VMSs traffic

asked 2017-06-25 05:22:11 -0500

amirdhaoui gravatar image

updated 2017-06-26 07:07:18 -0500

I installed Openstack Newton. I wan to access (SSH) to instances

In addition of compute and controller nodes, I added a gateway node to forward traffic from internet to VMs. Nodes addresses

Controller Compute Gateway

I added iptables roules in the gateway eg. to access to dashboard I added this rule iptables -t nat -A PREROUTING -i ${EXT_NIC} -p tcp --dport 443 -j DNAT --to $

and it's working.

My purpose now is to forward traffic to VMs My ext net is floating IP range

Instance IP

When I ping the instance from the controller it works When I try to ping it from the gateway, it fails.

This made me confused It is obligatory that all VMs traffic pass through the controller ?

If no, how I can fix this ?

Thank you ^^

edit retag flag offensive close merge delete


There are many ways to set up Neutron and to connect instances. It's quite different if instances are connected to a self-service network or a provider network. In the former case, it depends whether the router is distributed or not.

Provide more details about the configuration.

Bernd Bausch gravatar imageBernd Bausch ( 2017-06-26 06:36:20 -0500 )edit

If you use ML2 with mechanism driver Openvswitch, find connectivity and traffic flow information at https://docs.openstack.org/ocata/netw.... In case of Linuxbridge, https://docs.openstack.org/ocata/netw.... Ocata and Newton should be the same.

Bernd Bausch gravatar imageBernd Bausch ( 2017-06-26 06:41:43 -0500 )edit

I am using networking option 2. connects the controller, the compute and the gateway nodes, this network is connected to internet. I extended this physical network to be used as ext-net for instances, my ext-net is The floating IP range also in the same net

amirdhaoui gravatar imageamirdhaoui ( 2017-06-26 07:14:26 -0500 )edit

What is network option 2?

Bernd Bausch gravatar imageBernd Bausch ( 2017-06-26 08:58:52 -0500 )edit

Networking Option 2: Self-service networks

amirdhaoui gravatar imageamirdhaoui ( 2017-06-26 09:26:06 -0500 )edit