[Openstack] nova-network-snat weird behavior

YIP Wai Peng yipwp at comp.nus.edu.sg
Wed Dec 12 16:17:32 UTC 2012

Dear all,

I am running FlatDHCPNetwork. I have two interfaces, em1 and em2.
- em1 is my flat_interface for fixed ( and node
( ips.
- em2 is my public_interface for floating ips (

When I create an instance, I notice that the following iptable rule
gets created:
-A nova-network-snat -s -o em2 -j SNAT --to-source

Strangely, the interface in the -o option seems to be always following
the "public_interface = em2" configuration in '/etc/nova/nova.conf'.
If I don't define it, then the rule that gets created is
-A nova-network-snat -s -o eth0 -j SNAT --to-source

This results in outgoing traffic from instances not being SNAT
correctly, because the iptable rule is applied on the public_interface
and not flat_network_bridge

FWIW, I changed public_interface to vmnetbr0 (that bridges em1 and
vnet0), and the instance was able to ping out. But that shouldn't be
the correct configuration, should it?

Can someone tell me what am I doing wrong?

(I am running openstack-nova-network-2012.2-1 on fedora)

public_interface = em2
flat_interface = em1
fixed_range =
floating_range =
flat_network_bridge = vmnetbr0
multi_host = True


More information about the Openstack mailing list