Re: [openstack-dev] [OSSN 0029] Neutron FWaaS rules lack port restrictions when using protocol 'any'

2014-09-29 Thread Nathan Kinder
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 An update for this Security Note has been published to clarify that Neutron's FWaaS extension is still experimental. The updated version of OSSN-0029 is available here: https://wiki.openstack.org/wiki/OSSN/OSSN-0029 Thanks, - -NGK On 09/24/2014

[openstack-dev] [OSSN 0029] Neutron FWaaS rules lack port restrictions when using protocol 'any'

2014-09-24 Thread Nathan Kinder
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Neutron FWaaS rules lack port restrictions when using protocol 'any' - --- ### Summary ### A bug in the Neutron FWaaS (Firewall as a Service) code results in iptables rules being generated that do not reflect desired port restrictions. This behaviour