<!-- 
RSS generated by JIRA (8.20.10#820010-sha1:ace47f9899e9ee25d7157d59aa17ab06aee30d3d) at Wed Feb 07 20:21:45 UTC 2024

It is possible to restrict the fields that are returned in this document by specifying the 'field' parameter in your request.
For example, to request only the issue key and summary append 'field=key&field=summary' to the URL of your request.
-->
<rss version="0.92" >
<channel>
    <title>OpenDaylight JIRA</title>
    <link>https://jira.opendaylight.org</link>
    <description>This file is an XML representation of an issue</description>
    <language>en-us</language>    <build-info>
        <version>8.20.10</version>
        <build-number>820010</build-number>
        <build-date>22-06-2022</build-date>
    </build-info>


<item>
            <title>[NETVIRT-513] AAP with prefix 0.0.0.0/0 shouldn&apos;t be supported for remote security group rules</title>
                <link>https://jira.opendaylight.org/browse/NETVIRT-513</link>
                <project id="10144" key="NETVIRT">netvirt</project>
                    <description>&lt;p&gt;Supporting AAP with prefix 0.0.0.0/0 for remote security group rules would lead to a potential security breach. This would result in allowing the traffic from all the IPs.&lt;/p&gt;

&lt;p&gt;Below is a sample flow related to remote security group rules for VM (10.10.10.3). This would include nw_src match to allow traffic from VM (10.10.10.3).&lt;/p&gt;

&lt;p&gt; cookie=0x6900000, duration=3111.415s, table=252, n_packets=0, n_bytes=0, priority=1001,ct_state=+new+trk,ip,metadata=0x30000000000/0xfffff0000000000,nw_src=10.10.10.3 actions=ct(commit,zone=5001),resubmit(,220)&lt;/p&gt;

&lt;p&gt;Below is a sample flow related to remote security group rules for VM having AAP with prefix 0.0.0.0/0. This doesn&apos;t have nw_src match which would result in allowing the traffic from all the IPs.&lt;/p&gt;

&lt;p&gt;cookie=0x6900000, duration=3111.415s, table=252, n_packets=0, n_bytes=0, priority=1001,ct_state=+new+trk,ip,metadata=0x30000000000/0xfffff0000000000 actions=ct(commit,zone=5001),resubmit(,220).&lt;/p&gt;

&lt;p&gt;This bug is raised to not support AAP with 0.0.0.0/0 as part of remote security group rules/flows.&lt;/p&gt;</description>
                <environment>&lt;p&gt;Operating System: All&lt;br/&gt;
Platform: All&lt;/p&gt;</environment>
        <key id="20434">NETVIRT-513</key>
            <summary>AAP with prefix 0.0.0.0/0 shouldn&apos;t be supported for remote security group rules</summary>
                <type id="10104" iconUrl="https://jira.opendaylight.org/secure/viewavatar?size=xsmall&amp;avatarId=10303&amp;avatarType=issuetype">Bug</type>
                                                <status id="5" iconUrl="https://jira.opendaylight.org/images/icons/statuses/resolved.png" description="A resolution has been taken, and it is awaiting verification by reporter. From here issues are either reopened, or are closed.">Resolved</status>
                    <statusCategory id="3" key="done" colorName="green"/>
                                    <resolution id="10000">Done</resolution>
                                        <assignee username="somashekar.byrappa@ericsson.com">Somashekar Byrappa</assignee>
                                    <reporter username="somashekar.byrappa@ericsson.com">Somashekar Byrappa</reporter>
                        <labels>
                    </labels>
                <created>Tue, 7 Mar 2017 06:50:44 +0000</created>
                <updated>Mon, 3 Apr 2017 17:40:39 +0000</updated>
                            <resolved>Mon, 3 Apr 2017 17:40:39 +0000</resolved>
                                    <version>Boron</version>
                                                    <component>General</component>
                        <due></due>
                            <votes>0</votes>
                                    <watches>1</watches>
                                                                                                                <comments>
                            <comment id="37367" author="somashekar.byrappa@ericsson.com" created="Tue, 7 Mar 2017 06:56:26 +0000"  >&lt;p&gt;Support for AAP with 0.0.0.0/0 should be retained only for anti spoofing flows which are configured in table 40/251.&lt;/p&gt;</comment>
                            <comment id="37368" author="n.vivekanandan@ericsson.com" created="Mon, 3 Apr 2017 17:40:39 +0000"  >&lt;p&gt;This issues is fixed in master via:&lt;br/&gt;
&lt;a href=&quot;https://git.opendaylight.org/gerrit/53006&quot; class=&quot;external-link&quot; target=&quot;_blank&quot; rel=&quot;nofollow noopener&quot;&gt;https://git.opendaylight.org/gerrit/53006&lt;/a&gt;&lt;/p&gt;</comment>
                    </comments>
                    <attachments>
                    </attachments>
                <subtasks>
                    </subtasks>
                <customfields>
                                                                            <customfield id="customfield_11400" key="com.atlassian.jira.plugins.jira-development-integration-plugin:devsummary">
                        <customfieldname>Development</customfieldname>
                        <customfieldvalues>
                            
                        </customfieldvalues>
                    </customfield>
                                                                                                                        <customfield id="customfield_10208" key="com.atlassian.jira.plugin.system.customfieldtypes:textfield">
                        <customfieldname>External issue ID</customfieldname>
                        <customfieldvalues>
                            <customfieldvalue>7912</customfieldvalue>

                        </customfieldvalues>
                    </customfield>
                                                                <customfield id="customfield_10201" key="com.atlassian.jira.plugin.system.customfieldtypes:url">
                        <customfieldname>External issue URL</customfieldname>
                        <customfieldvalues>
                            <customfieldvalue><![CDATA[https://bugs.opendaylight.org/show_bug.cgi?id=7912]]></customfieldvalue>

                        </customfieldvalues>
                    </customfield>
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                <customfield id="customfield_10000" key="com.pyxis.greenhopper.jira:gh-lexo-rank">
                        <customfieldname>Rank</customfieldname>
                        <customfieldvalues>
                            <customfieldvalue>0|i01s9j:</customfieldvalue>

                        </customfieldvalues>
                    </customfield>
                                                                                                                                                                                </customfields>
    </item>
</channel>
</rss>