Ask Your Question
0

can fwaas work if installed with already created routers? [closed]

asked 2017-04-19 10:49:38 -0500

juangallego gravatar image

updated 2017-04-19 10:50:59 -0500

I am working with OCATA. I installed a basic openstack with two nodes, controller and compute. I setup a SDN with two external networks and one internal network, a router and 3 centos 7 virtual machines with associated ips. Everything worked fine with no problems. Next I wanted to install fwaas plugin. I followed the guide which is at fwaas-v2-scenario.html in the official documentation But when I reached the "Configure Firewall-as-a-Service v2¶" section and executed the firse step

neutron firewall-rule-create

I received a "resource not found" error. Looking at the log file l3-agent.log I saw this error:

l3-agent.log:2017-04-19 09:14:18.550 63785 DEBUG neutron_fwaas.services.firewall.agents.l3reference.firewall_l3_agent [-] Process router add, router_id: 'eff3e6db-2043-4495-b42a-21bd205d22cb' _process_router_add /usr/lib/python2.7/site-packages/neutron_fwaas/services/firewall/agents/l3reference/firewall_l3_agent.py:186

l3-agent.log:2017-04-19 09:14:18.584 63785 DEBUG neutron_fwaas.services.firewall.agents.l3reference.firewall_l3_agent [req-0c64f69d-e828-47af-83b8-45beedcee158 - - - - -] Retrieve Firewall with rules from Plugin get_firewalls_for_tenant /usr/lib/python2.7/site-packages/neutron_fwaas/services/firewall/agents/l3reference/firewall_l3_agent.py:44

l3-agent.log:2017-04-19 09:14:18.595 63785 DEBUG neutron_fwaas.services.firewall.agents.l3reference.firewall_l3_agent [req-f7ae5870-e368-4396-b300-5ad2f7e821d7 - - - - -] Retrieve Firewall with rules from Plugin get_firewalls_for_tenant /usr/lib/python2.7/site-packages/neutron_fwaas/services/firewall/agents/l3reference/firewall_l3_agent.py:44

l3-agent.log:2017-04-19 09:14:18.609 63785 DEBUG neutron_fwaas.services.firewall.agents.l3reference.firewall_l3_agent [-] Process router add, router_id: '8c503eae-4790-4280-8ec3-d80a9d940c0e' _process_router_add /usr/lib/python2.7/site-packages/neutron_fwaas/services/firewall/agents/l3reference/firewall_l3_agent.py:186

l3-agent.log:2017-04-19 09:14:18.615 63785 ERROR neutron_fwaas.services.firewall.agents.l3reference.firewall_l3_agent [req-0c64f69d-e828-47af-83b8-45beedcee158 - - - - -] FWaaS RPC info call failed for '88874974-ba4b-4bb8-af95-6414860e1043'.

l3-agent.log:2017-04-19 09:14:18.615 63785 ERROR neutron_fwaas.services.firewall.agents.l3reference.firewall_l3_agent Traceback (most recent call last):

l3-agent.log:2017-04-19 09:14:18.615 63785 ERROR neutron_fwaas.services.firewall.agents.l3reference.firewall_l3_agent   File "/usr/lib/python2.7/site-packages/neutron_fwaas/services/firewall/agents/l3reference/firewall_l3_agent.py", line 220, in add_router

l3-agent.log:2017-04-19 09:14:18.615 63785 ERROR neutron_fwaas.services.firewall.agents.l3reference.firewall_l3_agent     self._process_router_add(new_router)

l3-agent.log:2017-04-19 09:14:18.615 63785 ERROR neutron_fwaas.services.firewall.agents.l3reference.firewall_l3_agent   File "/usr/lib/python2.7/site-packages/neutron_fwaas/services/firewall/agents/l3reference/firewall_l3_agent.py", line 195, in _process_router_add

l3-agent.log:2017-04-19 09:14:18.615 63785 ERROR neutron_fwaas.services.firewall.agents.l3reference.firewall_l3_agent     fw_list = self.fwplugin_rpc.get_firewalls_for_tenant(ctx)

l3-agent.log:2017-04-19 09:14:18.615 63785 ERROR neutron_fwaas.services.firewall.agents.l3reference.firewall_l3_agent   File "/usr/lib/python2.7/site-packages/neutron_fwaas/services/firewall/agents/l3reference/firewall_l3_agent.py", line 46, in get_firewalls_for_tenant

l3-agent.log:2017-04-19 09:14:18.615 63785 ERROR neutron_fwaas.services.firewall.agents.l3reference.firewall_l3_agent     return cctxt.call(context, 'get_firewalls_for_tenant', host=self.host)

l3-agent.log:2017-04-19 09:14:18.615 63785 ERROR neutron_fwaas.services.firewall.agents.l3reference.firewall_l3_agent   File "/usr/lib/python2.7/site-packages/neutron/common/rpc.py", line 127, in call

l3-agent.log:2017-04-19 09:14:18.615 63785 ERROR neutron_fwaas.services.firewall.agents.l3reference.firewall_l3_agent     return self._original_context.call(ctxt, method, **kwargs)

l3-agent.log:2017-04-19 09:14:18.615 63785 ERROR neutron_fwaas ...
(more)
edit retag flag offensive reopen merge delete

Closed for the following reason the question is answered, right answer was accepted by juangallego
close date 2017-04-19 12:23:26.140217

1 answer

Sort by » oldest newest most voted
0

answered 2017-04-19 12:22:54 -0500

juangallego gravatar image

This was a configuration issue. The cited guide in the description is wrong on whats has to be done in order to configure FWAAS. The correct guide is the one at redhat

Products & Services=>Product Documentation=>Red Hat OpenStack Platform=>10 Networking Guide=> Chapter 17. Configure Firewall-as-a-Service (FWaaS)

edit flag offensive delete link more

Get to know Ask OpenStack

Resources for moderators

Question Tools

1 follower

Stats

Asked: 2017-04-19 10:49:38 -0500

Seen: 44 times

Last updated: Apr 19