Internet doesn't get forwarded via master node
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
Fuel for OpenStack |
Invalid
|
Medium
|
Maksim Malchuk | ||
6.1.x |
Fix Released
|
Medium
|
Maksim Malchuk | ||
7.0.x |
Invalid
|
Medium
|
Maksim Malchuk | ||
8.0.x |
Invalid
|
Medium
|
Maksim Malchuk |
Bug Description
ISO #302
fuellib_sha: "e9c3ba332b0512
After installation of Fuel Master using vbox scripts, I'm not able to ping Internet from boostrap nodes. I see that DNS resolution works just fine, and I can see traffic coming to the Master node and even goes out from the right Interface (eth2, which is configured in Vbox as NAT).
The problem is that traffic doesn't go back to the bootstrap node.
I've found following rules in POSTROUTING on master node:
Chain POSTROUTING (policy ACCEPT)
target prot opt source destination
MASQUERADE tcp -- 10.20.0.0/24 0.0.0.0/0 /* 004 forward_admin_net */
MASQUERADE all -- 172.17.0.0/16 0.0.0.0/0
When I changed the first rule to:
MASQUERADE all -- 10.20.0.0/24 !10.20.0.0/24
via iptables -t nat -A POSTROUTING -s 10.20.0.0/24 \! -d 10.20.0.0/24 -j MASQUERADE, and deleting the original rule, traffic started to pass.
Please research if it's really the original issue. iptables rule is being created in deployment/
Changed in fuel: | |
assignee: | nobody → Fuel Library Team (fuel-library) |
Changed in fuel: | |
importance: | Undecided → Medium |
status: | New → Triaged |
tags: | added: low-hanging-fruit |
Changed in fuel: | |
milestone: | 6.1 → 7.0 |
tags: | removed: low-hanging-fruit |
Changed in fuel: | |
assignee: | Fuel Library Team (fuel-library) → Oleksiy Molchanov (omolchanov) |
Changed in fuel: | |
assignee: | Oleksiy Molchanov (omolchanov) → Vladimir Kuklin (vkuklin) |
Changed in fuel: | |
assignee: | Vladimir Kuklin (vkuklin) → Oleksiy Molchanov (omolchanov) |
tags: | added: area-library |
I've increased priority to High, as this affects Ubuntu provisioning for me on VBox demo installation.