Re: [ovs-dev] [PATCH] ovn: Add stateful ACL support.

2015-10-16 Thread Justin Pettit
> On Oct 15, 2015, at 5:21 PM, Ben Pfaff wrote: > > On Thu, Oct 15, 2015 at 10:32:51AM -0700, Justin Pettit wrote: >> Add support for the "allow-related" ACL action. This is dependent on >> the OVS conntrack functionality, which is not available on all platforms >> or kernel versions. >> >> He

Re: [ovs-dev] [PATCH] ovn: Add stateful ACL support.

2015-10-15 Thread Ben Pfaff
On Thu, Oct 15, 2015 at 10:32:51AM -0700, Justin Pettit wrote: > Add support for the "allow-related" ACL action. This is dependent on > the OVS conntrack functionality, which is not available on all platforms > or kernel versions. > > Here is a sample policy that will allow all tenants in logical

[ovs-dev] [PATCH] ovn: Add stateful ACL support.

2015-10-15 Thread Justin Pettit
Add support for the "allow-related" ACL action. This is dependent on the OVS conntrack functionality, which is not available on all platforms or kernel versions. Here is a sample policy that will allow all tenants in logical switch "ls0" to SSH to each other. Anyone can make an HTTP request to "