Bug 1393562
Summary: | OVS VXLAN port does not receive packets in OSP director ODL deployment | ||
---|---|---|---|
Product: | Red Hat OpenStack | Reporter: | Tim Rozet <trozet> |
Component: | openstack-tripleo-heat-templates | Assignee: | Tim Rozet <trozet> |
Status: | CLOSED ERRATA | QA Contact: | Itzik Brown <itbrown> |
Severity: | high | Docs Contact: | |
Priority: | high | ||
Version: | 10.0 (Newton) | CC: | apevec, chrisw, egarver, jschluet, mburns, nyechiel, rhel-osp-director-maint, rhos-maint, srevivo, trozet |
Target Milestone: | rc | Keywords: | Triaged |
Target Release: | 10.0 (Newton) | ||
Hardware: | x86_64 | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | openstack-tripleo-heat-templates-5.1.0-2.el7ost | Doc Type: | If docs needed, set a value |
Doc Text: | Story Points: | --- | |
Clone Of: | Environment: |
N/A
|
|
Last Closed: | 2016-12-14 16:31:22 UTC | Type: | Bug |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: | |||
Bug Depends On: | |||
Bug Blocks: | 1258832 |
Description
Tim Rozet
2016-11-09 21:07:46 UTC
Hi Tim, I looked at your setup today. The VXLAN UDP ports were being blocked by iptables. Adding an exception allowed traffic to pass on the overlay. [heat-admin@compute-0 ~]$ sudo iptables -L Chain INPUT (policy ACCEPT) target prot opt source destination ACCEPT udp -- anywhere anywhere udp dpt:4789 ... [heat-admin@compute-0 ~]$ ping 16.0.0.1 PING 16.0.0.1 (16.0.0.1) 56(84) bytes of data. 64 bytes from 16.0.0.1: icmp_seq=1 ttl=64 time=0.611 ms 64 bytes from 16.0.0.1: icmp_seq=2 ttl=64 time=0.206 ms 64 bytes from 16.0.0.1: icmp_seq=3 ttl=64 time=0.236 ms ^C --- 16.0.0.1 ping statistics --- 3 packets transmitted, 3 received, 0% packet loss, time 2000ms rtt min/avg/max/mdev = 0.206/0.351/0.611/0.184 ms Thanks Eric for debugging on my the setup. As you thought it looks like there is a bug in how firewall is being configured with TripleO. I filed it upstream as https://bugs.launchpad.net/tripleo/+bug/1641191 There is no bug with OVS or the kernel, the problem is VXLAN traffic is being blocked by iptables because TripleO firewall is not configured to allow it if neutron OVS agent is not being used. Going to move this bug to OSP Director and provide a fix upstream. Code is merged in master branch. Will need to be backported to stable/newton. (In reply to Tim Rozet from comment #2) > Thanks Eric for debugging on my the setup. As you thought it looks like > there is a bug in how firewall is being configured with TripleO. I filed it > upstream as > https://bugs.launchpad.net/tripleo/+bug/1641191 > > There is no bug with OVS or the kernel, the problem is VXLAN traffic is > being blocked by iptables because TripleO firewall is not configured to > allow it if neutron OVS agent is not being used. > > Going to move this bug to OSP Director and provide a fix upstream. Thanks Eric and Tim for the collaboration and quick turnaround! /Nir Verified with openstack-tripleo-heat-templates-5.1.0-3.el7ost.noarch Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory, and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. https://rhn.redhat.com/errata/RHEA-2016-2948.html |