[openstack-dev] [neutron]

Ihar Hrachyshka ihrachys at redhat.com
Fri Nov 18 13:41:03 UTC 2016


> On 18 Nov 2016, at 13:58, Iago Santos Pardo <iago.santos.pardo at cern.ch> wrote:
> 
> Hello, 
> 
> We are using Neutron with the linuxbridge plugin and security groups enabled and we have some custom rules in iptables running on the compute nodes. When the agent rebuilds the firewall it changes the rules order, putting the neutron chains on the top. Is there any way to preserve the rules order and tell neutron to ignore our rules or stuck them on the top?

Can’t you express the needed behaviour with security groups API itself?

Ihar


More information about the OpenStack-dev mailing list