Before apply patch we have next rules:
...
-A neutron-openvswi-iac16f023-b -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
-A neutron-openvswi-iac16f023-b -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
...
After apply patch we have next rules:
...
-A neutron-openvswi-o9ceef79b-3 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
-A neutron-openvswi-o9ceef79b-3 -j RETURN
-A neutron-openvswi-o9ceef79b-3 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
...
Verified on 7.0 Ubuntu with installed mirror packages: perestroika- repo-tst. infra.mirantis. net/review/ CR-14561/ mos-repos/ ubuntu/ 7.0/dists/ mos7.0- proposed/
http://
Before apply patch we have next rules: openvswi- iac16f023- b -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP openvswi- iac16f023- b -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
...
-A neutron-
-A neutron-
...
After apply patch we have next rules: openvswi- o9ceef79b- 3 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN openvswi- o9ceef79b- 3 -j RETURN openvswi- o9ceef79b- 3 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
...
-A neutron-
-A neutron-
-A neutron-
...