
For vlan type network, we add a segment match flow to the openflow security group ingress table. Then the packets will be recorded in conntrack table, and the reply packets can be processed properly. Conflicts: doc/source/contributor/internals/openvswitch_firewall.rst Change-Id: Ieded0654d0ad16235ec923b822dcd842bd7735e5 Closes-Bug: #1831534 (cherry picked from commit aa58542e823d23d233524cd5639c7ec4bb757769)