any way to add a dhcpd ip to the firewall?

asked 2016-05-12 13:43:03 -0500

yee379 gravatar image

so i have my hypervisors and neutron node connected to a cisco nexus device and i'm using vlans. the cisco nexus does this thing where if i have a dhcp relay / ip helper configured, then local broadcast dhcp traffic will be blocked. this means that i have to add the dhcp server ip's from openstack as dhcp relay addresses on the cisco network interface.

this has the unfortunate side effect of the dhcp reply's coming back from the gateway address of the network rather than that of the dhcp service that was created by neutron. ie if i have the dhcp service port at 1.1.1.5, then the reply comes back from 1.1.1.1 (the vlan interface gateway address).

this then gets blocked by the local iptables firewall of the instance, ie:

Chain neutron-openvswi-i595970cb-6 (1 references)
num  target     prot opt source               destination
1    RETURN     all  --  0.0.0.0/0            0.0.0.0/0            state RELATED,ESTABLISHED /* Direct packets associated with a known session to the RETURN chain. */
2    RETURN     udp  --  1.1.1.5         0.0.0.0/0            udp spt:67 udp dpt:68
3    RETURN     all  --  0.0.0.0/0            0.0.0.0/0            match-set NIPv4558449c5-7876-4157-bf71- src
4    RETURN     tcp  --  0.0.0.0/0            0.0.0.0/0            tcp dpt:22
5    DROP       all  --  0.0.0.0/0            0.0.0.0/0            state INVALID /* Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack. */
6    neutron-openvswi-sg-fallback  all  --  0.0.0.0/0            0.0.0.0/0            /* Send unmatched traffic to the fallback chain. */

notice line number 2.

i can turn of dhcp relay completely on the cisco for that vlan and it does work as expected, however, i'm sharing that vlan with other non-openstack hosts currently (so those hosts need the dhcp relay).

so my question is whether there is a way add the 1.1.1.1 gateway address to the iptables.

cheers!

edit retag flag offensive close merge delete