Octavia Pike DVR HA floating ip problem

asked 2018-03-02 09:16:51 -0500

Octavia Pike DVR HA floating ip problem, latest build.

This bug looks fixed, not bound floating ip is being created in SNAT namespace: ( (

VIP works well in vxlan networks, however VIP cannot be reached via floating IP. it is a DVR HA setup.

SNAT namespace:


-A neutron-l3-agent-OUTPUT -d -j DNAT --to-destination -A neutron-l3-agent-POSTROUTING ! -i qg-35d599d9-40 ! -o qg-35d599d9-40 -m conntrack ! --ctstate DNAT -j ACCEPT -A neutron-l3-agent-PREROUTING -d -j DNAT --to-destination -A neutron-l3-agent-float-snat -s -j SNAT --to-source -A neutron-l3-agent-snat -j neutron-l3-agent-float-snat -A neutron-l3-agent-snat -o qg-35d599d9-40 -m connmark --mark 0x4010000/0xffff0000 -j ACCEPT -A neutron-l3-agent-snat -o qg-35d599d9-40 -j SNAT --to-source -A neutron-l3-agent-snat -m mark ! --mark 0x2/0xffff -m conntrack --ctstate DNAT -j SNAT --to-source


packets are going to snat namespace: > ICMP echo request, id 56271, seq 904, length 64

however apparently those are not being routed to the VIP, but VIP is reachable directly from SNAT namespace

telnet 443 Trying Connected to Escape character is '^]'.

netstat -nr Kernel IP routing table Destination Gateway Genmask Flags MSS Window irtt Iface UG 0 0 0 qg-35d599d9-40 U 0 0 0 qg-35d599d9-40 U 0 0 0 ha-6585c53d-42 U 0 0 0 ha-6585c53d-42 U 0 0 0 sg-610ad56a-70


probably this is related to address scopes in DVR HA setup. I have raised a neutron bug for it: (

answered 2018-03-13 10:20:52 -0500

Thanks for tracking that down and opening a neutron bug for it! Others are likely to run into that as well. johnsom

