*** saneax has quit IRC | 00:04 | |
*** mahito has quit IRC | 00:07 | |
*** mdorman has quit IRC | 00:08 | |
*** mahito has joined #openstack-operators | 00:09 | |
*** VW has quit IRC | 00:11 | |
*** markvoelker has joined #openstack-operators | 00:13 | |
*** blair has joined #openstack-operators | 00:17 | |
*** markvoelker has quit IRC | 00:18 | |
klindgren__ | mgagne, you around? | 00:24 |
---|---|---|
mgagne | klindgren__: I am, what can I do for you? | 00:25 |
klindgren__ | cool - you said a while ago that you had a hack to re-add the NWfilter stuff to vifs crated under neutron | 00:25 |
klindgren__ | does that hack also work with allowed address pairs? | 00:25 |
mgagne | klindgren__: not at all, it's not aware of allowed address pairs | 00:26 |
klindgren__ | *sigh* | 00:27 |
klindgren__ | looks like the platform independent arp spoofing stuff has been rejected on the final patches | 00:27 |
mgagne | yea, I'm not even sure how I will migrate out from that after anti-spoofing lands in neutron | 00:27 |
klindgren__ | but the OVS based arp spoofing filters got put in | 00:27 |
*** Piet_ has joined #openstack-operators | 00:27 | |
klindgren__ | mgagne, we did the migration not to long ago - luckily neutron rebuilds all the iptables rules | 00:28 |
klindgren__ | so restart neutron-<whatever>-agent | 00:28 |
klindgren__ | it will ad its filter rules above neutrons | 00:28 |
mgagne | klindgren__: how do you remove the ones defined by libvirt? | 00:29 |
klindgren__ | above novas* | 00:29 |
klindgren__ | hrm | 00:29 |
klindgren__ | thinking.... | 00:29 |
klindgren__ | I dont actually recall having to do that.... | 00:29 |
mgagne | we are talking about ebtables right? | 00:30 |
klindgren__ | I assume this is where my testing went south | 00:30 |
klindgren__ | :-) | 00:30 |
*** klindgren__ is now known as klindgren | 00:33 | |
*** stanchan has quit IRC | 00:40 | |
klindgren | so I am pretty sure I focused on iptables only in my testing. Not realizing that arp couldn't be filtered by iptables - at the time. | 00:40 |
WormMan | yay! arptables, yay! ebtables | 00:49 |
WormMan | yay! lobotomy! | 00:49 |
WormMan | er, sorry :) | 00:49 |
*** chlong has quit IRC | 00:52 | |
*** chlong has joined #openstack-operators | 00:54 | |
klindgren | WormMan, exactly | 01:06 |
*** alop has quit IRC | 01:37 | |
*** rsemenov has quit IRC | 01:40 | |
*** mahito has quit IRC | 01:44 | |
*** mahito has joined #openstack-operators | 01:46 | |
*** mahito_ has joined #openstack-operators | 01:48 | |
*** mahito has quit IRC | 01:48 | |
*** mahito has joined #openstack-operators | 01:49 | |
*** mahito_ has quit IRC | 01:49 | |
*** dboik has joined #openstack-operators | 01:52 | |
*** dboik_ has joined #openstack-operators | 01:54 | |
*** dboik has quit IRC | 01:57 | |
*** markvoelker has joined #openstack-operators | 02:02 | |
*** markvoelker has quit IRC | 02:07 | |
*** Piet_ has quit IRC | 02:15 | |
*** zul has quit IRC | 03:08 | |
*** zul has joined #openstack-operators | 03:20 | |
*** csoukup has joined #openstack-operators | 03:47 | |
*** csoukup has quit IRC | 03:47 | |
*** markvoelker has joined #openstack-operators | 03:50 | |
*** markvoelker has quit IRC | 03:55 | |
*** matrohon has joined #openstack-operators | 03:56 | |
*** saneax has joined #openstack-operators | 04:03 | |
*** matrohon has quit IRC | 04:36 | |
*** maishsk_afk has quit IRC | 04:44 | |
*** maishsk_afk_ has joined #openstack-operators | 04:44 | |
*** markvoelker has joined #openstack-operators | 05:39 | |
*** markvoelker has quit IRC | 05:44 | |
*** maishsk_afk_ has quit IRC | 05:49 | |
*** maishsk_afk has joined #openstack-operators | 05:50 | |
*** belmoreira has joined #openstack-operators | 05:55 | |
*** blair has quit IRC | 05:56 | |
*** maishsk_afk has quit IRC | 06:08 | |
*** maishsk_afk has joined #openstack-operators | 06:14 | |
*** maishsk_afk has quit IRC | 06:22 | |
*** simon-AS559 has joined #openstack-operators | 06:37 | |
*** maishsk_afk has joined #openstack-operators | 06:38 | |
*** simon-AS559 has quit IRC | 07:14 | |
*** matrohon has joined #openstack-operators | 07:15 | |
*** beddari has quit IRC | 07:20 | |
*** Miouge_ has joined #openstack-operators | 07:26 | |
*** maishsk_afk has quit IRC | 07:27 | |
*** markvoelker has joined #openstack-operators | 07:28 | |
*** Miouge has quit IRC | 07:29 | |
*** Miouge_ is now known as Miouge | 07:29 | |
*** Miouge has quit IRC | 07:31 | |
*** markvoelker has quit IRC | 07:33 | |
*** beddari has joined #openstack-operators | 07:33 | |
*** Miouge has joined #openstack-operators | 07:35 | |
*** beddari1 has quit IRC | 07:46 | |
*** mahito has quit IRC | 07:59 | |
*** simon-AS559 has joined #openstack-operators | 08:00 | |
*** simon-AS5591 has joined #openstack-operators | 08:01 | |
*** simon-AS559 has quit IRC | 08:04 | |
*** Miouge has quit IRC | 08:05 | |
*** maishsk_afk has joined #openstack-operators | 08:07 | |
*** Miouge has joined #openstack-operators | 08:08 | |
*** beddari1 has joined #openstack-operators | 08:09 | |
*** beddari1 has quit IRC | 08:10 | |
*** Miouge has quit IRC | 08:11 | |
*** bvandenh has joined #openstack-operators | 08:11 | |
*** Miouge has joined #openstack-operators | 08:22 | |
*** maishsk_afk has quit IRC | 08:24 | |
*** maishsk_afk has joined #openstack-operators | 08:25 | |
*** maishsk_afk has quit IRC | 08:29 | |
*** chlong has quit IRC | 08:34 | |
*** markvoelker has joined #openstack-operators | 09:17 | |
*** markvoelker has quit IRC | 09:22 | |
*** racedo_ has joined #openstack-operators | 09:23 | |
*** markvoelker has joined #openstack-operators | 10:17 | |
*** markvoelker has quit IRC | 10:23 | |
*** markvoelker has joined #openstack-operators | 11:18 | |
*** markvoelker has quit IRC | 11:22 | |
*** blair has joined #openstack-operators | 11:23 | |
*** radez is now known as radez_g0n3 | 11:23 | |
*** blair has quit IRC | 11:26 | |
*** blair has joined #openstack-operators | 11:38 | |
*** blair has quit IRC | 11:38 | |
*** racedo_ has quit IRC | 11:40 | |
*** ferest has joined #openstack-operators | 12:11 | |
*** maishsk_afk has joined #openstack-operators | 12:12 | |
*** zul has quit IRC | 12:16 | |
*** zul has joined #openstack-operators | 12:16 | |
*** ferest has quit IRC | 12:17 | |
*** maishsk_afk has quit IRC | 12:18 | |
*** xavpaice has quit IRC | 12:22 | |
*** xavpaice has joined #openstack-operators | 12:22 | |
*** dminer has joined #openstack-operators | 12:31 | |
*** markvoelker has joined #openstack-operators | 12:34 | |
*** racedo_ has joined #openstack-operators | 12:35 | |
*** VW has joined #openstack-operators | 12:36 | |
*** markvoelker has quit IRC | 12:38 | |
*** bvandenh_ has joined #openstack-operators | 12:39 | |
*** bvandenh has quit IRC | 12:39 | |
*** racedo_ has quit IRC | 12:39 | |
*** bvandenh_ has quit IRC | 12:43 | |
*** radez_g0n3 is now known as radez | 12:52 | |
*** maishsk_afk has joined #openstack-operators | 12:52 | |
*** racedo_ has joined #openstack-operators | 12:54 | |
*** bvandenh_ has joined #openstack-operators | 12:56 | |
*** MeganR has left #openstack-operators | 12:58 | |
*** alaski is now known as lascii | 13:02 | |
*** Piet has joined #openstack-operators | 13:15 | |
*** bvandenh_ has quit IRC | 13:20 | |
*** VW has quit IRC | 13:34 | |
*** maishsk_afk has quit IRC | 13:35 | |
*** racedo_ has quit IRC | 13:37 | |
*** jaypipes is now known as leakypipes | 13:43 | |
*** racedo_ has joined #openstack-operators | 13:51 | |
*** maishsk_afk has joined #openstack-operators | 13:56 | |
*** simon-AS559 has joined #openstack-operators | 13:59 | |
*** VW has joined #openstack-operators | 14:00 | |
*** simon-AS5591 has quit IRC | 14:02 | |
*** markvoelker has joined #openstack-operators | 14:05 | |
*** saneax has quit IRC | 14:09 | |
*** maishsk_afk has quit IRC | 14:09 | |
dmsimard | klindgren: Saw your chat with mgagne yesterday | 14:09 |
*** markvoelker has quit IRC | 14:09 | |
*** esker has joined #openstack-operators | 14:09 | |
*** racedo_ has quit IRC | 14:12 | |
dmsimard | mgagne and I work on the same public cloud - We had this case of a customer that tried to attach multiple NICs to his VMs with IPs in the same subnet and lots of interesting things happen when you do that | 14:13 |
dmsimard | Like the "who has" ARP requests make it to the right NIC but the replies are sent from another NIC so it's caught by anti-spoofing | 14:13 |
*** esker has quit IRC | 14:14 | |
*** esker has joined #openstack-operators | 14:15 | |
dmsimard | Apparently it's hard to have IP addresses in the same subnet on different network interfaces (usually you'd put them as secondary like eth1:1, etc.) | 14:17 |
dmsimard | The workaround he's come up with: http://paste.openstack.org/show/266066/ | 14:18 |
dmsimard | Obviously configuring additional IPs as eth1:1 would fail due to anti-spoofing | 14:19 |
*** racedo_ has joined #openstack-operators | 14:19 | |
clayton | I was reading about something similar this morning. apparently another approach is to create a neutron port with multiple ip addresses | 14:19 |
clayton | then you can configure the addition ethx:y interfaces | 14:19 |
*** maishsk_afk has joined #openstack-operators | 14:21 | |
dmsimard | clayton: Interesting, does look like you can do that upon creation of the port but not afterwards (via port-update) | 14:22 |
dmsimard | I might just try that to see what happens | 14:22 |
clayton | it looks like you can also disable the anti-spoofing rules in kilo, reading up on that now | 14:23 |
clayton | we're running our openstack dev environments on top of openstack, so I want to be able to run virtual routers w/vxlan networks in that environment | 14:23 |
clayton | so I need to be able to give the node running the virtual router the ability to spoof traffic | 14:23 |
*** rlrevell has joined #openstack-operators | 14:24 | |
dmsimard | Oh, we have a dev environment based on Openstack too but we've disabled anti-spoofing and security groups altogether | 14:24 |
dmsimard | Makes it.. easier | 14:24 |
clayton | we run out dev environments on top of the prod environment, so that might not work for us ;) | 14:25 |
dmsimard | Fair enough | 14:25 |
clayton | ideally I want to be able to disable it on a per network basis, or worst case, per port basis | 14:25 |
*** simon-AS559 has quit IRC | 14:27 | |
*** maishsk_afk has quit IRC | 14:30 | |
dmsimard | Yeah, anti-spoofing is great and all but makes stuff like load balancing or routing a pain | 14:32 |
*** belmoreira has quit IRC | 14:42 | |
*** maishsk_afk has joined #openstack-operators | 14:52 | |
klindgren | I didn't think you could have more than 1 ip address on a port in neutron? | 14:53 |
andyhky | klindgren: https://wiki.openstack.org/wiki/Neutron/APIv2-specification#Port | 14:54 |
andyhky | fixed_ips is a list | 14:54 |
dmsimard | The option is repeatable | 14:56 |
dmsimard | On the port-create command | 14:56 |
*** maishsk_afk has quit IRC | 15:00 | |
klindgren | dmsimard per the CLI tool for port update: subnet_id=SUBNET,ip_address=IP_ADDR Desired IP and/or subnet for this port: subnet_id=<name_or_id>,ip_address=<ip>. You can repeat this option | 15:05 |
dmsimard | klindgren: For port update or port create? I don't see the option on update - if it exists my client might be outdated | 15:06 |
klindgren | http://docs.openstack.org/cli-reference/content/neutronclient_commands.html#neutronclient_subcommand_port-update | 15:06 |
klindgren | its under update | 15:06 |
dmsimard | Ah, yup - just updated neutronclient and I see it now. | 15:07 |
*** Miouge has quit IRC | 15:08 | |
*** Miouge has joined #openstack-operators | 15:25 | |
*** simon-AS559 has joined #openstack-operators | 15:27 | |
*** simon-AS5591 has joined #openstack-operators | 15:28 | |
*** simon-AS559 has quit IRC | 15:29 | |
*** markvoelker has joined #openstack-operators | 15:30 | |
*** mdorman has joined #openstack-operators | 15:31 | |
*** racedo_ has quit IRC | 15:31 | |
*** simon-AS5591 has quit IRC | 15:33 | |
*** markvoelker has quit IRC | 15:34 | |
*** gyee_ has joined #openstack-operators | 15:38 | |
*** alop has joined #openstack-operators | 15:45 | |
*** david-lyle has quit IRC | 15:46 | |
*** david-lyle has joined #openstack-operators | 15:46 | |
*** alop has quit IRC | 15:48 | |
*** matrohon has quit IRC | 15:52 | |
*** alop has joined #openstack-operators | 15:54 | |
*** Miouge has quit IRC | 16:00 | |
*** matrohon has joined #openstack-operators | 16:22 | |
*** Miouge has joined #openstack-operators | 16:23 | |
*** simon-AS559 has joined #openstack-operators | 16:35 | |
*** simon-AS559 has quit IRC | 16:41 | |
*** Miouge has quit IRC | 16:42 | |
*** Miouge has joined #openstack-operators | 16:44 | |
*** Miouge has quit IRC | 16:45 | |
*** Miouge has joined #openstack-operators | 16:46 | |
*** alop has quit IRC | 16:50 | |
*** VW has quit IRC | 16:57 | |
*** markvoelker has joined #openstack-operators | 17:19 | |
*** markvoelker has quit IRC | 17:24 | |
*** harlowja has quit IRC | 17:27 | |
*** harlowja has joined #openstack-operators | 17:32 | |
*** dminer has quit IRC | 18:04 | |
*** Piet has quit IRC | 18:18 | |
*** alop has joined #openstack-operators | 18:18 | |
*** VW has joined #openstack-operators | 18:32 | |
*** VW has quit IRC | 18:33 | |
*** VW has joined #openstack-operators | 18:34 | |
*** VW has quit IRC | 18:34 | |
*** VW has joined #openstack-operators | 18:35 | |
*** VW has quit IRC | 18:39 | |
*** blair has joined #openstack-operators | 18:41 | |
*** blair has quit IRC | 18:41 | |
*** VW has joined #openstack-operators | 18:44 | |
*** harlowja has quit IRC | 18:46 | |
*** gyee_ has quit IRC | 18:47 | |
*** harlowja has joined #openstack-operators | 18:53 | |
*** serverascode has quit IRC | 18:54 | |
*** jraim has quit IRC | 18:54 | |
*** simonmcc has quit IRC | 18:54 | |
*** j05hk has quit IRC | 19:00 | |
*** markvoelker has joined #openstack-operators | 19:08 | |
*** dminer has joined #openstack-operators | 19:09 | |
*** markvoelker has quit IRC | 19:12 | |
*** radez is now known as radez_g0n3 | 19:15 | |
klindgren | dmsimard, couldn't you also fix that by playing with the arp sysctl settings arp_announce and arp_ignore? | 19:22 |
klindgren | EG arp_ignore = 1 1 - reply only if the target IP address is local address | 19:23 |
klindgren | configured on the incoming interface | 19:23 |
klindgren | default is 0 which is reply to any request for any ip configured on any interface | 19:24 |
dmsimard | klindgren: I haven't spent too much time on the whole thing (yet) | 19:24 |
dmsimard | Ideally iptables and ebtables would be managed by neutron and would handle everything gracefully | 19:25 |
dmsimard | But we're not going to see that until Liberty (or Kilo? Haven't checked the commits in a bit) | 19:25 |
klindgren | yea - which btw the last 2 of the 4 patches for that have been abondend now | 19:25 |
dmsimard | How come ? | 19:25 |
klindgren | I dunno | 19:26 |
klindgren | I have been trying to get more info - bascially they rejected the code or concept or something | 19:26 |
dmsimard | Oh haven't I seen something about them wanting to do something "different" than what they implemented for iptables ? | 19:26 |
klindgren | Mark M is going to solve it some other way | 19:26 |
klindgren | I htink the complaints were that an Ebtables manager and an iptables manager did similar stuff and could probably be refactored to use the same code path | 19:27 |
klindgren | or something like that - but I haven't found any links ot the discussion | 19:27 |
klindgren | https://bugs.launchpad.net/neutron/+bug/1274034 | 19:28 |
openstack | Launchpad bug 1274034 in neutron "Neutron firewall anti-spoofing does not prevent ARP poisoning" [High,In progress] - Assigned to Mark McClain (markmcclain) | 19:28 |
klindgren | specifically https://bugs.launchpad.net/neutron/+bug/1274034/comments/56 | 19:28 |
*** leakypipes has quit IRC | 19:34 | |
*** mdorman has quit IRC | 19:50 | |
*** mdorman has joined #openstack-operators | 19:56 | |
*** j05hk has joined #openstack-operators | 20:02 | |
*** rlrevell has quit IRC | 20:03 | |
*** VW has quit IRC | 20:19 | |
*** markvoelker has joined #openstack-operators | 20:24 | |
*** VW has joined #openstack-operators | 20:25 | |
*** markvoelker has quit IRC | 20:28 | |
*** jraim has joined #openstack-operators | 20:38 | |
*** simonmcc has joined #openstack-operators | 20:44 | |
*** serverascode has joined #openstack-operators | 20:50 | |
*** toddnni has joined #openstack-operators | 21:16 | |
*** csoukup has joined #openstack-operators | 21:18 | |
*** VW has quit IRC | 21:18 | |
*** esker has quit IRC | 21:29 | |
*** VW has joined #openstack-operators | 21:29 | |
*** Miouge has quit IRC | 21:37 | |
*** blair has joined #openstack-operators | 21:38 | |
*** Marga_ has joined #openstack-operators | 21:39 | |
*** Marga_ has quit IRC | 21:39 | |
*** Marga_ has joined #openstack-operators | 21:40 | |
*** openstack has joined #openstack-operators | 21:42 | |
*** Piet has joined #openstack-operators | 21:51 | |
*** csoukup has quit IRC | 21:51 | |
*** ToMiles has quit IRC | 21:54 | |
*** matrohon has quit IRC | 22:02 | |
*** markvoelker has joined #openstack-operators | 22:12 | |
*** VW has quit IRC | 22:12 | |
*** VW has joined #openstack-operators | 22:13 | |
*** markvoelker has quit IRC | 22:17 | |
*** VW has quit IRC | 22:25 | |
*** dminer has quit IRC | 22:34 | |
*** jsnow is now known as jsnow[dead] | 22:36 | |
*** j05hk has quit IRC | 22:38 | |
*** rlrevell has joined #openstack-operators | 22:45 | |
*** Marga_ has quit IRC | 22:53 | |
*** bradjones is now known as bradjones_away | 23:00 | |
*** rlrevell has left #openstack-operators | 23:17 | |
*** bradjones_away is now known as bradjones | 23:20 | |
*** bradjones has quit IRC | 23:42 | |
*** bradjones has joined #openstack-operators | 23:42 | |
*** bradjones is now known as bradjones_away | 23:47 | |
*** dboik_ has quit IRC | 23:50 | |
*** bradjones_away is now known as bradjones|away | 23:52 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!