N->O upgrade, blanks ipv6 rules before activating it.
authorSofer Athlan-Guyot <sathlang@redhat.com>
Fri, 24 Mar 2017 12:45:10 +0000 (13:45 +0100)
committerSofer Athlan-Guyot <sathlang@redhat.com>
Mon, 27 Mar 2017 09:39:09 +0000 (11:39 +0200)
commit440901b5026d0927ce74ab358fbe3d430f91b38a
tree059e45f348028ee12559ffe652126be92440132f
parent189a950a7b8bc33caa6ed43baeb3aeefdd5d582b
N->O upgrade, blanks ipv6 rules before activating it.

When the firewall is enabled with ipv6, the default rules set is
taken as not ipv6 firewall was present for Newton.  This make
communication impossible until puppet is run again.

This ensures that no rules are loaded when the firewall is enabled.

This mimic this patch[1]

[1] https://github.com/openstack/tripleo-heat-templates/commit/ae8aac36143d5dadb08af0d275f513678909dcc7

Change-Id: Id878b5caae666a799c89c8466ce46b9ecb86d9f7
Closes-Bug: #1675782
(cherry picked from commit 670399a2caeecd9259bea454e9518ab6c92cff49)
puppet/services/tripleo-firewall.yaml