How to setup security groups for IPv6 with nova-network?

We've got a Folsom cloud running nova-network in FlatDHCP multi-host, currently with just a single public fixed range.

We followed the relevant config docs to get IPv6 going (plus adding a bunch of rules allowing ICMPv6 on the compute bridges for NDP). Then we found this in the instance networking docs :

Currently, ipv6 and other protocols cannot be managed with the security rules, making them permitted by default

Is that accurate or is it possible to get secgroups going for IPv6 under nova-network?

For some reason the links in my post are not marking up as they did in the preview...

It's currently not supported. This is definitely a major feature that's missing from nova-network (and nuetron).

I just came across this in Google and wanted to mention that as of Havana+, nova-network and IPv6 security groups do work. We are seeing some issues with port ranges, though.

Possible useful information:

  • Use /128 for individual IPv6 addresses
  • Use ::/0 as the equivilent
