<div dir="ltr">It looks like security groups aren't enabled. Make sure you don't have a config option setting 'enable_security_group' to False.<div><br></div><div>Check the startup log, you should see something like "Driver configuration doesn't match with enable_security_group" and "Disabled allowed-address-pairs extension."</div></div><div class="gmail_extra"><br><div class="gmail_quote">On Mon, Jun 8, 2015 at 7:50 AM, Ken D'Ambrosio <span dir="ltr"><<a href="mailto:ken@jots.org" target="_blank">ken@jots.org</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><span class=""><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">
You have better chances of getting an answer if you asked the -dev list and add > [Neutron] to the subject (done here).<br>
<br>
That said, can you tell us a bit more about your deployment? You can also hop<br>
on #openstack-neutron on Freenode to look for neutron developers who can help<br>
you more interactively.<br>
<br>
Cheers,<br>
Armando<br>
</blockquote>
<br></span>
Hi.  As per Armando's suggestion, e-mailing openstack-dev for advice, and have pasted files and command output, below.  Our Ubuntu-based Openstack installations do not seem to be enabling "allowed address pairs".  It seems that we (or Ubuntu) are disabling them somehow, and we were wondering if you might have advice on where to look.  If there's any additional information you need, please let us know.<br>
<br>
Thanks kindly,<br>
<br>
-Ken<br>
<br>
-------------------- files and output below ------------------------<br>
<br>
<br>
ubuntu@magnificent-hill:~$ neutron ext-list<br>
+-----------------------+-----------------------------------------------+<br>
| alias                 | name                                          |<br>
+-----------------------+-----------------------------------------------+<br>
| service-type          | Neutron Service Type Management               |<br>
| ext-gw-mode           | Neutron L3 Configurable external gateway mode |<br>
| l3_agent_scheduler    | L3 Agent Scheduler                            |<br>
| lbaas_agent_scheduler | Loadbalancer Agent Scheduler                  |<br>
| external-net          | Neutron external network                      |<br>
| binding               | Port Binding                                  |<br>
| metering              | Neutron Metering                              |<br>
| agent                 | agent                                         |<br>
| quotas                | Quota management support                      |<br>
| dhcp_agent_scheduler  | DHCP Agent Scheduler                          |<br>
| multi-provider        | Multi Provider Network                        |<br>
| fwaas                 | Firewall service                              |<br>
| router                | Neutron L3 Router                             |<br>
| vpnaas                | VPN service                                   |<br>
| extra_dhcp_opt        | Neutron Extra DHCP opts                       |<br>
| provider              | Provider Network                              |<br>
| lbaas                 | LoadBalancing service                         |<br>
| extraroute            | Neutron Extra Route                           |<br>
+-----------------------+-----------------------------------------------+<br>
<br>
<br>
neutron.conf:<br>
##################################################################<br>
# [ WARNING ]<br>
# Configuration file maintained by Juju. Local changes may be overwritten.<br>
##################################################################<br>
[DEFAULT]<br>
verbose = False<br>
debug = False<br>
lock_path = /var/lock/neutron<br>
core_plugin = neutron.plugins.ml2.plugin.Ml2Plugin<br>
rabbit_userid = neutron<br>
rabbit_virtual_host = openstack<br>
rabbit_password = myhashhere<br>
rabbit_host = 10.10.3.6<br>
control_exchange = neutron<br>
notification_driver = neutron.openstack.common.notifier.list_notifier<br>
list_notifier_drivers = neutron.openstack.common.notifier.rabbit_notifier<br>
[agent]<br>
root_helper = sudo /usr/bin/neutron-rootwrap /etc/neutron/rootwrap.conf<br>
------------ end neutron.conf ---------------<br>
<br>
ml2_conf.ini:<br>
###############################################################################<br>
# [ WARNING ]<br>
# Configuration file maintained by Juju. Local changes may be overwritten.<br>
###############################################################################<br>
[ml2]<br>
type_drivers = gre,vxlan,vlan,flat<br>
tenant_network_types = gre,vxlan,vlan,flat<br>
mechanism_drivers = openvswitch,l2population<br>
<br>
[ml2_type_gre]<br>
tunnel_id_ranges = 1:1000<br>
<br>
[ml2_type_vxlan]<br>
vni_ranges = 1001:2000<br>
<br>
[ml2_type_vlan]<br>
network_vlan_ranges = physnet1:1000:2000<br>
<br>
[ml2_type_flat]<br>
flat_networks =<br>
<br>
[ovs]<br>
enable_tunneling = True<br>
local_ip = 10.10.3.8<br>
bridge_mappings = physnet1:br-data<br>
<br>
[agent]<br>
tunnel_types = gre<br>
l2_population = False<br>
<br>
<br>
[securitygroup]<br>
firewall_driver = neutron.agent.linux.iptables_firewall.OVSHybridIptablesFirewallDriver<br>
------------ end ml2_conf.ini ---------------<br>
<br>
__________________________________________________________________________<br>
OpenStack Development Mailing List (not for usage questions)<br>
Unsubscribe: <a href="http://OpenStack-dev-request@lists.openstack.org?subject:unsubscribe" target="_blank">OpenStack-dev-request@lists.openstack.org?subject:unsubscribe</a><br>
<a href="http://lists.openstack.org/cgi-bin/mailman/listinfo/openstack-dev" target="_blank">http://lists.openstack.org/cgi-bin/mailman/listinfo/openstack-dev</a><br>
</blockquote></div><br><br clear="all"><div><br></div>-- <br><div class="gmail_signature"><div>Kevin Benton</div></div>
</div>