aboutsummaryrefslogtreecommitdiffstats
path: root/puppet/services/neutron-l3.yaml
diff options
context:
space:
mode:
authorEmilien Macchi <emilien@redhat.com>2016-10-06 11:18:14 -0400
committerEmilien Macchi <emilien@redhat.com>2016-10-06 12:07:35 -0400
commit7322d60610764f728ce58d4e8a39a6c54c652643 (patch)
tree0d58f2bc7b8b4e9328806c1d8ff6217b64ef409d /puppet/services/neutron-l3.yaml
parentddd4d3cd9f5012b505c1ed2c4ee6a62dde37dbaf (diff)
Enable firewalling by default on compute nodes
- Move VXLAN and VRRP rules from Neutron Server to the right services. - Enable Firewall by default on Compute nodes. Change-Id: I99d172dcedaf6be297aad184cc51fe9f292a57e1
Diffstat (limited to 'puppet/services/neutron-l3.yaml')
-rw-r--r--puppet/services/neutron-l3.yaml3
1 files changed, 3 insertions, 0 deletions
diff --git a/puppet/services/neutron-l3.yaml b/puppet/services/neutron-l3.yaml
index 9e223374..a89e3d75 100644
--- a/puppet/services/neutron-l3.yaml
+++ b/puppet/services/neutron-l3.yaml
@@ -67,5 +67,8 @@ outputs:
- neutron::agents::l3::external_network_bridge: {get_param: NeutronExternalNetworkBridge}
neutron::agents::l3::router_delete_namespaces: True
neutron::agents::l3::agent_mode : {get_param: NeutronL3AgentMode}
+ tripleo.neutron_l3.firewall_rules:
+ '106 neutron_l3 vrrp':
+ proto: vrrp
step_config: |
include tripleo::profile::base::neutron::l3