Ask Your Question
1

devstack: [Neutron] instances unreachables

asked 2014-08-07 07:24:48 -0500

Jorge Tudela gravatar image

Hi all,

I have succesfully deployed an AIO Devstack (Icehouse) with Neutron and OVS on a Ubuntu 14.04. Main problem I have is network configuration. Althought I have read tones ofarticles, questions, Im still stuck on it...

https://ask.openstack.org/en/question/11172/devstack-networking-for-standalone-virtualbox-vm-cant-ping-tofrom-instances/ (https://ask.openstack.org/en/question...) https://ask.openstack.org/en/question/11446/devstack-instance-not-reachable-on-virtualhost-with-nat/ (https://ask.openstack.org/en/question...) https://ask.openstack.org/en/question/35100/cannot-access-instance-with-assigned-floating-ip/ (https://ask.openstack.org/en/question...) http://openstack.redhat.com/Networking

The host public network is 10.7.6.0/24. I have to NICs in my machine.

My local conf is:

[[local|localrc]]
APACHE_ENABLED_SERVICES+=keystone
LOGFILE=$DEST/logs/stack.sh.log
disable_service n-net
enable_service q-svc
enable_service q-agt
enable_service q-dhcp
enable_service q-l3
enable_service q-meta
enable_service neutron
HOST_IP=10.7.6.41
FLOATING_RANGE=10.7.6.0/24
Q_FLOATING_ALLOCATION_POOL=start=10.7.6.224,end=10.7.6.254
FIXED_RANGE=10.0.0.0/24
FIXED_NETWORK_SIZE=256
FLAT_INTERFACE=eth0
ADMIN_PASSWORD=password
MYSQL_PASSWORD=$ADMIN_PASSWORD
RABBIT_PASSWORD=$ADMIN_PASSWORD
SERVICE_PASSWORD=$ADMIN_PASSWORD
SERVICE_TOKEN=tokentoken

This is my host network config:

1: lo: <LOOPBACK,UP,LOWER_UP> mtu 65536 qdisc noqueue state UNKNOWN group default
    link/loopback 00:00:00:00:00:00 brd 00:00:00:00:00:00
    inet 127.0.0.1/8 scope host lo
       valid_lft forever preferred_lft forever
    inet6 ::1/128 scope host
       valid_lft forever preferred_lft forever
2: eth0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc pfifo_fast state UP group default qlen 1000
    link/ether 00:50:56:a4:00:54 brd ff:ff:ff:ff:ff:ff
    inet 10.7.6.41/24 brd 10.7.6.255 scope global eth0
       valid_lft forever preferred_lft forever
    inet6 fe80::250:56ff:fea4:54/64 scope link
       valid_lft forever preferred_lft forever
3: eth1: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc pfifo_fast master ovs-system state UP group default qlen 1000
    link/ether 00:50:56:a4:00:5c brd ff:ff:ff:ff:ff:ff
4: virbr0: <NO-CARRIER,BROADCAST,MULTICAST,UP> mtu 1500 qdisc noqueue state DOWN group default
    link/ether 62:6c:ac:f4:18:1d brd ff:ff:ff:ff:ff:ff
    inet 192.168.122.1/24 brd 192.168.122.255 scope global virbr0
       valid_lft forever preferred_lft forever
5: ovs-system: <BROADCAST,MULTICAST> mtu 1500 qdisc noop state DOWN group default
    link/ether 42:a9:87:5c:bd:35 brd ff:ff:ff:ff:ff:ff
6: br-int: <BROADCAST,UP,LOWER_UP> mtu 1500 qdisc noqueue state UNKNOWN group default
    link/ether de:aa:ec:da:ab:4d brd ff:ff:ff:ff:ff:ff
    inet6 fe80::fca1:d3ff:fe49:64d8/64 scope link
       valid_lft forever preferred_lft forever
7: br-ex: <BROADCAST,UP,LOWER_UP> mtu 1500 qdisc noqueue state UNKNOWN group default
    link/ether 00:50:56:a4:00:5c brd ff:ff:ff:ff:ff:ff
    inet 10.7.6.42/24 scope global br-ex
       valid_lft forever preferred_lft forever

I have manually configured br-ex to be attached to eth1, my non IPed NIC.

sudo ip addr flush eth1
sudo ovs-vsctl ...
(more)
edit retag flag offensive close merge delete

1 answer

Sort by ยป oldest newest most voted
0

answered 2014-08-10 23:43:21 -0500

Guillaume gravatar image

Hi,

I faced this problem when trying to get Icehouse working on VirtualBox. I could ping the public host interface (192.168.50.50) from my instance (10.0.0.4) but i was unable to ping my physical router (192.168.50.1) from my instance or my internal router (interfaces on 10.0.0.0/24 and 192.168.50.0/24).

I solve my problem by enabling promiscuity mode in my VirtualBox network interface settings.

edit flag offensive delete link more

Comments

Hi Guillaume, thanks for your answer.

I can now ping floatings IPs from inside the router...but I cannot ping/ssh instances yet.

Althought is curious that when I ping an instance floating IP from another server of my network, I dont get any response, but arp table entry is registered ok!

It seems maybe that, among other things, the security rules that I added arent working...

nova secgroup-add-rule default icmp -1 -1 0.0.0.0/0
nova secgroup-add-rule default tcp 22 22 0.0.0.0/0

Im still trying..

Jorge Tudela gravatar imageJorge Tudela ( 2014-08-12 06:09:59 -0500 )edit

I cannot reach the outside world from the router, I can not ping any server of my public network from inside the router.. I think this is the key. Maybe Im missing sth regarding router routes..

stack@ubuntu-devstack2:~/devstack$ sudo ip netns exec qrouter-921d5cf3-1f97-4304-baf4-d6de64568fc5 route -n
Kernel IP routing table
Destination     Gateway         Genmask         Flags Metric Ref    Use Iface
10.0.0.0        0.0.0.0         255.255.255.0   U     0      0        0 qr-acb3a09c-45
10.7.6.0        0.0.0.0         255.255.255.0   U     0      0        0 qg-f4762f69-68
Jorge Tudela gravatar imageJorge Tudela ( 2014-08-13 07:33:46 -0500 )edit

Your Answer

Please start posting anonymously - your entry will be published after you log in or create a new account.

Add Answer

Get to know Ask OpenStack

Resources for moderators

Question Tools

2 followers

Stats

Asked: 2014-08-07 07:21:50 -0500

Seen: 879 times

Last updated: Aug 10 '14