Revision history [back]

Port Down for owner : network:router_gateway is normal ( it's working port )

Port Down for owner : network:router_gateway is normal ( it's working port )
Shapshot from working Network Node (Kilo)

[root@ip-192-169-142-147 ~(keystone_admin)]# neutron router-list
+--------------------------------------+------------+------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------+-------------+-------+
| id                                   | name       | external_gateway_info                                                                                                                                                                    | distributed | ha    |
+--------------------------------------+------------+------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------+-------------+-------+
| 75ba0f05-3e92-4c37-a21a-0ee2f799caff | RouterDemo | {"network_id": "2471ca6a-175e-4b60-b4c8-b83eeb188801", "enable_snat": true, "external_fixed_ips": [{"subnet_id": "ca6b7767-f302-443d-a14d-2753f71d9112", "ip_address": "172.24.4.227"}]} | False       | False |
+--------------------------------------+------------+------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------+-------------+-------+
[root@ip-192-169-142-147 ~(keystone_admin)]# neutron router-port-list RouterDemo
+--------------------------------------+------+-------------------+-------------------------------------------------------------------------------------+
| id                                   | name | mac_address       | fixed_ips                                                                           |
+--------------------------------------+------+-------------------+-------------------------------------------------------------------------------------+
| 0fa52704-1d73-4400-b89a-e1cc9137cdf2 |      | fa:16:3e:53:62:6a | {"subnet_id": "ca6b7767-f302-443d-a14d-2753f71d9112", "ip_address": "172.24.4.227"} |
| 86a4b5cc-5036-43db-b0c4-ea69db4cee41 |      | fa:16:3e:81:40:a6 | {"subnet_id": "1062b25e-73a5-44b6-a921-3903c98e5d9c", "ip_address": "50.0.0.1"}     |
+--------------------------------------+------+-------------------+-------------------------------------------------------------------------------------+
[root@ip-192-169-142-147 ~(keystone_admin)]# neutron show-port 0fa52704-1d73-4400-b89a-e1cc9137cdf2
Unknown command [u'show-port', u'0fa52704-1d73-4400-b89a-e1cc9137cdf2']
[root@ip-192-169-142-147 ~(keystone_admin)]# neutron port-show  0fa52704-1d73-4400-b89a-e1cc9137cdf2 
+-----------------------+-------------------------------------------------------------------------------------+
| Field                 | Value                                                                               |
+-----------------------+-------------------------------------------------------------------------------------+
| admin_state_up        | True                                                                                |
| allowed_address_pairs |                                                                                     |
| binding:host_id       | ip-192-169-142-147.ip.secureserver.net                                              |
| binding:profile       | {}                                                                                  |
| binding:vif_details   | {"port_filter": true, "ovs_hybrid_plug": true}                                      |
| binding:vif_type      | ovs                                                                                 |
| binding:vnic_type     | normal                                                                              |
| device_id             | 75ba0f05-3e92-4c37-a21a-0ee2f799caff                                                |
| device_owner          | network:router_gateway                                                              |
| extra_dhcp_opts       |                                                                                     |
| fixed_ips             | {"subnet_id": "ca6b7767-f302-443d-a14d-2753f71d9112", "ip_address": "172.24.4.227"} |
| id                    | 0fa52704-1d73-4400-b89a-e1cc9137cdf2                                                |
| mac_address           | fa:16:3e:53:62:6a                                                                   |
| name                  |                                                                                     |
| network_id            | 2471ca6a-175e-4b60-b4c8-b83eeb188801                                                |
| security_groups       |                                                                                     |
| status                | DOWN                                                                                |
| tenant_id             |                                                                                     |
+-----------------------+-------------------------------------------------------------------------------------+
[root@ip-192-169-142-147 ~(keystone_admin)]#

Port Down for owner : network:router_gateway is normal ( it's working port )
Shapshot from working Network Node (Kilo)

 [root@ip-192-169-142-147 ~(keystone_admin)]# neutron router-list
 +--------------------------------------+------------+------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------+-------------+-------+
 | id                                   | name       | external_gateway_info                                                                                                                                                                    | distributed | ha    |
 +--------------------------------------+------------+------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------+-------------+-------+
 | 75ba0f05-3e92-4c37-a21a-0ee2f799caff | RouterDemo | {"network_id": "2471ca6a-175e-4b60-b4c8-b83eeb188801", "enable_snat": true, "external_fixed_ips": [{"subnet_id": "ca6b7767-f302-443d-a14d-2753f71d9112", "ip_address": "172.24.4.227"}]} | False       | False |
 +--------------------------------------+------------+------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------+-------------+-------+
 [root@ip-192-169-142-147 ~(keystone_admin)]# neutron router-port-list RouterDemo
 +--------------------------------------+------+-------------------+-------------------------------------------------------------------------------------+
 | id                                   | name | mac_address       | fixed_ips                                                                           |
 +--------------------------------------+------+-------------------+-------------------------------------------------------------------------------------+
 | 0fa52704-1d73-4400-b89a-e1cc9137cdf2 |      | fa:16:3e:53:62:6a | {"subnet_id": "ca6b7767-f302-443d-a14d-2753f71d9112", "ip_address": "172.24.4.227"} |
 | 86a4b5cc-5036-43db-b0c4-ea69db4cee41 |      | fa:16:3e:81:40:a6 | {"subnet_id": "1062b25e-73a5-44b6-a921-3903c98e5d9c", "ip_address": "50.0.0.1"}     |
 +--------------------------------------+------+-------------------+-------------------------------------------------------------------------------------+
[root@ip-192-169-142-147 ~(keystone_admin)]# neutron show-port 0fa52704-1d73-4400-b89a-e1cc9137cdf2
Unknown command [u'show-port', u'0fa52704-1d73-4400-b89a-e1cc9137cdf2']
 [root@ip-192-169-142-147 ~(keystone_admin)]# neutron port-show  0fa52704-1d73-4400-b89a-e1cc9137cdf2 
 +-----------------------+-------------------------------------------------------------------------------------+
 | Field                 | Value                                                                               |
 +-----------------------+-------------------------------------------------------------------------------------+
 | admin_state_up        | True                                                                                |
 | allowed_address_pairs |                                                                                     |
 | binding:host_id       | ip-192-169-142-147.ip.secureserver.net                                              |
 | binding:profile       | {}                                                                                  |
 | binding:vif_details   | {"port_filter": true, "ovs_hybrid_plug": true}                                      |
 | binding:vif_type      | ovs                                                                                 |
 | binding:vnic_type     | normal                                                                              |
 | device_id             | 75ba0f05-3e92-4c37-a21a-0ee2f799caff                                                |
 | device_owner          | network:router_gateway                                                              |
 | extra_dhcp_opts       |                                                                                     |
 | fixed_ips             | {"subnet_id": "ca6b7767-f302-443d-a14d-2753f71d9112", "ip_address": "172.24.4.227"} |
 | id                    | 0fa52704-1d73-4400-b89a-e1cc9137cdf2                                                |
 | mac_address           | fa:16:3e:53:62:6a                                                                   |
 | name                  |                                                                                     |
 | network_id            | 2471ca6a-175e-4b60-b4c8-b83eeb188801                                                |
 | security_groups       |                                                                                     |
 | status                | DOWN                                                                                |
 | tenant_id             |                                                                                     |
 +-----------------------+-------------------------------------------------------------------------------------+
 [root@ip-192-169-142-147 ~(keystone_admin)]#

UPDATE 1
Set up security rools

$. keystonerc_demo
$ neutron security-group-rule-create --protocol icmp \
  --direction ingress --remote-ip-prefix 0.0.0.0/0 default
$ neutron security-group-rule-create --protocol tcp \
  --port-range-min 22 --port-range-max 22 \
  --direction ingress --remote-ip-prefix 0.0.0.0/0 default

END UPDATE

Port Down for owner : network:router_gateway is normal ( it's working port )
Shapshot from working Network Node (Kilo)

    [root@ip-192-169-142-147 ~(keystone_admin)]# neutron router-list
    +--------------------------------------+------------+------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------+-------------+-------+
    | id                                   | name       | external_gateway_info                                                                                                                                                                    | distributed | ha    |
    +--------------------------------------+------------+------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------+-------------+-------+
    | 75ba0f05-3e92-4c37-a21a-0ee2f799caff | RouterDemo | {"network_id": "2471ca6a-175e-4b60-b4c8-b83eeb188801", "enable_snat": true, "external_fixed_ips": [{"subnet_id": "ca6b7767-f302-443d-a14d-2753f71d9112", "ip_address": "172.24.4.227"}]} | False       | False |
    +--------------------------------------+------------+------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------+-------------+-------+
 [root@ip-192-169-142-147 ~(keystone_admin)]# neutron router-port-list RouterDemo
    +--------------------------------------+------+-------------------+-------------------------------------------------------------------------------------+
    | id                                   | name | mac_address       | fixed_ips                                                                           |
    +--------------------------------------+------+-------------------+-------------------------------------------------------------------------------------+
    | 0fa52704-1d73-4400-b89a-e1cc9137cdf2 |      | fa:16:3e:53:62:6a | {"subnet_id": "ca6b7767-f302-443d-a14d-2753f71d9112", "ip_address": "172.24.4.227"} |
    | 86a4b5cc-5036-43db-b0c4-ea69db4cee41 |      | fa:16:3e:81:40:a6 | {"subnet_id": "1062b25e-73a5-44b6-a921-3903c98e5d9c", "ip_address": "50.0.0.1"}     |
    +--------------------------------------+------+-------------------+-------------------------------------------------------------------------------------+
 [root@ip-192-169-142-147 ~(keystone_admin)]# neutron port-show  0fa52704-1d73-4400-b89a-e1cc9137cdf2 
    +-----------------------+-------------------------------------------------------------------------------------+
    | Field                 | Value                                                                               |
    +-----------------------+-------------------------------------------------------------------------------------+
    | admin_state_up        | True                                                                                |
    | allowed_address_pairs |                                                                                     |
    | binding:host_id       | ip-192-169-142-147.ip.secureserver.net                                              |
    | binding:profile       | {}                                                                                  |
    | binding:vif_details   | {"port_filter": true, "ovs_hybrid_plug": true}                                      |
    | binding:vif_type      | ovs                                                                                 |
    | binding:vnic_type     | normal                                                                              |
    | device_id             | 75ba0f05-3e92-4c37-a21a-0ee2f799caff                                                |
    | device_owner          | network:router_gateway                                                              |
    | extra_dhcp_opts       |                                                                                     |
    | fixed_ips             | {"subnet_id": "ca6b7767-f302-443d-a14d-2753f71d9112", "ip_address": "172.24.4.227"} |
    | id                    | 0fa52704-1d73-4400-b89a-e1cc9137cdf2                                                |
    | mac_address           | fa:16:3e:53:62:6a                                                                   |
    | name                  |                                                                                     |
    | network_id            | 2471ca6a-175e-4b60-b4c8-b83eeb188801                                                |
    | security_groups       |                                                                                     |
    | status                | DOWN                                                                                |
    | tenant_id             |                                                                                     |
    +-----------------------+-------------------------------------------------------------------------------------+
    [root@ip-192-169-142-147 ~(keystone_admin)]#

UPDATE 1
Set up security rools

$. keystonerc_demo
$ neutron security-group-rule-create --protocol icmp \
  --direction ingress --remote-ip-prefix 0.0.0.0/0 default
$ neutron security-group-rule-create --protocol tcp \
  --port-range-min 22 --port-range-max 22 \
  --direction ingress --remote-ip-prefix 0.0.0.0/0 default

END UPDATE


image description

Port Down for owner : network:router_gateway is normal ( it's working port )
Shapshot from working Network Node (Kilo)

    [root@ip-192-169-142-147 ~(keystone_admin)]# neutron router-list
    +--------------------------------------+------------+------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------+-------------+-------+
    | id                                   | name       | external_gateway_info                                                                                                                                                                    | distributed | ha    |
    +--------------------------------------+------------+------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------+-------------+-------+
    | 75ba0f05-3e92-4c37-a21a-0ee2f799caff | RouterDemo | {"network_id": "2471ca6a-175e-4b60-b4c8-b83eeb188801", "enable_snat": true, "external_fixed_ips": [{"subnet_id": "ca6b7767-f302-443d-a14d-2753f71d9112", "ip_address": "172.24.4.227"}]} | False       | False |
    +--------------------------------------+------------+------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------+-------------+-------+
 [root@ip-192-169-142-147 ~(keystone_admin)]# neutron router-port-list RouterDemo
    +--------------------------------------+------+-------------------+-------------------------------------------------------------------------------------+
    | id                                   | name | mac_address       | fixed_ips                                                                           |
    +--------------------------------------+------+-------------------+-------------------------------------------------------------------------------------+
    | 0fa52704-1d73-4400-b89a-e1cc9137cdf2 |      | fa:16:3e:53:62:6a | {"subnet_id": "ca6b7767-f302-443d-a14d-2753f71d9112", "ip_address": "172.24.4.227"} |
    | 86a4b5cc-5036-43db-b0c4-ea69db4cee41 |      | fa:16:3e:81:40:a6 | {"subnet_id": "1062b25e-73a5-44b6-a921-3903c98e5d9c", "ip_address": "50.0.0.1"}     |
    +--------------------------------------+------+-------------------+-------------------------------------------------------------------------------------+
 [root@ip-192-169-142-147 ~(keystone_admin)]# neutron port-show  0fa52704-1d73-4400-b89a-e1cc9137cdf2 
    +-----------------------+-------------------------------------------------------------------------------------+
    | Field                 | Value                                                                               |
    +-----------------------+-------------------------------------------------------------------------------------+
    | admin_state_up        | True                                                                                |
    | allowed_address_pairs |                                                                                     |
    | binding:host_id       | ip-192-169-142-147.ip.secureserver.net                                              |
    | binding:profile       | {}                                                                                  |
    | binding:vif_details   | {"port_filter": true, "ovs_hybrid_plug": true}                                      |
    | binding:vif_type      | ovs                                                                                 |
    | binding:vnic_type     | normal                                                                              |
    | device_id             | 75ba0f05-3e92-4c37-a21a-0ee2f799caff                                                |
    | device_owner          | network:router_gateway                                                              |
    | extra_dhcp_opts       |                                                                                     |
    | fixed_ips             | {"subnet_id": "ca6b7767-f302-443d-a14d-2753f71d9112", "ip_address": "172.24.4.227"} |
    | id                    | 0fa52704-1d73-4400-b89a-e1cc9137cdf2                                                |
    | mac_address           | fa:16:3e:53:62:6a                                                                   |
    | name                  |                                                                                     |
    | network_id            | 2471ca6a-175e-4b60-b4c8-b83eeb188801                                                |
    | security_groups       |                                                                                     |
    | status                | DOWN                                                                                |
    | tenant_id             |                                                                                     |
    +-----------------------+-------------------------------------------------------------------------------------+
    [root@ip-192-169-142-147 ~(keystone_admin)]#

UPDATE 2

It looks like your management network is the same as external  (xxx.64.91.0/24)
You need 3 NICs on Network Node
Eth0 to support mgmt network (any), but different from external
Eth1 to VXLAN tunnel ( as you have right now )
Eth2 to become OVS port of OVS bridge br-ex xxx.64.91.55
Three node deployment ( via my experience ) requires mgmt network different from external

END UPDATE

UPDATE 1
Set up security rools

$. keystonerc_demo
$ neutron security-group-rule-create --protocol icmp \
  --direction ingress --remote-ip-prefix 0.0.0.0/0 default
$ neutron security-group-rule-create --protocol tcp \
  --port-range-min 22 --port-range-max 22 \
  --direction ingress --remote-ip-prefix 0.0.0.0/0 default

END UPDATE
image description Port Down for owner : network:router_gateway is normal ( it's working port )
Shapshot from working Network Node (Kilo)

    [root@ip-192-169-142-147 ~(keystone_admin)]# neutron router-list
    +--------------------------------------+------------+------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------+-------------+-------+
    | id                                   | name       | external_gateway_info                                                                                                                                                                    | distributed | ha    |
    +--------------------------------------+------------+------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------+-------------+-------+
    | 75ba0f05-3e92-4c37-a21a-0ee2f799caff | RouterDemo | {"network_id": "2471ca6a-175e-4b60-b4c8-b83eeb188801", "enable_snat": true, "external_fixed_ips": [{"subnet_id": "ca6b7767-f302-443d-a14d-2753f71d9112", "ip_address": "172.24.4.227"}]} | False       | False |
    +--------------------------------------+------------+------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------+-------------+-------+
 [root@ip-192-169-142-147 ~(keystone_admin)]# neutron router-port-list RouterDemo
    +--------------------------------------+------+-------------------+-------------------------------------------------------------------------------------+
    | id                                   | name | mac_address       | fixed_ips                                                                           |
    +--------------------------------------+------+-------------------+-------------------------------------------------------------------------------------+
    | 0fa52704-1d73-4400-b89a-e1cc9137cdf2 |      | fa:16:3e:53:62:6a | {"subnet_id": "ca6b7767-f302-443d-a14d-2753f71d9112", "ip_address": "172.24.4.227"} |
    | 86a4b5cc-5036-43db-b0c4-ea69db4cee41 |      | fa:16:3e:81:40:a6 | {"subnet_id": "1062b25e-73a5-44b6-a921-3903c98e5d9c", "ip_address": "50.0.0.1"}     |
    +--------------------------------------+------+-------------------+-------------------------------------------------------------------------------------+
 [root@ip-192-169-142-147 ~(keystone_admin)]# neutron port-show  0fa52704-1d73-4400-b89a-e1cc9137cdf2 
    +-----------------------+-------------------------------------------------------------------------------------+
    | Field                 | Value                                                                               |
    +-----------------------+-------------------------------------------------------------------------------------+
    | admin_state_up        | True                                                                                |
    | allowed_address_pairs |                                                                                     |
    | binding:host_id       | ip-192-169-142-147.ip.secureserver.net                                              |
    | binding:profile       | {}                                                                                  |
    | binding:vif_details   | {"port_filter": true, "ovs_hybrid_plug": true}                                      |
    | binding:vif_type      | ovs                                                                                 |
    | binding:vnic_type     | normal                                                                              |
    | device_id             | 75ba0f05-3e92-4c37-a21a-0ee2f799caff                                                |
    | device_owner          | network:router_gateway                                                              |
    | extra_dhcp_opts       |                                                                                     |
    | fixed_ips             | {"subnet_id": "ca6b7767-f302-443d-a14d-2753f71d9112", "ip_address": "172.24.4.227"} |
    | id                    | 0fa52704-1d73-4400-b89a-e1cc9137cdf2                                                |
    | mac_address           | fa:16:3e:53:62:6a                                                                   |
    | name                  |                                                                                     |
    | network_id            | 2471ca6a-175e-4b60-b4c8-b83eeb188801                                                |
    | security_groups       |                                                                                     |
    | status                | DOWN                                                                                |
    | tenant_id             |                                                                                     |
    +-----------------------+-------------------------------------------------------------------------------------+
    [root@ip-192-169-142-147 ~(keystone_admin)]#

UPDATE 2

It looks like your management network is the same as external  (xxx.64.91.0/24)
You need 3 NICs on Network Node
Eth0 to support mgmt network (any), but different from external
Eth1 to support VXLAN tunnel ( as you have right now )
Eth2 to become OVS port of OVS bridge br-ex xxx.64.91.55
Three node deployment with dedicated Network node ( via my experience ) requires mgmt network different from external

END UPDATE

UPDATE 1
Set up security rools

$. keystonerc_demo
$ neutron security-group-rule-create --protocol icmp \
  --direction ingress --remote-ip-prefix 0.0.0.0/0 default
$ neutron security-group-rule-create --protocol tcp \
  --port-range-min 22 --port-range-max 22 \
  --direction ingress --remote-ip-prefix 0.0.0.0/0 default

END UPDATE
image description Port Down for owner : network:router_gateway is normal ( it's working port )
Shapshot from working Network Node (Kilo)

    [root@ip-192-169-142-147 ~(keystone_admin)]# neutron router-list
    +--------------------------------------+------------+------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------+-------------+-------+
    | id                                   | name       | external_gateway_info                                                                                                                                                                    | distributed | ha    |
    +--------------------------------------+------------+------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------+-------------+-------+
    | 75ba0f05-3e92-4c37-a21a-0ee2f799caff | RouterDemo | {"network_id": "2471ca6a-175e-4b60-b4c8-b83eeb188801", "enable_snat": true, "external_fixed_ips": [{"subnet_id": "ca6b7767-f302-443d-a14d-2753f71d9112", "ip_address": "172.24.4.227"}]} | False       | False |
    +--------------------------------------+------------+------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------+-------------+-------+
 [root@ip-192-169-142-147 ~(keystone_admin)]# neutron router-port-list RouterDemo
    +--------------------------------------+------+-------------------+-------------------------------------------------------------------------------------+
    | id                                   | name | mac_address       | fixed_ips                                                                           |
    +--------------------------------------+------+-------------------+-------------------------------------------------------------------------------------+
    | 0fa52704-1d73-4400-b89a-e1cc9137cdf2 |      | fa:16:3e:53:62:6a | {"subnet_id": "ca6b7767-f302-443d-a14d-2753f71d9112", "ip_address": "172.24.4.227"} |
    | 86a4b5cc-5036-43db-b0c4-ea69db4cee41 |      | fa:16:3e:81:40:a6 | {"subnet_id": "1062b25e-73a5-44b6-a921-3903c98e5d9c", "ip_address": "50.0.0.1"}     |
    +--------------------------------------+------+-------------------+-------------------------------------------------------------------------------------+
 [root@ip-192-169-142-147 ~(keystone_admin)]# neutron port-show  0fa52704-1d73-4400-b89a-e1cc9137cdf2 
    +-----------------------+-------------------------------------------------------------------------------------+
    | Field                 | Value                                                                               |
    +-----------------------+-------------------------------------------------------------------------------------+
    | admin_state_up        | True                                                                                |
    | allowed_address_pairs |                                                                                     |
    | binding:host_id       | ip-192-169-142-147.ip.secureserver.net                                              |
    | binding:profile       | {}                                                                                  |
    | binding:vif_details   | {"port_filter": true, "ovs_hybrid_plug": true}                                      |
    | binding:vif_type      | ovs                                                                                 |
    | binding:vnic_type     | normal                                                                              |
    | device_id             | 75ba0f05-3e92-4c37-a21a-0ee2f799caff                                                |
    | device_owner          | network:router_gateway                                                              |
    | extra_dhcp_opts       |                                                                                     |
    | fixed_ips             | {"subnet_id": "ca6b7767-f302-443d-a14d-2753f71d9112", "ip_address": "172.24.4.227"} |
    | id                    | 0fa52704-1d73-4400-b89a-e1cc9137cdf2                                                |
    | mac_address           | fa:16:3e:53:62:6a                                                                   |
    | name                  |                                                                                     |
    | network_id            | 2471ca6a-175e-4b60-b4c8-b83eeb188801                                                |
    | security_groups       |                                                                                     |
    | status                | DOWN                                                                                |
    | tenant_id             |                                                                                     |
    +-----------------------+-------------------------------------------------------------------------------------+
    [root@ip-192-169-142-147 ~(keystone_admin)]#

UPDATE 22 08/29/2015

It looks like your management network is the same as external  (xxx.64.91.0/24)
You need 3 NICs on Network Node
Eth0 to support mgmt network (any), but different from external
Eth1 to support VXLAN tunnel ( as you have right now )
Eth2 to become OVS port of OVS bridge br-ex xxx.64.91.55
Three node deployment with dedicated Network node ( via my experience ) requires mgmt network different from external

Please, remind me which configuration you have Controller+Network+Compute or (Controller/Network)+Compute
END UPDATE

UPDATE 1
Set up security rools

$. keystonerc_demo
$ neutron security-group-rule-create --protocol icmp \
  --direction ingress --remote-ip-prefix 0.0.0.0/0 default
$ neutron security-group-rule-create --protocol tcp \
  --port-range-min 22 --port-range-max 22 \
  --direction ingress --remote-ip-prefix 0.0.0.0/0 default

END UPDATE
image description Port Down for owner : network:router_gateway is normal ( it's working port )
Shapshot from working Network Node (Kilo)

    [root@ip-192-169-142-147 ~(keystone_admin)]# neutron router-list
    +--------------------------------------+------------+------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------+-------------+-------+
    | id                                   | name       | external_gateway_info                                                                                                                                                                    | distributed | ha    |
    +--------------------------------------+------------+------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------+-------------+-------+
    | 75ba0f05-3e92-4c37-a21a-0ee2f799caff | RouterDemo | {"network_id": "2471ca6a-175e-4b60-b4c8-b83eeb188801", "enable_snat": true, "external_fixed_ips": [{"subnet_id": "ca6b7767-f302-443d-a14d-2753f71d9112", "ip_address": "172.24.4.227"}]} | False       | False |
    +--------------------------------------+------------+------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------+-------------+-------+
 [root@ip-192-169-142-147 ~(keystone_admin)]# neutron router-port-list RouterDemo
    +--------------------------------------+------+-------------------+-------------------------------------------------------------------------------------+
    | id                                   | name | mac_address       | fixed_ips                                                                           |
    +--------------------------------------+------+-------------------+-------------------------------------------------------------------------------------+
    | 0fa52704-1d73-4400-b89a-e1cc9137cdf2 |      | fa:16:3e:53:62:6a | {"subnet_id": "ca6b7767-f302-443d-a14d-2753f71d9112", "ip_address": "172.24.4.227"} |
    | 86a4b5cc-5036-43db-b0c4-ea69db4cee41 |      | fa:16:3e:81:40:a6 | {"subnet_id": "1062b25e-73a5-44b6-a921-3903c98e5d9c", "ip_address": "50.0.0.1"}     |
    +--------------------------------------+------+-------------------+-------------------------------------------------------------------------------------+
 [root@ip-192-169-142-147 ~(keystone_admin)]# neutron port-show  0fa52704-1d73-4400-b89a-e1cc9137cdf2 
    +-----------------------+-------------------------------------------------------------------------------------+
    | Field                 | Value                                                                               |
    +-----------------------+-------------------------------------------------------------------------------------+
    | admin_state_up        | True                                                                                |
    | allowed_address_pairs |                                                                                     |
    | binding:host_id       | ip-192-169-142-147.ip.secureserver.net                                              |
    | binding:profile       | {}                                                                                  |
    | binding:vif_details   | {"port_filter": true, "ovs_hybrid_plug": true}                                      |
    | binding:vif_type      | ovs                                                                                 |
    | binding:vnic_type     | normal                                                                              |
    | device_id             | 75ba0f05-3e92-4c37-a21a-0ee2f799caff                                                |
    | device_owner          | network:router_gateway                                                              |
    | extra_dhcp_opts       |                                                                                     |
    | fixed_ips             | {"subnet_id": "ca6b7767-f302-443d-a14d-2753f71d9112", "ip_address": "172.24.4.227"} |
    | id                    | 0fa52704-1d73-4400-b89a-e1cc9137cdf2                                                |
    | mac_address           | fa:16:3e:53:62:6a                                                                   |
    | name                  |                                                                                     |
    | network_id            | 2471ca6a-175e-4b60-b4c8-b83eeb188801                                                |
    | security_groups       |                                                                                     |
    | status                | DOWN                                                                                |
    | tenant_id             |                                                                                     |
    +-----------------------+-------------------------------------------------------------------------------------+
    [root@ip-192-169-142-147 ~(keystone_admin)]#

UPDATE 2 08/29/2015

It looks like your management network is the same as external  (xxx.64.91.0/24)
You need 3 NICs on Network Node
Eth0 to support mgmt network (any), but different from external
Eth1 to support VXLAN tunnel ( as you have right now )
Eth2 to become OVS port of OVS bridge br-ex xxx.64.91.55
Three node deployment with dedicated Network node ( via my experience ) requires mgmt network different from external

Please, remind me which configuration you have Controller+Network+Compute or (Controller/Network)+ComputeSee https://ask.openstack.org/en/question/67738/br-ex-configuration-on-ubuntu/
END UPDATE

UPDATE 1
Set up security rools

$. keystonerc_demo
$ neutron security-group-rule-create --protocol icmp \
  --direction ingress --remote-ip-prefix 0.0.0.0/0 default
$ neutron security-group-rule-create --protocol tcp \
  --port-range-min 22 --port-range-max 22 \
  --direction ingress --remote-ip-prefix 0.0.0.0/0 default

END UPDATE
image description Port Down for owner : network:router_gateway is normal ( it's working port )
Shapshot from working Network Node (Kilo)

    [root@ip-192-169-142-147 ~(keystone_admin)]# neutron router-list
    +--------------------------------------+------------+------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------+-------------+-------+
    | id                                   | name       | external_gateway_info                                                                                                                                                                    | distributed | ha    |
    +--------------------------------------+------------+------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------+-------------+-------+
    | 75ba0f05-3e92-4c37-a21a-0ee2f799caff | RouterDemo | {"network_id": "2471ca6a-175e-4b60-b4c8-b83eeb188801", "enable_snat": true, "external_fixed_ips": [{"subnet_id": "ca6b7767-f302-443d-a14d-2753f71d9112", "ip_address": "172.24.4.227"}]} | False       | False |
    +--------------------------------------+------------+------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------+-------------+-------+
 [root@ip-192-169-142-147 ~(keystone_admin)]# neutron router-port-list RouterDemo
    +--------------------------------------+------+-------------------+-------------------------------------------------------------------------------------+
    | id                                   | name | mac_address       | fixed_ips                                                                           |
    +--------------------------------------+------+-------------------+-------------------------------------------------------------------------------------+
    | 0fa52704-1d73-4400-b89a-e1cc9137cdf2 |      | fa:16:3e:53:62:6a | {"subnet_id": "ca6b7767-f302-443d-a14d-2753f71d9112", "ip_address": "172.24.4.227"} |
    | 86a4b5cc-5036-43db-b0c4-ea69db4cee41 |      | fa:16:3e:81:40:a6 | {"subnet_id": "1062b25e-73a5-44b6-a921-3903c98e5d9c", "ip_address": "50.0.0.1"}     |
    +--------------------------------------+------+-------------------+-------------------------------------------------------------------------------------+
 [root@ip-192-169-142-147 ~(keystone_admin)]# neutron port-show  0fa52704-1d73-4400-b89a-e1cc9137cdf2 
    +-----------------------+-------------------------------------------------------------------------------------+
    | Field                 | Value                                                                               |
    +-----------------------+-------------------------------------------------------------------------------------+
    | admin_state_up        | True                                                                                |
    | allowed_address_pairs |                                                                                     |
    | binding:host_id       | ip-192-169-142-147.ip.secureserver.net                                              |
    | binding:profile       | {}                                                                                  |
    | binding:vif_details   | {"port_filter": true, "ovs_hybrid_plug": true}                                      |
    | binding:vif_type      | ovs                                                                                 |
    | binding:vnic_type     | normal                                                                              |
    | device_id             | 75ba0f05-3e92-4c37-a21a-0ee2f799caff                                                |
    | device_owner          | network:router_gateway                                                              |
    | extra_dhcp_opts       |                                                                                     |
    | fixed_ips             | {"subnet_id": "ca6b7767-f302-443d-a14d-2753f71d9112", "ip_address": "172.24.4.227"} |
    | id                    | 0fa52704-1d73-4400-b89a-e1cc9137cdf2                                                |
    | mac_address           | fa:16:3e:53:62:6a                                                                   |
    | name                  |                                                                                     |
    | network_id            | 2471ca6a-175e-4b60-b4c8-b83eeb188801                                                |
    | security_groups       |                                                                                     |
    | status                | DOWN                                                                                |
    | tenant_id             |                                                                                     |
    +-----------------------+-------------------------------------------------------------------------------------+
    [root@ip-192-169-142-147 ~(keystone_admin)]#

UPDATE 2 08/29/2015
See https://ask.openstack.org/en/question/67738/br-ex-configuration-on-ubuntu/
Replace with your IPs

auto br-ex
 iface br-ex inet static
 address 192.168.1.(XX)
 netmask 255.255.255.0
 gateway 192.168.1.1
 dns-nameservers 8.8.8.8

# The external network interface
auto eth0
iface eth0  inet manual
        up ip link set dev $IFACE up
        down ip link set dev $IFACE down

END UPDATE

UPDATE 1
Set up security rools

$. keystonerc_demo
$ neutron security-group-rule-create --protocol icmp \
  --direction ingress --remote-ip-prefix 0.0.0.0/0 default
$ neutron security-group-rule-create --protocol tcp \
  --port-range-min 22 --port-range-max 22 \
  --direction ingress --remote-ip-prefix 0.0.0.0/0 default

END UPDATE
image description Port Down for owner : network:router_gateway is normal ( it's working port )
Shapshot from working Network Node (Kilo)

    [root@ip-192-169-142-147 ~(keystone_admin)]# neutron router-list
    +--------------------------------------+------------+------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------+-------------+-------+
    | id                                   | name       | external_gateway_info                                                                                                                                                                    | distributed | ha    |
    +--------------------------------------+------------+------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------+-------------+-------+
    | 75ba0f05-3e92-4c37-a21a-0ee2f799caff | RouterDemo | {"network_id": "2471ca6a-175e-4b60-b4c8-b83eeb188801", "enable_snat": true, "external_fixed_ips": [{"subnet_id": "ca6b7767-f302-443d-a14d-2753f71d9112", "ip_address": "172.24.4.227"}]} | False       | False |
    +--------------------------------------+------------+------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------+-------------+-------+
 [root@ip-192-169-142-147 ~(keystone_admin)]# neutron router-port-list RouterDemo
    +--------------------------------------+------+-------------------+-------------------------------------------------------------------------------------+
    | id                                   | name | mac_address       | fixed_ips                                                                           |
    +--------------------------------------+------+-------------------+-------------------------------------------------------------------------------------+
    | 0fa52704-1d73-4400-b89a-e1cc9137cdf2 |      | fa:16:3e:53:62:6a | {"subnet_id": "ca6b7767-f302-443d-a14d-2753f71d9112", "ip_address": "172.24.4.227"} |
    | 86a4b5cc-5036-43db-b0c4-ea69db4cee41 |      | fa:16:3e:81:40:a6 | {"subnet_id": "1062b25e-73a5-44b6-a921-3903c98e5d9c", "ip_address": "50.0.0.1"}     |
    +--------------------------------------+------+-------------------+-------------------------------------------------------------------------------------+
 [root@ip-192-169-142-147 ~(keystone_admin)]# neutron port-show  0fa52704-1d73-4400-b89a-e1cc9137cdf2 
    +-----------------------+-------------------------------------------------------------------------------------+
    | Field                 | Value                                                                               |
    +-----------------------+-------------------------------------------------------------------------------------+
    | admin_state_up        | True                                                                                |
    | allowed_address_pairs |                                                                                     |
    | binding:host_id       | ip-192-169-142-147.ip.secureserver.net                                              |
    | binding:profile       | {}                                                                                  |
    | binding:vif_details   | {"port_filter": true, "ovs_hybrid_plug": true}                                      |
    | binding:vif_type      | ovs                                                                                 |
    | binding:vnic_type     | normal                                                                              |
    | device_id             | 75ba0f05-3e92-4c37-a21a-0ee2f799caff                                                |
    | device_owner          | network:router_gateway                                                              |
    | extra_dhcp_opts       |                                                                                     |
    | fixed_ips             | {"subnet_id": "ca6b7767-f302-443d-a14d-2753f71d9112", "ip_address": "172.24.4.227"} |
    | id                    | 0fa52704-1d73-4400-b89a-e1cc9137cdf2                                                |
    | mac_address           | fa:16:3e:53:62:6a                                                                   |
    | name                  |                                                                                     |
    | network_id            | 2471ca6a-175e-4b60-b4c8-b83eeb188801                                                |
    | security_groups       |                                                                                     |
    | status                | DOWN                                                                                |
    | tenant_id             |                                                                                     |
    +-----------------------+-------------------------------------------------------------------------------------+
    [root@ip-192-169-142-147 ~(keystone_admin)]#