[caclmgrd] remove default DROP rule on FORWARD chain (#5034)
This commit is contained in:
parent
0ec979dd30
commit
4a2db8e216
@ -358,9 +358,7 @@ class ControlPlaneAclManager(object):
|
||||
# add iptables/ip6tables commands to drop all other incoming packets
|
||||
if num_ctrl_plane_acl_rules > 0:
|
||||
iptables_cmds.append("iptables -A INPUT -j DROP")
|
||||
iptables_cmds.append("iptables -A FORWARD -j DROP")
|
||||
iptables_cmds.append("ip6tables -A INPUT -j DROP")
|
||||
iptables_cmds.append("ip6tables -A FORWARD -j DROP")
|
||||
|
||||
return iptables_cmds
|
||||
|
||||
|
Reference in New Issue
Block a user