summaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorVishvananda Ishaya <vishvananda@yahoo.com>2010-09-29 06:17:39 -0700
committerVishvananda Ishaya <vishvananda@yahoo.com>2010-09-29 06:17:39 -0700
commita86507b3224eb051fea97f65bd5653758fa91668 (patch)
tree9e3ac551a084621da6953428a4a13b8c7eb95b24
parent5fa5a0b0b9e13f8f44b257eac0385730c959b92f (diff)
downloadnova-a86507b3224eb051fea97f65bd5653758fa91668.tar.gz
nova-a86507b3224eb051fea97f65bd5653758fa91668.tar.xz
nova-a86507b3224eb051fea97f65bd5653758fa91668.zip
fix ordering of rules to actually allow out and drop in
-rw-r--r--nova/virt/libvirt_conn.py8
1 files changed, 4 insertions, 4 deletions
diff --git a/nova/virt/libvirt_conn.py b/nova/virt/libvirt_conn.py
index c86f3ffb7..9d889cf29 100644
--- a/nova/virt/libvirt_conn.py
+++ b/nova/virt/libvirt_conn.py
@@ -527,8 +527,8 @@ class NWFilterFirewall(object):
def nova_base_ipv4_filter(self):
retval = "<filter name='nova-base-ipv4' chain='ipv4'>"
for protocol in ['tcp', 'udp', 'icmp']:
- for direction,action,priority in [('out','accept', 400),
- ('in','drop', 399)]:
+ for direction,action,priority in [('out','accept', 399),
+ ('inout','drop', 400)]:
retval += """<rule action='%s' direction='%s' priority='%d'>
<%s />
</rule>""" % (action, direction,
@@ -540,8 +540,8 @@ class NWFilterFirewall(object):
def nova_base_ipv6_filter(self):
retval = "<filter name='nova-base-ipv6' chain='ipv6'>"
for protocol in ['tcp', 'udp', 'icmp']:
- for direction,action,priority in [('out','accept',400),
- ('in','drop',399)]:
+ for direction,action,priority in [('out','accept',399),
+ ('inout','drop',400)]:
retval += """<rule action='%s' direction='%s' priority='%d'>
<%s-ipv6 />
</rule>""" % (action, direction,