In multirack environment its impossible to create 3 nated networks with connectivity to each other
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
Fuel for OpenStack |
Confirmed
|
Medium
|
Fuel QA Team |
Bug Description
This set of filter rules being created by 2 nated networks.
-A FORWARD -d 10.0.13.0/24 -o fuelbr18200 -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
-A FORWARD -s 10.0.13.0/24 -i fuelbr18200 -j ACCEPT
-A FORWARD -i fuelbr18200 -o fuelbr18200 -j ACCEPT
-A FORWARD -o fuelbr18200 -j REJECT --reject-with icmp-port-
-A FORWARD -i fuelbr18200 -j REJECT --reject-with icmp-port-
-A FORWARD -d 10.0.14.0/24 -o fuelbr18201 -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
-A FORWARD -s 10.0.14.0/24 -i fuelbr18201 -j ACCEPT
-A FORWARD -i fuelbr18201 -o fuelbr18201 -j ACCEPT
-A FORWARD -o fuelbr18201 -j REJECT --reject-with icmp-port-
-A FORWARD -i fuelbr18201 -j REJECT --reject-with icmp-port-
In this configuration connectivity from .14.0/24 to 13.0/24 will never work because traffic will be blocked by
-A FORWARD -o fuelbr18200 -j REJECT --reject-with icmp-port-
e.g. packet from 10.0.14.3 inport fuelbr18201 to 10.0.13.3 outport fuelbr18200 will be rejected.
Changed in fuel: | |
milestone: | none → 10.0 |
assignee: | nobody → Fuel DevOps (fuel-devops) |
importance: | Undecided → Medium |
status: | New → Confirmed |
Changed in fuel: | |
assignee: | Fuel QA Team (fuel-qa) → Aleksandr Didenko (adidenko) |
status: | Won't Fix → Confirmed |
Changed in fuel: | |
assignee: | Aleksandr Didenko (adidenko) → Fuel QA Team (fuel-qa) |
Looks like this bug is related to fuel-devops developed by Fuel QA Team.