IPsec shutdown and re-up the external-interface ,routing missing
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
neutron |
Invalid
|
Undecided
|
Unassigned |
Bug Description
[openstack version kilo]
lan1 192.168.252.0/24
|
| 192.168.252.1
| 172.77.3.39 floatingip
qrouter
| 172.88.1.39
|
|
internet
|
|
| 172.88.1.38
qrouter
| 172.77.3.38 floatingip
| 192.168.253.1
|
lan2 192.168.253.0/24
After setting up ipsec-tunnel successfully,lan1 can ping lan2.Then shut down qrouter external gateway v-interface and re-up,ipsec-
[before re-uping]
Kernel IP routing table
Destination Gateway Genmask Flags Metric Ref Use Iface
0.0.0.0 172.88.1.254 0.0.0.0 UG 0 0 0 qg-8889b596-a5
172.77.3.0 0.0.0.0 255.255.255.0 U 0 0 0 qg-8889b596-a5
172.77.3.38 0.0.0.0 255.255.255.255 UH 0 0 0 *
172.88.1.0 0.0.0.0 255.255.255.0 U 0 0 0 qg-8889b596-a5
192.168.252.0 172.88.1.254 255.255.255.0 UG 0 0 0 qg-8889b596-a5 ⭐-->will missing
192.168.253.0 0.0.0.0 255.255.255.0 U 0 0 0 qr-799ac9c5-58
[after re-uping]
Kernel IP routing table
Destination Gateway Genmask Flags Metric Ref Use Iface
0.0.0.0 172.88.1.254 0.0.0.0 UG 0 0 0 qg-8889b596-a5
172.77.3.0 0.0.0.0 255.255.255.0 U 0 0 0 qg-8889b596-a5
172.77.3.38 0.0.0.0 255.255.255.255 UH 0 0 0 *
172.88.1.0 0.0.0.0 255.255.255.0 U 0 0 0 qg-8889b596-a5
192.168.253.0 0.0.0.0 255.255.255.0 U 0 0 0 qr-799ac9c5-58
description: | updated |
Thanks for the report. I guess the ipsec tunnel is configured via vpnaas extension, can you confirm that? Also relevant logs can help (L3 agent for example)