summaryrefslogtreecommitdiffstats
path: root/docs/configguide
diff options
context:
space:
mode:
authorBin Hu <bh526r@att.com>2016-01-18 11:09:39 -0800
committerBin Hu <bh526r@att.com>2016-01-18 19:13:07 +0000
commit2a4dcce1e07f5e9f2befbcbc02f6e326b22f60b1 (patch)
tree94ed59bdf0d61affa37108afc29ea530e4e32619 /docs/configguide
parent0541eba0bfd54ce38162330a9a79d9d89219685e (diff)
JIRA:IPVSIX-29
Change-Id: Ie5d35e46c67bdf6c77e2a515e2421469d043634b Signed-off-by: Bin Hu <bh526r@att.com> (cherry picked from commit e56e6c8971233f591a6c7a67ebcfa8069b18860c)
Diffstat (limited to 'docs/configguide')
-rw-r--r--docs/configguide/featureconfig.rst38
1 files changed, 36 insertions, 2 deletions
diff --git a/docs/configguide/featureconfig.rst b/docs/configguide/featureconfig.rst
index b6064fc..b402374 100644
--- a/docs/configguide/featureconfig.rst
+++ b/docs/configguide/featureconfig.rst
@@ -336,6 +336,42 @@ configuration and metadata files
git clone https://github.com/sridhargaddam/opnfv_os_ipv6_poc.git /opt/stack/opnfv_os_ipv6_poc
+----------------------------------------------
+Disable Security Groups in OpenStack ML2 Setup
+----------------------------------------------
+
+Please **NOTE** that although Security Groups feature has been disabled automatically
+through ``local.conf`` configuration file by some installers such as ``devstack``, it is very likely
+that other installers such as ``Apex``, ``Compass``, ``Fuel`` or ``Joid`` will enable Security
+Groups feature after installation.
+
+**Please make sure that Security Groups are disabled in the setup**
+
+**OPNFV-SEC-1**: Change the settings in
+``/etc/neutron/plugins/ml2/ml2_conf.ini`` as follows
+
+.. code-block:: bash
+
+ # /etc/neutron/plugins/ml2/ml2_conf.ini
+ [securitygroup]
+ enable_security_group = False
+ firewall_driver = neutron.agent.firewall.NoopFirewallDriver
+
+**OPNFV-SEC-2**: Change the settings in ``/etc/nova/nova.conf`` as follows
+
+.. code-block:: bash
+
+ # /etc/nova/nova.conf
+ [DEFAULT]
+ security_group_api = nova
+ firewall_driver = nova.virt.firewall.NoopFirewallDriver
+
+**OPNFV-SEC-3**: After updating the settings, you will have to restart the
+``Neutron`` and ``Nova`` services.
+
+**Please note that the commands of restarting** ``Neutron`` **and** ``Nova`` **would vary
+depending on the installer. Please refer to relevant documentation of specific installers**
+
---------------------------------------------------
Source the Credentials in OpenStack Controller Node
---------------------------------------------------
@@ -688,5 +724,3 @@ to reach external ``ipv6-router``.
exit
-
-