weizhouapache commented on issue #9053:
URL: https://github.com/apache/cloudstack/issues/9053#issuecomment-2099909230

   > > my finding is, the LB always works, no matter what ACL rules are. I have 
created an issue #9054
   > 
   > I'd guess that LB works because its iptables rules are in the "INPUT" 
chain which is checked before the "FORWARD" chain (where the ACL for the tier 
resides).
   > 
   
   agree @cdfgallo 
   thanks for the points.
   
   > > > > The major issue in my testing is, LB on additional public IP range 
always works, even if the ACL rule list is set to "default_deny". can you test 
and confirm it ? @cdfgallo
   > > > 
   > > > 
   > > > I'll try that @weizhouapache
   > > 
   > > 
   > > thanks @cdfgallo If port forwarding works with the ingress rule with 
private port , can we close this issue ?
   > 
   > @weizhouapache yes, we can close the issue!
   
   closing


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: commits-unsubscr...@cloudstack.apache.org

For queries about this service, please contact Infrastructure at:
us...@infra.apache.org

Reply via email to