diff options
| author | Soren Hansen <soren@linux2go.dk> | 2011-01-25 21:20:42 +0100 |
|---|---|---|
| committer | Soren Hansen <soren@linux2go.dk> | 2011-01-25 21:20:42 +0100 |
| commit | e44b28a0daa771c67fa8672f89f7d52ee1bfec22 (patch) | |
| tree | 2910b43f9b4ee566b36b0f8c2b057ad85d07c53d | |
| parent | 588bf6717a11930435ad3b3aa1941cff8495e2b5 (diff) | |
| download | nova-e44b28a0daa771c67fa8672f89f7d52ee1bfec22.tar.gz nova-e44b28a0daa771c67fa8672f89f7d52ee1bfec22.tar.xz nova-e44b28a0daa771c67fa8672f89f7d52ee1bfec22.zip | |
Perform same filtering for OUTPUT as FORWARD in iptables. This removes a way around the filtering.
| -rw-r--r-- | nova/virt/libvirt_conn.py | 1 |
1 files changed, 1 insertions, 0 deletions
diff --git a/nova/virt/libvirt_conn.py b/nova/virt/libvirt_conn.py index 37eb02e4f..ac7fd8ef0 100644 --- a/nova/virt/libvirt_conn.py +++ b/nova/virt/libvirt_conn.py @@ -1228,6 +1228,7 @@ class IptablesFirewallDriver(FirewallDriver): our_chains += [':nova-local - [0:0]'] our_rules += ['-A FORWARD -j nova-local'] + our_rules += ['-A OUTPUT -j nova-local'] security_groups = {} # Add our chains |
