Adds ipset support for Security Groups

Iptables chain is linear storage and filtering, when iptables rules are
large, the load of l2 agent is heavy, this patch introduces ipset to
security group for improving the security group performance.

Change-Id: I6ff0ac519d0b9034d3bb5270885ed3cc1805674d
Implements: blueprint add-ipset-to-security
DocImpact
This commit is contained in:
shihanzhang 2014-08-04 17:31:01 +08:00
parent f74110cd99
commit 473a7e66a1

View File

@ -38,6 +38,7 @@ data_files =
etc/neutron/rootwrap.d/debug.filters etc/neutron/rootwrap.d/debug.filters
etc/neutron/rootwrap.d/dhcp.filters etc/neutron/rootwrap.d/dhcp.filters
etc/neutron/rootwrap.d/iptables-firewall.filters etc/neutron/rootwrap.d/iptables-firewall.filters
etc/neutron/rootwrap.d/ipset-firewall.filters
etc/neutron/rootwrap.d/l3.filters etc/neutron/rootwrap.d/l3.filters
etc/neutron/rootwrap.d/lbaas-haproxy.filters etc/neutron/rootwrap.d/lbaas-haproxy.filters
etc/neutron/rootwrap.d/linuxbridge-plugin.filters etc/neutron/rootwrap.d/linuxbridge-plugin.filters