTACK-779 Egress feature for external device SRX, for 4.1 the priority decreased. Egress firewall rules for guest network --- Key: CLOUDSTACK-299 URL: https://issues.apache.org

[jira] [Assigned] (CLOUDSTACK-299) Egress firewall rules for guest network

2013-01-03 Thread Manan Shah (JIRA)
[ https://issues.apache.org/jira/browse/CLOUDSTACK-299?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Manan Shah reassigned CLOUDSTACK-299: - Assignee: Jayapal Reddy Egress firewall rules for guest network

RE: Egress firewall rules for guest network.

2012-11-05 Thread Jayapal Reddy Uradi
Updated the Egress firewall rules FS. https://cwiki.apache.org/confluence/display/CLOUDSTACK/Egress+firewall+rules+for+guest+network Thanks, Jayapal -Original Message- From: Jayapal Reddy Uradi [mailto:jayapalreddy.ur...@citrix.com] Sent: Wednesday, October 17, 2012 8:12 PM

RE: Egress firewall rules for guest network.

2012-10-17 Thread Jayapal Reddy Uradi
NetworkACL rule. Thanks, Jayapal Thanks, Jayapal -Original Message- From: Anthony Xu Sent: Monday, October 15, 2012 6:38 AM To: cloudstack-dev@incubator.apache.org Cc: Jayapal Reddy Uradi Subject: RE: Egress firewall rules for guest network

RE: Egress firewall rules for guest network.

2012-10-16 Thread Jayapal Reddy Uradi
for configuring firewall rules per public IP. Thanks, Jayapal Thanks, Jayapal -Original Message- From: Anthony Xu Sent: Monday, October 15, 2012 6:38 AM To: cloudstack-dev@incubator.apache.org Cc: Jayapal Reddy Uradi Subject: RE: Egress firewall rules for guest network

Re: Egress firewall rules for guest network.

2012-10-16 Thread Alena Prokharchyk
Thanks, Jayapal -Original Message- From: Anthony Xu Sent: Monday, October 15, 2012 6:38 AM To: cloudstack-dev@incubator.apache.org Cc: Jayapal Reddy Uradi Subject: RE: Egress firewall rules for guest network. We need to understand how network ACL rules are different from Firewall

RE: Egress firewall rules for guest network.

2012-10-14 Thread Anthony Xu
which public IP it goes through -Original Message- From: Alena Prokharchyk [mailto:alena.prokharc...@citrix.com] Sent: Wednesday, October 10, 2012 9:44 AM To: cloudstack-dev@incubator.apache.org Cc: Jayapal Reddy Uradi Subject: Re: Egress firewall rules for guest network. Hi Jayapal, See

Re: Egress firewall rules for guest network.

2012-10-11 Thread Prasanna Santhanam
My two cents: I did evaluate both the options of using current network ACL functionality to implement the egress firewall rules and enhance CreateFirewall API to support both ingress and egress. If we go down the path of implementing egress firewall with Network ACL it increases the scope of

RE: Egress firewall rules for guest network.

2012-10-10 Thread Jayapal Reddy Uradi
, Jayapal -Original Message- From: David Nalley [mailto:da...@gnsa.us] Sent: Wednesday, October 10, 2012 8:41 AM To: cloudstack-dev@incubator.apache.org Subject: Re: Egress firewall rules for guest network. On Tue, Oct 9, 2012 at 11:07 PM, Jayapal Reddy Uradi jayapalreddy.ur...@citrix.com

RE: Egress firewall rules for guest network.

2012-10-10 Thread Jayapal Reddy Uradi
...@citrix.com] Sent: Tuesday, October 09, 2012 10:43 PM To: cloudstack-dev@incubator.apache.org Subject: Re: Egress firewall rules for guest network. On 10/9/12 8:10 AM, David Nalley da...@gnsa.us wrote: On Tue, Oct 9, 2012 at 5:14 AM, Jayapal Reddy Uradi jayapalreddy.ur...@citrix.com wrote: The egress

Re: Egress firewall rules for guest network.

2012-10-10 Thread Alena Prokharchyk
/DENY permissions and Priority to the network ACLs. Thanks, Jayapal -Original Message- From: Alena Prokharchyk [mailto:alena.prokharc...@citrix.com] Sent: Tuesday, October 09, 2012 10:43 PM To: cloudstack-dev@incubator.apache.org Subject: Re: Egress firewall rules for guest network. On 10/9

Egress firewall rules for guest network.

2012-10-09 Thread Jayapal Reddy Uradi
traffic is allowed. I have created a functional spec here: https://cwiki.apache.org/confluence/display/CLOUDSTACK/Egress+firewall+rules+for+guest+network Please review and provide your comments. Thanks, Jayapal

[jira] [Created] (CLOUDSTACK-299) Egress firewall rules for guest network

2012-10-09 Thread Jayapal Reddy (JIRA)
Jayapal Reddy created CLOUDSTACK-299: Summary: Egress firewall rules for guest network Key: CLOUDSTACK-299 URL: https://issues.apache.org/jira/browse/CLOUDSTACK-299 Project: CloudStack

[jira] [Commented] (CLOUDSTACK-299) Egress firewall rules for guest network

2012-10-09 Thread Prasanna Santhanam (JIRA)
spec posted on the wiki: https://cwiki.apache.org/confluence/display/CLOUDSTACK/Egress+firewall+rules+for+guest+network Egress firewall rules for guest network --- Key: CLOUDSTACK-299 URL: https

Re: Egress firewall rules for guest network.

2012-10-09 Thread Wido den Hollander
. When you specify a egress rule only that rule specific traffic is allowed. I have created a functional spec here: https://cwiki.apache.org/confluence/display/CLOUDSTACK/Egress+firewall+rules+for+guest+network Please review and provide your comments. Seems great! But why assume that we

Re: Egress firewall rules for guest network.

2012-10-09 Thread David Nalley
the traffic is ALLOWED to public network. When you specify a egress rule only that rule specific traffic is allowed. I have created a functional spec here: https://cwiki.apache.org/confluence/display/CLOUDSTACK/Egress+firewall+rules+for+guest+network Please review and provide your comments

Re: Egress firewall rules for guest network.

2012-10-09 Thread Abhinandan Prateek
On 09/10/12 8:40 PM, David Nalley da...@gnsa.us wrote: On Tue, Oct 9, 2012 at 5:14 AM, Jayapal Reddy Uradi jayapalreddy.ur...@citrix.com wrote: The egress firewall rules feature will configure the egress rules for guest network on VR/External firewall to ALLOW specified traffic to outside

Re: Egress firewall rules for guest network.

2012-10-09 Thread Alena Prokharchyk
On 10/9/12 8:10 AM, David Nalley da...@gnsa.us wrote: On Tue, Oct 9, 2012 at 5:14 AM, Jayapal Reddy Uradi jayapalreddy.ur...@citrix.com wrote: The egress firewall rules feature will configure the egress rules for guest network on VR/External firewall to ALLOW specified traffic to outside and

RE: Egress firewall rules for guest network.

2012-10-09 Thread Jayapal Reddy Uradi
: Egress firewall rules for guest network. On Tue, Oct 9, 2012 at 5:14 AM, Jayapal Reddy Uradi jayapalreddy.ur...@citrix.com wrote: The egress firewall rules feature will configure the egress rules for guest network on VR/External firewall to ALLOW specified traffic to outside and BLOCK

Re: Egress firewall rules for guest network.

2012-10-09 Thread David Nalley
On Tue, Oct 9, 2012 at 11:07 PM, Jayapal Reddy Uradi jayapalreddy.ur...@citrix.com wrote: Hi David, The traffic type is optional and default to ingress. For egress it is required to pass with the 'egress'. Thanks, Jayapal The fs is very confusing then. In the API parameters and info