GitHub user rhtyd reopened a pull request:

    https://github.com/apache/cloudstack/pull/2034

    [4.9+][network blocker] CLOUDSTACK-9838: Allow ingress traffic between 
guest VMs via snat IPs

    This enables the firewall/mangle tables rules to ACCEPT instead of RETURN, 
which
    is the same behaviour as observed in ACS 4.5. By accepting the traffic, 
guest
    VMs will be able to communicate tcp traffic between each other over snat 
public
    IPs.
    
    This is a regression from ACS 4.5, observed in ACS 4.9.2.0.
    Pinging for review - @PaulAngus @borisstoyanov @DagSonsteboSB 
@abhinandanprateek @DaanHoogland and others
    
    @blueorangutan package

You can merge this pull request into a Git repository by running:

    $ git pull https://github.com/shapeblue/cloudstack CLOUDSTACK-9838

Alternatively you can review and apply these changes as the patch at:

    https://github.com/apache/cloudstack/pull/2034.patch

To close this pull request, make a commit to your master/trunk branch
with (at least) the following in the commit message:

    This closes #2034
    
----
commit f4835294869f01def94618f2c206160ccb3b719f
Author: Rohit Yadav <rohit.ya...@shapeblue.com>
Date:   2017-04-07T11:44:18Z

    CLOUDSTACK-9838: Allow ingress traffic between guest VMs via snat IPs
    
    This enables the firewall/mangle tables rules to ACCEPT instead of RETURN, 
which
    is the same behaviour as observed in ACS 4.5. By accepting the traffic, 
guest
    VMs will be able to communicate tcp traffic between each other over snat 
public
    IPs.
    
    Signed-off-by: Rohit Yadav <rohit.ya...@shapeblue.com>

----


---
If your project is set up for it, you can reply to this email and have your
reply appear on GitHub as well. If your project does not have this feature
enabled and wishes so, or if the feature is enabled but not working, please
contact infrastructure at infrastruct...@apache.org or file a JIRA ticket
with INFRA.
---

Reply via email to