[ https://issues.apache.org/jira/browse/CLOUDSTACK-242?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ]
Prasanna Santhanam reassigned CLOUDSTACK-242: --------------------------------------------- Assignee: John Kinsella > haproxy listens on all interfaces on VR > --------------------------------------- > > Key: CLOUDSTACK-242 > URL: https://issues.apache.org/jira/browse/CLOUDSTACK-242 > Project: CloudStack > Issue Type: Bug > Security Level: Public(Anyone can view this level - this is the > default.) > Components: Install and Setup > Affects Versions: 4.0.0 > Reporter: Clement Chen > Assignee: John Kinsella > Labels: security > Fix For: 4.1.0 > > > haproxy listens on all three network interfaces (public, guest and cloud link > local) on port 35999 on a virtual router. > Listening on the public interface opens up an attack entry point. We should > limit the interface haproxy listens to guest or cloud link local if possible. -- This message is automatically generated by JIRA. If you think it was sent incorrectly, please contact your JIRA administrators For more information on JIRA, see: http://www.atlassian.com/software/jira