[kolla] neutron-l3-agent namespace NAT table not working?

Jon Masters jcm at jonmasters.org
Sat Jan 4 04:44:24 UTC 2020


Hi there,

I've got a weird problem with the neutron-l3-agent container on my
deployment. It comes up, sets up the iptables rules in the qrouter
namespace (and I can see these using "ip netns...") but traffic isn't
having DNAT or SNAT applied. What's most strange is that manually adding a
LOG jump target to the iptables nat PRE/POSTROUTING chains (after enabling
nf logging sent to the host kernel, confirmed that works) doesn't result in
any log entries. It's as if the nat table isn't being applied at all for
any packets traversing the qrouter namespace. This is driving me crazy :)

Anyone got some quick suggestions? (assume I tried the obvious stuff).

Jon.

-- 
Computer Architect
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.openstack.org/pipermail/openstack-discuss/attachments/20200103/f1a970ef/attachment.html>


More information about the openstack-discuss mailing list