Re: [Blocker] Default ip table rules on VR

2015-08-03 Thread Wilder Rodrigues
: This is a security issue with high impact. We should treat it as a blocker. -Original Message- From: Jayapal Reddy Uradi [mailto:jayapalreddy.ur...@citrix.com] Sent: 30 July 2015 02:07 PM To: dev@cloudstack.apache.org dev@cloudstack.apache.org Subject: Re: [Blocker] Default ip table rules

Re: [Blocker] Default ip table rules on VR

2015-08-03 Thread Wilder Rodrigues
with high impact. We should treat it as a blocker. -Original Message- From: Jayapal Reddy Uradi [mailto:jayapalreddy.ur...@citrix.com] Sent: 30 July 2015 02:07 PM To: dev@cloudstack.apache.org dev@cloudstack.apache.org Subject: Re: [Blocker] Default ip table rules on VR I see VR

Re: [Blocker] Default ip table rules on VR

2015-08-03 Thread Sanjeev N
Subject: Re: [Blocker] Default ip table rules on VR I see VR ingress traffic is blocked by default from iptables mangle table. But on the guest interface all the traffic is accepted. Also egress firewall rule will break because of FORWARD policy. Thanks, Jayapal On 30-Jul-2015

Re: [Blocker] Default ip table rules on VR

2015-08-03 Thread Wilder Rodrigues
it as a blocker. -Original Message- From: Jayapal Reddy Uradi [mailto:jayapalreddy.ur...@citrix.com] Sent: 30 July 2015 02:07 PM To: dev@cloudstack.apache.org dev@cloudstack.apache.org Subject: Re: [Blocker] Default ip table rules on VR I see VR ingress traffic is blocked by default from

Re: [Blocker] Default ip table rules on VR

2015-07-30 Thread Daan Hoogland
Guys, I see votes here but no arguments. Why is it a blocker? From: Jayapal Reddy Uradi [mailto:jayapalreddy.ur...@citrix.com] Sent: 30 July 2015 02:07 PM To: dev@cloudstack.apache.org dev@cloudstack.apache.org Subject: Re: [Blocker] Default ip table rules on VR I see VR ingress traffic

Re: [Blocker] Default ip table rules on VR

2015-07-30 Thread Wilder Rodrigues
] Default ip table rules on VR I see VR ingress traffic is blocked by default from iptables mangle table. But on the guest interface all the traffic is accepted. Also egress firewall rule will break because of FORWARD policy. Thanks, Jayapal On 30-Jul-2015, at 12:53 PM, Jayapal Reddy Uradi

Re: [Blocker] Default ip table rules on VR

2015-07-30 Thread Sanjeev N
: 30 July 2015 02:07 PM To: dev@cloudstack.apache.org dev@cloudstack.apache.org Subject: Re: [Blocker] Default ip table rules on VR I see VR ingress traffic is blocked by default from iptables mangle table. But on the guest interface all the traffic is accepted. Also egress firewall rule

Re: [Blocker] Default ip table rules on VR

2015-07-30 Thread Sanjeev N
[mailto:jayapalreddy.ur...@citrix.com] Sent: 30 July 2015 02:07 PM To: dev@cloudstack.apache.org dev@cloudstack.apache.org Subject: Re: [Blocker] Default ip table rules on VR I see VR ingress traffic is blocked by default from iptables mangle table. But on the guest interface all the traffic

Re: [Blocker] Default ip table rules on VR

2015-07-30 Thread Jayapal Reddy Uradi
I see VR ingress traffic is blocked by default from iptables mangle table. But on the guest interface all the traffic is accepted. Also egress firewall rule will break because of FORWARD policy. Thanks, Jayapal On 30-Jul-2015, at 12:53 PM, Jayapal Reddy Uradi jayapalreddy.ur...@citrix.com

RE: [Blocker] Default ip table rules on VR

2015-07-30 Thread Kishan Kavala
This is a security issue with high impact. We should treat it as a blocker. -Original Message- From: Jayapal Reddy Uradi [mailto:jayapalreddy.ur...@citrix.com] Sent: 30 July 2015 02:07 PM To: dev@cloudstack.apache.org dev@cloudstack.apache.org Subject: Re: [Blocker] Default ip table

Re: [Blocker] Default ip table rules on VR

2015-07-30 Thread Daan Hoogland
I changed it to critical. It is only a blocker if we agree on this list that it is. On Thu, Jul 30, 2015 at 6:44 AM, Sanjeev N sanj...@apache.org wrote: Hi, In latest ACS builds, the ip table rules in VR have ACCEPT as the default policy in INPUT and FORWARD chains, instead of DROP. Created

Re: [Blocker] Default ip table rules on VR

2015-07-30 Thread Jayapal Reddy Uradi
It is security concern on the VR. All the ingress traffic onto the VR is accepted. Let it be blocker. Thanks, Jayapal On 30-Jul-2015, at 12:28 PM, Daan Hoogland daan.hoogl...@gmail.com wrote: I changed it to critical. It is only a blocker if we agree on this list that it is. On Thu, Jul

[Blocker] Default ip table rules on VR

2015-07-29 Thread Sanjeev N
Hi, In latest ACS builds, the ip table rules in VR have ACCEPT as the default policy in INPUT and FORWARD chains, instead of DROP. Created a blocker bug for this issue https://issues.apache.org/jira/browse/CLOUDSTACK-8688 Can somebody please fix it? Thanks, Sanjeev