Ask Your Question

Make Openstack instance a router

asked 2014-01-03 09:52:12 -0600

mythus gravatar image

updated 2014-01-03 11:53:50 -0600

larsks gravatar image


I am using Havana release and I need to make a Instance behave like a openvpn server and router, something like cloudpipe but L3. I have following setup external net --- instance(router) --- internal net --- other hosts

The internal network is gre based L2 network in my tenant. The router instance have one interface in the external network and on in the internal. The issue I face is that neutron security groups , have the following rules per port - this is to the internal network:

Chain neutron-openvswi-sbb49f61d-5 (1 references)
 pkts bytes target     prot opt in     out     source               destination         
    6   504 RETURN     all  --  *      *               MAC FA:16:3E:EA:20:7F
1368K  124M DROP       all  --  *      *  

This is nice for security, but packets source is not my interface ip when instance forward packets. Do you know better way to work around this limitation than manualy editing the iptables rules ?

Best regards,

edit retag flag offensive close merge delete

1 answer

Sort by ยป oldest newest most voted

answered 2015-01-15 17:18:56 -0600

Pmcg gravatar image (

This will allow you to specify CIDRs allowed to leave the port. It would appear you can omit the mac as well.

edit flag offensive delete link more

Your Answer

Please start posting anonymously - your entry will be published after you log in or create a new account.

Add Answer

[hide preview]

Get to know Ask OpenStack

Resources for moderators

Question Tools

1 follower


Asked: 2014-01-03 09:52:12 -0600

Seen: 357 times

Last updated: Jan 03 '14