Network security group logging: only DROP events being logged
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
neutron |
New
|
Undecided
|
Unassigned |
Bug Description
Network security group logging not working: empty file being created w/o actual logs
On the clear Openstack (Ubuntu Xenial, Queens release) I have tried to enable a security groups logging as stated in https:/
=================
Actual behaviour: Logfile has been created in place specified in config from "neutron" user, but:
- only DROP events has been created; ACCEPT events are missing;
- ICMP traffic is not logged at all.
Expected behaviour: Logfile has been created & NSG traffic data also being logged into for bot ACCEPT and DROP events.
==========
Additional information:
a) OpenStack has been deployed from scratch using Juju and upstream bundles (with only two charms being modified locally, enabling necessary config changes for following upstream documentation mentioned above), here is actual charm link: http://
b) Full OpenStack configuration commands from flavors till verifying that networking itself is working: http://
c) Config files that should be modified, according to documentation:
neutron-api neutron.conf: http://
neutron-gateway /etc/neutron/
nova-compute /etc/neutron/
Security groups rules: http://
OVS firewall log without any traffic yet: http://
Try to reach HTTPS (which is blocked by security groups): http://
But, if try to login to SSH (it's enabled via NSG rules) - nothing appears in NSG log; however, corresponding rules has been applied to Open vSwitch: http://
Also, nothing also happens in NSG log when trying to reach instance by ICMP (regular ping, for example).
summary: |
- Network security group logging not working: empty file being created w/o - actual logs + Network security group logging not working: only DROP events being + logged |
summary: |
- Network security group logging not working: only DROP events being - logged + Network security group logging: only DROP events being logged |
description: | updated |
description: | updated |
This looks like a duplicate of https:/ /bugs.launchpad .net/neutron/ +bug/1782576 can you confirm? Fixes for that have been backported as well. Thanks.