Cannot login, ping, or ssh to cirros test image

asked 2013-12-19 19:14:02 -0600

auroraskyes gravatar image

updated 2013-12-19 19:14:53 -0600

I used devstack to build a single node openstack server with neutron enabled. I am able to launch an instance and assign a foating IP, but I can't ping the image, ssh in, or use the dashboard console to login. What steps do I need to take next?

edit retag flag offensive close merge delete

3 answers

Sort by ยป oldest newest most voted

answered 2013-12-19 21:38:03 -0600

larsks gravatar image

First, try logging in on the instance console (using your browser) and try to "ifdown" then "ifup" interace eth0. In some situations, there appears to be a delay in setting up networking appropriately and the DHCP client gives up before obtaining an ip address.

If the instance is able to successfully obtain a fixed ip address, try pinging its fixed address from inside the appropriate router or dhcp namespace. Run:

# ip netns

Which will return something like:


These are network namespaces associated with the DHCP agent for your private subnet and the router associated with your public network. Assuming that your instance has a fixed ip of, try something like:

# ip netns exec qdhcp-a2be4bdd-a44a-4e64-ab16-a3297e479a31 ping

If this does not work, make sure your instance is associated with the necessary security groups to permit inbound ICMP or ssh traffic. If this does work, let me know and we'll work from there.

edit flag offensive delete link more


I have attempted to login with the console, but a can't find the correct credentials to login. I have tried the following and it won't give me access: U: cirros P: cubswin:) U: admin P: master (This was what I setup for the keypair when launching the instance) What login information do I need to login?

auroraskyes gravatar imageauroraskyes ( 2013-12-20 15:35:55 -0600 )edit

@auroraskyes cirros/cubswin:) would be the correct username/password of cirrus vm. For ubuntu/fedora vm, they only support ssh by pem file, instead of username and password. To boot a new vm, we can particularly configure the root password in horizon. This is so-called admin password injection feature.

DennyZhang gravatar imageDennyZhang ( 2013-12-22 00:18:55 -0600 )edit

In My case the last command didn't work. ping says Destination Host Unreachable I was checking CirrrOS log. and It has not got an IP through dhcp. service neutron-dhcp-agent status says active.

neel-basu-z gravatar imageneel-basu-z ( 2014-11-19 05:30:11 -0600 )edit

+1 for security groups. Mirantis' HA installation has a security group "default", which has "Ingress" of default, when it should be CIDR

tudor gravatar imagetudor ( 2015-01-18 17:49:30 -0600 )edit

@larsks : I know this thread is pretty old now, but can you expand the answer to include what to do if it _does_ work? I'm in that situation currently (but having used packstack) and your command was the first to move me forward after hours of reading through junk threads here.

7yl4r gravatar image7yl4r ( 2017-04-06 16:27:02 -0600 )edit

answered 2014-09-16 00:52:45 -0600

Neal gravatar image
I can ping floating ip but I cannot ping fixed ip,
[root@rdo ~]# ip netns exec qrouter-8d75ad85-efca-4d59-ba84-ce291951dfd7 ping
PING ( 56(84) bytes of data.
64 bytes from icmp_seq=1 ttl=64 time=0.912 ms
64 bytes from icmp_seq=2 ttl=64 time=0.507 ms
64 bytes from icmp_seq=3 ttl=64 time=0.419 ms
64 bytes from icmp_seq=4 ttl=64 time=0.485 ms
--- ping statistics ---
4 packets transmitted, 4 received, 0% packet loss, time 3652ms
rtt min/avg/max/mdev = 0.419/0.580/0.912/0.196 ms

but I cannot ping like this 
[root@sjc01rdo ~]# ping
PING ( 56(84) bytes of data.
From icmp_seq=1 Destination Host Unreachable
edit flag offensive delete link more


can you make this as comment not answer.

SGPJ gravatar imageSGPJ ( 2014-09-16 02:40:44 -0600 )edit

answered 2014-11-19 05:10:21 -0600

Venkata Seshadri gravatar image


I'm able to ping instance from network namespace but not directly from controller or any other nodes. i have three node architecture. Can any1 help?

edit flag offensive delete link more


I solved this to do this route add -net netmask dev br-ex route add -net gw netmask dev br-ex add two rule for route.then if not please check your routes's default route ip netns exec qrouter-2a2b2640-6f9a-42f8-b269-ab8bb5cd

Neal gravatar imageNeal ( 2014-11-20 00:20:12 -0600 )edit

ip netns exec qrouter-2a2b2640-6f9a-42f8-b269-ab8bb5cd9fa3 route

Neal gravatar imageNeal ( 2014-11-20 00:22:22 -0600 )edit

Get to know Ask OpenStack

Resources for moderators

Question Tools

1 follower


Asked: 2013-12-19 19:14:02 -0600

Seen: 10,655 times

Last updated: Nov 19 '14