Re: [Blocker] Default ip table rules on VR

2015-08-03 Thread Wilder Rodrigues
the old >>> iptables-vpcrouter/iptables-router files. >>> >>> Cheers, >>> Wilder >>> >>> >>>> On 31 Jul 2015, at 06:03, Sanjeev N wrote: >>>> >>>> Thanks for working on it Wilder !! >>>>

Re: [Blocker] Default ip table rules on VR

2015-08-03 Thread Wilder Rodrigues
ilder Rodrigues < >>> wrodrig...@schubergphilis.com> wrote: >>> >>>> Hi, >>>> >>>> We discussed that one yesterday and I already assigned the issue to >> myself >>>> on Jira. I will fix it. >>>> >>>> Cheers, >

Re: [Blocker] Default ip table rules on VR

2015-08-03 Thread Sanjeev N
> > >> > >> > >>> On 30 Jul 2015, at 14:09, Sanjeev N wrote: > >>> > >>> Agree with Kishan Kavala and Jayapal. > >>> > >>> On Thu, Jul 30, 2015 at 2:13 PM, Kishan Kavala < > kishan.kav...@citrix.com > >>

Re: [Blocker] Default ip table rules on VR

2015-08-03 Thread Wilder Rodrigues
e with Kishan Kavala and Jayapal. >>> >>> On Thu, Jul 30, 2015 at 2:13 PM, Kishan Kavala >> >>> wrote: >>> >>>> This is a security issue with high impact. >>>> We should treat it as a blocker. >>>> >>>> ---

Re: [Blocker] Default ip table rules on VR

2015-07-30 Thread Sanjeev N
e should treat it as a blocker. > >> > >> -Original Message- > >> From: Jayapal Reddy Uradi [mailto:jayapalreddy.ur...@citrix.com] > >> Sent: 30 July 2015 02:07 PM > >> To: > >> Subject: Re: [Blocker] Default ip table rules on VR > >&g

Re: [Blocker] Default ip table rules on VR

2015-07-30 Thread Daan Hoogland
Guys, I see votes here but no arguments. Why is it a blocker? >>> From: Jayapal Reddy Uradi [mailto:jayapalreddy.ur...@citrix.com] >>> Sent: 30 July 2015 02:07 PM >>> To: >>> Subject: Re: [Blocker] Default ip table rules on VR >>> >>> I see

Re: [Blocker] Default ip table rules on VR

2015-07-30 Thread Wilder Rodrigues
e: > >> This is a security issue with high impact. >> We should treat it as a blocker. >> >> -Original Message- >> From: Jayapal Reddy Uradi [mailto:jayapalreddy.ur...@citrix.com] >> Sent: 30 July 2015 02:07 PM >> To: >> Subject: Re: [Blo

Re: [Blocker] Default ip table rules on VR

2015-07-30 Thread Sanjeev N
t: 30 July 2015 02:07 PM > To: > Subject: Re: [Blocker] Default ip table rules on VR > > I see VR ingress traffic is blocked by default from iptables mangle table. > But on the guest interface all the traffic is accepted. > Also egress firewall rule will break because of FORWARD

RE: [Blocker] Default ip table rules on VR

2015-07-30 Thread Kishan Kavala
This is a security issue with high impact. We should treat it as a blocker. -Original Message- From: Jayapal Reddy Uradi [mailto:jayapalreddy.ur...@citrix.com] Sent: 30 July 2015 02:07 PM To: Subject: Re: [Blocker] Default ip table rules on VR I see VR ingress traffic is blocked by

Re: [Blocker] Default ip table rules on VR

2015-07-30 Thread Jayapal Reddy Uradi
I see VR ingress traffic is blocked by default from iptables mangle table. But on the guest interface all the traffic is accepted. Also egress firewall rule will break because of FORWARD policy. Thanks, Jayapal On 30-Jul-2015, at 12:53 PM, Jayapal Reddy Uradi wrote: > > It is security concern

Re: [Blocker] Default ip table rules on VR

2015-07-30 Thread Jayapal Reddy Uradi
It is security concern on the VR. All the ingress traffic onto the VR is accepted. Let it be blocker. Thanks, Jayapal On 30-Jul-2015, at 12:28 PM, Daan Hoogland wrote: > I changed it to critical. It is only a blocker if we agree on this > list that it is. > > On Thu, Jul 30, 2015 at 6:44 AM

Re: [Blocker] Default ip table rules on VR

2015-07-29 Thread Daan Hoogland
I changed it to critical. It is only a blocker if we agree on this list that it is. On Thu, Jul 30, 2015 at 6:44 AM, Sanjeev N wrote: > Hi, > > In latest ACS builds, the ip table rules in VR have ACCEPT as the default > policy in INPUT and FORWARD chains, instead of DROP. > > Created a blocker bu