ovs router cannot access vm, but vms can access out
Recently after a power failure, all my compute nodes and controller needed to be restarted. Prior to the failure, everything was running great. After starting back up, every configuration looks the same, the instances can ping out to the network, however, the instances are no longer accessible by public or private (via namespace execution) ip for ssh -- only through the console, which makes their purpose in the network fail, as they are to control various vital services I am running.
The odd thing is, the namespace router can ping itself, the instances show up in an arp -an on the namespace, the router can ping the external network, and the vms can ping the routers private ip for the subnet they are on, as well as other instances on that private network (so they are obtaining their dhcp addresses from the network node). The problem is, the router cannot ping the instances in the namespace, and nothing can ping their public floating ip address (but the meta data still shows up on the instance with the correct ip).
I have tried restarting the controller/network node, followed by restarting the computes and vice versa. The same thing results. I have also tried to restart the services on compute nodes in different orders (openvswitch followed by neutron services and nova services in nearly all permutations I can think of). GRE tunnels are there, otherwise my instances wouldn't be able to ping out and ovs-vsctl shows them normally.
What would cause this issue? Is there a database somewhere stopping flows or something else? The iptables in the namespace look fine to me:
-P INPUT ACCEPT
-P FORWARD ACCEPT
-P OUTPUT ACCEPT
-N neutron-filter-top
-N neutron-
-N neutron-
-N neutron-
-N neutron-
-N neutron-
-N neutron-
-N neutron-
-N neutron-
-A INPUT -j neutron-
-A INPUT -j neutron-
-A FORWARD -j neutron-filter-top
-A FORWARD -j neutron-
-A FORWARD -j neutron-
-A OUTPUT -j neutron-filter-top
-A OUTPUT -j neutron-
-A OUTPUT -j neutron-
-A neutron-filter-top -j neutron-
-A neutron-filter-top -j neutron-
-A neutron-
-A neutron-
Any help is appreciated, I need to get things back up.
Question information
- Language:
- English Edit question
- Status:
- Expired
- For:
- Ubuntu neutron Edit question
- Assignee:
- No assignee Edit question
- Last query:
- Last reply: