DNSMASQ wrong addresses allocated after changing DHCP Clients between Neutron vRouters NET
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
neutron |
Expired
|
Undecided
|
Unassigned |
Bug Description
I'm using OpenStack, basically creating Virtual Routers with net/subnets, and DNSMASQ is the DHCP Server for them (via neutron-dhcp driver).
My test scenario contains 2 virtual routers (2 namespaces as router) with 1 DHCP each (2 namespaces as dhcp servers) on the Neutron Network Server. The Subnet are 100.97.97.0/24 for NET with VLAN 997, and Subnet 100.98.98.0/24 for Network with VLAN 998. Both are on the same physical interface (BR-NET2).
The 2 DHCP servers have available .11 to .64 IP address range (54 addresses). (dnsmasq config file is bellow)
I'm generation 60 MAC addresses randomly as source MAC address to test DHCP Client requests. Theses 60 addresses are always the same.
The DHCP Client script tester is connected to Network with VLAN 997 and subnet 100.97.97.0/24. I generate DHCP client MAC addresses and only 54 are allocated, as expected. So, addresses from range 100.97.97.11 to 100.97.97.64 are allocated to client requests. This is OK. Then I stop the DHCP client script tester and wait some time. (script bellow)
When the DHCP lease timer start expire on this DHCP Server, about 600s after the first address allocated (it means, start cleaning entries from /var/lib/
The problems is, sometimes after this "LAN changing" (change the DHCP client tester from VLAN 997 to VLAN 998), the addresses OFFERED are from a wrong NET. When it happens, the allocated addresses always are from 100.101.1.0/24 network (.11 to .64 too). There is no vROUTER and DHCP Server running with this subnet, like shown bellow:
[root@devel91 (keystone_admin)] openstack subnet list
+------
| ID | Name | Network | Subnet |
+------
| 2ede81d1-
| 3c3082ce-
| 4a0adcce-
| 5bcabde7-
| 7f7ab506-
| a7483019-
| a9fda48a-
+------
[root@devel91 (keystone_admin)]
The problem seems to happen only if some addresses still on leases file from the first network (subnet 100.97.97.0/24) and the same MAC requests a new address without do RELEASE before RENEW.
How to debug this to find the trigger?
This is a test scenario, but it happened in real server is use. So, I can do more tests and debugs.
There is no relevant info on /var/log/
>>> DHCP Client Discover script (simulates a limited number of client DHCP discovery)
#/sbin/bash
CUSTOMERQTD=200 #This is only a counter for loop test
CUSTOMERCOUNT=1 #Increse 1 customer
echo "Discovery logs on /tmp/dhcptest"
mkdir /tmp/dhcptest 2>/dev/null
cd /tmp/dhcptest
while [ $CUSTOMERCOUNT -le $CUSTOMERQTD ]
do
XX=$(printf "%02X\n" $(shuf -i 11-70 -n 1)) #Generate 60 MAC addresses where only 54 get an address from dnsmasq
sleep 1
dhtest -i em2 -f -m A0:11:$XX:33:44:$XX #-f is a broadcast request
echo "------
CUSTOMERCOUNT=
done
#DHTEST used is:
#wget https:/
#unzip master.zip
#cd dhtest-master/
>>> DNSMASQ config
/etc/neutron/
log-queries
log-dhcp
log-facility=
dhcp-option-
dhcp-option-
dhcp-reply-delay=1
dhcp-range=
dhcp-option=
dhcp-range=
dhcp-option=
dhcp-range=
dhcp-option=
dhcp-range=
dhcp-option=
dhcp-range=
dhcp-option=
dhcp-range=
dhcp-option=
dhcp-range=
dhcp-option=
dhcp-range=
dhcp-option=
dhcp-range=
dhcp-option=
dhcp-range=
dhcp-option=
dhcp-range=
dhcp-option=
dhcp-range=
dhcp-option=
dhcp-range=
dhcp-option=
dhcp-range=
dhcp-option=
dhcp-range=
dhcp-option=
dhcp-range=
dhcp-option=
dhcp-range=
dhcp-option=
dhcp-range=
dhcp-option=
dhcp-range=
dhcp-option=
dhcp-range=
dhcp-option=
dhcp-range=
dhcp-option=
dhcp-range=
dhcp-option=
dhcp-range=
dhcp-option=
dhcp-range=
dhcp-option=
dhcp-range=
dhcp-option=
dhcp-range=
dhcp-option=
dhcp-range=
dhcp-option=
dhcp-range=
dhcp-option=
dhcp-range=
dhcp-option=
dhcp-range=
dhcp-option=
>>> dnsmasq.log when the first problem happens.
Nov 26 11:12:06 dnsmasq-dhcp[3975]: 1712147283 DHCPDISCOVER(
Nov 26 11:12:06 dnsmasq-dhcp[3975]: 1712147283 tags: infra-81-subnet, tape56ef56c-66
Nov 26 11:12:06 dnsmasq-dhcp[3975]: 1712147283 reply delay: 1
Nov 26 11:12:07 dnsmasq-dhcp[3975]: 1712147283 DHCPOFFER(
Nov 26 11:12:07 dnsmasq-dhcp[3975]: Ignoring duplicate dhcp-option 26
Nov 26 11:12:07 dnsmasq-dhcp[3975]: 1712147283 requested options: 1:netmask, 28:broadcast, 3:router, 15:domain-name,
Nov 26 11:12:07 dnsmasq-dhcp[3975]: 1712147283 requested options: 6:dns-server
Nov 26 11:12:07 dnsmasq-dhcp[3975]: 1712147283 next server: 100.97.97.3
Nov 26 11:12:07 dnsmasq-dhcp[3975]: 1712147283 broadcast response
Nov 26 11:12:07 dnsmasq-dhcp[3975]: 1712147283 sent size: 1 option: 53 message-type 2
Nov 26 11:12:07 dnsmasq-dhcp[3975]: 1712147283 sent size: 4 option: 54 server-identifier 100.97.97.3
Nov 26 11:12:07 dnsmasq-dhcp[3975]: 1712147283 sent size: 4 option: 51 lease-time 10m
Nov 26 11:12:07 dnsmasq-dhcp[3975]: 1712147283 sent size: 4 option: 58 T1 5m
Nov 26 11:12:07 dnsmasq-dhcp[3975]: 1712147283 sent size: 4 option: 59 T2 8m45s
Nov 26 11:12:07 dnsmasq-dhcp[3975]: 1712147283 sent size: 4 option: 1 netmask 255.255.255.0
Nov 26 11:12:07 dnsmasq-dhcp[3975]: 1712147283 sent size: 4 option: 28 broadcast 100.97.97.255
Nov 26 11:12:07 dnsmasq-dhcp[3975]: 1712147283 sent size: 14 option: 15 domain-name openstacklocal
Nov 26 11:12:07 dnsmasq-dhcp[3975]: 1712147283 sent size: 4 option: 3 router 100.97.97.1
Nov 26 11:12:07 dnsmasq-dhcp[3975]: 1712147283 sent size: 8 option: 6 dns-server 170.231.46.176, 8.8.8.8
Nov 26 11:12:07 dnsmasq-dhcp[3975]: 1712147283 sent size: 2 option: 26 mtu 1500
Nov 26 11:12:07 dnsmasq-dhcp[3975]: 435880880 available DHCP subnet: 100.97.
Nov 26 11:12:07 dnsmasq-dhcp[3975]: 435880880 available DHCP range: 100.101.1.11 -- 100.101.1.64
Nov 26 11:12:07 dnsmasq-dhcp[3975]: 435880880 available DHCP range: 100.101.2.11 -- 100.101.2.64
Nov 26 11:12:07 dnsmasq-dhcp[3975]: 435880880 available DHCP range: 100.98.98.11 -- 100.98.98.64
Nov 26 11:12:07 dnsmasq-dhcp[3975]: 435880880 available DHCP range: 100.101.4.11 -- 100.101.4.64
Nov 26 11:12:07 dnsmasq-dhcp[3975]: 435880880 available DHCP range: 100.101.5.11 -- 100.101.5.64
Nov 26 11:12:07 dnsmasq-dhcp[3975]: 435880880 available DHCP range: 100.99.99.11 -- 100.99.99.64
Nov 26 11:12:07 dnsmasq-dhcp[3975]: 435880880 available DHCP range: 100.101.7.11 -- 100.101.7.64
Nov 26 11:12:07 dnsmasq-dhcp[3975]: 435880880 available DHCP range: 100.101.8.11 -- 100.101.8.64
Nov 26 11:12:07 dnsmasq-dhcp[3975]: 435880880 available DHCP range: 100.102.1.11 -- 100.102.1.64
Nov 26 11:12:07 dnsmasq-dhcp[3975]: 435880880 available DHCP range: 100.102.2.11 -- 100.102.2.64
Nov 26 11:12:07 dnsmasq-dhcp[3975]: 435880880 available DHCP range: 100.102.3.11 -- 100.102.3.64
Nov 26 11:12:07 dnsmasq-dhcp[3975]: 435880880 available DHCP range: 100.97.97.11 -- 100.97.97.64
Nov 26 11:12:07 dnsmasq-dhcp[3975]: 435880880 available DHCP range: 100.102.5.11 -- 100.102.5.64
Nov 26 11:12:07 dnsmasq-dhcp[3975]: 435880880 available DHCP range: 100.102.6.11 -- 100.102.6.64
Nov 26 11:12:07 dnsmasq-dhcp[3975]: 435880880 available DHCP range: 100.102.7.11 -- 100.102.7.64
Nov 26 11:12:07 dnsmasq-dhcp[3975]: 435880880 available DHCP range: 100.102.8.11 -- 100.102.8.64
Nov 26 11:12:07 dnsmasq-dhcp[3975]: 435880880 available DHCP range: 100.103.1.11 -- 100.103.1.64
Nov 26 11:12:07 dnsmasq-dhcp[3975]: 435880880 available DHCP range: 100.103.2.11 -- 100.103.2.64
Nov 26 11:12:07 dnsmasq-dhcp[3975]: 435880880 available DHCP range: 100.103.3.11 -- 100.103.3.64
Nov 26 11:12:07 dnsmasq-dhcp[3975]: 435880880 available DHCP range: 100.103.4.11 -- 100.103.4.64
Nov 26 11:12:07 dnsmasq-dhcp[3975]: 435880880 available DHCP range: 100.103.5.11 -- 100.103.5.64
Nov 26 11:12:07 dnsmasq-dhcp[3975]: 435880880 available DHCP range: 100.103.6.11 -- 100.103.6.64
Nov 26 11:12:07 dnsmasq-dhcp[3975]: 435880880 available DHCP range: 100.103.7.11 -- 100.103.7.64
Nov 26 11:12:07 dnsmasq-dhcp[3975]: 435880880 available DHCP range: 100.103.8.11 -- 100.103.8.64
Nov 26 11:12:07 dnsmasq-dhcp[3975]: 435880880 available DHCP range: 100.104.1.11 -- 100.104.1.64
Nov 26 11:12:07 dnsmasq-dhcp[3975]: 435880880 available DHCP range: 100.96.96.11 -- 100.96.96.64
Nov 26 11:12:10 dnsmasq-dhcp[3975]: 435880880 DHCPDISCOVER(
Nov 26 11:12:10 dnsmasq-dhcp[3975]: 435880880 tags: infra-70-subnet, tape56ef56c-66
Nov 26 11:12:10 dnsmasq-dhcp[3975]: 435880880 reply delay: 1
Nov 26 11:12:10 dnsmasq-dhcp[3975]: 435880880 DHCPOFFER(
Nov 26 11:12:10 dnsmasq-dhcp[3975]: Ignoring duplicate dhcp-option 26
Nov 26 11:12:10 dnsmasq-dhcp[3975]: 435880880 requested options: 1:netmask, 28:broadcast, 3:router, 15:domain-name,
Nov 26 11:12:10 dnsmasq-dhcp[3975]: 435880880 requested options: 6:dns-server
Nov 26 11:12:10 dnsmasq-dhcp[3975]: 435880880 next server: 100.97.97.3
Nov 26 11:12:10 dnsmasq-dhcp[3975]: 435880880 broadcast response
Nov 26 11:12:10 dnsmasq-dhcp[3975]: 435880880 sent size: 1 option: 53 message-type 2
Nov 26 11:12:10 dnsmasq-dhcp[3975]: 435880880 sent size: 4 option: 54 server-identifier 100.97.97.3
Nov 26 11:12:10 dnsmasq-dhcp[3975]: 435880880 sent size: 4 option: 51 lease-time 10m
Nov 26 11:12:10 dnsmasq-dhcp[3975]: 435880880 sent size: 4 option: 58 T1 5m
Nov 26 11:12:10 dnsmasq-dhcp[3975]: 435880880 sent size: 4 option: 59 T2 8m45s
Nov 26 11:12:10 dnsmasq-dhcp[3975]: 435880880 sent size: 4 option: 1 netmask 255.0.0.0
Nov 26 11:12:10 dnsmasq-dhcp[3975]: 435880880 sent size: 4 option: 28 broadcast 100.97.97.255
Nov 26 11:12:10 dnsmasq-dhcp[3975]: 435880880 sent size: 14 option: 15 domain-name openstacklocal
Nov 26 11:12:10 dnsmasq-dhcp[3975]: 435880880 sent size: 4 option: 3 router 100.101.1.1
Nov 26 11:12:10 dnsmasq-dhcp[3975]: 435880880 sent size: 8 option: 6 dns-server 170.231.46.176, 8.8.8.8
Nov 26 11:12:10 dnsmasq-dhcp[3975]: 435880880 sent size: 2 option: 26 mtu 1500
Nov 26 11:12:10 dnsmasq-dhcp[3975]: 1712147283 available DHCP subnet: 100.97.
Nov 26 11:12:10 dnsmasq-dhcp[3975]: 1712147283 available DHCP range: 100.101.1.11 -- 100.101.1.64
Nov 26 11:12:10 dnsmasq-dhcp[3975]: 1712147283 available DHCP range: 100.101.2.11 -- 100.101.2.64
Nov 26 11:12:10 dnsmasq-dhcp[3975]: 1712147283 available DHCP range: 100.98.98.11 -- 100.98.98.64
Nov 26 11:12:10 dnsmasq-dhcp[3975]: 1712147283 available DHCP range: 100.101.4.11 -- 100.101.4.64
Nov 26 11:12:10 dnsmasq-dhcp[3975]: 1712147283 available DHCP range: 100.101.5.11 -- 100.101.5.64
Nov 26 11:12:10 dnsmasq-dhcp[3975]: 1712147283 available DHCP range: 100.99.99.11 -- 100.99.99.64
Nov 26 11:12:10 dnsmasq-dhcp[3975]: 1712147283 available DHCP range: 100.101.7.11 -- 100.101.7.64
Nov 26 11:12:10 dnsmasq-dhcp[3975]: 1712147283 available DHCP range: 100.101.8.11 -- 100.101.8.64
Nov 26 11:12:10 dnsmasq-dhcp[3975]: 1712147283 available DHCP range: 100.102.1.11 -- 100.102.1.64
Nov 26 11:12:10 dnsmasq-dhcp[3975]: 1712147283 available DHCP range: 100.102.2.11 -- 100.102.2.64
The scenario:
- Install Controller+Network with packstack (Tested on Mitaka, Pike and Queens)
- phys_net2 is mapped to access interface where VLAN 997 and 998
- Create neutron Networks
#External/Uplink side (WAN for each Virtual Router)
openstack network create ext-net-pub-1 --external --provider-
openstack subnet create ext-subnet-pub-1 --network ext-net-pub-1 --subnet-range 100.100.0.0/24 --allocation-pool start=100.
#Virtual Router1
openstack project create vROUTER-997
openstack router create vROUTER-997 --availability-
openstack network create vROUTER-997-net --external --provider-
openstack subnet create vROUTER-997-subnet --network vROUTER-997-net --subnet-range 100.97.97.0/24 --allocation-pool start=100.
openstack router add subnet vROUTER-997 vROUTER-997-subnet
openstack router set --external-gateway ext-net-pub-1 vROUTER-997
#Virtual Router2
openstack project create vROUTER-998
openstack router create vROUTER-998 --availability-
openstack network create vROUTER-998-net --external --provider-
openstack subnet create vROUTER-998-subnet --network vROUTER-998-net --subnet-range 100.98.98.0/24 --allocation-pool start=100.
openstack router add subnet vROUTER-998 vROUTER-998-subnet
openstack router set --external-gateway ext-net-pub-1 vROUTER-998
- Configure DNSMASQ with config posted above
- Start DHCP Client script on VLAN 997, wait for some time to lease timeout start clear addresses on /var/lib/
Also posted on: http://
Thanks any help
Luis
I also installed 2 other servers, one with Centos7 and other with Debian8,
without Openstack/Neutron. Both with the same DNSMASQ config I originally
posted.
On both I was using version DNSMASQ 2.76 (also upgraded to 2.78), using the same
ethernet interface swapping between 100.97.97.1/24 and 100.98.98.1/24, and everything works as expected. I also tested with 2 different interfaces on each case and also worked fine.
The DHCP client always was the same in all cases (Debian8, Centos7, and
Centos7 with Neutron).
It seems that the problem only happens when using DNSMAQ with Neutron
routers.