[ClusterLabs] RES: RES: Can't get a group of IP address up when moving to a new version of Pacemaker/Corosync

2015-09-04 Thread Carlos Xavier
Tank you Dejan.

I Just tested the command the RA is trying to run on a OpenSuse installation 
ant it worked fine. The command is:

" iptables -I INPUT -d 172.31.0.148 -i lo -j CLUSTERIP--new   --clustermac 
b1:0a:7b:8b:9c:70  --total-nodes 2 --local-node 1
--hashmode sourceip-sourceport"

After that I could see that a module named "ipt_CLUSTERIP" was loaded.
Looking at the SLES12 installation I couldn't locate that module.

I'm going to escalate the trouble to our Datacenter provider. Meanwhile I'll 
try to use the old IPaddr2 RA, since we are going to
use LVS for load balance. With it we don't need support for iptables.

Best regards,
Carlos
 

> -Mensagem original-
> De: Dejan Muhamedagic [mailto:deja...@fastmail.fm]
> Enviada em: sexta-feira, 4 de setembro de 2015 07:55
> Para: users@clusterlabs.org
> Assunto: Re: [ClusterLabs] RES: Can't get a group of IP address up when 
> moving to a new version of
> Pacemaker/Corosync
> 
> Hi,
> 
> On Wed, Sep 02, 2015 at 03:44:47PM -0300, Carlos Xavier wrote:
> > Hi Kristoffer.
> >
> > Tank you very much for fast reply.
> >
> > I did a cleanup of the resource and took a look at the log and could see 
> > that the issue has
> something to do with the RA IPaddr2 trying to set some iptables rule, 
> although we are not using any
> iptables rule set.
> >
> > crm(live)resource# cleanup c-ip-httpd
> > Cleaning up ip_ccardbusiness:0 on apolo Cleaning up ip_ccardbusiness:0
> > on diana Cleaning up ip_ccardgift:0 on apolo Cleaning up
> > ip_ccardgift:0 on diana Cleaning up ip_intranet:0 on apolo Cleaning up
> > ip_intranet:0 on diana Cleaning up ip_ccardbusiness:1 on apolo
> > Cleaning up ip_ccardbusiness:1 on diana Cleaning up ip_ccardgift:1 on
> > apolo Cleaning up ip_ccardgift:1 on diana Cleaning up ip_intranet:1 on
> > apolo Cleaning up ip_intranet:1 on diana Waiting for 12 replies from
> > the CRMd OK
> >
> > And on the log we have
> >
> [...]
> > 2015-09-02T14:40:54.184995-03:00 apolo IPaddr2(ip_ccardbusiness)[8360]: 
> > ERROR: iptables failed
> > 2015-09-02T14:40:54.187651-03:00 apolo lrmd[5182]:   notice: 
> > operation_finished:
> ip_ccardbusiness_start_0:8360:stderr [ iptables: No chain/target/match by 
> that name. ]
> 
> The target used is CLUSTERIP. Do you have the iptables extensions installed 
> (you should)? The package
> is called xtables-plugins. It should contain a library with CLUSTERIP support.
> 
> [...]
> 
> > Is there a way to stop the IPaddr2 RA to try to manage the iptables rule?
> 
> No, there isn't. Not a specialist on this, but so far nobody complained about 
> iptables use. The
> underlying problem should be solved.
> 
> Since you're running a SLE product, you can also ask for help from the SUSE 
> support.
> 
> Thanks,
> 
> Dejan
> 
> ___
> Users mailing list: Users@clusterlabs.org 
> http://clusterlabs.org/mailman/listinfo/users
> 
> Project Home: http://www.clusterlabs.org Getting started:
> http://www.clusterlabs.org/doc/Cluster_from_Scratch.pdf
> Bugs: http://bugs.clusterlabs.org



___
Users mailing list: Users@clusterlabs.org
http://clusterlabs.org/mailman/listinfo/users

Project Home: http://www.clusterlabs.org
Getting started: http://www.clusterlabs.org/doc/Cluster_from_Scratch.pdf
Bugs: http://bugs.clusterlabs.org


[ClusterLabs] RES: RES: Can't get a group of IP address up when moving to a new version of Pacemaker/Corosync

2015-09-03 Thread Carlos Xavier
Tank you very much Ken.

I'll take a close look at that.
Is there any documentation where I can learn more about the Pacemaker/IPtables 
integration?
The chain that needs to be created has the same name of the resource I'm trying 
to clone?

Shouldn't the IPaddr2 RA solve this issue by itself? When it sees that there is 
no Chain useful to add the rule, instead of giving a error create that chain?

Regards,
Carlos.


> -Mensagem original-
> De: Ken Gaillot [mailto:kgail...@redhat.com]
> Enviada em: quarta-feira, 2 de setembro de 2015 16:16
> Para: users@clusterlabs.org
> Assunto: Re: [ClusterLabs] RES: Can't get a group of IP address up when 
> moving to a new version of
> Pacemaker/Corosync
> 
> On 09/02/2015 01:44 PM, Carlos Xavier wrote:
> > Hi Kristoffer.
> >
> > Tank you very much for fast reply.
> >
> > I did a cleanup of the resource and took a look at the log and could see 
> > that the issue has
> something to do with the RA IPaddr2 trying to set some iptables rule, 
> although we are not using any
> iptables rule set.
> >
> > crm(live)resource# cleanup c-ip-httpd
> > Cleaning up ip_ccardbusiness:0 on apolo Cleaning up ip_ccardbusiness:0
> > on diana Cleaning up ip_ccardgift:0 on apolo Cleaning up
> > ip_ccardgift:0 on diana Cleaning up ip_intranet:0 on apolo Cleaning up
> > ip_intranet:0 on diana Cleaning up ip_ccardbusiness:1 on apolo
> > Cleaning up ip_ccardbusiness:1 on diana Cleaning up ip_ccardgift:1 on
> > apolo Cleaning up ip_ccardgift:1 on diana Cleaning up ip_intranet:1 on
> > apolo Cleaning up ip_intranet:1 on diana Waiting for 12 replies from
> > the CRMd OK
> >
> > And on the log we have
> >
> > 2015-09-02T14:40:54.074834-03:00 apolo crmd[5185]:  warning:
> > update_failcount: Updating failcount for ip_ccardbusiness on diana
> > after failed start: rc=1 (update=INFINITY, time=1441215654)
> > 2015-09-02T14:40:54.075034-03:00 apolo crmd[5185]:  warning: 
> > status_from_rc: Action 33
> (ip_ccardbusiness:0_start_0) on diana failed (target: 0 vs. rc: 1): Error 
> 2015-09-02T14:40:54.075230-
> 03:00 apolo crmd[5185]:  warning: update_failcount: Updating failcount for 
> ip_ccardbusiness on diana
> after failed start: rc=1 (update=INFINITY, time=1441215654) 
> 2015-09-02T14:40:54.075427-03:00 apolo
> crmd[5185]:  warning: update_failcount: Updating failcount for 
> ip_ccardbusiness on diana after failed
> start: rc=1 (update=INFINITY, time=1441215654)
> > 2015-09-02T14:40:54.078344-03:00 apolo crmd[5185]:   notice: 
> > abort_transition_graph: Transition
> aborted by status-168427778-fail-count-ip_ccardbusiness, 
> fail-count-ip_ccardbusiness=INFINITY:
> Transient attribute change (create cib=0.378.14, source=te_update_diff:391,
> path=/cib/status/node_state[@id='168427778']/transient_attributes[@id='168427778']/instance_attributes
> [@id='status-168427778'], 0)
> > 2015-09-02T14:40:54.184995-03:00 apolo IPaddr2(ip_ccardbusiness)[8360]: 
> > ERROR: iptables failed
> > 2015-09-02T14:40:54.187651-03:00 apolo lrmd[5182]:   notice: 
> > operation_finished:
> ip_ccardbusiness_start_0:8360:stderr [ iptables: No chain/target/match by 
> that name. ]
> > 2015-09-02T14:40:54.187978-03:00 apolo lrmd[5182]:   notice: 
> > operation_finished:
> ip_ccardbusiness_start_0:8360:stderr [ ocf-exit-reason:iptables failed ]
> > 2015-09-02T14:40:54.203780-03:00 apolo crmd[5185]:   notice: 
> > process_lrm_event: Operation
> ip_ccardbusiness_start_0: unknown error (node=apolo, call=88, rc=1, 
> cib-update=1321, confirmed=true)
> > 2015-09-02T14:40:54.204026-03:00 apolo crmd[5185]:   notice: 
> > process_lrm_event: apolo-
> ip_ccardbusiness_start_0:88 [ iptables: No chain/target/match by that 
> name.\nocf-exit-reason:iptables
> failed\n ]
> > 2015-09-02T14:40:54.206111-03:00 apolo crmd[5185]:  warning:
> > status_from_rc: Action 43 (ip_ccardbusiness:1_start_0) on apolo failed
> > (target: 0 vs. rc: 1): Error 2015-09-02T14:40:54.206442-03:00 apolo
> > crmd[5185]:  warning: update_failcount: Updating failcount for
> > ip_ccardbusiness on apolo after failed start: rc=1 (update=INFINITY,
> > time=1441215654) 2015-09-02T14:40:54.206663-03:00 apolo crmd[5185]:  
> > warning: update_failcount:
> Updating failcount for ip_ccardbusiness on apolo after failed start: rc=1 
> (update=INFINITY,
> time=1441215654) 2015-09-02T14:40:54.206859-03:00 apolo crmd[5185]:  warning: 
> status_from_rc: Action
> 43 (ip_ccardbusiness:1_start_0) on apolo failed (target: 0 vs. rc: 1): Error 
> 2015-09-
> 02T14:40:54.207109-03:00 apolo crmd[5185]:  warning: update_failcount: 
> Updating failcount for
> ip_ccardbusiness on apolo after failed start: rc=1 (update=INFINITY, 
> time=1441215654) 2015-09-
> 02T14:40:54.207489-03:00 apolo crmd[5185]:  warning: update_failcount: 
> Updating failcount for
> ip_ccardbusiness on apolo after failed start: rc=1 (update=INFINITY, 
> time=1441215654)
> > 2015-09-02T14:40:54.207829-03:00 apolo crmd[5185]:   notice: run_graph: 
> > Transition 1166
> (Complete=14, Pending=0, Fired=0,