Skip to content

CFP-12781: Host Firewall Before NodePort DNAT#97

Open
jakubhlavnicka wants to merge 1 commit into
cilium:mainfrom
jakubhlavnicka:cfp-12781-host-firewall-before-nodeport-dnat
Open

CFP-12781: Host Firewall Before NodePort DNAT#97
jakubhlavnicka wants to merge 1 commit into
cilium:mainfrom
jakubhlavnicka:cfp-12781-host-firewall-before-nodeport-dnat

Conversation

@jakubhlavnicka
Copy link
Copy Markdown

Add CFP for enforcing host firewall ingress policy before NodePort DNAT/SNAT, which enables CiliumClusterwideNetworkPolicy to match on original external source IPs and NodePort destination ports.

Tracks: cilium/cilium#12781

Signed-off-by: Jakub Hlavnicka <jakub.hlavnicka@illumio.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant