]> review.fuel-infra Code Review - openstack-build/neutron-build.git/commit
Only mark metadata packets on internal interfaces
authorBertrand Lallau <bertrand.lallau@thalesgroup.com>
Thu, 23 Jul 2015 09:31:49 +0000 (11:31 +0200)
committerBertrand Lallau <bertrand.lallau@thalesgroup.com>
Fri, 21 Aug 2015 14:32:53 +0000 (16:32 +0200)
commitf23eb3290a1943c12e0ffbfd812ff5443f57af3c
tree35649e87181b925506f2b2588716e604dba12402
parent6f109bd6423a01d8aadd099652a3909fff89f090
Only mark metadata packets on internal interfaces

Currently iptables rules set on L3 agent with metadata_proxy enabled
mark all packets coming from all interfaces including external interfaces.

This change updates PREROUTING rules from MANGLE table to mark packets
only from internal interfaces.

Change-Id: I01549df7b99be84cd46b6f97a5fd62aec1f43275
Closes-Bug: #1477553
neutron/agent/metadata/driver.py
neutron/tests/unit/agent/metadata/test_driver.py