Ask Your Question
0

Trouble shooting for two VM ping issue.

asked 2016-07-15 04:25:27 -0500

kramer gravatar image

This is a question about openvswitch. To make my question clear, I need to describe my network topology briefly.

I have two compute node. Each node is having one VM. They are in the same subnet and same VLAN(VLAN ID 150).
The network topology is like :

VM_A <--> br-int <--> br-vlan(compute1) <--> br-vlan(compute2) <--> br-int <--> VM_B

VM_A ping VM_B failed. So I try to do some trouble shooting. Below are the information:

  1. I can catch the ARP package on br-vlan of compute2

  2. Here is the dump-flow of br-vlan

    # ovs-ofctl dump-flows br-vlan
    
    NXST_FLOW reply (xid=0x4):
      table=0, n_packets=0, priority=4,in_port=2,dl_vlan=2 actions=mod_vlan_vid:150,NORMAL
      table=0, n_packets=0, priority=2,in_port=2 actions=drop
      table=0, n_packets=56485, priority=0 actions=NORMAL
    
      # The port 2 is the port connecting br-int and br-vlan
    
  3. Here is the dump-flow of br-int

    # ovs-ofctl dump-flows br-int --sort=in_port
      table=0, n_packets=0, priority=3,in_port=1,dl_vlan=150 actions=mod_vlan_vid:2,NORMAL
      table=0, n_packets=13239, priority=2,in_port=1 actions=drop
      table=0, n_packets=0, priority=10,icmp6,in_port=3,icmp_type=136 actions=resubmit(,24)
      table=0, n_packets=0, priority=10,arp,in_port=3 actions=resubmit(,24)
      table=0, n_packets=0, priority=9,in_port=3 actions=resubmit(,25)
      table=24, n_packets=0, priority=2,icmp6,in_port=3,icmp_type=136,nd_target=fe80::f816:3eff:fe90:628a actions=NORMAL
      table=24, n_packets=0, priority=2,arp,in_port=3,arp_spa=10.0.100.6 actions=resubmit(,25)
      table=25, n_packets=0, priority=2,in_port=3,dl_src=fa:16:3e:90:62:8a actions=NORMAL
      table=0, n_packets=13247, priority=2,in_port=4 actions=drop
      table=0, n_packets=1333, priority=0 actions=NORMAL
      table=23, n_packets=0, priority=0 actions=drop
      table=24, n_packets=0, priority=0 actions=drop
    
      # The port 1 is the one connecting br-int and br-vlan
      # The port  3 is the one connecting VM_B and br-int
    
  4. Port 3 on br-int is a tap device connect to VM. I did tcpdump on this device but there is no package been capture.

  5. I try to catch packages on br-vlan. I found that the ARP request from VM_A is not having a vlan tag.

So my question is

A: Why VM_A can not ping VM_B. If you can find out the reason please tell me..

edit retag flag offensive close merge delete

2 answers

Sort by ยป oldest newest most voted
0

answered 2016-07-18 01:52:19 -0500

Check Firewall security groups whether ICMP is enabled or not, if enabled please paste output of

ifconfig ovs-vsctl show ip route netstat -nr nuetron stuff

edit flag offensive delete link more
0

answered 2016-07-16 11:30:42 -0500

Mohit gravatar image

Can you check the following flag in nova.conf:

allow_same_net_traffic=False

Toggle this to True might help

edit flag offensive delete link more

Your Answer

Please start posting anonymously - your entry will be published after you log in or create a new account.

Add Answer

Get to know Ask OpenStack

Resources for moderators

Question Tools

1 follower

Stats

Asked: 2016-07-15 04:25:27 -0500

Seen: 274 times

Last updated: Jul 18 '16