Bug 1378459 - [RFE] Allow deny rules on security groups
Summary: [RFE] Allow deny rules on security groups
Keywords:
Status: CLOSED WONTFIX
Alias: None
Product: Red Hat OpenStack
Classification: Red Hat
Component: openstack-neutron
Version: 7.0 (Kilo)
Hardware: Unspecified
OS: Unspecified
unspecified
medium
Target Milestone: ---
: ---
Assignee: Assaf Muller
QA Contact: Toni Freger
URL:
Whiteboard:
Depends On:
Blocks: 1381612
TreeView+ depends on / blocked
 
Reported: 2016-09-22 13:09 UTC by Petr Barta
Modified: 2022-08-10 17:03 UTC (History)
8 users (show)

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Environment:
Last Closed: 2016-10-06 08:54:58 UTC
Target Upstream Version:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Issue Tracker OSP-6231 0 None None None 2022-08-10 17:03:39 UTC
Red Hat Knowledge Base (Solution) 6186201 0 None None None 2021-07-14 19:42:16 UTC

Description Petr Barta 2016-09-22 13:09:09 UTC
Description of problem:

Allow deny rules on security groups.

Use case:
If customer creates, for example, a rule to allow incoming traffic to port 80, it's not possible explicitly deny traffic from a specific network, and therefore customer has to know all networks which he wants to allow traffic from, and modify the security group rules every time a new network is created.

Client wants to allow traffic by default to all networks, and create deny rules to explicitly deny traffic from some networks.

Useful as well when there is a network attack (hacking attempt, DOS) and customer wants to block the attacking IP only.


Customer is aware of FWaaS possibility, which allows creation of deny/reject rules, but as it is technology preview only, does not want to use it in production environment, therefore request for enhancement.

We have discussed as well possibility to filter traffic on the instance's side (by using for example iptables/firewalld on OS level), but this is feasible as security team can be separate from administrator's team of the instances, and therefore security team does not have access to the OS on instances.


Actual results:

Not possible to create "deny" security group rules.

Expected results:

Ability to create "allow" and/or "deny" security groups rules, to block unwonted traffic, rather then having to list all traffic which is allowed to come in.

Additional info:

Comment 9 RHEL Program Management 2016-10-06 08:54:58 UTC
Product Management has reviewed and declined this request.
You may appeal this decision by reopening this request.


Note You need to log in before you can comment on or make changes to this bug.