[R2.0-Build 12]: ping to outside network not going thro with policy with service instance

Bug #1401874 reported by alok kumar
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
Juniper Openstack
Status tracked in Trunk
R2.0
Fix Released
Critical
alok kumar
R2.1
New
Critical
alok kumar
Trunk
New
Critical
alok kumar

Bug Description

test scenarios:

- VN 'public' (10.204.220.192/29) and VN 'vnet1' (9.9.9.0/24) connected with policy(via transparent firewall)
- policy allows all traffic between these VNs
- route target(64512:20001) is added in vnet1. so default route(0.0.0.0/0) leaked in vnet1 and public, as expected
- now ping from public(10.204.220.192/29) VN's VM to outside should go through but it fails.

ping between public and vnet1 is working as expected.

Naveen has debugged the issue and found that VRF
default-domain:SecurityGroupRegressionTests7-31434507:vnet1:service-898e40eb-b772-4c4d-ae79-d331a27f8ff6-default-domain_SecurityGroupRegressionTests7-31434507_si_trans_firewall doesn't have route 0/0 because it doesn't have route import target:64512:20001.

for target:64512:2000 grp list, please check snapshot attached.

setup info:

env.roledefs = {
    'all': [host1,host2,host3,host4,host5],
    'cfgm': [host1,host2,host5],
    'openstack':[host2],
    'control': [host2,host1],
    'compute': [host3,host4],
    'collector': [host2,host1],
    'webui': [host1],
    'database': [host1,host2,host5],
    'build': [host_build],
}

env.hostnames = {
    'all': ['nodec64', 'nodeg18', 'nodeh8', 'nodec11', 'nodec12']
}

Tags: config
Revision history for this message
alok kumar (kalok) wrote :
alok kumar (kalok)
tags: added: blocker
alok kumar (kalok)
tags: added: config
removed: vrouter
Revision history for this message
Nischal Sheth (nsheth) wrote :

@Alok

I assume this is not a problem anymore with Build 22.

Revision history for this message
alok kumar (kalok) wrote :

yes, its working now for R2.0.

Nischal Sheth (nsheth)
tags: removed: contrail-control
information type: Proprietary → Public
tags: removed: blocker
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Bug attachments

Remote bug watches

Bug watches keep track of this bug in other bug trackers.