OVS ARP spoofing protection breaks floating IPs without port security extension
Bug #1487338 reported by
Kevin Benton
This bug affects 2 people
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
neutron |
Fix Released
|
Medium
|
Kevin Benton | ||
Kilo |
New
|
Undecided
|
Unassigned |
Bug Description
The OVS ARP spoofing protection depends on the port security extension being enabled to disable ARP spoofing protection on router interfaces that have floating IP traffic on them. So if the port security extension is disabled the router interface will get ARP spoofing rules, which don't know about the floating IPs and will drop the ARP requests for them.
Changed in neutron: | |
milestone: | none → liberty-rc1 |
importance: | Undecided → Medium |
Changed in neutron: | |
status: | Fix Committed → Fix Released |
Changed in neutron: | |
milestone: | liberty-rc1 → 7.0.0 |
To post a comment you must log in.
Fix proposed to branch: master /review. openstack. org/215491
Review: https:/