[caclmgrd] remove default DROP rule on FORWARD chain (#5034)
This commit is contained in:
parent
59072a627b
commit
6120145bf1
@ -410,9 +410,7 @@ class ControlPlaneAclManager(object):
|
||||
# add iptables/ip6tables commands to drop all other incoming packets
|
||||
if num_ctrl_plane_acl_rules > 0:
|
||||
iptables_cmds.append("iptables -A INPUT -j DROP")
|
||||
iptables_cmds.append("iptables -A FORWARD -j DROP")
|
||||
iptables_cmds.append("ip6tables -A INPUT -j DROP")
|
||||
iptables_cmds.append("ip6tables -A FORWARD -j DROP")
|
||||
|
||||
return iptables_cmds
|
||||
|
||||
|
Loading…
Reference in New Issue
Block a user