[openstack-dev] [neutron] Firewall is ineffective with floating ip?

2014-06-05 Thread Xurong Yang
Hi, Stackers, Use case description: Firewal is not working when setting the destination-ip-address as VM's floating ip Steps to Reproduce: 1. create one network and attached it to the newly created router 2. Create VMs on the above network 3. create security group rule for icmp 4. create an

Re: [openstack-dev] [neutron] Firewall is ineffective with floating ip?

2014-06-05 Thread ZZelle
Hi, When the router receives packets from the external network, iptables does sequentially: 1) NAT PREROUTING table: translate floatingip to fixed ip 2) FILTER FORWARD table: apply FW rules ... on fixed ips because floatingip has been translated to fixed ip So disabling the ping to the

Re: [openstack-dev] [neutron] Firewall is ineffective with floating ip?

2014-06-05 Thread Xurong Yang
Yes, right, but why can't use floating ip? Administrator or user should care the floating ip for instance rather fix ip. So i think firewall also take effect about floating ip. Thanks, Xurong Yang 2014-06-05 19:32 GMT+08:00 ZZelle zze...@gmail.com: Hi, When the router receives packets from