weizhouapache commented on issue #9053: URL: https://github.com/apache/cloudstack/issues/9053#issuecomment-2099909230
> > my finding is, the LB always works, no matter what ACL rules are. I have created an issue #9054 > > I'd guess that LB works because its iptables rules are in the "INPUT" chain which is checked before the "FORWARD" chain (where the ACL for the tier resides). > agree @cdfgallo thanks for the points. > > > > The major issue in my testing is, LB on additional public IP range always works, even if the ACL rule list is set to "default_deny". can you test and confirm it ? @cdfgallo > > > > > > > > > I'll try that @weizhouapache > > > > > > thanks @cdfgallo If port forwarding works with the ingress rule with private port , can we close this issue ? > > @weizhouapache yes, we can close the issue! closing -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: commits-unsubscr...@cloudstack.apache.org For queries about this service, please contact Infrastructure at: us...@infra.apache.org