asked 2014-05-15 20:30:17 -0500

Why do not need set promiscuous mode of data nic in OpenStack vlan? If this, will the nic not filter the data packages that haven't the same mac as physical nic?

2 answers

answered 2014-05-15 21:51:51 -0500

Where did you see this? I think I got something similar and no, nothing has to be done to the NIC. Can you give us more info?

Thanks from the reply. My question is why do not need? In no-promiscuous mode, the nic will filter the data package that have not the same mac as physical nic, and so I think the vm have different mac would not receive the data package through the physical nic.

I would guess that real NIC is already assembled in way allowing promiscuous mode. I actually have the same question.

answered 2015-06-24 08:38:28 -0500

I'am searching for this term too and I found the text as a note here:

http://docs.openstack.org/icehouse/install-guide/install/yum/content/neutron_initial-networks-verify.html (http://docs.openstack.org/icehouse/in...)

Note If you are building your OpenStack nodes as virtual machines, you must configure the hypervisor to permit promiscuous mode on the external network.

Why do I need this ? I would like not to set the "promiscuous mode" because of security reasons.

Maybe someone can help me ?


