<div dir="ltr"><br><div class="gmail_quote">---------- Forwarded message ----------<br>From: <b class="gmail_sendername">ICHIBA Sara</b> <span dir="ltr"><<a href="mailto:ichi.sara@gmail.com">ichi.sara@gmail.com</a>></span><br>Date: 2015-05-19 15:53 GMT+02:00<br>Subject: Re: [Rdo-list] Fwd: [Neutron] router can't ping external gateway<br>To: Marius Cornea <<a href="mailto:mcornea@redhat.com">mcornea@redhat.com</a>><br><br><br><div dir="ltr">no i don't. <br>[root@localhost ~(keystone_admin)]# ifconfig eth0 | grep -i up<br>eth0: flags=4163<UP,BROADCAST,RUNNING,MULTICAST> mtu 1500<br><br><br></div><div class="HOEnZb"><div class="h5"><div class="gmail_extra"><br><div class="gmail_quote">2015-05-19 15:41 GMT+02:00 Marius Cornea <span dir="ltr"><<a href="mailto:mcornea@redhat.com" target="_blank">mcornea@redhat.com</a>></span>:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">Hm, do you have promiscuous mode turned on for the port eth0 is connected to ?<br>
<span><br>
----- Original Message -----<br>
> From: "ICHIBA Sara" <<a href="mailto:ichi.sara@gmail.com" target="_blank">ichi.sara@gmail.com</a>><br>
</span><div><div>> To: "Marius Cornea" <<a href="mailto:mcornea@redhat.com" target="_blank">mcornea@redhat.com</a>>, <a href="mailto:rdo-list@redhat.com" target="_blank">rdo-list@redhat.com</a><br>
> Sent: Tuesday, May 19, 2015 2:42:28 PM<br>
> Subject: Re: [Rdo-list] Fwd: [Neutron] router can't ping external gateway<br>
><br>
> [root@localhost ~]# ip netns exec<br>
> qrouter-85fa9459-503d-4996-86f3-6042604fed74 ip -s -s neigh flush<br>
> 192.168.5.1<br>
> Nothing to flush.<br>
><br>
><br>
> [root@pc20 ~]# tcpdump -i eth0 arp<br>
> tcpdump: verbose output suppressed, use -v or -vv for full protocol decode<br>
> listening on eth0, link-type EN10MB (Ethernet), capture size 65535 bytes<br>
> 14:39:31.292222 ARP, Request who-has PC22.home (Broadcast) tell<br>
> livebox.home, length 46<br>
> 14:39:31.293093 ARP, Request who-has livebox.home tell PC20.home, length 28<br>
> 14:39:31.293882 ARP, Reply livebox.home is-at 00:23:48:9e:85:7c (oui<br>
> Unknown), length 46<br>
> 14:39:32.300067 ARP, Request who-has PC22.home (Broadcast) tell<br>
> livebox.home, length 46<br>
> 14:39:33.310100 ARP, Request who-has PC22.home (Broadcast) tell<br>
> livebox.home, length 46<br>
> 14:39:34.320335 ARP, Request who-has PC22.home (Broadcast) tell<br>
> livebox.home, length 46<br>
> 14:39:35.330123 ARP, Request who-has PC22.home (Broadcast) tell<br>
> livebox.home, length 46<br>
> 14:39:36.289836 ARP, Request who-has PC20.home tell livebox.home, length 46<br>
> 14:39:36.289873 ARP, Reply PC20.home is-at 00:0c:29:9d:02:44 (oui Unknown),<br>
> length 28<br>
> 14:39:36.340219 ARP, Request who-has PC22.home (Broadcast) tell<br>
> livebox.home, length 46<br>
> 14:39:51.026708 ARP, Request who-has PC20.home (00:0c:29:9d:02:44 (oui<br>
> Unknown)) tell 192.168.5.99, length 46<br>
> 14:39:51.026733 ARP, Reply PC20.home is-at 00:0c:29:9d:02:44 (oui Unknown),<br>
> length 28<br>
> 14:39:56.027218 ARP, Request who-has livebox.home tell PC20.home, length 28<br>
> 14:39:56.027848 ARP, Reply livebox.home is-at 00:23:48:9e:85:7c (oui<br>
> Unknown), length 46<br>
> 14:40:01.035292 ARP, Request who-has 192.168.5.99 tell PC20.home, length 28<br>
> 14:40:01.035925 ARP, Reply 192.168.5.99 is-at 74:46:a0:9e:ff:a5 (oui<br>
> Unknown), length 46<br>
> 14:40:01.454515 ARP, Request who-has PC22.home (Broadcast) tell<br>
> livebox.home, length 46<br>
> 14:40:02.460552 ARP, Request who-has PC22.home (Broadcast) tell<br>
> livebox.home, length 46<br>
> 14:40:03.470625 ARP, Request who-has PC22.home (Broadcast) tell<br>
> livebox.home, length 46<br>
> 14:40:04.480937 ARP, Request who-has PC22.home (Broadcast) tell<br>
> livebox.home, length 46<br>
> 14:40:05.490810 ARP, Request who-has PC22.home (Broadcast) tell<br>
> livebox.home, length 46<br>
> 14:40:06.500671 ARP, Request who-has PC22.home (Broadcast) tell<br>
> livebox.home, length 46<br>
> 14:40:21.527063 ARP, Request who-has PC20.home (00:0c:29:9d:02:44 (oui<br>
> Unknown)) tell 192.168.5.99, length 46<br>
> 14:40:21.527157 ARP, Reply PC20.home is-at 00:0c:29:9d:02:44 (oui Unknown),<br>
> length 28<br>
> 14:40:36.747216 ARP, Request who-has 192.168.5.99 tell PC20.home, length 28<br>
> 14:40:36.747765 ARP, Reply 192.168.5.99 is-at 74:46:a0:9e:ff:a5 (oui<br>
> Unknown), length 46<br>
> 14:40:51.527605 ARP, Request who-has PC20.home (00:0c:29:9d:02:44 (oui<br>
> Unknown)) tell 192.168.5.99, length 46<br>
> 14:40:51.527638 ARP, Reply PC20.home is-at 00:0c:29:9d:02:44 (oui Unknown),<br>
> length 28<br>
> 14:41:01.729345 ARP, Request who-has PC20.home (Broadcast) tell<br>
> livebox.home, length 46<br>
> 14:41:01.729408 ARP, Reply PC20.home is-at 00:0c:29:9d:02:44 (oui Unknown),<br>
> length 28<br>
> 14:41:21.528760 ARP, Request who-has PC20.home (00:0c:29:9d:02:44 (oui<br>
> Unknown)) tell 192.168.5.99, length 46<br>
> 14:41:21.528792 ARP, Reply PC20.home is-at 00:0c:29:9d:02:44 (oui Unknown),<br>
> length 28<br>
> 14:41:26.540361 ARP, Request who-has 192.168.5.99 tell PC20.home, length 28<br>
> 14:41:26.540809 ARP, Reply 192.168.5.99 is-at 74:46:a0:9e:ff:a5 (oui<br>
> Unknown), length 46<br>
> 14:41:31.900298 ARP, Request who-has PC19.home (Broadcast) tell<br>
> livebox.home, length 46<br>
> 14:41:31.950399 ARP, Request who-has PC20.home (Broadcast) tell<br>
> livebox.home, length 46<br>
> 14:41:31.950410 ARP, Reply PC20.home is-at 00:0c:29:9d:02:44 (oui Unknown),<br>
> length 28<br>
> 14:41:51.529113 ARP, Request who-has PC20.home (00:0c:29:9d:02:44 (oui<br>
> Unknown)) tell 192.168.5.99, length 46<br>
> 14:41:51.529147 ARP, Reply PC20.home is-at 00:0c:29:9d:02:44 (oui Unknown),<br>
> length 28<br>
> 14:41:56.539268 ARP, Request who-has 192.168.5.99 tell PC20.home, length 28<br>
> 14:41:56.539912 ARP, Reply 192.168.5.99 is-at 74:46:a0:9e:ff:a5 (oui<br>
> Unknown), length 46<br>
> 14:42:02.102645 ARP, Request who-has PC19.home (Broadcast) tell<br>
> livebox.home, length 46<br>
><br>
><br>
><br>
><br>
> 2015-05-19 14:32 GMT+02:00 Marius Cornea <<a href="mailto:mcornea@redhat.com" target="_blank">mcornea@redhat.com</a>>:<br>
><br>
> > Delete and check if other computers in the network are receiving<br>
> > broadcasts:<br>
> ><br>
> > ip netns exec qrouter-85fa9459-503d-4996-86f3-6042604fed74 ip -s -s neigh<br>
> > flush 192.168.5.1<br>
> > tcpdump -i <if_name> arp #on one of the computers in the 192.168.5.0<br>
> > network<br>
> > ip netns exec qrouter-85fa9459-503d-4996-86f3-6042604fed74 ping 192.168.5.1<br>
> ><br>
> > See if any ARP requests reach the computer where you run tcpdump.<br>
> ><br>
> > I'm still thinking about some blocking stuff happening in the vswitch<br>
> > since the ICMP requests are sent to the eth0 interface so they should reach<br>
> > the vswitch port.<br>
> ><br>
> > ----- Original Message -----<br>
> > > From: "ICHIBA Sara" <<a href="mailto:ichi.sara@gmail.com" target="_blank">ichi.sara@gmail.com</a>><br>
> > > To: "Marius Cornea" <<a href="mailto:mcornea@redhat.com" target="_blank">mcornea@redhat.com</a>><br>
> > > Cc: <a href="mailto:rdo-list@redhat.com" target="_blank">rdo-list@redhat.com</a><br>
> > > Sent: Tuesday, May 19, 2015 2:15:06 PM<br>
> > > Subject: Re: [Rdo-list] Fwd: [Neutron] router can't ping external gateway<br>
> > ><br>
> > > [root@localhost ~(keystone_admin)]# ip netns exec<br>
> > > qrouter-85fa9459-503d-4996-86f3-6042604fed74 ip n | grep '192.168.5.1 '<br>
> > > 192.168.5.1 dev qg-e1b584b4-db lladdr 00:23:48:9e:85:7c STALE<br>
> > ><br>
> > ><br>
> > ><br>
> > ><br>
> > ><br>
> > > 2015-05-19 14:12 GMT+02:00 Marius Cornea <<a href="mailto:mcornea@redhat.com" target="_blank">mcornea@redhat.com</a>>:<br>
> > ><br>
> > > > Is there an ARP entry for 192.168.5.1 ?<br>
> > > ><br>
> > > > ip n | grep '192.168.5.1 ' in the router namespace<br>
> > > ><br>
> > > ><br>
> > > ><br>
> > > > ----- Original Message -----<br>
> > > > > From: "ICHIBA Sara" <<a href="mailto:ichi.sara@gmail.com" target="_blank">ichi.sara@gmail.com</a>><br>
> > > > > To: <a href="mailto:rdo-list@redhat.com" target="_blank">rdo-list@redhat.com</a><br>
> > > > > Sent: Tuesday, May 19, 2015 1:42:11 PM<br>
> > > > > Subject: [Rdo-list] Fwd: [Neutron] router can't ping external<br>
> > gateway<br>
> > > > ><br>
> > > > ><br>
> > > > > ---------- Forwarded message ----------<br>
> > > > > From: ICHIBA Sara < <a href="mailto:ichi.sara@gmail.com" target="_blank">ichi.sara@gmail.com</a> ><br>
> > > > > Date: 2015-05-19 13:41 GMT+02:00<br>
> > > > > Subject: Re: [Rdo-list] [Neutron] router can't ping external gateway<br>
> > > > > To: Marius Cornea < <a href="mailto:mcornea@redhat.com" target="_blank">mcornea@redhat.com</a> ><br>
> > > > ><br>
> > > > ><br>
> > > > > The forged transmissions on the vswitch are accepted. What's next?<br>
> > > > ><br>
> > > > > 2015-05-19 13:29 GMT+02:00 Marius Cornea < <a href="mailto:mcornea@redhat.com" target="_blank">mcornea@redhat.com</a> > :<br>
> > > > ><br>
> > > > ><br>
> > > > > Oh, ESXi...I remember that the vswitch had some security features in<br>
> > > > place.<br>
> > > > > You can check those and I think the one that you're looking for is<br>
> > called<br>
> > > > > forged retransmits.<br>
> > > > ><br>
> > > > > Thanks,<br>
> > > > > Marius<br>
> > > > ><br>
> > > > > ----- Original Message -----<br>
> > > > > > From: "ICHIBA Sara" < <a href="mailto:ichi.sara@gmail.com" target="_blank">ichi.sara@gmail.com</a> ><br>
> > > > > > To: "Marius Cornea" < <a href="mailto:mcornea@redhat.com" target="_blank">mcornea@redhat.com</a> ><br>
> > > > > > Cc: <a href="mailto:rdo-list@redhat.com" target="_blank">rdo-list@redhat.com</a><br>
> > > > > > Sent: Tuesday, May 19, 2015 1:17:20 PM<br>
> > > > > > Subject: Re: [Rdo-list] [Neutron] router can't ping external<br>
> > gateway<br>
> > > > > ><br>
> > > > > > the ICMP requests arrives to the eth0 interface<br>
> > > > > > [root@localhost ~]# tcpdump -i eth0 icmp<br>
> > > > > > tcpdump: WARNING: eth0: no IPv4 address assigned<br>
> > > > > > tcpdump: verbose output suppressed, use -v or -vv for full protocol<br>
> > > > decode<br>
> > > > > > listening on eth0, link-type EN10MB (Ethernet), capture size 65535<br>
> > > > bytes<br>
> > > > > > 13:14:13.205573 IP 192.168.5.70 > 192.168.5.1 : ICMP echo request,<br>
> > id<br>
> > > > > > 31055,<br>
> > > > > > seq 1, length 64<br>
> > > > > > 13:14:14.205303 IP 192.168.5.70 > 192.168.5.1 : ICMP echo request,<br>
> > id<br>
> > > > > > 31055,<br>
> > > > > > seq 2, length 64<br>
> > > > > > 13:14:15.205391 IP 192.168.5.70 > 192.168.5.1 : ICMP echo request,<br>
> > id<br>
> > > > > > 31055,<br>
> > > > > > seq 3, length 64<br>
> > > > > > 13:14:16.205397 IP 192.168.5.70 > 192.168.5.1 : ICMP echo request,<br>
> > id<br>
> > > > > > 31055,<br>
> > > > > > seq 4, length 64<br>
> > > > > > 13:14:17.205408 IP 192.168.5.70 > 192.168.5.1 : ICMP echo request,<br>
> > id<br>
> > > > > > 31055,<br>
> > > > > > seq 5, length 64<br>
> > > > > > 13:14:18.205412 IP 192.168.5.70 > 192.168.5.1 : ICMP echo request,<br>
> > id<br>
> > > > > > 31055,<br>
> > > > > > seq 6, length 64<br>
> > > > > > 13:14:19.205392 IP 192.168.5.70 > 192.168.5.1 : ICMP echo request,<br>
> > id<br>
> > > > > > 31055,<br>
> > > > > > seq 7, length 64<br>
> > > > > > 13:14:20.205357 IP 192.168.5.70 > 192.168.5.1 : ICMP echo request,<br>
> > id<br>
> > > > > > 31055,<br>
> > > > > > seq 8, length 64<br>
> > > > > > 13:14:33.060267<br>
> > > > > ><br>
> > > > > ><br>
> > > > > > what should I do next?<br>
> > > > > ><br>
> > > > > > P.S: My compute and controller hosts are ESXi VMs and I can ssh to<br>
> > > > both of<br>
> > > > > > them without a problem.<br>
> > > > > ><br>
> > > > > > 2015-05-19 13:00 GMT+02:00 Marius Cornea < <a href="mailto:mcornea@redhat.com" target="_blank">mcornea@redhat.com</a> >:<br>
> > > > > ><br>
> > > > > > > Also, I'm seeing that you have 2 default routes on your host.<br>
> > I'm not<br>
> > > > > > > sure<br>
> > > > > > > it affects the setup but try keeping only one: e.g. 'ip route del<br>
> > > > default<br>
> > > > > > > via 192.168.4.1' to delete the eth1 one.<br>
> > > > > > ><br>
> > > > > > > ======[root@localhost ~(keystone_admin)]# ip r<br>
> > > > > > > default via 192.168.5.1 dev br-ex<br>
> > > > > > > default via 192.168.4.1 dev eth1<br>
> > > > > > ><br>
> > > > > > > ----- Original Message -----<br>
> > > > > > > > From: "Marius Cornea" < <a href="mailto:mcornea@redhat.com" target="_blank">mcornea@redhat.com</a> ><br>
> > > > > > > > To: "ICHIBA Sara" < <a href="mailto:ichi.sara@gmail.com" target="_blank">ichi.sara@gmail.com</a> ><br>
> > > > > > > > Cc: <a href="mailto:rdo-list@redhat.com" target="_blank">rdo-list@redhat.com</a><br>
> > > > > > > > Sent: Tuesday, May 19, 2015 12:50:45 PM<br>
> > > > > > > > Subject: Re: [Rdo-list] [Neutron] router can't ping external<br>
> > > > gateway<br>
> > > > > > > ><br>
> > > > > > > > Hi,<br>
> > > > > > > ><br>
> > > > > > > > Try to see if any of the ICMP requests leave the eth0 interface<br>
> > > > like<br>
> > > > > > > 'tcpdump<br>
> > > > > > > > -i eth0 icmp' while pinging 192.168.5.1 from the router<br>
> > namespace.<br>
> > > > > > > ><br>
> > > > > > > > Thanks,<br>
> > > > > > > > Marius<br>
> > > > > > > ><br>
> > > > > > > > ----- Original Message -----<br>
> > > > > > > > > From: "ICHIBA Sara" < <a href="mailto:ichi.sara@gmail.com" target="_blank">ichi.sara@gmail.com</a> ><br>
> > > > > > > > > To: "Boris Derzhavets" < <a href="mailto:bderzhavets@hotmail.com" target="_blank">bderzhavets@hotmail.com</a> >,<br>
> > > > > > > > > <a href="mailto:rdo-list@redhat.com" target="_blank">rdo-list@redhat.com</a><br>
> > > > > > > > > Sent: Tuesday, May 19, 2015 12:12:30 PM<br>
> > > > > > > > > Subject: Re: [Rdo-list] [Neutron] router can't ping external<br>
> > > > gateway<br>
> > > > > > > > ><br>
> > > > > > > > > ====updates<br>
> > > > > > > > ><br>
> > > > > > > > > I have deleted my networks, rebooted my machines and<br>
> > configured<br>
> > > > an<br>
> > > > > > > other<br>
> > > > > > > > > network. Now I can see the qr bridge mapped to the router but<br>
> > > > still<br>
> > > > > > > can't<br>
> > > > > > > > > ping the external gateway:<br>
> > > > > > > > ><br>
> > > > > > > > > ====[root@localhost ~(keystone_admin)]# ip netns exec<br>
> > > > > > > > > qrouter-85fa9459-503d-4996-86f3-6042604fed74 ip r<br>
> > > > > > > > > default via 192.168.5.1 dev qg-e1b584b4-db<br>
> > > > > > > > > <a href="http://10.0.0.0/24" target="_blank">10.0.0.0/24</a> dev qr-7b330e0e-5c proto kernel scope link src<br>
> > > > 10.0.0.1<br>
> > > > > > > > > <a href="http://192.168.5.0/24" target="_blank">192.168.5.0/24</a> dev qg-e1b584b4-db proto kernel scope link<br>
> > src<br>
> > > > > > > 192.168.5.70<br>
> > > > > > > > ><br>
> > > > > > > > > ====[root@localhost ~(keystone_admin)]# ip netns exec<br>
> > > > > > > > > qrouter-85fa9459-503d-4996-86f3-6042604fed74 ip a<br>
> > > > > > > > > 1: lo: <LOOPBACK,UP,LOWER_UP> mtu 65536 qdisc noqueue state<br>
> > > > UNKNOWN<br>
> > > > > > > > > link/loopback 00:00:00:00:00:00 brd 00:00:00:00:00:00<br>
> > > > > > > > > inet <a href="http://127.0.0.1/8" target="_blank">127.0.0.1/8</a> scope host lo<br>
> > > > > > > > > valid_lft forever preferred_lft forever<br>
> > > > > > > > > inet6 ::1/128 scope host<br>
> > > > > > > > > valid_lft forever preferred_lft forever<br>
> > > > > > > > > 12: qg-e1b584b4-db: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu<br>
> > 1500<br>
> > > > qdisc<br>
> > > > > > > > > noqueue<br>
> > > > > > > > > state UNKNOWN<br>
> > > > > > > > > link/ether fa:16:3e:68:83:f8 brd ff:ff:ff:ff:ff:ff<br>
> > > > > > > > > inet <a href="http://192.168.5.70/24" target="_blank">192.168.5.70/24</a> brd 192.168.5.255 scope global<br>
> > > > qg-e1b584b4-db<br>
> > > > > > > > > valid_lft forever preferred_lft forever<br>
> > > > > > > > > inet <a href="http://192.168.5.73/32" target="_blank">192.168.5.73/32</a> brd 192.168.5.73 scope global<br>
> > > > qg-e1b584b4-db<br>
> > > > > > > > > valid_lft forever preferred_lft forever<br>
> > > > > > > > > inet6 fe80::f816:3eff:fe68:83f8/64 scope link<br>
> > > > > > > > > valid_lft forever preferred_lft forever<br>
> > > > > > > > > 13: qr-7b330e0e-5c: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu<br>
> > 1500<br>
> > > > qdisc<br>
> > > > > > > > > noqueue<br>
> > > > > > > > > state UNKNOWN<br>
> > > > > > > > > link/ether fa:16:3e:92:9c:90 brd ff:ff:ff:ff:ff:ff<br>
> > > > > > > > > inet <a href="http://10.0.0.1/24" target="_blank">10.0.0.1/24</a> brd 10.0.0.255 scope global qr-7b330e0e-5c<br>
> > > > > > > > > valid_lft forever preferred_lft forever<br>
> > > > > > > > > inet6 fe80::f816:3eff:fe92:9c90/64 scope link<br>
> > > > > > > > > valid_lft forever preferred_lft forever<br>
> > > > > > > > ><br>
> > > > > > > > ><br>
> > > > > > > > > =====[root@localhost ~(keystone_admin)]# ip netns exec<br>
> > > > > > > > > qrouter-85fa9459-503d-4996-86f3-6042604fed74 ping 192.168.5.1<br>
> > > > > > > > > PING 192.168.5.1 (192.168.5.1) 56(84) bytes of data.<br>
> > > > > > > > > From 192.168.5.70 icmp_seq=10 Destination Host Unreachable<br>
> > > > > > > > > From 192.168.5.70 icmp_seq=11 Destination Host Unreachable<br>
> > > > > > > > > From 192.168.5.70 icmp_seq=12 Destination Host Unreachable<br>
> > > > > > > > > From 192.168.5.70 icmp_seq=13 Destination Host Unreachable<br>
> > > > > > > > > From 192.168.5.70 icmp_seq=14 Destination Host Unreachable<br>
> > > > > > > > > From 192.168.5.70 icmp_seq=15 Destination Host Unreachable<br>
> > > > > > > > > From 192.168.5.70 icmp_seq=16 Destination Host Unreachable<br>
> > > > > > > > > From 192.168.5.70 icmp_seq=17 Destination Host Unreachable<br>
> > > > > > > > ><br>
> > > > > > > > ><br>
> > > > > > > > > =====[root@localhost ~(keystone_admin)]# ovs-vsctl show<br>
> > > > > > > > > 19de58db-509d-4de8-bd88-9222019b13f1<br>
> > > > > > > > > Bridge br-int<br>
> > > > > > > > > fail_mode: secure<br>
> > > > > > > > > Port "tap2decc1bc-bf"<br>
> > > > > > > > > tag: 2<br>
> > > > > > > > > Interface "tap2decc1bc-bf"<br>
> > > > > > > > > type: internal<br>
> > > > > > > > > Port br-int<br>
> > > > > > > > > Interface br-int<br>
> > > > > > > > > type: internal<br>
> > > > > > > > > Port patch-tun<br>
> > > > > > > > > Interface patch-tun<br>
> > > > > > > > > type: patch<br>
> > > > > > > > > options: {peer=patch-int}<br>
> > > > > > > > > Port "qr-7b330e0e-5c"<br>
> > > > > > > > > tag: 2<br>
> > > > > > > > > Interface "qr-7b330e0e-5c"<br>
> > > > > > > > > type: internal<br>
> > > > > > > > > Port "qvo164afbd4-0c"<br>
> > > > > > > > > tag: 2<br>
> > > > > > > > > Interface "qvo164afbd4-0c"<br>
> > > > > > > > > Bridge br-ex<br>
> > > > > > > > > Port "eth0"<br>
> > > > > > > > > Interface "eth0"<br>
> > > > > > > > > Port br-ex<br>
> > > > > > > > > Interface br-ex<br>
> > > > > > > > > type: internal<br>
> > > > > > > > > Port "qg-e1b584b4-db"<br>
> > > > > > > > > Interface "qg-e1b584b4-db"<br>
> > > > > > > > > type: internal<br>
> > > > > > > > > Bridge br-tun<br>
> > > > > > > > > Port br-tun<br>
> > > > > > > > > Interface br-tun<br>
> > > > > > > > > type: internal<br>
> > > > > > > > > Port "vxlan-c0a80520"<br>
> > > > > > > > > Interface "vxlan-c0a80520"<br>
> > > > > > > > > type: vxlan<br>
> > > > > > > > > options: {df_default="true", in_key=flow,<br>
> > > > local_ip="192.168.5.33",<br>
> > > > > > > > > out_key=flow, remote_ip="192.168.5.32"}<br>
> > > > > > > > > Port patch-int<br>
> > > > > > > > > Interface patch-int<br>
> > > > > > > > > type: patch<br>
> > > > > > > > > options: {peer=patch-tun}<br>
> > > > > > > > > ovs_version: "2.3.1"<br>
> > > > > > > > ><br>
> > > > > > > > ><br>
> > > > > > > > ><br>
> > > > > > > > ><br>
> > > > > > > > > 2015-05-19 11:58 GMT+02:00 ICHIBA Sara < <a href="mailto:ichi.sara@gmail.com" target="_blank">ichi.sara@gmail.com</a><br>
> > > :<br>
> > > > > > > > ><br>
> > > > > > > > ><br>
> > > > > > > > ><br>
> > > > > > > > > can you show me your plugin.ini file? /etc/neutron/plugin.ini<br>
> > > > and the<br>
> > > > > > > other<br>
> > > > > > > > > file /etc/neutron/plugins/openvswitch/ovs_neutron_plugin.ini<br>
> > > > > > > > ><br>
> > > > > > > > ><br>
> > > > > > > > > 2015-05-19 10:47 GMT+02:00 Boris Derzhavets <<br>
> > > > <a href="mailto:bderzhavets@hotmail.com" target="_blank">bderzhavets@hotmail.com</a><br>
> > > > > > > > :<br>
> > > > > > > > ><br>
> > > > > > > > ><br>
> > > > > > > > ><br>
> > > > > > > > > There is one thing , which I clearly see . It is<br>
> > > > qrouter-namespace<br>
> > > > > > > > > misconfiguration. There is no qr-xxxxx bridge attached to<br>
> > br-int<br>
> > > > > > > > > Picture , in general, should look like this<br>
> > > > > > > > ><br>
> > > > > > > > > ubuntu@ubuntu-System:~$ sudo ip netns exec<br>
> > > > > > > > > qrouter-6cb93ddd-2637-449d-8b10-7c07da49ee8c route -n<br>
> > > > > > > > ><br>
> > > > > > > > > Kernel IP routing table<br>
> > > > > > > > > Destination Gateway Genmask Flags Metric Ref Use Iface<br>
> > > > > > > > > 0.0.0.0 192.168.12.15 0.0.0.0 UG 0 0 0 qg-a753a8f5-c8<br>
> > > > > > > > > 10.254.1.0 0.0.0.0 255.255.255.0 U 0 0 0 qr-393d9f71-53<br>
> > > > > > > > > 192.168.12.0 0.0.0.0 255.255.255.0 U 0 0 0 qg-a753a8f5-c8<br>
> > > > > > > > ><br>
> > > > > > > > > ubuntu@ubuntu-System:~$ sudo ip netns exec<br>
> > > > > > > > > qrouter-6cb93ddd-2637-449d-8b10-7c07da49ee8c ifconfig<br>
> > > > > > > > > lo Link encap:Local Loopback<br>
> > > > > > > > > inet addr:127.0.0.1 Mask:255.0.0.0<br>
> > > > > > > > > inet6 addr: ::1/128 Scope:Host<br>
> > > > > > > > > UP LOOPBACK RUNNING MTU:65536 Metric:1<br>
> > > > > > > > > RX packets:0 errors:0 dropped:0 overruns:0 frame:0<br>
> > > > > > > > > TX packets:0 errors:0 dropped:0 overruns:0 carrier:0<br>
> > > > > > > > > collisions:0 txqueuelen:0<br>
> > > > > > > > > RX bytes:0 (0.0 B) TX bytes:0 (0.0 B)<br>
> > > > > > > > ><br>
> > > > > > > > > qg-a753a8f5-c8 Link encap:Ethernet HWaddr fa:16:3e:a2:11:b4<br>
> > > > > > > > > inet addr:192.168.12.150 Bcast:192.168.12.255<br>
> > Mask:255.255.255.0<br>
> > > > > > > > > inet6 addr: fe80::f816:3eff:fea2:11b4/64 Scope:Link<br>
> > > > > > > > > UP BROADCAST RUNNING MTU:1500 Metric:1<br>
> > > > > > > > > RX packets:24504 errors:0 dropped:0 overruns:0 frame:0<br>
> > > > > > > > > TX packets:17367 errors:0 dropped:0 overruns:0 carrier:0<br>
> > > > > > > > > collisions:0 txqueuelen:0<br>
> > > > > > > > > RX bytes:24328699 (24.3 MB) TX bytes:1443691 (1.4 MB)<br>
> > > > > > > > ><br>
> > > > > > > > > qr-393d9f71-53 Link encap:Ethernet HWaddr fa:16:3e:9e:ec:01<br>
> > > > > > > > > inet addr:10.254.1.1 Bcast:10.254.1.255 Mask:255.255.255.0<br>
> > > > > > > > > inet6 addr: fe80::f816:3eff:fe9e:ec01/64 Scope:Link<br>
> > > > > > > > > UP BROADCAST RUNNING MTU:1500 Metric:1<br>
> > > > > > > > > RX packets:22487 errors:0 dropped:5 overruns:0 frame:0<br>
> > > > > > > > > TX packets:24736 errors:0 dropped:0 overruns:0 carrier:0<br>
> > > > > > > > > collisions:0 txqueuelen:0<br>
> > > > > > > > > RX bytes:2379287 (2.3 MB) TX bytes:24338711 (24.3 MB)<br>
> > > > > > > > ><br>
> > > > > > > > > I would also advise you to post a question also on<br>
> > > > <a href="http://ask.openstack.org" target="_blank">ask.openstack.org</a><br>
> > > > > > > > ><br>
> > > > > > > > > Boris.<br>
> > > > > > > > ><br>
> > > > > > > > ><br>
> > > > > > > > ><br>
> > > > > > > > > Date: Tue, 19 May 2015 09:48:58 +0200<br>
> > > > > > > > > From: <a href="mailto:ichi.sara@gmail.com" target="_blank">ichi.sara@gmail.com</a><br>
> > > > > > > > > To: <a href="mailto:rdo-list@redhat.com" target="_blank">rdo-list@redhat.com</a><br>
> > > > > > > > > Subject: [Rdo-list] [Neutron] router can't ping external<br>
> > gateway<br>
> > > > > > > > ><br>
> > > > > > > > ><br>
> > > > > > > > > Hey people,<br>
> > > > > > > > > I have an issue with my networking. I connected my openstack<br>
> > to<br>
> > > > an<br>
> > > > > > > external<br>
> > > > > > > > > network I did all the changes required. But still my router<br>
> > can't<br>
> > > > > > > reach the<br>
> > > > > > > > > external gateway.<br>
> > > > > > > > ><br>
> > > > > > > > > =====ifcfg-br-ex<br>
> > > > > > > > > DEVICE=br-ex<br>
> > > > > > > > > DEVICETYPE=ovs<br>
> > > > > > > > > TYPE=OVSBridge<br>
> > > > > > > > > BOOTPROTO=static<br>
> > > > > > > > > IPADDR=192.168.5.33<br>
> > > > > > > > > NETMASK=255.255.255.0<br>
> > > > > > > > > ONBOOT=yes<br>
> > > > > > > > > GATEWAY=192.168.5.1<br>
> > > > > > > > > DNS1=8.8.8.8<br>
> > > > > > > > > DNS2=192.168.5.1<br>
> > > > > > > > ><br>
> > > > > > > > ><br>
> > > > > > > > > ====ifcfg-eth0<br>
> > > > > > > > > DEVICE=eth0<br>
> > > > > > > > > HWADDR=00:0c:29:a2:b1:b9<br>
> > > > > > > > > ONBOOT=yes<br>
> > > > > > > > > TYPE=OVSPort<br>
> > > > > > > > > NM_CONTROLLED=yes<br>
> > > > > > > > > DEVICETYPE=ovs<br>
> > > > > > > > > OVS_BRIDGE=br-ex<br>
> > > > > > > > ><br>
> > > > > > > > > ======[root@localhost ~(keystone_admin)]# ovs-vsctl show<br>
> > > > > > > > > 19de58db-509d-4de8-bd88-9222019b13f1<br>
> > > > > > > > > Bridge br-int<br>
> > > > > > > > > fail_mode: secure<br>
> > > > > > > > > Port "tap8652132e-b8"<br>
> > > > > > > > > tag: 1<br>
> > > > > > > > > Interface "tap8652132e-b8"<br>
> > > > > > > > > type: internal<br>
> > > > > > > > > Port br-int<br>
> > > > > > > > > Interface br-int<br>
> > > > > > > > > type: internal<br>
> > > > > > > > > Port patch-tun<br>
> > > > > > > > > Interface patch-tun<br>
> > > > > > > > > type: patch<br>
> > > > > > > > > options: {peer=patch-int}<br>
> > > > > > > > > Bridge br-ex<br>
> > > > > > > > > Port "qg-5f8ebe30-40"<br>
> > > > > > > > > Interface "qg-5f8ebe30-40"<br>
> > > > > > > > > type: internal<br>
> > > > > > > > > Port "eth0"<br>
> > > > > > > > > Interface "eth0"<br>
> > > > > > > > > Port br-ex<br>
> > > > > > > > > Interface br-ex<br>
> > > > > > > > > type: internal<br>
> > > > > > > > > Bridge br-tun<br>
> > > > > > > > > Port "vxlan-c0a80520"<br>
> > > > > > > > > Interface "vxlan-c0a80520"<br>
> > > > > > > > > type: vxlan<br>
> > > > > > > > > options: {df_default="true", in_key=flow,<br>
> > > > local_ip="192.168.5.33",<br>
> > > > > > > > > out_key=flow, remote_ip="192.168.5.32"}<br>
> > > > > > > > > Port br-tun<br>
> > > > > > > > > Interface br-tun<br>
> > > > > > > > > type: internal<br>
> > > > > > > > > Port patch-int<br>
> > > > > > > > > Interface patch-int<br>
> > > > > > > > > type: patch<br>
> > > > > > > > > options: {peer=patch-tun}<br>
> > > > > > > > > ovs_version: "2.3.1"<br>
> > > > > > > > ><br>
> > > > > > > > > =====[root@localhost ~(keystone_admin)]# ping 192.168.5.1<br>
> > > > > > > > > PING 192.168.5.1 (192.168.5.1) 56(84) bytes of data.<br>
> > > > > > > > > 64 bytes from 192.168.5.1 : icmp_seq=1 ttl=64 time=1.76 ms<br>
> > > > > > > > > 64 bytes from 192.168.5.1 : icmp_seq=2 ttl=64 time=1.88 ms<br>
> > > > > > > > > 64 bytes from 192.168.5.1 : icmp_seq=3 ttl=64 time=1.45 ms<br>
> > > > > > > > > ^C<br>
> > > > > > > > > --- 192.168.5.1 ping statistics ---<br>
> > > > > > > > > 3 packets transmitted, 3 received, 0% packet loss, time<br>
> > 2002ms<br>
> > > > > > > > > rtt min/avg/max/mdev = 1.452/1.699/1.880/0.187 ms<br>
> > > > > > > > > [root@localhost ~(keystone_admin)]#<br>
> > > > > > > > ><br>
> > > > > > > > > ======[root@localhost ~(keystone_admin)]# ip netns exec<br>
> > > > > > > > > qrouter-85fa9459-503d-4996-86f3-6042604fed74 ip a<br>
> > > > > > > > > 1: lo: <LOOPBACK,UP,LOWER_UP> mtu 65536 qdisc noqueue state<br>
> > > > UNKNOWN<br>
> > > > > > > > > link/loopback 00:00:00:00:00:00 brd 00:00:00:00:00:00<br>
> > > > > > > > > inet <a href="http://127.0.0.1/8" target="_blank">127.0.0.1/8</a> scope host lo<br>
> > > > > > > > > valid_lft forever preferred_lft forever<br>
> > > > > > > > > inet6 ::1/128 scope host<br>
> > > > > > > > > valid_lft forever preferred_lft forever<br>
> > > > > > > > > 14: qg-5f8ebe30-40: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu<br>
> > 1500<br>
> > > > qdisc<br>
> > > > > > > > > noqueue<br>
> > > > > > > > > state UNKNOWN<br>
> > > > > > > > > link/ether fa:16:3e:c2:1b:5e brd ff:ff:ff:ff:ff:ff<br>
> > > > > > > > > inet <a href="http://192.168.5.70/24" target="_blank">192.168.5.70/24</a> brd 192.168.5.255 scope global<br>
> > > > qg-5f8ebe30-40<br>
> > > > > > > > > valid_lft forever preferred_lft forever<br>
> > > > > > > > > inet6 fe80::f816:3eff:fec2:1b5e/64 scope link<br>
> > > > > > > > > valid_lft forever preferred_lft forever<br>
> > > > > > > > > [root@localhost ~(keystone_admin)]#<br>
> > > > > > > > ><br>
> > > > > > > > ><br>
> > > > > > > > > ======[root@localhost ~(keystone_admin)]# ip r<br>
> > > > > > > > > default via 192.168.5.1 dev br-ex<br>
> > > > > > > > > default via 192.168.4.1 dev eth1<br>
> > > > > > > > > <a href="http://169.254.0.0/16" target="_blank">169.254.0.0/16</a> dev eth0 scope link metric 1002<br>
> > > > > > > > > <a href="http://169.254.0.0/16" target="_blank">169.254.0.0/16</a> dev eth1 scope link metric 1003<br>
> > > > > > > > > <a href="http://169.254.0.0/16" target="_blank">169.254.0.0/16</a> dev br-ex scope link metric 1005<br>
> > > > > > > > > <a href="http://192.168.4.0/24" target="_blank">192.168.4.0/24</a> dev eth1 proto kernel scope link src<br>
> > 192.168.4.14<br>
> > > > > > > > > <a href="http://192.168.5.0/24" target="_blank">192.168.5.0/24</a> dev br-ex proto kernel scope link src<br>
> > > > 192.168.5.33<br>
> > > > > > > > > [root@localhost ~(keystone_admin)]#<br>
> > > > > > > > ><br>
> > > > > > > > ><br>
> > > > > > > > > ======[root@localhost ~(keystone_admin)]# ip netns exec<br>
> > > > > > > > > qrouter-85fa9459-503d-4996-86f3-6042604fed74 ip r<br>
> > > > > > > > > default via 192.168.5.1 dev qg-5f8ebe30-40<br>
> > > > > > > > > <a href="http://192.168.5.0/24" target="_blank">192.168.5.0/24</a> dev qg-5f8ebe30-40 proto kernel scope link<br>
> > src<br>
> > > > > > > 192.168.5.70<br>
> > > > > > > > > [root@localhost ~(keystone_admin)]#<br>
> > > > > > > > ><br>
> > > > > > > > ><br>
> > > > > > > > > ======[root@localhost ~(keystone_admin)]# ip netns exec<br>
> > > > > > > > > qrouter-85fa9459-503d-4996-86f3-6042604fed74 ping 192.168.5.1<br>
> > > > > > > > > PING 192.168.5.1 (192.168.5.1) 56(84) bytes of data.<br>
> > > > > > > > > ^C<br>
> > > > > > > > > --- 192.168.5.1 ping statistics ---<br>
> > > > > > > > > 5 packets transmitted, 0 received, 100% packet loss, time<br>
> > 3999ms<br>
> > > > > > > > ><br>
> > > > > > > > > any hints??<br>
> > > > > > > > ><br>
> > > > > > > > ><br>
> > > > > > > > ><br>
> > > > > > > > ><br>
> > > > > > > > ><br>
> > > > > > > > > _______________________________________________ Rdo-list<br>
> > mailing<br>
> > > > list<br>
> > > > > > > > > <a href="mailto:Rdo-list@redhat.com" target="_blank">Rdo-list@redhat.com</a><br>
> > > > <a href="https://www.redhat.com/mailman/listinfo/rdo-list" target="_blank">https://www.redhat.com/mailman/listinfo/rdo-list</a><br>
> > > > > > > To<br>
> > > > > > > > > unsubscribe: <a href="mailto:rdo-list-unsubscribe@redhat.com" target="_blank">rdo-list-unsubscribe@redhat.com</a><br>
> > > > > > > > ><br>
> > > > > > > > ><br>
> > > > > > > > ><br>
> > > > > > > > > _______________________________________________<br>
> > > > > > > > > Rdo-list mailing list<br>
> > > > > > > > > <a href="mailto:Rdo-list@redhat.com" target="_blank">Rdo-list@redhat.com</a><br>
> > > > > > > > > <a href="https://www.redhat.com/mailman/listinfo/rdo-list" target="_blank">https://www.redhat.com/mailman/listinfo/rdo-list</a><br>
> > > > > > > > ><br>
> > > > > > > > > To unsubscribe: <a href="mailto:rdo-list-unsubscribe@redhat.com" target="_blank">rdo-list-unsubscribe@redhat.com</a><br>
> > > > > > > ><br>
> > > > > > > > _______________________________________________<br>
> > > > > > > > Rdo-list mailing list<br>
> > > > > > > > <a href="mailto:Rdo-list@redhat.com" target="_blank">Rdo-list@redhat.com</a><br>
> > > > > > > > <a href="https://www.redhat.com/mailman/listinfo/rdo-list" target="_blank">https://www.redhat.com/mailman/listinfo/rdo-list</a><br>
> > > > > > > ><br>
> > > > > > > > To unsubscribe: <a href="mailto:rdo-list-unsubscribe@redhat.com" target="_blank">rdo-list-unsubscribe@redhat.com</a><br>
> > > > > > > ><br>
> > > > > > ><br>
> > > > > ><br>
> > > > ><br>
> > > > ><br>
> > > > ><br>
> > > > > _______________________________________________<br>
> > > > > Rdo-list mailing list<br>
> > > > > <a href="mailto:Rdo-list@redhat.com" target="_blank">Rdo-list@redhat.com</a><br>
> > > > > <a href="https://www.redhat.com/mailman/listinfo/rdo-list" target="_blank">https://www.redhat.com/mailman/listinfo/rdo-list</a><br>
> > > > ><br>
> > > > > To unsubscribe: <a href="mailto:rdo-list-unsubscribe@redhat.com" target="_blank">rdo-list-unsubscribe@redhat.com</a><br>
> > > ><br>
> > ><br>
> ><br>
><br>
</div></div></blockquote></div><br></div>
</div></div></div><br></div>