Note: This bug is displayed in read-only format because the product is no longer active in Red Hat Bugzilla.

Bug 1269849

Summary: security groups iptables can block legitimate traffic as INVALID
Product: Red Hat OpenStack Reporter: Nir Magnezi <nmagnezi>
Component: openstack-neutronAssignee: Nir Magnezi <nmagnezi>
Status: CLOSED ERRATA QA Contact: Eran Kuris <ekuris>
Severity: high Docs Contact:
Priority: high    
Version: 7.0 (Kilo)CC: amuller, bschmaus, chrisw, ekuris, jlibosva, lpeer, mlopes, nyechiel, oblaut, sputhenp, tfreger, yeylon
Target Milestone: z3Keywords: ZStream
Target Release: 7.0 (Kilo)Flags: nmagnezi: needinfo-
nmagnezi: needinfo-
Hardware: x86_64   
OS: Linux   
Whiteboard:
Fixed In Version: openstack-neutron-2015.1.1-13.el7ost Doc Type: Bug Fix
Doc Text:
Prior to this update, the Linux iptables implementation of security groups included a default rule to drop any INVALID packets. Consequently, it was possible that iptables could block legitimate traffic as INVALID, such as SCTP protocol. This update address this issue by processing user-defined iptables rules before the INVALID DROP rule.
Story Points: ---
Clone Of: 1268413 Environment:
Last Closed: 2015-12-21 16:58:54 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 1268413, 1338971    
Bug Blocks:    

Comment 1 Jakub Libosvar 2015-10-14 15:01:13 UTC
This bug should be targeted to RHOS 7, we have bug 1268413 for RHOS 6. Re-setting

Comment 3 Eran Kuris 2015-11-23 07:32:56 UTC
Need info to reproduce the issue there is no explanation how to try to reproduce the issue .

Comment 4 Eran Kuris 2015-11-23 09:21:49 UTC
verified on OSP-7 puddle 2015-11-20.2
[root@puma06 ~(keystone_admin)]# sudo iptables -nvL  neutron-openvswi-of216d9d9-f --line-numbers
Chain neutron-openvswi-of216d9d9-f (2 references)
num   pkts bytes target     prot opt in     out     source               destination         
1        2   656 RETURN     udp  --  *      *       0.0.0.0/0            0.0.0.0/0            udp spt:68 dpt:67 /* Allow DHCP client traffic. */
2      257 22268 neutron-openvswi-sf216d9d9-f  all  --  *      *       0.0.0.0/0            0.0.0.0/0           
3        0     0 DROP       udp  --  *      *       0.0.0.0/0            0.0.0.0/0            udp spt:67 dpt:68 /* Prevent DHCP Spoofing by VM. */
4      141 12300 RETURN     all  --  *      *       0.0.0.0/0            0.0.0.0/0            state RELATED,ESTABLISHED /* Direct packets associated with a known session to the RETURN chain. */
5      116  9968 RETURN     all  --  *      *       0.0.0.0/0            0.0.0.0/0           
6        0     0 RETURN     sctp --  *      *       0.0.0.0/0            0.0.0.0/0           
7        0     0 DROP       all  --  *      *       0.0.0.0/0            0.0.0.0/0            state INVALID /* Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack. */
8        0     0 neutron-openvswi-sg-fallback  all  --  *      *       0.0.0.0/0            0.0.0.0/0            /* Send unmatched traffic to the fallback chain. */

Comment 9 errata-xmlrpc 2015-12-21 16:58:54 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://access.redhat.com/errata/RHBA-2015:2652