[NETVIRT-241] Sg - Missing rule for table 252 while Trying to open ssh connection between 2 vm's Created: 06/Nov/16  Updated: 19/Oct/17  Resolved: 21/Nov/16

Status: Resolved
Project: netvirt
Component/s: General
Affects Version/s: Boron
Fix Version/s: None

Type: Bug
Reporter: zan cohen Assignee: Unassigned
Resolution: Won't Do Votes: 0
Labels: None
Remaining Estimate: Not Specified
Time Spent: Not Specified
Original Estimate: Not Specified
Environment:

Operating System: All
Platform: All


Attachments: Microsoft Word defect_7094.docx     File screen-karaf.zipx    
External issue ID: 7094

 Description   

1.Add 2 security groups:
****************************
Sg1=All_Tcp(ingress+Egress)
Sg2=Default

2.Lunch 2 vm's:
****************
vm_x assosiate to SG1
vm_y assosiate to SG2

Action:
*******
Try to open ssh connection from vm_x toward vm_y - connection failed!!

Defect:
*******
view vm_x ovs rules tables 40+41+42 and verify learn rule existence - o.k
view vm_y ovs rules tables 251+252+253 - no rules exist for table 252

Note!!!(see in Attachment comparison)
*************************************
Try to open ssh connection from vm_y to vm_x - o.k
it can be seen that afterward this step rule for table 252 is added and ssh connction from vm_x toward vm_y succeed



 Comments   
Comment by zan cohen [ 06/Nov/16 ]

Attachment defect_7094.docx has been added with description: comparison for Note(see description)

Comment by zan cohen [ 06/Nov/16 ]

Attachment screen-karaf.zipx has been added with description: karaf logs

Comment by zan cohen [ 06/Nov/16 ]

It seems thta there is a problem with Default Sg.
Sg (with Custom Tcp port 80) vs Sg With All protocol work properely!!

Comment by Koby Aizer [ 06/Nov/16 ]

This is a known networking-odl issue.
Default security group rules aren't pushed down to netvirt.

This is expected to be resolved in networking-odl Newton (committed a few days ago).
https://review.openstack.org/#/c/390783/

Comment by Koby Aizer [ 21/Nov/16 ]

This is resolved in newton, and a known issue in mitaka. In mitaka, need to configure explicit SG groups ALLOW rules.

Generated at Wed Feb 07 20:21:04 UTC 2024 using Jira 8.20.10#820010-sha1:ace47f9899e9ee25d7157d59aa17ab06aee30d3d.