Hi All,
So we're playing with "ipfilter-net*" to specifically state what IPs a VM is allowed to use - that works fine.
However, if the INPUT firewall is set to ACCEPT, it allows all traffic to any IPs and not just those in the IPset.
I would say that the INPUT needs to still honour what is set in the IPset as that is set as a "only allow these IPs" so no matter what the user could create in their firewalls on the node via API, that rule should never be overridden - i.e should always be the highest priority.
If not, it largely makes the feature useless.
Matt
So we're playing with "ipfilter-net*" to specifically state what IPs a VM is allowed to use - that works fine.
However, if the INPUT firewall is set to ACCEPT, it allows all traffic to any IPs and not just those in the IPset.
I would say that the INPUT needs to still honour what is set in the IPset as that is set as a "only allow these IPs" so no matter what the user could create in their firewalls on the node via API, that rule should never be overridden - i.e should always be the highest priority.
If not, it largely makes the feature useless.
Matt