2016-07-29 09:24:09 |
Artem Savinov |
description |
Core plugin for neutron 'vmware_nsx.plugin.NsxV3Plugin'.
if I create a sg rule via ui/cli that allows all inbound icmp(tcp/udp) traffic - i get exception in neutron.log
example:
neutron security-group-rule-create --protocol icmp --remote-ip-prefix 0.0.0.0/0 default
2016-07-29 09:20:19.841 19130 ERROR neutron.api.v2.resource [req-f18fa262-5512-405e-995f-d5ec28a9e5a0 7a5ae270b2c841ba93f9e41a2a84fb99 897223ebd2024fcca383db0a0b4e4a64 - - -] create failed
2016-07-29 09:20:19.841 19130 ERROR neutron.api.v2.resource Traceback (most recent call last):
2016-07-29 09:20:19.841 19130 ERROR neutron.api.v2.resource File "/usr/lib/python2.7/dist-packages/neutron/api/v2/resource.py", line 84, in resource
2016-07-29 09:20:19.841 19130 ERROR neutron.api.v2.resource result = method(request=request, **args)
2016-07-29 09:20:19.841 19130 ERROR neutron.api.v2.resource File "/usr/lib/python2.7/dist-packages/neutron/api/v2/base.py", line 410, in create
2016-07-29 09:20:19.841 19130 ERROR neutron.api.v2.resource return self._create(request, body, **kwargs)
2016-07-29 09:20:19.841 19130 ERROR neutron.api.v2.resource File "/usr/lib/python2.7/dist-packages/oslo_db/api.py", line 148, in wrapper
2016-07-29 09:20:19.841 19130 ERROR neutron.api.v2.resource ectxt.value = e.inner_exc
2016-07-29 09:20:19.841 19130 ERROR neutron.api.v2.resource File "/usr/lib/python2.7/dist-packages/oslo_utils/excutils.py", line 220, in __exit__
2016-07-29 09:20:19.841 19130 ERROR neutron.api.v2.resource self.force_reraise()
2016-07-29 09:20:19.841 19130 ERROR neutron.api.v2.resource File "/usr/lib/python2.7/dist-packages/oslo_utils/excutils.py", line 196, in force_reraise
2016-07-29 09:20:19.841 19130 ERROR neutron.api.v2.resource six.reraise(self.type_, self.value, self.tb)
2016-07-29 09:20:19.841 19130 ERROR neutron.api.v2.resource File "/usr/lib/python2.7/dist-packages/oslo_db/api.py", line 138, in wrapper
2016-07-29 09:20:19.841 19130 ERROR neutron.api.v2.resource return f(*args, **kwargs)
2016-07-29 09:20:19.841 19130 ERROR neutron.api.v2.resource File "/usr/lib/python2.7/dist-packages/neutron/api/v2/base.py", line 521, in _create
2016-07-29 09:20:19.841 19130 ERROR neutron.api.v2.resource obj = do_create(body)
2016-07-29 09:20:19.841 19130 ERROR neutron.api.v2.resource File "/usr/lib/python2.7/dist-packages/neutron/api/v2/base.py", line 503, in do_create
2016-07-29 09:20:19.841 19130 ERROR neutron.api.v2.resource request.context, reservation.reservation_id)
2016-07-29 09:20:19.841 19130 ERROR neutron.api.v2.resource File "/usr/lib/python2.7/dist-packages/oslo_utils/excutils.py", line 220, in __exit__
2016-07-29 09:20:19.841 19130 ERROR neutron.api.v2.resource self.force_reraise()
2016-07-29 09:20:19.841 19130 ERROR neutron.api.v2.resource File "/usr/lib/python2.7/dist-packages/oslo_utils/excutils.py", line 196, in force_reraise
2016-07-29 09:20:19.841 19130 ERROR neutron.api.v2.resource six.reraise(self.type_, self.value, self.tb)
2016-07-29 09:20:19.841 19130 ERROR neutron.api.v2.resource File "/usr/lib/python2.7/dist-packages/neutron/api/v2/base.py", line 496, in do_create
2016-07-29 09:20:19.841 19130 ERROR neutron.api.v2.resource return obj_creator(request.context, **kwargs)
2016-07-29 09:20:19.841 19130 ERROR neutron.api.v2.resource File "/usr/lib/python2.7/dist-packages/vmware_nsx/plugins/nsx_v3/plugin.py", line 1807, in create_security_group_rule
2016-07-29 09:20:19.841 19130 ERROR neutron.api.v2.resource return self.create_security_group_rule_bulk(context, bulk_rule)[0]
2016-07-29 09:20:19.841 19130 ERROR neutron.api.v2.resource File "/usr/lib/python2.7/dist-packages/vmware_nsx/plugins/nsx_v3/plugin.py", line 1818, in create_security_group_rule_bulk
2016-07-29 09:20:19.841 19130 ERROR neutron.api.v2.resource context, section_id, nsgroup_id, security_group_rules_db)
2016-07-29 09:20:19.841 19130 ERROR neutron.api.v2.resource File "/usr/lib/python2.7/dist-packages/vmware_nsx/nsxlib/v3/security.py", line 134, in create_firewall_rules
2016-07-29 09:20:19.841 19130 ERROR neutron.api.v2.resource sg_rule, nsgroup_id, remote_nsgroup_id)
2016-07-29 09:20:19.841 19130 ERROR neutron.api.v2.resource File "/usr/lib/python2.7/dist-packages/vmware_nsx/nsxlib/v3/security.py", line 112, in _get_fw_rule_from_sg_rule
2016-07-29 09:20:19.841 19130 ERROR neutron.api.v2.resource service = _decide_service(sg_rule)
2016-07-29 09:20:19.841 19130 ERROR neutron.api.v2.resource File "/usr/lib/python2.7/dist-packages/vmware_nsx/nsxlib/v3/security.py", line 61, in _decide_service
2016-07-29 09:20:19.841 19130 ERROR neutron.api.v2.resource l4_protocol = _get_l4_protocol_name(sg_rule['protocol'])
2016-07-29 09:20:19.841 19130 ERROR neutron.api.v2.resource File "/usr/lib/python2.7/dist-packages/vmware_nsx/nsxlib/v3/security.py", line 43, in _get_l4_protocol_name
2016-07-29 09:20:19.841 19130 ERROR neutron.api.v2.resource protocol_number = constants.IP_PROTOCOL_MAP.get(protocol_number,
2016-07-29 09:20:19.841 19130 ERROR neutron.api.v2.resource AttributeError: 'module' object has no attribute 'IP_PROTOCOL_MAP'
2016-07-29 09:20:19.841 19130 ERROR neutron.api.v2.resource |
Core plugin for neutron 'vmware_nsx.plugin.NsxV3Plugin'.
if I create a sg rule via ui/cli that allows all inbound icmp(tcp/udp) traffic - i get exception in neutron.log
example:
neutron security-group-rule-create --protocol icmp --remote-ip-prefix 0.0.0.0/0 default
error:
http://paste.openstack.org/show/543860/ |
|