neutron does not create the necessary iptables rules for l3 and dhcp agents when linuxbridge used
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
neutron |
Fix Released
|
Undecided
|
Slawek Kaplonski |
Bug Description
Version: pike
openstack-
Config: according to https:/
ml2 linuxbridge vxlan
neutron creates rules in neutron-
Expected:
neutron creates rules like -A neutron-
# iptables-save
# Generated by iptables-save v1.4.21 on Thu Sep 28 18:16:57 2017
*nat
:PREROUTING ACCEPT [23760:1495817]
:INPUT ACCEPT [22739:1402147]
:OUTPUT ACCEPT [1778:116606]
:POSTROUTING ACCEPT [2260:170214]
COMMIT
# Completed on Thu Sep 28 18:16:57 2017
# Generated by iptables-save v1.4.21 on Thu Sep 28 18:16:57 2017
*mangle
:PREROUTING ACCEPT [922003:1129881715]
:INPUT ACCEPT [906034:1128976690]
:FORWARD ACCEPT [20488:1851370]
:OUTPUT ACCEPT [774093:3908358570]
:POSTROUTING ACCEPT [793969:3910141934]
COMMIT
# Completed on Thu Sep 28 18:16:57 2017
# Generated by iptables-save v1.4.21 on Thu Sep 28 18:16:57 2017
*raw
:PREROUTING ACCEPT [922261:1129974352]
:OUTPUT ACCEPT [774348:3908396136]
:neutron-
:neutron-
-A PREROUTING -j neutron-
-A OUTPUT -j neutron-
COMMIT
# Completed on Thu Sep 28 18:16:57 2017
# Generated by iptables-save v1.4.21 on Thu Sep 28 18:16:57 2017
*filter
:INPUT ACCEPT [0:0]
:FORWARD ACCEPT [0:0]
:OUTPUT ACCEPT [27196:421070402]
:neutron-filter-top - [0:0]
:neutron-
:neutron-
:neutron-
:neutron-
:neutron-
:neutron-
-A INPUT -j neutron-
-A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT
-A INPUT -p icmp -j ACCEPT
-A INPUT -i lo -j ACCEPT
-A INPUT -p tcp -m state --state NEW -m tcp --dport 22 -j ACCEPT
-A INPUT -j REJECT --reject-with icmp-host-
-A FORWARD -j neutron-filter-top
-A FORWARD -j neutron-
-A FORWARD -j REJECT --reject-with icmp-host-
-A OUTPUT -j neutron-filter-top
-A OUTPUT -j neutron-
-A neutron-filter-top -j neutron-
-A neutron-
-A neutron-
-A neutron-
-A neutron-
-A neutron-
COMMIT
# Completed on Thu Sep 28 18:16:57 2017
# brctl show
bridge name bridge id STP enabled interfaces
brq76f218a0-55 8000.1a1da1c5730b no tap5015bfe4-c5
brq8856ee40-24 8000.921ccb87ce25 no tap8d487e05-d8
Changed in neutron: | |
status: | Incomplete → New |
tags: | added: l3-ipam-dhcp linuxbridge |
tags: | added: neutron-proactive-backport-potential |
The l3-agent and dhcp-agent create iptables rules inside network namespaces, so won't be visible in the "root" namespace.
Is there a specific problem you're seeing?