Wednesday, 2019-06-19

*** yamamoto_ has joined #openstack-fwaas05:24
*** yamamoto has quit IRC05:27
*** irclogbot_3 has quit IRC05:30
*** irclogbot_3 has joined #openstack-fwaas05:31
*** threestrands has joined #openstack-fwaas06:27
openstackgerritSlawek Kaplonski proposed openstack/neutron-fwaas master: Switch legacy-neutron-fwaas-v2-dsvm-tempest job to python3  https://review.opendev.org/66616506:34
*** yamamoto_ has quit IRC07:54
*** trident has quit IRC07:57
*** threestrands has quit IRC07:59
*** trident has joined #openstack-fwaas08:01
*** yamamoto has joined #openstack-fwaas08:18
*** yamamoto has quit IRC08:29
*** yamamoto has joined #openstack-fwaas08:32
*** yamamoto has quit IRC08:32
CeeMachi fwaas team, is anyone online?09:06
CeeMacamotoki: jhesketh: trident: are any of you free to help with a config issue?09:07
*** yamamoto has joined #openstack-fwaas09:48
*** yamamoto has quit IRC09:57
*** yamamoto has joined #openstack-fwaas10:29
*** njohnston has joined #openstack-fwaas11:12
*** yamamoto has quit IRC11:57
*** yamamoto has joined #openstack-fwaas12:41
CeeMacnjohnston: are you about?14:31
*** yamamoto has quit IRC15:15
openstackgerritSlawek Kaplonski proposed openstack/neutron-fwaas master: Switch legacy-neutron-fwaas-v2-dsvm-tempest job to python3  https://review.opendev.org/66616516:53
*** trident has quit IRC17:02
*** trident has joined #openstack-fwaas17:04
njohnstonCeeMac: Hi!  Sprry I missed you yesterday.  How can I help?17:36
CeeMacHi njohnston , no worries I'm sure your a busy man :) just wondering if you could take a quick look at my config issue http://paste.openstack.org/show/75314417:42
CeeMacnjohnston: I'm running rocky with neutron ovs implementation17:43
njohnstonCeeMac: sure, checking it out17:43
CeeMacThanks17:43
openstackgerritSlawek Kaplonski proposed openstack/neutron-fwaas master: Switch legacy-neutron-fwaas-v2-dsvm-tempest job to python3  https://review.opendev.org/66616517:44
CeeMacI just can't quite put the pieces together17:44
njohnstonCeeMac: I'll fire a series of questions at you.17:45
CeeMacI've had to remove it from the env as were due to go into production but I'll be reworking my dev env soon to ovs and it would be great to understand which configs I need to change17:45
CeeMacSure17:46
njohnstonDo you have "service_plugins = firewall_v2" in /etc/neutron/neutron.conf?17:46
CeeMacYes17:46
njohnstonok, that was not in your paste, only the "service_provider" line was17:47
njohnstondo you have a "[fwaas]" section in /etc/neutron/neutron.conf?17:47
CeeMacSorry, I missed that bit. [fwaas] is in l3_agent.ini in my deployment (using openstack-ansible to deploy)17:53
CeeMacLooked at changing it but wasn't sure if it would need to be in neutron.conf just on neutron-server or in all network and conpute nodes too17:54
CeeMacIt does work in that all the services are running and the dashboard is present, I just get the error in the paste if I try and attach a port17:55
CeeMacnjohnston: I tried changing the settings as per the scenario for rocky with the hybrid provider but neutron-server looped errors with no service provider loaded.18:22
njohnstonCeeMac: What I am noticing as I read the scenario doc is that mismatched configs are specified: OVS firewall in "service_provider = FIREWALL:Iptables:neutron.agent.linux.iptables_firewall.OVSHybridIptablesFirewallDriver:default"18:36
njohnstonbut iptables firewall in "driver = neutron_fwaas.services.firewall.drivers.linux.iptables_fwaas_v2.IptablesFwaasDriver"18:36
njohnstonIIRC you would prefer OVS FW for all, correct CeeMac?18:36
CeeMacnjohnston: correct, does it nee to match up with the security group driver too?18:37
CeeMacI also got confused with the L2 firewall driver elements when digging in to the module specs18:37
CeeMacs/nee/need18:38
openstackgerritSlawek Kaplonski proposed openstack/neutron-fwaas master: Switch legacy-neutron-fwaas-v2-dsvm-tempest job to python3  https://review.opendev.org/66616518:41
njohnstonit all needs to match, you cannot do L3 security with one and L2 with the other18:41
CeeMacsecurity group is openvswitch currently18:42
njohnstonso service_provider should = FIREWALL_V2:fwaas_db:neutron_fwaas.services.firewall.service_drivers.agents.drivers.linux.l2.openvswitch_firewall.firewall:default18:43
njohnstonand in the [fwaas] section "driver" should = neutron_fwaas.services.firewall.service_drivers.agents.drivers.linux.l2.openvswitch_firewall.firewall:OVSFirewallDriver18:44
njohnstonsorry service_provider should = FIREWALL_V2:fwaas_db:neutron_fwaas.services.firewall.service_drivers.agents.drivers.linux.l2.openvswitch_firewall.firewall:OVSFirewallDriver:default18:44
njohnston(missed part of it in the copy and paste there)18:44
njohnstonno thats not right either18:46
CeeMacnjohnston: actually, it looks like the security group firewall_driver = iptables_hybrid18:48
CeeMacPresumably that should be openvswitch?18:50
njohnstonCeeMac: https://docs.openstack.org/releasenotes/neutron-fwaas/queens.html#known-issues18:51
njohnstonCeeMac: That link addresses that question as well as others I think you had about interoperability with SG18:52
CeeMacYeah I saw that earlier and I couldn't quite make sense of it. Think my brain was in knots. Incidentally I tried ovs as firewall driver and neutron-server borked18:53
CeeMacnjohnston: if you wouldn't mind could you do me a quick paste with the correct config in so I can keep a record for when I get back in the office tomorrow?18:54
CeeMacnjohnston: alternatively, is there a fallback option of iptables for both SG and FWaaS?18:56
njohnstonI need to see if I can come up with a working example, can I email you CeeMac?19:47
CeeMacSure, I'll dm you my address, if you could manage an example for both iptables and ovs options that would be amazing, then I can propose a patch to OSA with the working settings20:06
openstackgerritSlawek Kaplonski proposed openstack/neutron-fwaas master: Switch legacy-neutron-fwaas-v2-dsvm-tempest job to python3  https://review.opendev.org/66616521:14
*** yamamoto has joined #openstack-fwaas21:51
*** yamamoto has quit IRC21:56
*** yamamoto has joined #openstack-fwaas23:53

Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!