<div dir="ltr">

<p style="text-decoration-style:initial;text-decoration-color:initial;margin:0in 0in 0.0001pt;font-size:11pt;font-family:Calibri,sans-serif"><span style="font-size:12pt;color:black">Hi,<span></span></span></p><p style="text-decoration-style:initial;text-decoration-color:initial;margin:0in 0in 0.0001pt;font-size:11pt;font-family:Calibri,sans-serif"><span style="font-size:12pt;color:black"><span> </span></span></p><p style="text-decoration-style:initial;text-decoration-color:initial;margin:0in 0in 0.0001pt;font-size:11pt;font-family:Calibri,sans-serif"><span style="font-size:12pt;color:black">The FWaaS V2 spec (<a href="https://specs.openstack.org/openstack/neutron-specs/specs/mitaka/fwaas-api-2.0.html" target="_blank" style="color:blue;text-decoration:underline">https://specs.openstack.org/<wbr>openstack/neutron-specs/specs/<wbr>mitaka/fwaas-api-2.0.html</a>) <wbr>describes quite some changes.<span></span></span></p><p style="text-decoration-style:initial;text-decoration-color:initial;margin:0in 0in 0.0001pt;font-size:11pt;font-family:Calibri,sans-serif"><span style="font-size:12pt;color:black"><span> </span></span></p><p style="text-decoration-style:initial;text-decoration-color:initial;margin:0in 0in 0.0001pt;font-size:11pt;font-family:Calibri,sans-serif"><span style="font-size:12pt;color:black">Currently only some of that functionality seems to be implemented i.e. applying firewall groups on a L2/L3 port.<span></span></span></p><p style="text-decoration-style:initial;text-decoration-color:initial;margin:0in 0in 0.0001pt;font-size:11pt;font-family:Calibri,sans-serif"><span style="font-size:12pt;color:black"><span> </span></span></p><p style="text-decoration-style:initial;text-decoration-color:initial;margin:0in 0in 0.0001pt;font-size:11pt;font-family:Calibri,sans-serif"><span style="font-size:12pt;color:black">Does a roadmap exist, describing when/whether other features will be implemented as well? <span></span></span></p><p style="text-decoration-style:initial;text-decoration-color:initial;margin:0in 0in 0.0001pt;font-size:11pt;font-family:Calibri,sans-serif"><span style="font-size:12pt;color:black">Not implemented features mentioned in the spec include:<span></span></span></p><ul type="disc" style="font-size:small;text-decoration-style:initial;text-decoration-color:initial;margin-bottom:0in"><li class="MsoNormal" style="margin:0in 0in 0.0001pt;color:black;font-size:11pt;font-family:Calibri,sans-serif"><span style="font-size:12pt">firewall group construct as well as a way to specify allowed sources and destinations in firewall rules<span></span></span></li><li class="MsoNormal" style="margin:0in 0in 0.0001pt;color:black;font-size:11pt;font-family:Calibri,sans-serif"><span style="font-size:12pt">indirections through address group and service group<span></span></span></li><li class="MsoNormal" style="margin:0in 0in 0.0001pt;color:black;font-size:11pt;font-family:Calibri,sans-serif"><span style="font-size:12pt">allow multiple firewall group associations for the same Neutron port<span></span></span></li></ul><p class="MsoNormal" style="margin:0in 0in 0.0001pt;text-decoration-style:initial;text-decoration-color:initial;font-size:11pt;font-family:Calibri,sans-serif"><span style="font-size:12pt;color:black"><span> </span></span></p><p style="text-decoration-style:initial;text-decoration-color:initial;margin:0in 0in 0.0001pt;font-size:11pt;font-family:Calibri,sans-serif"><span style="font-size:12pt;color:black">Best regards,<span></span></span></p><p style="text-decoration-style:initial;text-decoration-color:initial;margin:0in 0in 0.0001pt;font-size:11pt;font-family:Calibri,sans-serif"><span style="font-size:12pt;color:black">Glenn</span></p></div>