Ask Your Question
0

Multiple private nets and routing

asked 2015-05-22 11:40:30 -0500

droopy4096 gravatar image

updated 2015-05-28 15:32:35 -0500

rbowen gravatar image

I am setting up replica of my real-world deployment in terms of networks within single instance of OpenStack. For that I have to create 3 networks (1 for each tier): web, middleware, db.

I have created those networks successfully then I've added the routers between respective networks, yet my web tier can't reach middleware and middleware can't reach DB using those private nets.

I have created a separate "public" network to which all those nets can be routed (so that I can access VMs directly). This one works just fine.

Most details provided in gist:

https://gist.github.com/droopy4096/00...

To simplify: this time around I've used dashboard to create network infrastructure. So procedure I've followed:

  • created each network (front, mid, db, public) with according subnet.
  • created routers "bridging" specific pairs of network, e.g.: gb_front_mid_router is connecting front tier (web) and mid tier (middleware).
  • for each tier created secgroup with corresponding rules
  • created VMs for each tier assigned to specific private network with specific secgroups applied
  • checked that default secgroup seems to be allowing everything in (see gist)

pinging from systest-front to systest-mid (on 10.10/16 IPs) fails so far. Same goes for pings from mid to db etc.

what am I missing? Why traffic from one private net can't reach another? Anything needs to be added to configuration?

edit retag flag offensive close merge delete

1 answer

Sort by ยป oldest newest most voted
0

answered 2015-06-19 03:04:56 -0500

ihar-hrachyshka gravatar image

Do you have your iptables for bridges enabled at all? See: https://review.openstack.org/#/c/180867/ that enables them automatically on all platforms (it is off by default on RHEL). You may want to do the same using sysctl configuration on your system.

Please share iptables -L so that we may check whether rules are set properly.

edit flag offensive delete link more

Your Answer

Please start posting anonymously - your entry will be published after you log in or create a new account.

Add Answer

Get to know Ask OpenStack

Resources for moderators

Question Tools

1 follower

Stats

Asked: 2015-05-22 11:10:44 -0500

Seen: 247 times

Last updated: Jun 19 '15