Re: [Openstack] network question on openstack installation

2015-06-29 Thread Yngvi Páll Þorfinnsson
I Cc: openstack@lists.openstack.org Subject: RE: [Openstack] network question on openstack installation You should use the same IP addresses that are configured for the tunnel. It is expected that this scan takes some time as it iterates over all available network protocols. It is a bit concerning that G

Re: [Openstack] network question on openstack installation

2015-06-29 Thread Uwe Sauter
nds > > >-Original Message- >From: Yngvi Páll Þorfinnsson >Sent: 29. júní 2015 23:35 >To: 'Uwe Sauter'; 'YANG LI' >Cc: 'openstack@lists.openstack.org' >Subject: RE: [Openstack] network question on openstack installation > >It's

Re: [Openstack] network question on openstack installation

2015-06-29 Thread Yngvi Páll Þorfinnsson
23:28 To: 'Uwe Sauter'; YANG LI Cc: openstack@lists.openstack.org Subject: RE: [Openstack] network question on openstack installation Well this one finished finally Should I use the tunnel or mgmt IP ? root@compute5:/# nmap -sO 172.22.15.14 Starting Nmap 6.40 ( http://nmap.org ) at 2015

Re: [Openstack] network question on openstack installation

2015-06-29 Thread Yngvi Páll Þorfinnsson
s.openstack.org Subject: RE: [Openstack] network question on openstack installation Well this one finished finally Should I use the tunnel or mgmt IP ? root@compute5:/# nmap -sO 172.22.15.14 Starting Nmap 6.40 ( http://nmap.org ) at 2015-06-29 23:21 GMT Warning: 172.22.15.14 giving up

Re: [Openstack] network question on openstack installation

2015-06-29 Thread Yngvi Páll Þorfinnsson
: openstack@lists.openstack.org Subject: RE: [Openstack] network question on openstack installation Hm, I'm running out of ideas. Can you run those two commands to verify that GRE traffic can pass the firewalls: Network node: nmap -sO Compute node: nmap -sO In both cases, that's a

Re: [Openstack] network question on openstack installation

2015-06-29 Thread Yngvi Páll Þorfinnsson
2015 23:18 To: Yngvi Páll Þorfinnsson; YANG LI Cc: openstack@lists.openstack.org Subject: RE: [Openstack] network question on openstack installation Hm, I'm running out of ideas. Can you run those two commands to verify that GRE traffic can pass the firewalls: Network node: nmap -sO Co

Re: [Openstack] network question on openstack installation

2015-06-29 Thread Uwe Sauter
mp-port-unreachable > >Chain OUTPUT (policy ACCEPT 14 packets, 2340 bytes) >num pkts bytes target prot opt in out source > destination >10 0 ACCEPT udp -- * virbr0 0.0.0.0/0 > 0.0.0.0/0udp dpt:68 > > &g

Re: [Openstack] network question on openstack installation

2015-06-29 Thread Uwe Sauter
rfinnsson; YANG LI >Cc: openstack@lists.openstack.org >Subject: RE: [Openstack] network question on openstack installation > >As usual: it depends. But first things first: is there a reason why you >didn't configure your external network as shared? > >Then to the question ab

Re: [Openstack] network question on openstack installation

2015-06-29 Thread Uwe Sauter
m configuing the external >network as a VLAN ? > >Best regards >Yngvi > >From: Yngvi Páll Þorfinnsson >Sent: 29. júní 2015 21:57 >To: Uwe Sauter; YANG LI >Cc: openstack@lists.openstack.org >Subject: Re: [Openstack] network question on openstack installation > >O

Re: [Openstack] network question on openstack installation

2015-06-29 Thread Uwe Sauter
e instance) > > >grep ERR nova-compute.log >2015-06-29 21:11:11.801 4166 ERROR nova.compute.manager [-] [instance: >af901a2b-2462-4c19-b1f1-237371fd8177] Instance failed to spawn > > >I‘ve attached the neutron agent-show and neutron (sub)net-list in the >attached file. > > >Best

Re: [Openstack] network question on openstack installation

2015-06-29 Thread Yngvi Páll Þorfinnsson
: [Openstack] network question on openstack installation As usual: it depends. But first things first: is there a reason why you didn't configure your external network as shared? Then to the question about several provider networks. Depending on your company's network it can totally mak

Re: [Openstack] network question on openstack installation

2015-06-29 Thread Yngvi Páll Þorfinnsson
...@gmail.com] Sent: 29. júní 2015 22:46 To: Yngvi Páll Þorfinnsson; YANG LI Cc: openstack@lists.openstack.org Subject: RE: [Openstack] network question on openstack installation One more thing. Please provide iptables -L -nv --line-numbers for network and compute nodes. Am 30. Juni 2015 00:25:45

Re: [Openstack] network question on openstack installation

2015-06-29 Thread Uwe Sauter
hen I‘m configuing the external >network as a VLAN ? > >Best regards >Yngvi > >From: Yngvi Páll Þorfinnsson >Sent: 29. júní 2015 21:57 >To: Uwe Sauter; YANG LI >Cc: openstack@lists.openstack.org >Subject: Re: [Openstack] network question on openstack installation > &g

Re: [Openstack] network question on openstack installation

2015-06-29 Thread Yngvi Páll Þorfinnsson
Subject: Re: [Openstack] network question on openstack installation OK, I only found one fresh error Compute node; nova-compute.log ( as usually when I create instance) grep ERR nova-compute.log 2015-06-29 21:11:11.801 4166 ERROR nova.compute.manager [-] [instance: af901a2b-2462-4c19-b1f1-237371fd8177

Re: [Openstack] network question on openstack installation

2015-06-29 Thread Yngvi Páll Þorfinnsson
LI Cc: openstack@lists.openstack.org Subject: RE: [Openstack] network question on openstack installation Can you check for ERRORs in: Network node: neutron server log, neutron openvswitch agent log, openvswitch log Nova controller node: nova api log, nova scheduler log Compute node: nova compute

Re: [Openstack] network question on openstack installation

2015-06-29 Thread Yngvi Páll Þorfinnsson
-show and neutron (sub)net-list in the attached file. Best regards Yngvi From: Uwe Sauter [mailto:uwe.sauter...@gmail.com] Sent: 29. júní 2015 21:34 To: Yngvi Páll Þorfinnsson; YANG LI Cc: openstack@lists.openstack.org Subject: RE: [Openstack] network question on openstack installation Can you

Re: [Openstack] network question on openstack installation

2015-06-29 Thread Uwe Sauter
5a-f505fc0e072d >Unable to find network with name '11fab5ad-c457-4175-9e5a-f505fc0e072d' >root@controller2:/# >root@controller2:/# source demo-openrc.sh >root@controller2:/# neutron net-show >11fab5ad-c457-4175-9e5a-f505fc0e072d >Unable to find network with name '11fa

Re: [Openstack] network question on openstack installation

2015-06-29 Thread Yngvi Páll Þorfinnsson
ped the neutron, and resynced Best regards Yngvi From: Uwe Sauter [mailto:uwe.sauter...@gmail.com] Sent: 29. júní 2015 21:16 To: Yngvi Páll Þorfinnsson; YANG LI Cc: openstack@lists.openstack.org Subject: RE: [Openstack] network question on openstack installation Yes. Just keep in mind that if you e

Re: [Openstack] network question on openstack installation

2015-06-29 Thread Uwe Sauter
Running upgrade aae5706a396 -> 32f3915891fd, >cisco_apic_driver_update >INFO [alembic.migration] Running upgrade 32f3915891fd -> 58fe87a01143, >cisco_csr_routing >INFO [alembic.migration] Running upgrade 58fe87a01143 -> 236b90af57ab, >ml2_type_driver_refactor_dynamic_segments >INFO

Re: [Openstack] network question on openstack installation

2015-06-29 Thread Yngvi Páll Þorfinnsson
brightens the dark side of Neutron configuration, Uwe Am 29.06.2015 um 22:19 schrieb Yngvi Páll Þorfinnsson: > HI Uwe > No, I did'nt drop the keystone ;-) > > But is this the correct way to resync neutron ? > > # neutron-db-manage --config-file /etc/neutron/neutron.con

Re: [Openstack] network question on openstack installation

2015-06-29 Thread Uwe Sauter
Yngvi > > -Original Message- > From: Uwe Sauter [mailto:uwe.sauter...@gmail.com] > Sent: 29. júní 2015 18:08 > To: YANG LI > Cc: openstack@lists.openstack.org > Subject: Re: [Openstack] network question on openstack installation > > It depends on your switch… some

Re: [Openstack] network question on openstack installation

2015-06-29 Thread Yngvi Páll Þorfinnsson
Yngvi -Original Message- From: Uwe Sauter [mailto:uwe.sauter...@gmail.com] Sent: 29. júní 2015 18:08 To: YANG LI Cc: openstack@lists.openstack.org Subject: Re: [Openstack] network question on openstack installation It depends on your switch… some drop tagged packets on an access port, o

Re: [Openstack] network question on openstack installation

2015-06-29 Thread Uwe Sauter
It depends on your switch… some drop tagged packets on an access port, others allow tagged packets, if the packet VLAN ID equals the configured VLAN ID. I'd reconfigure the provider network type to "flat" but that's personal taste. You could also reconfigure the switch port to be a trunking port

Re: [Openstack] network question on openstack installation

2015-06-29 Thread YANG LI
thank you, Uwe. our provider network actually is untagged, but I did specified VLAN ID when I create our external network and everything still works. will this cause issue later on? eutron net-create --provider:network_type=vlan —provider:segmentation_id= --provider:physical_network=physnet1 --r

Re: [Openstack] network question on openstack installation

2015-06-29 Thread YANG LI
Thank so much, James for detailed explanation. This all make sense to me now. Thanks, Yang On Jun 27, 2015, at 1:10 PM, James Denton mailto:james.den...@rackspace.com>> wrote: Hi Yang, Another confusion I have is about network_vlan_ranges. Is this network VLAN id range? Yes, it is. But the r

Re: [Openstack] network question on openstack installation

2015-06-29 Thread YANG LI
thank you, Andreas for the information. I am not familiar with availability zones. It is good to know we have this option. Thanks, Yang > On Jun 26, 2015, at 9:07 AM, Andreas Scheuring > wrote: > > One way would be to achieve this via "Availability zones". Just create 2 > host aggregates (and

Re: [Openstack] network question on openstack installation

2015-06-27 Thread James Denton
Hi Yang, > Another confusion I have is about network_vlan_ranges. Is this network VLAN > id range? Yes, it is. But the range is only used for tenant networks when tenant_network_types == vlan. Neutron will automatically assign a vlan ID from this range when a user creates a network. > If so,

Re: [Openstack] network question on openstack installation

2015-06-27 Thread Uwe Sauter
Hi Yang, it depends on whether your provider network is tagged or untagged. If it is untagged (the switch port is an "access" port) then you don't specify the VLAN ID for the external network (as it will get tagged by the switch). If the provider network is tagged (the switch port is a "trunk" p

Re: [Openstack] network question on openstack installation

2015-06-27 Thread YANG LI
Thank you so much, James! This is so helpful. Another confusion I have is about network_vlan_ranges. Is this network VLAN id range? If so, does it has to match external network? For example, we only have one external VLAN we can use as Our provider network and that VLAN id is 775 (xxx.xxx.xxx.0/

Re: [Openstack] network question on openstack installation

2015-06-26 Thread Andreas Scheuring
One way would be to achieve this via "Availabilty zones". Just create 2 host aggregates (and with it a such a zone) and add a hypervisor to each of them (host aggreate to availability zone is 1:1 mapping) The instance launch dialog allows you to select the zone. Hope this helps On Fr, 2015-06-2

Re: [Openstack] network question on openstack installation

2015-06-26 Thread James Denton
You can absolutely have instances in the same network span different compute nodes. As an admin, you can run ‘nova show ’ and see the host in the output: root@controller01:~# nova show 7bb18175-87da-4d1f-8dca-2ef07fee9d21 | grep host | OS-EXT-SRV-ATTR:host | compute02

Re: [Openstack] network question on openstack installation

2015-06-26 Thread YANG LI
Thanks, James for the explanation. it make more sense now. it is possible that a instances on same tenant network reside on different compute nodes right? how do I tell which compute node a instance is on? Thanks, Yang On Jun 24, 2015, at 10:27 AM, James Denton mailto:james.den.

Re: [Openstack] network question on openstack installation

2015-06-24 Thread James Denton
Hello. > all three nodes will have eth0 on management/api network. since I am using > ml2 plugin with vlan for tenant network, I think all compute node should have > eth1 as the second nic on provider network. Is this correct? I understand > provider network is for instance to get external acc

[Openstack] network question on openstack installation

2015-06-24 Thread YANG LI
I am working on install openstack from scratch, but get confused with network part. I want to have one controller node, two compute nodes. the controller node will only handle following services: glance-api glance-registry keystone nova-api nova-cert nova-conductor nova-consoleauth nova-novncpro