dhcp reply lost between int-br1 and br-int
Hi,
first of all, here my configuration:
O.S. CentOS 6.4 x86_64 (SELinux disabled)
Grizzly from RDO repos;
Quantum with ovs plugin and vlan (3 vlan id configured at switch level, from 3501 to 3503);
cloudctrl01 acts as keystone, glance, quantum-*, rabbitmq, mysql, nova-* (except network and compute); three interfaces: eth0 - management; eth1 - data; eth2 external;
nova01 acts as nova-compute; two interfaces: eth0 - management, eth1 - data.
As far i understand, the path in the compute node should be:
vm:demo01:eth0 <---> tapafa41705-77 <---> qbrafa41705-77 <---> qvbafa41705-77 <---> qvoafa41705-77 <---> br-int <---> int-br1 <---> phy-br1 <---> br1 <---> eth1
I suppose there something wrong on the compute node (nova01): with tcpdump i saw that dhcp reply arrive at int-br1 but not at br-int.
Additional info:
# uname -r
2.6.32-
# rpm -qa |grep openvs
openvswitch-
openstack-
kmod-openvswitc
# ip li
1: lo: <LOOPBACK,
link/loopback 00:00:00:00:00:00 brd 00:00:00:00:00:00
2: eth0: <BROADCAST,
link/ether e0:cb:4e:55:37:c9 brd ff:ff:ff:ff:ff:ff
3: eth1: <BROADCAST,
link/ether e0:cb:4e:55:36:79 brd ff:ff:ff:ff:ff:ff
4: ovs-system: <BROADCAST,
link/ether a2:ae:a7:4e:81:6c brd ff:ff:ff:ff:ff:ff
43: br-int: <BROADCAST,
link/ether 0a:4c:e0:02:1d:4c brd ff:ff:ff:ff:ff:ff
45: br1: <BROADCAST,
link/ether e0:cb:4e:55:36:79 brd ff:ff:ff:ff:ff:ff
46: phy-br1: <BROADCAST,
link/ether e6:98:6d:71:2b:24 brd ff:ff:ff:ff:ff:ff
47: int-br1: <BROADCAST,
link/ether 56:e1:03:b6:07:e5 brd ff:ff:ff:ff:ff:ff
60: qbrafa41705-77: <BROADCAST,
link/ether 4e:47:72:51:fe:7e brd ff:ff:ff:ff:ff:ff
61: qvoafa41705-77: <BROADCAST,
link/ether a6:c9:e2:a5:5e:52 brd ff:ff:ff:ff:ff:ff
62: qvbafa41705-77: <BROADCAST,
link/ether 4e:47:72:51:fe:7e brd ff:ff:ff:ff:ff:ff
63: tapafa41705-77: <BROADCAST,
link/ether fe:16:3e:0f:0b:f3 brd ff:ff:ff:ff:ff:ff
# ovs-vsctl show
cef7bfff-
Bridge br-int
Port "int-br1"
Port "qvoafa41705-77"
tag: 2
Port br-int
Bridge "br1"
Port "br1"
Port "phy-br1"
Port "eth1"
ovs_version: "1.10.0"
# iptables-save -c
# Generated by iptables-save v1.4.7 on Tue Jul 9 09:41:01 2013
*filter
:INPUT ACCEPT [1550565:
:FORWARD ACCEPT [0:0]
:OUTPUT ACCEPT [1218790:339095333]
:fail2ban-SSH - [0:0]
:quantum-filter-top - [0:0]
:quantum-
:quantum-
:quantum-
:quantum-
:quantum-
:quantum-
:quantum-
:quantum-
[1582086:
[0:0] -A INPUT -i virbr0 -p udp -m udp --dport 53 -j ACCEPT
[0:0] -A INPUT -i virbr0 -p tcp -m tcp --dport 53 -j ACCEPT
[0:0] -A INPUT -i virbr0 -p udp -m udp --dport 67 -j ACCEPT
[0:0] -A INPUT -i virbr0 -p tcp -m tcp --dport 67 -j ACCEPT
[31521:1958364] -A INPUT -p tcp -m multiport --dports 5900:5999 -m comment --comment "001 nova compute incoming" -j ACCEPT
[0:0] -A INPUT -p gre -j ACCEPT
[13649:906676] -A INPUT -p tcp -m tcp --dport 22 -j fail2ban-SSH
[86:29068] -A FORWARD -j quantum-filter-top
[86:29068] -A FORWARD -j quantum-
[0:0] -A FORWARD -d 192.168.122.0/24 -o virbr0 -m state --state RELATED,ESTABLISHED -j ACCEPT
[0:0] -A FORWARD -s 192.168.122.0/24 -i virbr0 -j ACCEPT
[0:0] -A FORWARD -i virbr0 -o virbr0 -j ACCEPT
[0:0] -A FORWARD -o virbr0 -j REJECT --reject-with icmp-port-
[0:0] -A FORWARD -i virbr0 -j REJECT --reject-with icmp-port-
[1218790:339095333] -A OUTPUT -j quantum-filter-top
[1218790:339095333] -A OUTPUT -j quantum-
[13649:906676] -A fail2ban-SSH -j RETURN
[1218876:339124401] -A quantum-filter-top -j quantum-
[43:14534] -A quantum-
[43:14534] -A quantum-
[0:0] -A quantum-
[0:0] -A quantum-
[0:0] -A quantum-
[0:0] -A quantum-
[43:14534] -A quantum-
[0:0] -A quantum-
[43:14534] -A quantum-
[0:0] -A quantum-
[0:0] -A quantum-
[0:0] -A quantum-
[0:0] -A quantum-
[0:0] -A quantum-
[0:0] -A quantum-
[43:14534] -A quantum-
[43:14534] -A quantum-
[43:14534] -A quantum-
[43:14534] -A quantum-
COMMIT
# Completed on Tue Jul 9 09:41:01 2013
# Generated by iptables-save v1.4.7 on Tue Jul 9 09:41:01 2013
*mangle
:PREROUTING ACCEPT [8663792:
:INPUT ACCEPT [7791107:
:FORWARD ACCEPT [294:97842]
:OUTPUT ACCEPT [6081439:
:POSTROUTING ACCEPT [6084802:
[0:0] -A POSTROUTING -o virbr0 -p udp -m udp --dport 68 -j CHECKSUM --checksum-fill
[0:0] -A POSTROUTING -p udp -m udp --dport 68 -j CHECKSUM --checksum-fill
COMMIT
# Completed on Tue Jul 9 09:41:01 2013
# Generated by iptables-save v1.4.7 on Tue Jul 9 09:41:01 2013
*nat
:PREROUTING ACCEPT [168879:18761154]
:POSTROUTING ACCEPT [10339:1134658]
:OUTPUT ACCEPT [10336:1133644]
:quantum-
:quantum-
:quantum-
:quantum-
:quantum-
:quantum-
[168879:18761154] -A PREROUTING -j quantum-
[10339:1134658] -A POSTROUTING -j quantum-
[10339:1134658] -A POSTROUTING -j quantum-
[0:0] -A POSTROUTING -s 192.168.122.0/24 ! -d 192.168.122.0/24 -p tcp -j MASQUERADE --to-ports 1024-65535
[0:0] -A POSTROUTING -s 192.168.122.0/24 ! -d 192.168.122.0/24 -p udp -j MASQUERADE --to-ports 1024-65535
[0:0] -A POSTROUTING -s 192.168.122.0/24 ! -d 192.168.122.0/24 -j MASQUERADE
[10336:1133644] -A OUTPUT -j quantum-
[10339:1134658] -A quantum-
[10339:1134658] -A quantum-
COMMIT
# Completed on Tue Jul 9 09:41:01 2013
Thanks in advance and kind regards,
Paolo
Question information
- Language:
- English Edit question
- Status:
- Solved
- For:
- neutron Edit question
- Assignee:
- No assignee Edit question
- Solved by:
- veronesp
- Solved:
- Last query:
- Last reply: