Bug 1305124 - Default For accept_ra Must Be "0"
Default For accept_ra Must Be "0"
Product: Red Hat OpenStack
Classification: Red Hat
Component: openstack-tripleo-heat-templates (Show other bugs)
7.0 (Kilo)
Unspecified Unspecified
urgent Severity urgent
: y3
: 7.0 (Kilo)
Assigned To: Jiri Stransky
Marius Cornea
: Triaged
Depends On:
Blocks: 1305128
  Show dependency treegraph
Reported: 2016-02-05 13:06 EST by Dan Sneddon
Modified: 2016-02-18 11:52 EST (History)
8 users (show)

See Also:
Fixed In Version: openstack-tripleo-heat-templates-0.8.6-117.el7ost
Doc Type: Bug Fix
Doc Text:
Compute nodes detected IPv6 router announcements (RA) on the Overcloud's IPv6-based Tenant network. This caused problems with the IPv6 routing table, such as setting the default route to the Neutron router. This fix sets the 'net.ipv6.conf.default.accept_ra' kernel parameter to 0 on all nodes. Now the Compute node no longer accepts router announcements from the Tenant networks.
Story Points: ---
Clone Of:
: 1305128 (view as bug list)
Last Closed: 2016-02-18 11:52:41 EST
Type: Bug
Regression: ---
Mount Type: ---
Documentation: ---
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---

Attachments (Terms of Use)

External Trackers
Tracker ID Priority Status Summary Last Updated
OpenStack gerrit 277182 None None None 2016-02-10 05:25 EST
Red Hat Bugzilla 1303758 None None None 2016-02-05 13:07 EST

  None (edit)
Description Dan Sneddon 2016-02-05 13:06:05 EST
Description of problem:
When using IPv6 tenant networks, the compute node will detect the IPv6 router announcements (RAs) from Neutron, which poisons the IPv6 route tables.

Version-Release number of selected component (if applicable):
OSP 7.3 Beta

How reproducible:

Steps to Reproduce:
1. Deploy overcloud
2. Create IPv6 tenant networks
3. Add a router to the network
4. Start an instance on the network

Actual results:
The qbr interface accepts the RA from the Neutron router, and the default route for IPv6 gets set to the Neutron router.

Expected results:
The compute nodes should ignore RAs on the OVS bridges

Additional info:
In order to turn this behavior on/off, you can edit /proc/sys/net/ipv6/conf/default/accept_ra to be "0" instead of "1".

You can also turn it on/off on a per-interface basis, e.g.:
echo "1" > /proc/sys/net/ipv6/conf/eth0/accept_ra

This needs to be tested, so we can determine if RAs will still be accepted on interfaces configured with IPv6, or if we need to set accept_ra to "1" for the individual interfaces.
Comment 2 Dan Sneddon 2016-02-07 12:03:15 EST
There is a downstream review of the changes needed to fix this bug here:


I tested it, and it appears to work.
Comment 3 Marios Andreou 2016-02-10 05:28:18 EST
followup after irc chat just now about where this fix lands:

the fix for this bug is included in the fix for bug 1303758 (links to gerrit above the description) - from that bug I can see it is in "Fixed In Version: openstack-tripleo-heat-templates-0.8.6-117.el7ost"
Comment 7 Marius Cornea 2016-02-12 08:31:35 EST
[root@overcloud-compute-0 ~]# cat /proc/sys/net/ipv6/conf/default/accept_ra
Comment 9 errata-xmlrpc 2016-02-18 11:52:41 EST
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.


Note You need to log in before you can comment on or make changes to this bug.