Hi,
I would like us to think of considering enabling an API that would allow 
‘deny’, for example an admin could overwrite a tenant’s security groups. For 
example, and admin may not want a specific source range to access the tenants 
VM’s. The guys working on FWaaS say that this may happen in V2, but that looks 
very far away. Making this change in Neutron would be pretty simple and give us 
a nice feature add. 
If you would like to work on this I would be happy to develop this with you. It 
could be added an extension.
Thanks
Gary

On 4/24/17, 6:37 AM, "Ihar Hrachyshka" <ihrac...@redhat.com> wrote:

    All traffic is denied by default. OpenStack security groups API is
    modeled to reflect what AWS does. You may find your needs better
    served by fwaas plugin for neutron that is not constrained by AWS
    compatibility.
    
    Ihar
    
    On Sun, Apr 23, 2017 at 8:33 PM, 田明明 <tianming20052...@163.com> wrote:
    > Can we add an "action" to security group rule api, so that we could 
dispatch
    > rules with "deny" action? Until now, security group only supports add
    > white-list rules but this couldn't satisfy many people's needs.
    >
    >
    >
    >
    >
    >
    >
    >
    >
    >
    >
    >
    >
    >
    >
    >
    >
    > __________________________________________________________________________
    > OpenStack Development Mailing List (not for usage questions)
    > Unsubscribe: openstack-dev-requ...@lists.openstack.org?subject:unsubscribe
    > http://lists.openstack.org/cgi-bin/mailman/listinfo/openstack-dev
    >
    
    __________________________________________________________________________
    OpenStack Development Mailing List (not for usage questions)
    Unsubscribe: openstack-dev-requ...@lists.openstack.org?subject:unsubscribe
    http://lists.openstack.org/cgi-bin/mailman/listinfo/openstack-dev
    

__________________________________________________________________________
OpenStack Development Mailing List (not for usage questions)
Unsubscribe: openstack-dev-requ...@lists.openstack.org?subject:unsubscribe
http://lists.openstack.org/cgi-bin/mailman/listinfo/openstack-dev

Reply via email to