[2.0-22~icehouse] Disparity in the packet-count in a analyser-firewall service chain between two networks

Bug #1407603 reported by Ganesha HV
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
Juniper Openstack
Fix Committed
High
Naveen N
R2.0
Won't Fix
High
Naveen N
R2.1
Fix Committed
High
Naveen N

Bug Description

Setup
====
nodec4 - cfgm/openstack/webui
nodec5 & nodec26 - ctrl
nodei27 & nodei28 - compute

1]. created a service chain between vn1 and vn2.

vm1 - nodei27
vm2, fw & analyser - nodei28

2]. The service chain has a firewall in in-network mode and a analyser in transparent mode.
3]. Started a 5-packet ping from vm1 to vm2.
4]. Expected to see 20 packets on the analyser, but seeing only 15 packets.

Shown to Naveen.

Ganesha HV (ganeshahv)
Changed in juniperopenstack:
milestone: r2.0-fcs → none
tags: added: regression
information type: Proprietary → Public
tags: added: blocker
Revision history for this message
OpenContrail Admin (ci-admin-f) wrote : A change has been merged

Reviewed: https://review.opencontrail.org/6750
Committed: http://github.org/Juniper/contrail-controller/commit/41af757411d5d54c9e52d122e6d5d5d6d67cfce5
Submitter: Zuul
Branch: R2.1

commit 41af757411d5d54c9e52d122e6d5d5d6d67cfce5
Author: Naveen N <email address hidden>
Date: Wed Jan 28 21:51:39 2015 -0800

* Apply mirroring action from VN Acl even if interface as ignore acl
flag

Mirroring action are derived from network acl, and in case of service
instance interface we would have vrf translate acl and action from
network acl would be ignored, if interface has vrf translate acl.
Due to this packet from service instance interface were never mirrored,
with this fix we pick mirroring action exclusively from network acl.
Closes-bug:#1407603

Change-Id: Iaab4a6d81632a9e615d27c2eead27114d8957265

Revision history for this message
OpenContrail Admin (ci-admin-f) wrote :

Reviewed: https://review.opencontrail.org/6894
Committed: http://github.org/Juniper/contrail-controller/commit/1c7514ac494ec10150739f01c1b83a9d840aa763
Submitter: Zuul
Branch: master

commit 1c7514ac494ec10150739f01c1b83a9d840aa763
Author: Naveen N <email address hidden>
Date: Wed Jan 28 21:51:39 2015 -0800

* Apply mirroring action from VN Acl even if interface as ignore acl
flag

Mirroring action are derived from network acl, and in case of service
instance interface we would have vrf translate acl and action from
network acl would be ignored, if interface has vrf translate acl.
Due to this packet from service instance interface were never mirrored,
with this fix we pick mirroring action exclusively from network acl.
Closes-bug:#1407603

Change-Id: Iaab4a6d81632a9e615d27c2eead27114d8957265
(cherry picked from commit 41af757411d5d54c9e52d122e6d5d5d6d67cfce5)

Changed in juniperopenstack:
status: New → Fix Committed
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.