Ask Your Question

Cannot reach floating IP from outside network

asked 2017-03-08 01:20:45 -0500

updated 2017-03-08 16:55:51 -0500

Host OS

  • Distributor ID: Debian
  • Description: Debian GNU/Linux 8.6
  • (jessie) Release: 8.6
  • Codename: jessie

Openstack Environement

  • RDO All-In-One installed on VMware workstation VM + Centos7

-During installation, Openstack is configured to use the external interface (192.168.0.[1-155]/24) (connecting VM to host) as "public" network..
-Configured a subnet range for floating IPs (not assigned by external network:192.168.0.[170-199]/24).
-Created an instance, assigned a floating IP (


==> Can ping/ssh to instance from within Openstack, but not from outside.

I can observe the floatng IP ( assigned to router external interface

[root@RDO-AIO ~(keystone_admin)]# ip netns exec qrouter-a2dd3739-fe62-4e79-8795-e3023419dc30 ip a
1: lo: <LOOPBACK,UP,LOWER_UP> mtu 65536 qdisc noqueue state UNKNOWN qlen 1
    link/loopback 00:00:00:00:00:00 brd 00:00:00:00:00:00
    inet scope host lo
       valid_lft forever preferred_lft forever
    inet6 ::1/128 scope host 
       valid_lft forever preferred_lft forever
9: qg-913f6089-a8: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue state UNKNOWN qlen 1000
    link/ether fa:16:3e:31:a4:f9 brd ff:ff:ff:ff:ff:ff
    inet brd scope global qg-913f6089-a8
       valid_lft forever preferred_lft forever
    inet brd scope global qg-913f6089-a8    <<<<<<<<<<<<<<<<<<<<<<<<  
       valid_lft forever preferred_lft forever
    inet6 f816:3eff:fe31:a4f9/64 scope global mngtmpaddr dynamic 
       valid_lft 86318sec preferred_lft 86318sec
    inet6 fe80::f816:3eff:fe31:a4f9/64 scope link 
       valid_lft forever preferred_lft forever

routing and arp on openstack looks OK

[root@RDO-AIO ~(keystone_admin)]# cat /proc/sys/net/ipv4/ip_forward

[root@RDO-AIO ~(keystone_admin)]# route
Kernel IP routing table
Destination     Gateway         Genmask         Flags Metric Ref    Use Iface
default         gateway         UG    0      0        0 br-ex
link-local     U     1002   0        0 eno16777736
link-local     U     1006   0        0 br-ex   U     0      0        0 br-ex   <<<<<<<<<<<<<<
[root@RDO-AIO ~(keystone_admin)]# 
[root@RDO-AIO ~(keystone_admin)]# arp
Address                  HWtype  HWaddress           Flags Mask            Iface            ether   b4:b5:2f:b1:fa:ec   C                     br-ex              ether   a2:c6:c7:14:c5:49   C                     br-ex            ether   fa:16:3e:31:a4:f9   C                     br-ex            ether   fa:16:3e:31:a4:f9   C                     br-ex   <<<<<<<<<<<<<  
gateway                  ether   f4:ca:e5:4c:ed:44   C                     br-ex

From outside network is pointing (route) to floatng iP's, used by instances, via Openstack host:

/ # ip a via dev ovsbr0

From Openstack host, I can see the ping coming but Openstack not forwarding it to the router namespace:

[root@RDO-AIO ~(keystone_admin)]# tcpdump icmp
tcpdump: verbose output suppressed, use -v or -vv for full protocol decode
listening on br-ex, link-type EN10MB (Ethernet), capture size 65535 bytes
IP ...
edit retag flag offensive close merge delete


Do you have a static route configured in your physical router to point to the virtual network?

WigiPedia gravatar imageWigiPedia ( 2017-03-08 12:16:39 -0500 )edit

Yes, I forget to mention this:
# ip route via dev ovsbr0

The traffic arrives at the Openstack host (arrocrding to the route from outside) but Openstack doesn't forward it to the router namespace.

AJ NOURI gravatar imageAJ NOURI ( 2017-03-08 16:52:44 -0500 )edit

The router will have a different IP address from the OpenStack host. If you specified a provider network with several IPs in range, it will grab one of those at random. Try pinging those IPs and set the route to whichever one responds.

WigiPedia gravatar imageWigiPedia ( 2017-03-09 13:36:03 -0500 )edit

3 answers

Sort by ยป oldest newest most voted

answered 2017-03-08 05:42:56 -0500

dbaxps gravatar image

updated 2017-03-08 05:56:49 -0500

Using as comment :-
RDO All-In-One (CentOS 7.3 && RDO ) installed on KVM Guest @Libvirt Subnet on top of VIRTHOST : - Centos7.3 or F25

VIRTHOST should to be set up on standard Linux Bridge

Ignore "Nova-Docker" Hypervisor configuration same would for standard libvirt/kvm driver cloud VMs.

Creatie external network via flat external network provider on Controller matching CIDR of Office LAN . Next : - is IP of external physical router device( for instance )

Office LAN is supposed to match external network (configured via flat network provider ) for VM's deployed system . VIRTHOST (F25) is based on linux bridge br0 having original interface enp3s0 as source interface

[root@fedora23wks network-scripts]# cat ifcfg-br0

[root@fedora23wks network-scripts]# cat ifcfg-enp3s0

Then run script
#!/bin/bash -x
chkconfig network on
systemctl stop NetworkManager
systemctl disable NetworkManager
service network restart

In case you attempt to play libvirt/kvm tricks it's much more efficient to set up RH's OS's and Hypervisor Libvirt/KVM all way around
Cloud VMs are just L2 KVM/Libvirt Guests . Nested KVM is better to set enabled.
Thus it would always work for sure due to avoiding repackaging to Debian as well as VMWARE as Guest OS hosting CentOS 7 && RDO.

edit flag offensive delete link more


Thanks @dbaxps, I'll definitly find some time to deploy this on KVM. For now I need to find a solution to the issue in hand. At least I need to point out what doesn't work, is it a configuration issue or the RDO on Vmware deployment doesn't work by design? If so, shouldn't be some warning from RDO?

AJ NOURI gravatar imageAJ NOURI ( 2017-03-08 16:42:53 -0500 )edit

In KVM case Libvirt subnet matching external and having br0 as attached VNIC provides INGRESS/EGRESS traffic support. I was forced to create several systems where VENV RDO deployment should have physical network attached to VIRTHOST as External.

dbaxps gravatar imagedbaxps ( 2017-03-09 02:55:13 -0500 )edit

The problem here I believe is VMWARE Hypervisor running on Debian Jessy.
My question is : Would VM (L1) running as VMWARE VM be pingable from outside ?

dbaxps gravatar imagedbaxps ( 2017-03-09 03:01:13 -0500 )edit

ping + SSH
ajn@~$ lsb_release -a
Distributor ID: Debian
Description: Debian GNU/Linux 8.6 (jessie)
Codename: jessie

ajn@~$ ssh root@
root@'s password:
Last login: Wed Mar 8 16:35:06 2017 from

AJ NOURI gravatar imageAJ NOURI ( 2017-03-09 06:41:14 -0500 )edit

answered 2017-03-08 20:14:54 -0500

Shaik Saddam Hussain gravatar image


Can you check the firewall configuration of your CentOS7 VM - for testing try disabling firewall and selinux and try reboot of VM then try reaching to Floating IP from outside

edit flag offensive delete link more


Hi Shaik, yes before installig Openstack:

systemctl disable firewalld
systemctl stop firewalld
systemctl disable NetworkManager
systemctl stop NetworkManager
systemctl enable network
systemctl start network

AJ NOURI gravatar imageAJ NOURI ( 2017-03-08 22:12:24 -0500 )edit

answered 2017-03-09 03:14:03 -0500

sspwin gravatar image

please check if the security group settings for the VM are allowing ICMP. try allowing all tcp traffic.

edit flag offensive delete link more


Hi sspwin, both tcp 22 and icmp are allowed, instances can ping & ssh to each other:

# openstack security group rule list <1fd0...>
| 6e819...bdf5945b9d39 | tcp | | 22:22 | None |
| 75b33...ca1-020573a09efe | icmp |

AJ NOURI gravatar imageAJ NOURI ( 2017-03-09 06:37:48 -0500 )edit

Get to know Ask OpenStack

Resources for moderators

Question Tools



Asked: 2017-03-08 01:20:45 -0500

Seen: 2,030 times

Last updated: Mar 09 '17