-
Epic
-
Resolution: Done
-
Highest
-
None
-
None
-
None
Enhance VPP classifier support to support OpenStack security groups uses cases (FDS/ML2-VPP). Ultimately the solution needs to:
- Support classifiers/filters on L2/bridging interfaces
- Filter on IP-addresses with address mask (IPv4 and IPv6)
- Filter on L4 port ranges
- Filter on L2 MAC addresses
- Support IPv6 with extension headers present
- Combinations of the above filters (e.g. MAC + IP)
- Filters on ingress and egress
More specifically, the following gaps have to be resolved:
- VPP L2 output classifier feature node (to support Neutron ingress rules on L2 bridge interfaces and L3 routed interfaces)
- support L4 classification with IPv6 extension header present (moderate priority)
See also: