FWaaS: Invalid port error on associating ports (distributed router) to firewall group
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
neutron |
Fix Released
|
Medium
|
Unassigned |
Bug Description
This bug is probably very similar to #1759773.
Creating a firewall group fails on CentOS 7.4. and OS Ocata with fwaas_v2 when using a port of a distributed router. The issue is also still present in Queens.
The validation only accepts "network:
The creation of the firewall group itself works, setting a port does not:
# openstack firewall group set --port ff2c03f4-
Failed to set firewall group 'oh_noes': Firewall Group Port ff2c03f4-
Neutron server returns request_ids: ['req-8a8a320b-
The port in question:
# openstack port show ff2c03f4-
{
"allowed_
"extra_
"updated_at": "2018-04-
"device_owner": "network:
"revision_
"port_
"fixed_ips": "ip_address=
"id": "ff2c03f4-
"security_
"option_value": null,
"binding_
"option_name": null,
"description": "",
"qos_policy_id": null,
"mac_address": "fa:16:
"project_id": "4c7effe5f22b4d
"status": "ACTIVE",
"binding_
"binding_
"binding_
"dns_assignment": "fqdn='
"ip_address": null,
"device_id": "f305a116-
"name": "",
"admin_state_up": "UP",
"network_id": "25b641fb-
"dns_name": "",
"created_at": "2018-04-
"subnet_id": null,
"binding_
}
description: | updated |
tags: | added: l3-dvr-backlog |
description: | updated |
Changed in neutron: | |
assignee: | nobody → Sridar Kandaswamy (skandasw) |
Changed in neutron: | |
status: | New → Triaged |
importance: | Undecided → Medium |
Changed in neutron: | |
assignee: | Yushiro FURUKAWA (y-furukawa-2) → Nguyen Phuong An (annp) |
tags: | added: pike-backport-potential queens-backport-potential |
Thank you for opening that bug. I would like to ask few more questions:
- would you like to provide logs from neutron server, please? it would be great to have logs related to req-8a8a320b- 659e-4364- 9604-d41e0b04d6 ea router_ interface" , please? logs would be welcome
- could you provide information about firewall group 'oh_noes', please?
- could you provide example for working scenario, with "network:
Thank you!