802164f2a2
This patch refactors the source and supporting files to use the top level package name of vmware_nsx_tempest_plugin. This better matches the project name as well as the name we plan to publish to PYPI with as per the discussion in [1]. A sample release has been published to the test pypi repo [2] to ensure this works. [1] https://review.openstack.org/#/c/584498/ [2] https://test.pypi.org/project/vmware-nsx-tempest-plugin/ Change-Id: I4cd89f49562c780754ebfb7e93c38b4e6556e314
342 lines
13 KiB
Plaintext
342 lines
13 KiB
Plaintext
<securityPolicyHierarchy>
|
|
<name>admin-policy-AA</name>
|
|
<description>8 firewall rules - ping, ssh from anywhere are OK</description>
|
|
<securityPolicy>
|
|
<revision>0</revision>
|
|
<name>security-policy-AA</name>
|
|
<description>Security Policy AA</description>
|
|
<clientHandle></clientHandle>
|
|
<isUniversal>false</isUniversal>
|
|
<universalRevision>0</universalRevision>
|
|
<inheritanceAllowed>false</inheritanceAllowed>
|
|
<precedence>5500</precedence>
|
|
<actionsByCategory>
|
|
<category>firewall</category>
|
|
<action class="firewallSecurityAction">
|
|
<revision>0</revision>
|
|
<name>dhcp-in</name>
|
|
<clientHandle></clientHandle>
|
|
<isUniversal>false</isUniversal>
|
|
<universalRevision>0</universalRevision>
|
|
<category>firewall</category>
|
|
<executionOrder>1</executionOrder>
|
|
<isEnabled>true</isEnabled>
|
|
<isActionEnforced>false</isActionEnforced>
|
|
<invalidSecondaryContainers>false</invalidSecondaryContainers>
|
|
<applications>
|
|
<application>
|
|
<revision>0</revision>
|
|
<name>DHCP-Client</name>
|
|
<clientHandle></clientHandle>
|
|
<isUniversal>false</isUniversal>
|
|
<universalRevision>0</universalRevision>
|
|
<inheritanceAllowed>true</inheritanceAllowed>
|
|
<element>
|
|
<applicationProtocol>UDP</applicationProtocol>
|
|
<value>68</value>
|
|
</element>
|
|
</application>
|
|
<application>
|
|
<revision>0</revision>
|
|
<name>DHCP-Server</name>
|
|
<clientHandle></clientHandle>
|
|
<isUniversal>false</isUniversal>
|
|
<universalRevision>0</universalRevision>
|
|
<inheritanceAllowed>true</inheritanceAllowed>
|
|
<element>
|
|
<applicationProtocol>UDP</applicationProtocol>
|
|
<value>67</value>
|
|
</element>
|
|
</application>
|
|
</applications>
|
|
<invalidApplications>false</invalidApplications>
|
|
<logged>false</logged>
|
|
<action>allow</action>
|
|
<direction>inbound</direction>
|
|
<outsideSecondaryContainer>false</outsideSecondaryContainer>
|
|
</action>
|
|
<action class="firewallSecurityAction">
|
|
<revision>0</revision>
|
|
<name>dhcp-out</name>
|
|
<clientHandle></clientHandle>
|
|
<isUniversal>false</isUniversal>
|
|
<universalRevision>0</universalRevision>
|
|
<category>firewall</category>
|
|
<executionOrder>2</executionOrder>
|
|
<isEnabled>true</isEnabled>
|
|
<isActionEnforced>false</isActionEnforced>
|
|
<invalidSecondaryContainers>false</invalidSecondaryContainers>
|
|
<applications>
|
|
<application>
|
|
<revision>0</revision>
|
|
<name>DHCP-Client</name>
|
|
<clientHandle></clientHandle>
|
|
<isUniversal>false</isUniversal>
|
|
<universalRevision>0</universalRevision>
|
|
<inheritanceAllowed>true</inheritanceAllowed>
|
|
<element>
|
|
<applicationProtocol>UDP</applicationProtocol>
|
|
<value>68</value>
|
|
</element>
|
|
</application>
|
|
<application>
|
|
<revision>0</revision>
|
|
<name>DHCP-Server</name>
|
|
<clientHandle></clientHandle>
|
|
<isUniversal>false</isUniversal>
|
|
<universalRevision>0</universalRevision>
|
|
<inheritanceAllowed>true</inheritanceAllowed>
|
|
<element>
|
|
<applicationProtocol>UDP</applicationProtocol>
|
|
<value>67</value>
|
|
</element>
|
|
</application>
|
|
</applications>
|
|
<invalidApplications>false</invalidApplications>
|
|
<logged>false</logged>
|
|
<action>allow</action>
|
|
<direction>outbound</direction>
|
|
<outsideSecondaryContainer>false</outsideSecondaryContainer>
|
|
</action>
|
|
<action class="firewallSecurityAction">
|
|
<revision>0</revision>
|
|
<name>ping-in</name>
|
|
<description>Everyone can ping me</description>
|
|
<clientHandle></clientHandle>
|
|
<isUniversal>false</isUniversal>
|
|
<universalRevision>0</universalRevision>
|
|
<category>firewall</category>
|
|
<executionOrder>3</executionOrder>
|
|
<isEnabled>true</isEnabled>
|
|
<isActionEnforced>false</isActionEnforced>
|
|
<invalidSecondaryContainers>false</invalidSecondaryContainers>
|
|
<applications>
|
|
<application>
|
|
<revision>0</revision>
|
|
<name>ICMP Echo</name>
|
|
<clientHandle></clientHandle>
|
|
<isUniversal>false</isUniversal>
|
|
<universalRevision>0</universalRevision>
|
|
<inheritanceAllowed>true</inheritanceAllowed>
|
|
<element>
|
|
<applicationProtocol>ICMP</applicationProtocol>
|
|
<value>echo-request</value>
|
|
</element>
|
|
</application>
|
|
<application>
|
|
<revision>0</revision>
|
|
<name>ICMP Redirect</name>
|
|
<clientHandle></clientHandle>
|
|
<isUniversal>false</isUniversal>
|
|
<universalRevision>0</universalRevision>
|
|
<inheritanceAllowed>true</inheritanceAllowed>
|
|
<element>
|
|
<applicationProtocol>ICMP</applicationProtocol>
|
|
<value>redirect</value>
|
|
</element>
|
|
</application>
|
|
<application>
|
|
<revision>0</revision>
|
|
<name>ICMP Echo Reply</name>
|
|
<clientHandle></clientHandle>
|
|
<isUniversal>false</isUniversal>
|
|
<universalRevision>0</universalRevision>
|
|
<inheritanceAllowed>true</inheritanceAllowed>
|
|
<element>
|
|
<applicationProtocol>ICMP</applicationProtocol>
|
|
<value>echo-reply</value>
|
|
</element>
|
|
</application>
|
|
</applications>
|
|
<invalidApplications>false</invalidApplications>
|
|
<logged>false</logged>
|
|
<action>allow</action>
|
|
<direction>inbound</direction>
|
|
<outsideSecondaryContainer>false</outsideSecondaryContainer>
|
|
</action>
|
|
<action class="firewallSecurityAction">
|
|
<revision>0</revision>
|
|
<name>ping-out</name>
|
|
<clientHandle></clientHandle>
|
|
<isUniversal>false</isUniversal>
|
|
<universalRevision>0</universalRevision>
|
|
<category>firewall</category>
|
|
<executionOrder>4</executionOrder>
|
|
<isEnabled>true</isEnabled>
|
|
<isActionEnforced>false</isActionEnforced>
|
|
<invalidSecondaryContainers>false</invalidSecondaryContainers>
|
|
<applications>
|
|
<application>
|
|
<revision>0</revision>
|
|
<name>ICMP Echo</name>
|
|
<clientHandle></clientHandle>
|
|
<isUniversal>false</isUniversal>
|
|
<universalRevision>0</universalRevision>
|
|
<inheritanceAllowed>true</inheritanceAllowed>
|
|
<element>
|
|
<applicationProtocol>ICMP</applicationProtocol>
|
|
<value>echo-request</value>
|
|
</element>
|
|
</application>
|
|
<application>
|
|
<revision>0</revision>
|
|
<name>ICMP Redirect</name>
|
|
<clientHandle></clientHandle>
|
|
<isUniversal>false</isUniversal>
|
|
<universalRevision>0</universalRevision>
|
|
<inheritanceAllowed>true</inheritanceAllowed>
|
|
<element>
|
|
<applicationProtocol>ICMP</applicationProtocol>
|
|
<value>redirect</value>
|
|
</element>
|
|
</application>
|
|
<application>
|
|
<revision>0</revision>
|
|
<name>ICMP Echo Reply</name>
|
|
<clientHandle></clientHandle>
|
|
<isUniversal>false</isUniversal>
|
|
<universalRevision>0</universalRevision>
|
|
<inheritanceAllowed>true</inheritanceAllowed>
|
|
<element>
|
|
<applicationProtocol>ICMP</applicationProtocol>
|
|
<value>echo-reply</value>
|
|
</element>
|
|
</application>
|
|
</applications>
|
|
<invalidApplications>false</invalidApplications>
|
|
<logged>false</logged>
|
|
<action>allow</action>
|
|
<direction>outbound</direction>
|
|
<outsideSecondaryContainer>false</outsideSecondaryContainer>
|
|
</action>
|
|
<action class="firewallSecurityAction">
|
|
<revision>0</revision>
|
|
<name>ssh-in-ok</name>
|
|
<clientHandle></clientHandle>
|
|
<isUniversal>false</isUniversal>
|
|
<universalRevision>0</universalRevision>
|
|
<category>firewall</category>
|
|
<executionOrder>5</executionOrder>
|
|
<isEnabled>true</isEnabled>
|
|
<isActionEnforced>false</isActionEnforced>
|
|
<invalidSecondaryContainers>false</invalidSecondaryContainers>
|
|
<applications>
|
|
<application>
|
|
<revision>0</revision>
|
|
<name>SSH</name>
|
|
<clientHandle></clientHandle>
|
|
<isUniversal>false</isUniversal>
|
|
<universalRevision>0</universalRevision>
|
|
<inheritanceAllowed>true</inheritanceAllowed>
|
|
<element>
|
|
<applicationProtocol>TCP</applicationProtocol>
|
|
<value>22</value>
|
|
</element>
|
|
</application>
|
|
</applications>
|
|
<invalidApplications>false</invalidApplications>
|
|
<logged>false</logged>
|
|
<action>allow</action>
|
|
<direction>inbound</direction>
|
|
<outsideSecondaryContainer>false</outsideSecondaryContainer>
|
|
</action>
|
|
<action class="firewallSecurityAction">
|
|
<revision>0</revision>
|
|
<name>ssh-out-ok</name>
|
|
<clientHandle></clientHandle>
|
|
<isUniversal>false</isUniversal>
|
|
<universalRevision>0</universalRevision>
|
|
<category>firewall</category>
|
|
<executionOrder>6</executionOrder>
|
|
<isEnabled>true</isEnabled>
|
|
<isActionEnforced>false</isActionEnforced>
|
|
<invalidSecondaryContainers>false</invalidSecondaryContainers>
|
|
<applications>
|
|
<application>
|
|
<revision>0</revision>
|
|
<name>SSH</name>
|
|
<clientHandle></clientHandle>
|
|
<isUniversal>false</isUniversal>
|
|
<universalRevision>0</universalRevision>
|
|
<inheritanceAllowed>true</inheritanceAllowed>
|
|
<element>
|
|
<applicationProtocol>TCP</applicationProtocol>
|
|
<value>22</value>
|
|
</element>
|
|
</application>
|
|
</applications>
|
|
<invalidApplications>false</invalidApplications>
|
|
<logged>false</logged>
|
|
<action>allow</action>
|
|
<direction>outbound</direction>
|
|
<outsideSecondaryContainer>false</outsideSecondaryContainer>
|
|
</action>
|
|
<action class="firewallSecurityAction">
|
|
<revision>0</revision>
|
|
<name>HTTP-ok</name>
|
|
<description>All can http(s) me</description>
|
|
<clientHandle></clientHandle>
|
|
<isUniversal>false</isUniversal>
|
|
<universalRevision>0</universalRevision>
|
|
<category>firewall</category>
|
|
<executionOrder>7</executionOrder>
|
|
<isEnabled>true</isEnabled>
|
|
<isActionEnforced>false</isActionEnforced>
|
|
<invalidSecondaryContainers>false</invalidSecondaryContainers>
|
|
<applications>
|
|
<application>
|
|
<revision>0</revision>
|
|
<name>HTTP</name>
|
|
<clientHandle></clientHandle>
|
|
<isUniversal>false</isUniversal>
|
|
<universalRevision>0</universalRevision>
|
|
<inheritanceAllowed>true</inheritanceAllowed>
|
|
<element>
|
|
<applicationProtocol>TCP</applicationProtocol>
|
|
<value>80</value>
|
|
</element>
|
|
</application>
|
|
<application>
|
|
<revision>0</revision>
|
|
<name>HTTPS</name>
|
|
<clientHandle></clientHandle>
|
|
<isUniversal>false</isUniversal>
|
|
<universalRevision>0</universalRevision>
|
|
<inheritanceAllowed>true</inheritanceAllowed>
|
|
<element>
|
|
<applicationProtocol>TCP</applicationProtocol>
|
|
<value>443</value>
|
|
</element>
|
|
</application>
|
|
</applications>
|
|
<invalidApplications>false</invalidApplications>
|
|
<logged>false</logged>
|
|
<action>allow</action>
|
|
<direction>inbound</direction>
|
|
<outsideSecondaryContainer>false</outsideSecondaryContainer>
|
|
</action>
|
|
<action class="firewallSecurityAction">
|
|
<revision>0</revision>
|
|
<name>sorry-nothing-allowed</name>
|
|
<clientHandle></clientHandle>
|
|
<isUniversal>false</isUniversal>
|
|
<universalRevision>0</universalRevision>
|
|
<category>firewall</category>
|
|
<executionOrder>8</executionOrder>
|
|
<isEnabled>true</isEnabled>
|
|
<isActionEnforced>false</isActionEnforced>
|
|
<invalidSecondaryContainers>false</invalidSecondaryContainers>
|
|
<invalidApplications>false</invalidApplications>
|
|
<logged>false</logged>
|
|
<action>reject</action>
|
|
<direction>inbound</direction>
|
|
<outsideSecondaryContainer>false</outsideSecondaryContainer>
|
|
</action>
|
|
</actionsByCategory>
|
|
<statusesByCategory>
|
|
<category>firewall</category>
|
|
<status>in_sync</status>
|
|
</statusesByCategory>
|
|
</securityPolicy>
|
|
</securityPolicyHierarchy>
|