Bug 1385338 - [RFE] [Neutron] VLAN aware VMs (Neutron trunk ports) - full support
Summary: [RFE] [Neutron] VLAN aware VMs (Neutron trunk ports) - full support
Alias: None
Product: Red Hat OpenStack
Classification: Red Hat
Component: openstack-neutron
Version: 10.0 (Newton)
Hardware: Unspecified
OS: Unspecified
Target Milestone: Upstream M3
: 11.0 (Ocata)
Assignee: Jakub Libosvar
QA Contact: Alexander Stafeyev
Depends On: 1435956 1444368 1448829
Blocks: 1336839 1421550 1431810 1452467
TreeView+ depends on / blocked
Reported: 2016-10-16 10:54 UTC by Nir Yechiel
Modified: 2017-05-19 05:52 UTC (History)
14 users (show)

Fixed In Version: openstack-neutron-10.0.0-0.20170121135214.4f70513.1.el7ost
Doc Type: Known Issue
Doc Text:
To implement the security groups trunk feature with neutron-openvswitch-agent, openvswitch firewall driver is required. This driver currently contains a bug 1444368 where ingress traffic is wrongly matched if there are two ports with same MAC address on different network segment on the same compute node. As a result, if a subport has the same MAC address as its parent port, ingress traffic won't be matched correctly for one of the ports. A workaround to achieve correctly handled traffic is to disable port-security on the parent port and subports. For example, to disable port security on port with UUID 12345, you need to remove security groups associated with the port: openstack port set --no-security-group --disable-port-security 12345 Note that no security groups rules will be applied to that port and traffic will not be filtered or protected against ip/mac/arp spoofing.
Clone Of:
: 1431810 1452467 (view as bug list)
Last Closed: 2017-05-17 19:35:20 UTC
Target Upstream Version:

Attachments (Terms of Use)

System ID Private Priority Status Summary Last Updated
Launchpad 1689300 0 None None None 2017-05-08 13:03:33 UTC
OpenStack gerrit 418867 0 'None' 'MERGED' 'trunk: Add tempest test validating subport connectivity' 2019-12-04 00:11:56 UTC
Red Hat Bugzilla 1444368 0 high CLOSED openvswitch firewall driver doesn't work properly when two ports on different network on the same compute node have the ... 2021-02-22 00:41:40 UTC
Red Hat Product Errata RHEA-2017:1245 0 normal SHIPPED_LIVE Red Hat OpenStack Platform 11.0 Bug Fix and Enhancement Advisory 2017-05-17 23:01:50 UTC

Internal Links: 1444368

Description Nir Yechiel 2016-10-16 10:54:21 UTC
Description of problem:

The VLAN aware VMs feature is shipped as technology preview with RHOSP 10 (see BZ 1281567). The plan is to graduate it to full support - with proper test coverage for both OVS and OVS-DPDK.

Comment 1 Nir Yechiel 2016-10-16 11:23:54 UTC
Link to previous, RHOSP 10 BZ (tech preview offering): https://bugzilla.redhat.com/show_bug.cgi?id=1281567

Link to related OSP director BZ: https://bugzilla.redhat.com/show_bug.cgi?id=1371842

Comment 8 Assaf Muller 2017-01-27 17:05:33 UTC
The RFE is only pending on the scenario test in patch 418867 and ensuring we have a QECI job set up for RHEL guests that runs the Neutron Tempest scenario tests. Therefor flipping to ON_QA.

Comment 10 Nir Yechiel 2017-01-30 13:10:17 UTC
A bug to make OVS firewall working with VLAN aware VMs feature doesn't have a fix in upstream yet. The relevant bug is: https://bugs.launchpad.net/neutron/+bug/1626010

In any case, note that the OVS firewall driver won't be fully supported before RHOSP 12 and is currently in tech preview.

Comment 24 errata-xmlrpc 2017-05-17 19:35:20 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.


Note You need to log in before you can comment on or make changes to this bug.