BMS LCM: instance fails due to tftp open timeout

Bug #1787693 reported by vageesan
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
Juniper Openstack
Status tracked in Trunk
R5.0
New
High
vageesan
Trunk
New
Critical
vageesan

Bug Description

   "PXE-E32 TFTP open timeout" message is seen and hence BMS instances are not able to do tftp boot.

Dheeraj also saw this issue in his setup.After cluster bring up ,instance came up only once with tftp boot.On deleting and re-spinning the instance, instance started failing in tftp boot.

Build: ocata-5.0-215.

Revision history for this message
vageesan (vageesant) wrote :
Revision history for this message
Dheeraj Gautam (dgautam) wrote :

This issue was happening due to the default security group.

It was verified that ping from baremetal to Underlay was working (both sides) but during pxe, TFTP (port 69 and other random ports) packets will be sent to-and-fro. QFX/MX blocks those packets and causes the PXE to fail.

By default Ingress/0.0.0.0/ANY/ANY rule is not there causing almost all traffic to block from openstack to baremetal.

Revision history for this message
Dheeraj Gautam (dgautam) wrote :

re-assigning back to Vageesan to retry after updating the default security group.

Revision history for this message
Jeba Paulaiyan (jebap) wrote :

Auto SG configs should be taken care by design.

tags: added: bms
removed: releaseblocker
Jeba Paulaiyan (jebap)
tags: added: releasenote
Revision history for this message
Jeba Paulaiyan (jebap) wrote :

Notes:

Incase of BMS LCM the TFTP and PXE boot traffic should be passed to the openstack node. The default security group applied on the fabric devices blocks these and BMS LCM fails. To workaround this, add Ingress/0.0.0.0/ANY/ANY rule to the security group.

information type: Proprietary → Public
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.