This firewall requires OVS 2.5+ version supporting conntrack and kernel conntrack datapath support (kernel>=4.3). For more information, see hhttps://review.openstack.org/#/c/249337/
in openvswitch_agent.ini - securitygroup section - set firewall_driver to openvswitch
Patch is now merged in upstream Newton.
I have updated virt/network/network-environment.yaml before overcloud deployment with NeutronOVSFirewallDriver: "openvswitch" .
The firewall driver after installation changed to "firewall_driver = openvswitch" /etc/neutron/plugins/ml2/openvswitch_agent.ini as it supposed to be.
Controller and Compute on top of RHEL release 7.3
All following tests succeeded to run on this setup:
Brent as far as documentation I think we can make do with a doctext here on this RHBZ that would explain how to enable the feature.
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.
For information on the advisory, and where to find the updated
files, follow the link below.
If the solution does not work for you, open a new bug report.