Thursday, 2018-01-04

*** lnicolas has quit IRC01:52
*** threestrands has joined #openstack-fwaas01:55
*** lnicolas has joined #openstack-fwaas02:00
*** bbzhao has quit IRC03:24
*** threestrands has quit IRC07:25
*** annp has joined #openstack-fwaas07:26
*** openstackgerrit has joined #openstack-fwaas08:58
openstackgerritCao Xuan Hoang proposed openstack/neutron-fwaas master: WIP [log]: Add rpc stuff for logging  https://review.openstack.org/53071508:58
*** annp has quit IRC10:12
-openstackstatus- NOTICE: zuul seems to have gotten stuck and will probably need a restart, please be patient11:27
*** openstackstatus has quit IRC11:28
*** openstack has quit IRC11:28
*** openstack has joined #openstack-fwaas13:08
*** ChanServ sets mode: +o openstack13:08
*** openstackstatus has joined #openstack-fwaas13:09
*** ChanServ sets mode: +v openstackstatus13:09
*** cleong has joined #openstack-fwaas13:35
*** annp has joined #openstack-fwaas13:51
xgerman_o/13:58
annphi xgerman13:59
annphi all13:59
annphappy new year :)13:59
xgerman_happy new year13:59
xgerman_ #startmeeting fwaas14:00
xgerman_mmh, is the bot sick?14:00
*** SarathMekala has joined #openstack-fwaas14:00
annpmaybe :)14:01
xgerman_ #startmeeting fwaas14:01
xgerman_#topic Announcements14:01
xgerman_:-(14:01
xgerman_well, I guess we need to go without bot today14:03
annpyes i think so14:03
xgerman_also just got note that both yushiro and sridark won’t be here :-(14:03
xgerman_so Q-3 is 1/2214:04
xgerman_#link https://releases.openstack.org/queens/schedule.html14:04
xgerman_#topic FWG and SG14:05
xgerman_if two ports are in the same SG the rules won’t apply, e.g. if you are blocking ping the two hosts can still ping each other14:06
xgerman_in FWG we apply the rules irregardless, e.g. we would bock the ping to the two ports14:06
xgerman_I am not sure if we should adapt SG behavior, keep ours, or do something completely different14:07
xgerman_thoughts?14:07
annpxgerman, I am not sure14:08
annpactually, i havent think about that14:09
SarathMekalaxgerman_, any idea what the reasoning behind SG behaviour is?14:09
*** yushiro has joined #openstack-fwaas14:10
xgerman_I can only speculate but maybe they tried to implement zones14:10
yushiroHi, sorry for late!!14:10
xgerman_no worries - meetbot is not working today14:10
xgerman_we were just talking about:14:11
yushiroxgerman_, Aha, OK.  I saw ur e-mail.  Thanks.14:11
xgerman_https://www.irccloud.com/pastebin/U9cW9o1H/14:11
annpxgerman, do you mean we need to consider source group id and dst group id in the firewall rule, right?14:11
SarathMekalahmm.. but even if two hosts belong to a zone there can be a rule to block traffic between them.. it works this way on Juniper FW devices14:11
SarathMekalanot sure about the industry behaviour14:11
xgerman_annp: in our spec that morte or less makes it easier to manage group of ports14:12
xgerman_SarathMekala: yeah, that makes sense.14:12
xgerman_Once we have remote FWG people can mimic the SG behavior, e.g. set in FWG A a rule whic references FWG A and allows access14:14
yushirothanks.  just watched..14:14
annpxgerman, yes but in the SG, we only care about remote group id14:15
xgerman_yeah, they only have it as source14:16
annpxgerman, and we dont care about local group id14:16
yushiro+1  SG retrieves 'remote_group_id' as 'source'.14:17
xgerman_yeah, my main worry is that people will expect us to behave like SG and wonder why we block their traffic…14:18
yushiroxgerman_, Ah, OK.  I see your concern point.14:19
xgerman_we can always document that…14:20
yushiroI think current SG is 'allow wins'.14:20
annpxgerman, +1 :)14:21
yushiroah, sorry.  What I'd like to say is that 'remote_group_id' wins in case of SG.14:21
xgerman_yeah, they modeled SG after AWS and they moved on, too14:22
yushiroOK14:23
yushiroHowever, I think FWaaS should keep 'deny wins'.  So, it's better to describe in document.14:23
xgerman_+114:24
SarathMekala+114:24
yushiroSo, if fwg includes at least 1 deny HTTP rule and this fwg is specified 'remote_firewall_group_id',14:25
yushiroHTTP access should be denied from IP addresses which is applied same FWG.14:25
yushiroI think this behavior looks safety side.14:26
yushiroannp, thought?14:27
annpyushiro, not sure, it will make sense for fwaas14:27
xgerman_I think being explicit with the allows and denying everyhting even if in the same FWG or remote FWG makes sense14:28
*** sarathmekala_ has joined #openstack-fwaas14:29
yushiroxgerman_, +1.  FWaaS behavior should keep consistency like 'deny win'14:30
yushiroAdding 'allow fwg rule' and 'remote_fwg_id' are same meaning --> applying 'allow' rule14:32
*** SarathMekala has quit IRC14:33
xgerman_yep, we to make sure to minimize confusion when people run both, FW and SG, and SG behavior changes because of FW14:33
doudeHi14:35
doudesorry I'm late14:35
yushirohi, happy new year!!, doude14:35
xgerman_+114:35
doudeThanks, Happy new year tp14:35
doudeto*14:35
annpxgerman, yushiro, SarathMekala, Can we come back this topic in next mtg? I would like to dig more about that :)14:35
xgerman_ok, sounds good14:36
yushiroannp, OK.  Maybe you're considering an 'order' of rule..  Let's dig it more.14:36
annpand in next mtg, I hope SridarK and chandanc will be there :)14:36
xgerman_+114:36
annpyushiro, yes :) you read my mind14:36
yushirohaha :)14:37
annpSo lets discuss in next mtg14:38
yushiroOK14:38
xgerman_+114:38
sarathmekala_+114:39
xgerman_#topic Q-314:39
annpand i have once more patch need your eye related to firewall driver14:39
annphttps://review.openstack.org/#/c/530450/14:39
yushiroOK14:41
xgerman_+114:41
annpIn this patch I try to fix the issue is specified in release note of co-existence patch14:41
xgerman_I think we have mostly conntrack and remote FWG left for Queens…14:41
annpso please have a look at it :)14:42
yushiroxgerman_, yes.14:42
yushiroI updated etherpad L.89~14:42
annpxgerman, yes, I think so14:43
*** yamamoto has quit IRC14:43
yushirobumped patch for Q-3 is 2.   1. Remote fwg   2. Auto association for default fwg14:43
xgerman_thanks14:44
xgerman_yeah, we accomplished a lot this cycle already —14:45
yushiroI think doude's work is also worth to try to merge during Q-3...14:46
xgerman_ok, we should totally aim for that14:46
-openstackstatus- NOTICE: zuul has been restarted, all queues have been reset. please recheck your patches when appropriate14:46
yushirowelcome back, zuul14:47
xgerman_;-)14:47
doudeI finished to rebase the master branch14:48
yushirodoude, +10 wow, great :)14:48
doudeI still have some code to rework (new code since my last patch set)14:48
doudeand after I need to validate nothing broken (devstack scripts, gates...)14:49
doudethen propose a new patch set to review14:49
xgerman_yeah, we will do the same once it’s proposed for review ;-)14:49
yushiroOK14:49
doudeok I hope to do that before next weekend14:49
xgerman_awesome14:50
yushiro:)14:50
yushirosarathmekala_, Do you have some announcement for horizon part for Q-3?14:50
yushiros/some/any14:51
sarathmekala_no yushiro14:51
yushiroOK.  BTW, I and xgerman_ has commented your google doc.  could you check it later ?? https://docs.google.com/document/d/1yKreFzwHsp-TMhB1xDH-EhGHBTGawFAaG1x6ukGJUK4/edit14:52
yushiro^^^ last year14:52
xgerman_with OpenStack going to yearly releases we should aim to get as much into Queens as possible14:52
sarathmekala_yeah.. had looked at them last year as well :)14:52
yushiro+100 yeah14:52
yushirosarathmekala_, OK :)14:53
sarathmekala_+114:53
sarathmekala_yushiro, xgerman_ I will add my replies to the comments14:53
yushirosarathmekala_, OK, thanks.  will check it later :)14:54
xgerman_T-614:54
*** annp has quit IRC14:55
yushiroPlease say it again.  Everyone, happy new year!! 201814:55
xgerman_+114:56
xgerman_also update your OS(es)14:56
yushiroI hope we can spend wonderful life in this year and make FWaaS much more better.14:56
yushiro:)14:57
sarathmekala_yushiro, same to you :)14:57
xgerman_+114:57
xgerman_#endmeeting :-)15:00
yushiroThanks.  bye bye15:00
xgerman_bye15:00
sarathmekala_bye all15:00
*** yushiro has quit IRC15:00
*** sarathmekala_ has quit IRC15:00
*** yamamoto has joined #openstack-fwaas15:01
doudebye15:02
*** mlavalle has joined #openstack-fwaas15:14
*** jafeha has quit IRC16:01
*** ChanServ sets mode: -r 16:47
*** jafeha has joined #openstack-fwaas16:57
*** mlavalle has left #openstack-fwaas17:07
*** SumitNaiksatam has joined #openstack-fwaas18:14
*** yamamoto has quit IRC18:29
*** yamamoto has joined #openstack-fwaas18:33
*** yamamoto has quit IRC18:37
*** yamamoto has joined #openstack-fwaas19:35
*** yamamoto has quit IRC19:42
*** SumitNaiksatam has quit IRC20:13
*** cleong has quit IRC21:23
*** threestrands has joined #openstack-fwaas21:35
*** threestrands has quit IRC21:35
*** threestrands has joined #openstack-fwaas21:35

Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!