Hi Jean-Philippe,

You can see the ACLs from the api server port (8082 and/or 8095 depending on 
whether multi-tenancy is off or on).

Sachin

> On Jul 8, 2015, at 4:32 AM, Jean-Philippe Braun <[email protected]> wrote:
> 
> So, I made some tests and the rules are working fine. The problem is that the
> types/codes are not reported in the intropect webui. I don't know any other 
> way
> to check the ACLs.
> 
> See this example: http://awesomescreenshot.com/0f451s0ob8
> 
> The second ACL for ICMP type 0, code 0. I thought the type/code should appear 
> in the dst_port_l section.
> 
> From neutron API:
> 
> | f1aa1580-ea02-411d-937a-2fd844ce4db5 | default | egress, IPv4, icmp 
> (type:8, code:0), remote_group_id: f1aa1580-ea02-411d-937a-2fd844ce4db5  |
> |                                      |         | ingress, IPv4, 22/tcp, 
> remote_ip_prefix: 0.0.0.0/0                                          |
> |                                      |         | ingress, IPv4, icmp 
> (type:0, code:0), remote_group_id: f1aa1580-ea02-411d-937a-2fd844ce4db5 |
> 
> 
> Jean-Philippe
> 
> 
> Le mardi 07 juil. 2015 à 17:11:15 (+0000), Sachin Bansal a écrit :
>> Could you show me an example? Send me the commands/apis you used to create 
>> the rules and the generated acl.
>> 
>> Sachin
>> 
>>> On Jul 7, 2015, at 9:14 AM, Jean-Philippe Braun <[email protected]> wrote:
>>> 
>>> Hi guys,
>>> 
>>> When working on the neutron API plugin I noticed that even if ICPM rules are
>>> created with specific types/codes the ACLs that are actually created on the
>>> vRouter side don't have any type/code. It's all or nothing.
>>> 
>>> As I am new to the project, I was wondering why this wasn't implemented. If
>>> there is no specific issue to implement this I will try to work on it.
>>> 
>>> Thanks
>>> 
>>> Jean-Philippe
>>> 
>>> _______________________________________________
>>> Dev mailing list
>>> [email protected]
>>> http://lists.opencontrail.org/mailman/listinfo/dev_lists.opencontrail.org
>> 

_______________________________________________
Dev mailing list
[email protected]
http://lists.opencontrail.org/mailman/listinfo/dev_lists.opencontrail.org

Reply via email to