[Openstack] Network node's security

2014-05-31 Thread walterxj
hi all:     The network node(s) is the only node(s) that expose to the internet,so it's security setting is more important,So I think it needs to be protect by iptables or firewall etc.     On the other hand,network nodes control all the vm instances' network traffic,I have no ideas how

Re: [Openstack] Network node's security

2014-05-31 Thread Clint Byrum
Be permissive on br-ex to allow VM traffic to flow out to the internet. Otherwise be protective of the host address that the machine listens to. Excerpts from walterxj's message of 2014-05-31 13:46:24 +0100: hi all: The network node(s) is the only node(s) that expose to the

Re: [Openstack] Network node's security

2014-05-31 Thread xu Walter
Thank you for your advice,Clint,I'll try. 2014-05-31 21:47 GMT+08:00 Clint Byrum cl...@fewbar.com: Be permissive on br-ex to allow VM traffic to flow out to the internet. Otherwise be protective of the host address that the machine listens to. Excerpts from walterxj's message of