18:32:31 #startmeeting Networking FWaaS 18:32:32 Meeting started Wed Jun 17 18:32:31 2015 UTC and is due to finish in 60 minutes. The chair is SridarK. Information about MeetBot at http://wiki.debian.org/MeetBot. 18:32:34 Useful Commands: #action #agreed #help #info #idea #link #topic #startvote. 18:32:36 The meeting name has been set to 'networking_fwaas' 18:32:44 o/ 18:32:46 hello all 18:32:52 hi all 18:32:59 Hi all 18:33:11 #topic Bugs 18:33:13 hello sridark 18:33:27 quick recap on bugs 18:33:42 #link https://bugs.launchpad.net/neutron/+bug/1455863 18:33:43 Launchpad bug 1455863 in neutron "FWAAS- FW Rule editing puts FW to error state " [Undecided,In progress] - Assigned to vishwanath jayaraman (vishwanathj) 18:33:53 Thanks Vish for addressing all the comments 18:34:14 i think we are good to go on this just waiting on some core attention 18:34:15 no problem 18:34:26 vishwanathj: did u have anything to discuss or add 18:34:40 no... 18:34:59 vishwanathj: ok cool 18:35:12 would be good if amotoki reviewed the test cases 18:35:14 #link https://bugs.launchpad.net/horizon/+bug/1454974 18:35:15 Launchpad bug 1454974 in OpenStack Dashboard (Horizon) "FWAAS- FW rules table is asymmetric." [Undecided,New] - Assigned to Kahou Lei (kahou82) 18:35:42 vishwanathj: i think u were not able to recreate this 18:35:42 i was not able to see the issue 18:35:47 yes 18:36:09 vishwanathj: thx - lets wait on the submitter to confirm - if this is not indeed an issue 18:36:18 ok 18:36:32 #link https://bugs.launchpad.net/neutron/+bug/1446074 18:36:41 Launchpad bug 1446074 in neutron "FWaaS - Missing tenant_id validation between firewall and firewall_policy in creating/updating firewall" [Low,In progress] - Assigned to Cedric Brandily (cbrandily) 18:36:49 i think this is also ready for core attention 18:37:13 I don't think Cedric is around for any further discussion 18:37:34 #link https://bugs.launchpad.net/neutron/+bug/1465440 18:37:35 Launchpad bug 1465440 in neutron "Firewall attribute "Shared" is set to None by default instead of 'False'" [High,Confirmed] - Assigned to vishwanath jayaraman (vishwanathj) 18:37:55 vishwanathj: thx for taking a look 18:38:29 vishwanathj: i added my comments on this - IMO the attribute not getting pushed to the db does look odd 18:38:54 would need Sumits input to the bug as well 18:38:59 vishwanathj: will need to dig more on the history - will also wait on Sumit for any more history on this 18:39:02 vishwanathj: yes 18:39:20 vishwanathj: perhaps we can wait on Sumit and then discuss to move forward 18:39:33 vishwanathj: anything else u wanted to discuss 18:39:34 i will push a patch and mark it as WIP 18:39:44 vishwanathj: sounds perfect 18:40:12 these were the bugs i had on my radar 18:40:22 any one else had other things that i missed 18:40:33 Hi Sridar 18:40:40 yanping: Hi 18:40:49 May I ask help for code review: https://review.openstack.org/#/c/190331/ 18:41:09 yanping: surely will take a look and request others to look as well 18:41:21 thanks a lot 18:41:24 yanping: i think u have made the change on the project 18:41:53 yes, I changed bug for project neutron 18:42:04 yanping: perfect 18:42:27 yanping: once a few of us look u can ask for some core attention 18:42:53 OK. Thanks. 18:43:09 yanping: np 18:43:41 if there are no other bugs - we can do a quick run of the specs although many people are missing today 18:43:58 Hello 18:43:59 #topic Traffic direction Spec 18:44:28 #link https://review.openstack.org/#/c/171340/ 18:44:45 i don't see slawek around and i know Vikram is out on PTO 18:45:13 i think we just need to close with Cedric on where the new attribute is to be applied 18:45:54 if we can close on that and reach consensus - we are good 18:46:46 Did anyone have anything else to add 18:47:14 I have reviewed it and have no further comments 18:47:44 vishwanathj: thx, i think we just need closure on this one aspect 18:48:26 #topic Service Objects/Group 18:48:40 badveli: congrats on the approval 18:48:57 thanks sridark 18:49:26 badveli: the floor is yours - would u like to discuss or bring up anything on the feature 18:50:06 nothing much as of now, need to work on some scenario tests 18:51:12 badveli: ok ur implementation plan will support this as a common feature that can be reused by other features as well correct ? 18:51:26 yes sridark 18:51:47 it will be reusable 18:52:05 badveli: cool - may be we can have more discussion in the next mtg if u are ready and comfortable 18:52:23 fine with me 18:52:33 badveli: ok great thx 18:52:43 thanks 18:52:48 #topic Logging Spec 18:52:56 Hi Sridark 18:52:59 #link https://review.openstack.org/#/c/132133/ 18:53:11 This is Hoang. I am on behaft of Yushiro 18:53:13 hoangcx: are u covering for yushiro 18:53:25 hoangcx: the floor is yours pls go ahead 18:53:34 Yeah. Yushiro wants to say "Hi" to Sridrak and all 18:53:56 May i ask to help with current WIP: https://review.openstack.org/#/c/188340/ 18:54:44 hoangcx: surely 18:54:57 hoangcx: we should also close on the spec and get that approved 18:55:11 i know there are some outstanding review comments 18:55:16 Beside this implementation, new logging API is currently implementing on Neutron 18:56:06 ok, will take a look and also reach out to yushiro to address the comments 18:56:08 in which we may centralize logging 18:56:09 on the spec 18:56:28 hoangcx: yes that is good and some of the comments are also in relation to this 18:56:30 Sridark: Yes. 18:56:51 hoangcx: i will take a look at the patch and also request others to look 18:57:07 About Hitcount function: Now we are under consideration 18:57:11 hoangcx: and we discuss on gerrit as well 18:57:14 Sridark: Thanks so much 18:57:40 Sridark: Yes. I see. 18:57:55 hoangcx: no worries - the hit count is something that yushiro and i also discussed at the summit and there was an earlier proposal to integrate with ceilometer 18:58:26 we can also get that moving with Pradeep Kilambi who was looking at ceilometer 18:58:41 hoangcx: sounds good thanks 18:59:00 hoangcx: anything else u would like to add ? 18:59:13 or discuss 18:59:14 Sridark: enough for me now. 18:59:21 hoangcx: ok thx 18:59:35 And waiting to get feedback about current implementation and new logging API discussion 18:59:47 hoangcx: yes perfect 19:00:00 #topic SG - FWaaS alignment 19:00:12 #link https://etherpad.openstack.org/p/fwaas_use_cases 19:00:21 xgerman: the floor is yours 19:00:31 thanks 19:01:14 We are still collecting use cases and I also feel the FWaaS is a puzzle in a bigger network security picture with IDS 19:01:26 avtually - end users we talked with mentioned IDS a lot 19:01:43 and DPI 19:02:14 xgerman: yes IDS - is it part of FW or a separate piece can be an interesting discussion 19:02:24 exactly 19:02:37 I hope that DPI can be added to service object/group at some point 19:02:46 xgerman: i guess there can be different views but this is certainly an important piece to pull in 19:02:48 DPI is not IDS though 19:03:05 yep, but I think we need both 19:03:10 mickeys: +1 or as a part of some the classifier discussions 19:03:20 * some of 19:04:00 johnsom: agree - it can be used to drive some the IDS actions 19:04:38 xgerman: also Sameer has added some inputs and i will reach out to him for more discussions as well 19:04:55 if u are not in discussion with him already 19:05:23 no, I have been in some bubble but our plan is to do some broader outreach in the next two weeks 19:05:34 My example I like to use is blocking HTTP Methods other than GET for example. That is a FW DPI action. 19:06:13 xgerman: sounds good 19:06:50 johnsom: yes and there can be whole host of more application based actions 19:07:32 Sridark: Do yu know Sameer's last name? 19:07:50 yeah, I have also seen people doing “on demand” scanning by using SDN rules - and.or put some basic IDS functionality on white box routers 19:07:51 yamahata also had an initial thought for looking at L4 - L7 use cases and along with many of us who were also interested 19:08:01 sballe: Sameer Satyam 19:08:08 from Rackspace 19:08:13 ok thx 19:08:16 ok, thx 19:08:17 np 19:09:38 xgerman: i agree this is going to take some time and effort to get all this in 19:10:59 xgerman: , others anything else we want to discuss on this topic ? 19:11:30 Once we have use cases we can prioritize and thing will be better 19:11:40 we can all use the ether pad link above to put use cases and thoughts/comments 19:11:48 +1 19:11:50 xgerman: agreed 19:12:20 that’s all frm me for now 19:12:26 those of us who also wear vendor hats can also reach out to our customers to provide inputs 19:12:32 xgerman: thx 19:12:41 SridarK that would be great! 19:13:08 #topic Open Discussion 19:13:25 other thoughts or things folks would like to bring up pls go ahead 19:14:15 anyone going to the neutron mid-cycle next week? 19:14:32 pc_m: are u going to be there ? 19:14:37 SridarK: yes 19:15:00 pc_m: cool - i am out of office so definitely not going - 19:15:18 pc_m, How does one got to the mid-cyle? is it by invitation only? 19:15:26 SridarK: That sounds like a whole lot more fun :) 19:15:27 everybody can go 19:15:31 vishwanathj: no u just sign up 19:15:35 vishwanathj: Anyone can go. 19:15:35 ok 19:15:39 pc_m: :-) 19:15:40 yeah, there is an etherpad 19:15:48 #link https://etherpad.openstack.org/p/neutron-liberty-mid-cycle 19:16:07 did not know about this...thanks for sharing 19:16:10 It's next Wed-Fri 19:16:44 pc_m: is the focus on the micro versioning ? 19:16:45 great learning experience, with many cores and experienced Neutron folks there. 19:17:13 SridarK: No, actually it's not on the list. The therpad has the agenda. 19:17:20 etherpad 19:17:39 Though they may still work on it some 19:17:44 pc_m: ok never mind stupid q - i should know how to click on a ling :-) 19:17:52 *link 19:17:53 :) 19:18:18 ok cook if nothing else we can try to get back 12 mins to go save the world :-) 19:18:38 The next meeting will be on Jul 1 19:18:43 cool. Thanks SridarK 19:18:58 alright folks have a good one 19:19:01 bye 19:19:08 bye 19:19:09 Thanks for today's discussion and see you in next meeting 19:19:11 bye 19:19:15 Bye 19:19:19 xgerman in your investigation was there a case for east west traffic inspection 19:19:22 bye 19:19:27 #endmeeting