Note: This bug is displayed in read-only format because the product is no longer active in Red Hat Bugzilla.

Bug 2282209

Summary: FIP bound with VIP is not working on [RHOSP16.2.6
Product: Red Hat OpenStack Reporter: Luigi Tamagnone <ltamagno>
Component: python-networking-ovnAssignee: Fernando Royo <froyo>
Status: CLOSED MIGRATED QA Contact: Bernard Cafarelli <bcafarel>
Severity: high Docs Contact:
Priority: high    
Version: 16.2 (Train)CC: apevec, astupnik, bcafarel, cgussobo, chrisbro, chrisw, cldavey, ebarrera, fpiccion, froyo, ihrachys, lhh, majopela, mariel, mhauryli, rcernin, scohen
Target Milestone: z7Keywords: Triaged
Target Release: 16.2 (Train on RHEL 8.4)   
Hardware: x86_64   
OS: All   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Cause: Virtual ports created with a custom device_owner was loosing the type.virtual on OVN NB DB as soon traffic was sent/received over it. Consequence: The Port Binding associated to the VIP port is recreated as soon Virtual Port change the type. Loosing the Chassis and virtual-parents info. In DVR envs, with distributed Floating IP, traffic over the FIP attached to the VIP is not replied. Fix: Virtual ports that would be use to redirect traffic over VM ports needs to be created using device_owner value of 'virtual_port'. Special case for Octavia, that is creating VIP LB ports using device_owner 'Octavia' is also covered.
Story Points: ---
Clone Of: Environment:
Last Closed: 2025-01-10 10:35:49 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2317059    
Bug Blocks:    

Description Luigi Tamagnone 2024-05-21 15:00:53 UTC
Description of problem:
After the update from 16.2.2 to 16.2.6 the FIP attached to a VIP seems not working anymore.

Version-Release number of selected component (if applicable):
Red Hat Openstack 16.2.6

Steps to Reproduce:
1. create a VIP port with owner neutron:LOADBALANCER
2. associate a FIP to that VIP
3. Add allowed-address pair for the VIP associated with instance port
4. add the ip to the os
5. ping or anything else with the FIP
6. from VIP side it's working
7. disable port security on VIP and the FIP is working working


Note from last test we notice that after the association was working and after a while stop working. ~14:48 CET time 21 of May

Actual results:
FIP attached to a  VIP is not reachable

Expected results:
FIP attached to a  VIP is reachable

Additional info:

Comment 1 Alex Stupnikov 2024-05-21 15:07:45 UTC
Bug #2269474

Comment 19 Fernando Royo 2024-06-14 09:52:39 UTC
*** Bug 2269474 has been marked as a duplicate of this bug. ***

Comment 22 Brent Eagles 2024-07-29 12:00:58 UTC
*** Bug 2299415 has been marked as a duplicate of this bug. ***

Comment 28 Fernando Royo 2024-11-08 09:51:00 UTC
*** Bug 2305743 has been marked as a duplicate of this bug. ***