Change abandoned by Harald Jensås (<email address hidden>) on branch: master
Review: https://review.openstack.org/609830
Reason: Hm, not sure it's the masquerade rule we want.
Could it be the RETURN rule, to ensure we do not masquerade. I.e route, but no NAT?
These are the interfaces on the undercloud in OVB job [1]:
inet 192.168.100.13/22 brd 192.168.103.255 scope global dynamic eth0
inet 192.168.24.1/24 brd 192.168.24.255 scope global br-ctlplane
inet 192.168.24.3/32 scope global br-ctlplane
inet 192.168.24.2/32 scope global br-ctlplane
These are the POSTROUTING rules:
-A POSTROUTING -s 10.0.0.0/24 -d 10.0.0.0/24 -m state --state NEW,RELATED,ESTABLISHED -m comment --comment "137 routed_network return 10.0.0.0/24 ipv4" -j RETURN
-A POSTROUTING -s 192.168.24.0/24 -d 192.168.24.0/24 -m state --state NEW,RELATED,ESTABLISHED -m comment --comment "137 routed_network return 192.168.24.0/24 ipv4" -j RETURN
-A POSTROUTING -s 10.0.0.0/24 -m state --state NEW,RELATED,ESTABLISHED -m comment --comment "138 routed_network masquerade 10.0.0.0/24 ipv4" -j MASQUERADE
-A POSTROUTING -s 192.168.24.0/24 -m state --state NEW,RELATED,ESTABLISHED -m comment --comment "138 routed_network masquerade 192.168.24.0/24 ipv4" -j MASQUERADE
err ... to late. Will have to look again tomorrow.
Change abandoned by Harald Jensås (<email address hidden>) on branch: master /review. openstack. org/609830
Review: https:/
Reason: Hm, not sure it's the masquerade rule we want.
Could it be the RETURN rule, to ensure we do not masquerade. I.e route, but no NAT?
These are the interfaces on the undercloud in OVB job [1]:
inet 192.168.100.13/22 brd 192.168.103.255 scope global dynamic eth0
inet 192.168.24.1/24 brd 192.168.24.255 scope global br-ctlplane
inet 192.168.24.3/32 scope global br-ctlplane
inet 192.168.24.2/32 scope global br-ctlplane
These are the POSTROUTING rules:
-A POSTROUTING -s 10.0.0.0/24 -d 10.0.0.0/24 -m state --state NEW,RELATED, ESTABLISHED -m comment --comment "137 routed_network return 10.0.0.0/24 ipv4" -j RETURN ESTABLISHED -m comment --comment "137 routed_network return 192.168.24.0/24 ipv4" -j RETURN ESTABLISHED -m comment --comment "138 routed_network masquerade 10.0.0.0/24 ipv4" -j MASQUERADE ESTABLISHED -m comment --comment "138 routed_network masquerade 192.168.24.0/24 ipv4" -j MASQUERADE
-A POSTROUTING -s 192.168.24.0/24 -d 192.168.24.0/24 -m state --state NEW,RELATED,
-A POSTROUTING -s 10.0.0.0/24 -m state --state NEW,RELATED,
-A POSTROUTING -s 192.168.24.0/24 -m state --state NEW,RELATED,
err ... to late. Will have to look again tomorrow.
[1] https:/ /logs.rdoprojec t.org/57/ 607557/ 10/openstack- check/tripleo- ci-centos- 7-ovb-3ctlr_ 1comp-featurese t053/befa75a/ logs/undercloud /var/log/ extra/network. txt.gz