*** armax has joined #openstack-operators | 00:30 | |
*** armax has quit IRC | 00:38 | |
*** armax has joined #openstack-operators | 01:02 | |
*** rebase has joined #openstack-operators | 01:09 | |
*** Rodrigo_BR has joined #openstack-operators | 01:14 | |
*** armax has quit IRC | 01:22 | |
*** VW has quit IRC | 01:41 | |
*** VW has joined #openstack-operators | 01:42 | |
*** zul has quit IRC | 01:43 | |
*** zul has joined #openstack-operators | 01:44 | |
*** Rodrigo_BR has quit IRC | 01:45 | |
*** Apoorva_ has quit IRC | 01:47 | |
*** rebase has quit IRC | 01:54 | |
*** VW_ has joined #openstack-operators | 02:18 | |
*** kukacz has quit IRC | 02:20 | |
*** VW has quit IRC | 02:21 | |
*** karthikpr has joined #openstack-operators | 02:29 | |
*** shewless_ has joined #openstack-operators | 02:33 | |
*** karthikpr has quit IRC | 02:33 | |
*** shashank_t_ has joined #openstack-operators | 02:46 | |
*** raginbajin has quit IRC | 02:47 | |
*** raginbajin has joined #openstack-operators | 02:52 | |
shewless_ | Is the firewall_driver in openvswitchagent.ini just a compute option? | 02:54 |
---|---|---|
shewless_ | I'm trying to figure out which part gets configured on the network node | 02:54 |
shewless_ | I see two relavent files: | 02:55 |
shewless_ | neutron/plugins/ml2/ml2_conf.ini and neutron/plugins/ml2/openvswitch_agent.ini | 02:56 |
shewless_ | anyone know what the significance of firewall_driver is on the network node and those two files? | 02:57 |
*** cemason1 has joined #openstack-operators | 03:03 | |
*** cemason has quit IRC | 03:03 | |
*** shewless_ has quit IRC | 03:04 | |
*** fandi has joined #openstack-operators | 03:53 | |
*** karthikpr has joined #openstack-operators | 04:09 | |
*** marst has joined #openstack-operators | 04:31 | |
*** haplo37 has quit IRC | 04:59 | |
*** fragatin_ has joined #openstack-operators | 05:01 | |
*** fragati__ has joined #openstack-operators | 05:03 | |
*** fragatina has quit IRC | 05:05 | |
*** fragatin_ has quit IRC | 05:06 | |
*** fandi has quit IRC | 05:07 | |
*** fragati__ has quit IRC | 05:07 | |
*** haplo37 has joined #openstack-operators | 05:08 | |
*** armax has joined #openstack-operators | 05:11 | |
*** arnewiebalck_ has joined #openstack-operators | 05:12 | |
*** karthikpr has quit IRC | 05:20 | |
*** fragatina has joined #openstack-operators | 05:21 | |
*** fragatina has quit IRC | 05:25 | |
*** fragatina has joined #openstack-operators | 05:33 | |
*** fragatina has quit IRC | 05:33 | |
*** fragatina has joined #openstack-operators | 05:34 | |
*** shashank_t_ has quit IRC | 05:53 | |
*** yprokule has joined #openstack-operators | 05:53 | |
*** karthikpr has joined #openstack-operators | 05:55 | |
*** shashank_t_ has joined #openstack-operators | 05:59 | |
*** karthikpr has quit IRC | 05:59 | |
*** shashank_t_ has quit IRC | 06:03 | |
*** arnewiebalck_ has quit IRC | 06:09 | |
*** aojea has joined #openstack-operators | 06:12 | |
*** aojea has quit IRC | 06:18 | |
*** armax has quit IRC | 06:29 | |
*** manheim has joined #openstack-operators | 07:22 | |
*** manheim has quit IRC | 07:22 | |
*** manheim has joined #openstack-operators | 07:23 | |
*** tesseract has joined #openstack-operators | 07:31 | |
*** simon-AS559 has joined #openstack-operators | 07:45 | |
*** belmoreira has joined #openstack-operators | 07:59 | |
*** simon-AS559 has quit IRC | 08:03 | |
*** simon-AS559 has joined #openstack-operators | 08:16 | |
*** mriedem has quit IRC | 08:16 | |
*** aojea has joined #openstack-operators | 08:18 | |
*** aojea has quit IRC | 08:18 | |
*** aojea has joined #openstack-operators | 08:19 | |
*** manheim has quit IRC | 08:33 | |
*** treiz has joined #openstack-operators | 09:02 | |
*** manheim has joined #openstack-operators | 09:03 | |
*** aojea_ has joined #openstack-operators | 09:10 | |
*** aojea has quit IRC | 09:12 | |
*** racedo has joined #openstack-operators | 09:21 | |
*** dbecker has joined #openstack-operators | 09:30 | |
*** derekh has joined #openstack-operators | 09:33 | |
yankcrime | shewless: possibly related to fwaas? | 09:40 |
*** electrofelix has joined #openstack-operators | 09:41 | |
*** pcaruana has joined #openstack-operators | 10:05 | |
*** karthik__ has joined #openstack-operators | 10:16 | |
*** shewless has quit IRC | 10:18 | |
*** karthik__ has quit IRC | 10:21 | |
*** manheim has quit IRC | 10:24 | |
*** manheim has joined #openstack-operators | 10:26 | |
*** karthikpr has joined #openstack-operators | 10:33 | |
*** manheim has quit IRC | 10:35 | |
*** manheim has joined #openstack-operators | 10:36 | |
*** karthikpr has quit IRC | 10:38 | |
*** karthikpr has joined #openstack-operators | 10:50 | |
*** karthikpr has quit IRC | 10:54 | |
*** armax has joined #openstack-operators | 11:02 | |
*** karthikpr has joined #openstack-operators | 11:07 | |
*** Dinesh_Bhor has quit IRC | 11:07 | |
*** karthikpr has quit IRC | 11:11 | |
*** armax has quit IRC | 11:16 | |
*** Dinesh_Bhor has joined #openstack-operators | 11:20 | |
*** alexpilotti has quit IRC | 11:40 | |
*** alexpilotti has joined #openstack-operators | 11:41 | |
*** alexpilotti has quit IRC | 11:45 | |
*** alexpilotti has joined #openstack-operators | 12:13 | |
*** karthikpr has joined #openstack-operators | 12:17 | |
*** karthikpr has quit IRC | 12:18 | |
*** manheim has quit IRC | 12:20 | |
*** manheim has joined #openstack-operators | 12:21 | |
*** d0ugal has quit IRC | 12:24 | |
*** liverpooler has quit IRC | 12:26 | |
*** liverpooler has joined #openstack-operators | 12:26 | |
*** racedo has quit IRC | 12:34 | |
*** shewless has joined #openstack-operators | 13:01 | |
*** karthik__ has joined #openstack-operators | 13:03 | |
*** karthik__ has quit IRC | 13:04 | |
*** mriedem has joined #openstack-operators | 13:06 | |
*** karthikpr has joined #openstack-operators | 13:07 | |
*** karthikpr has quit IRC | 13:11 | |
*** cemason1 has quit IRC | 13:11 | |
*** cemason has joined #openstack-operators | 13:15 | |
*** manheim has quit IRC | 13:21 | |
*** karthikpr has joined #openstack-operators | 13:34 | |
*** karthikpr has quit IRC | 13:38 | |
*** Dinesh_Bhor has quit IRC | 13:39 | |
*** manheim has joined #openstack-operators | 13:42 | |
*** jamesdenton has joined #openstack-operators | 13:43 | |
*** d0ugal has joined #openstack-operators | 13:45 | |
*** dansmith is now known as superdan | 13:49 | |
*** rebase has joined #openstack-operators | 13:51 | |
*** karthikpr has joined #openstack-operators | 13:53 | |
*** rebase has quit IRC | 13:55 | |
*** VW_ has quit IRC | 13:57 | |
*** karthikpr has quit IRC | 13:58 | |
*** alexpilotti has quit IRC | 13:58 | |
*** alexpilotti has joined #openstack-operators | 13:59 | |
*** kstev has joined #openstack-operators | 13:59 | |
*** alexpilotti has quit IRC | 14:03 | |
*** racedo has joined #openstack-operators | 14:17 | |
*** jbadiapa has quit IRC | 14:18 | |
*** alexpilotti has joined #openstack-operators | 14:20 | |
*** electrofelix has quit IRC | 14:21 | |
*** electrofelix has joined #openstack-operators | 14:21 | |
*** shashank_t_ has joined #openstack-operators | 14:22 | |
*** VW has joined #openstack-operators | 14:25 | |
*** chlong has joined #openstack-operators | 14:25 | |
*** yprokule has quit IRC | 14:30 | |
*** jbadiapa has joined #openstack-operators | 14:33 | |
zioproto | hello all. I have a Openstack Heat problem. I want as an admin list all the heat stacks for all the tenants. If I try to do the command "openstack stack list --all-projects" I get a funny error "ERROR: You are not authorized to use global_index." | 14:34 |
zioproto | with the legacy "heat" client I dont see any command line option to list all tenants | 14:34 |
*** jsheeren has joined #openstack-operators | 14:36 | |
zioproto | maybe I found the problem ... policy.json | 14:37 |
*** electrofelix has quit IRC | 14:38 | |
*** electrofelix has joined #openstack-operators | 14:38 | |
*** electrofelix has quit IRC | 14:41 | |
*** electrofelix has joined #openstack-operators | 14:41 | |
*** marst has quit IRC | 14:41 | |
zioproto | I fixed it ! "stacks:global_index": "rule:context_is_admin", in the policy.json where context_is_admin is defined as "context_is_admin": "role:admin", | 14:45 |
zioproto | but I had to figure it out from https://ask.openstack.org/en/question/91180/magnum-bay-create-timeout-you-are-not-authorized-to-use-global_index/ that talks about something else | 14:46 |
*** fragatina has quit IRC | 14:47 | |
*** marst has joined #openstack-operators | 14:49 | |
*** erhudy has quit IRC | 14:50 | |
*** fragatina has joined #openstack-operators | 14:53 | |
*** karthikpr has joined #openstack-operators | 14:55 | |
*** haplo37 has quit IRC | 14:55 | |
*** jbadiapa has quit IRC | 14:55 | |
*** jbadiapa has joined #openstack-operators | 14:56 | |
*** alexpilo_ has joined #openstack-operators | 14:57 | |
*** Vivek__ is now known as Vivek | 14:58 | |
*** Vivek has quit IRC | 14:58 | |
*** Vivek has joined #openstack-operators | 14:58 | |
*** alexpilotti has quit IRC | 14:58 | |
*** alexpilo_ has quit IRC | 15:02 | |
*** haplo37 has joined #openstack-operators | 15:05 | |
*** alexpilotti has joined #openstack-operators | 15:06 | |
*** karthikpr has quit IRC | 15:08 | |
*** jsheeren has quit IRC | 15:10 | |
*** rebase has joined #openstack-operators | 15:13 | |
*** rebase has quit IRC | 15:18 | |
zioproto | yankcrime: Now I know why I hit every upgrade this collate issues. The puppet modules are changing my settings: https://github.com/openstack/puppet-openstacklib/blob/master/manifests/db/mysql.pp#L59 | 15:29 |
klindgren | Is anyone here configuring neutron-openvswitch-agent to use ovsdb vs's using rootwrap for ovs configuration options? | 15:45 |
*** gyee has joined #openstack-operators | 15:45 | |
klindgren | THe documentation on how to do this is......... lacking...... to say the least. | 15:45 |
*** rebase has joined #openstack-operators | 15:48 | |
*** d0ugal has quit IRC | 15:52 | |
*** manheim has quit IRC | 15:56 | |
*** manheim has joined #openstack-operators | 15:56 | |
*** rebase has quit IRC | 15:59 | |
*** rebase has joined #openstack-operators | 15:59 | |
*** manheim has quit IRC | 16:01 | |
*** pcaruana has quit IRC | 16:03 | |
*** manheim has joined #openstack-operators | 16:13 | |
*** d0ugal has joined #openstack-operators | 16:14 | |
*** d0ugal has quit IRC | 16:14 | |
*** d0ugal has joined #openstack-operators | 16:14 | |
*** Oku_OS is now known as Oku_OS-away | 16:15 | |
*** belmoreira has quit IRC | 16:21 | |
*** manheim has quit IRC | 16:22 | |
*** d0ugal has quit IRC | 16:22 | |
*** manheim has joined #openstack-operators | 16:22 | |
*** manheim has quit IRC | 16:27 | |
*** shashank_t_ has quit IRC | 16:35 | |
*** shashank_t_ has joined #openstack-operators | 16:35 | |
*** kstev has quit IRC | 16:38 | |
*** Apoorva has joined #openstack-operators | 16:42 | |
*** Apoorva has quit IRC | 16:42 | |
*** Apoorva has joined #openstack-operators | 16:42 | |
*** fragatina has quit IRC | 16:46 | |
*** simon-AS559 has quit IRC | 16:52 | |
*** kstev has joined #openstack-operators | 16:54 | |
*** aojea_ has quit IRC | 16:56 | |
yankcrime | lol zioproto | 16:56 |
yankcrime | (╯°□°)╯︵ ┻━┻ | 16:56 |
*** racedo has quit IRC | 16:57 | |
*** makowals has quit IRC | 17:00 | |
shewless | Hi guys. Have you ever seen conntrack go out of control on your compute nodes? To the point where networking fails? | 17:08 |
shewless | If I'm using hybridiptables for my firewall_driver can I blacklist the conntrac? | 17:08 |
*** electrofelix has quit IRC | 17:13 | |
*** catintheroof has joined #openstack-operators | 17:14 | |
*** catintheroof has quit IRC | 17:15 | |
*** catintheroof has joined #openstack-operators | 17:15 | |
*** makowals has joined #openstack-operators | 17:17 | |
*** d0ugal has joined #openstack-operators | 17:17 | |
*** racedo has joined #openstack-operators | 17:20 | |
*** simon-AS559 has joined #openstack-operators | 17:21 | |
shewless | anyone? I'm seeing over 500,000 conntrack connections on each compute.. getting crazy! | 17:23 |
*** simon-AS5591 has joined #openstack-operators | 17:23 | |
*** simon-AS559 has quit IRC | 17:26 | |
admin0 | just ? | 17:26 |
admin0 | shewless: our alerting is at 2 mil conntrack connections | 17:27 |
shewless | admin0: that info helps! so it's acceptable to bump the max I guess :D | 17:27 |
shewless | (in your experience) | 17:27 |
admin0 | yes | 17:31 |
admin0 | but if its out of the blue, you have an abuser, or a victim | 17:31 |
admin0 | of ddos | 17:31 |
admin0 | we graph all conntrack per compute nodes and then we can isolate from where its coming from | 17:31 |
admin0 | or going to | 17:31 |
*** marst has quit IRC | 17:37 | |
yankcrime | shewless: yes | 17:40 |
yankcrime | it's usually, as admin0 says, the sign of a compromised vm or abusive behaviour (i.e a spammer) | 17:40 |
*** derekh has quit IRC | 17:40 | |
admin0 | or a new customer who is running a new blog that has links to some most-wanted HD videos, or someone running his haproxy | 17:41 |
shewless | yankcrime, admin0: any recommendations to isolate the abuser? We can isolate to compute node already but not sure how to further drill down to instance | 17:42 |
admin0 | you can look into the conntrack table | 17:42 |
admin0 | and do some sort, awk magic | 17:42 |
shewless | are you using linux bridge networking? | 17:42 |
admin0 | conntrack -L | bash-magic :) | 17:43 |
shewless | admin0: thanks. Would I be looking to isolate by mac or instance id or something? | 17:43 |
shewless | Am I just looking for the thing that has the most entries? | 17:44 |
admin0 | things that has most entries | 17:44 |
yankcrime | yeah we've some messy bit of python that narrows down the abuser | 17:44 |
shewless | okay let me have a look | 17:45 |
shewless | but you are both using linux bridge I take it? | 17:45 |
shewless | no option to "blacklist" conntrack? | 17:45 |
yankcrime | OVS in our case | 17:45 |
shewless | yankcrime: hmm. I didn't think you needed conntrack with OVS | 17:45 |
yankcrime | well, we still have linux bridges | 17:45 |
shewless | are you using the hybridiptables firewall_driver? | 17:46 |
yankcrime | in order to apply iptables rules for security groups | 17:46 |
shewless | Ah.. so that's what I know as the hybridiptables firewall_driver | 17:46 |
shewless | why not just use the openvswitch to do that? it should work with newer versions of OVS right? | 17:46 |
admin0 | i am linux-bridge | 17:47 |
yankcrime | there's been some progress in that area, but the version of openstack and ovs we're on means you still need linux bridges in the mix in order to be able to apply rules to vm's tap devices | 17:48 |
shewless | yankcrime: thanks.. that's what we're doing too.. though I want to move to straight ovs | 17:48 |
shewless | admin0: thanks for the info. | 17:49 |
*** manheim has joined #openstack-operators | 17:49 | |
*** manheim has quit IRC | 17:49 | |
*** tesseract has quit IRC | 17:50 | |
*** manheim has joined #openstack-operators | 17:50 | |
*** alexpilotti has quit IRC | 17:52 | |
*** alexpilotti has joined #openstack-operators | 17:52 | |
shewless | yankcrime, admin0: do you guys know: if I create a network with port security disabled AND I'm using OVS + linux bridge for firewall: will this traffic go through conntrack? | 17:56 |
*** rebase has quit IRC | 17:59 | |
*** rebase has joined #openstack-operators | 17:59 | |
*** marst has joined #openstack-operators | 18:01 | |
shewless | yankcrime, admin0: also. my conntrack -L is showing me a bunch of IP addresses that seem to be local to the instance. Since my stacks use the same ip ranges for the most part I'm not sure how I can track down the offender. Are there any other optoins to use with -L? | 18:02 |
*** alexpilotti has quit IRC | 18:10 | |
*** manheim has quit IRC | 18:14 | |
*** manheim has joined #openstack-operators | 18:15 | |
*** d0ugal has quit IRC | 18:17 | |
yankcrime | shewless: pretty sure iptables is still involved, it just disables the anti-spoofing rules for that particular port | 18:17 |
shewless | yankcrime: darn. So I expect users to send a lot of traffic | 18:18 |
shewless | so I guess just increase conntrack | 18:18 |
yankcrime | and in our case for the tests we perform we actually parse /proc/sys/net/netfilter/nf_conntrack_max directly | 18:18 |
shewless | do you mean /proc/net/ip_conntrack? | 18:19 |
yankcrime | and then the conntrack output we use is 'conntrack -L -o xml' | 18:19 |
yankcrime | iirc there's not that many options to userland conntrack tool | 18:20 |
*** dtrainor has quit IRC | 18:21 | |
shewless | yankcrime: do you know if you need the firewall_driver set on the controller/network node or just the compute nodes? | 18:21 |
*** manheim has quit IRC | 18:24 | |
*** chlong has quit IRC | 18:24 | |
shewless | admin0, yankcrime: does "a lot of traffic" always equal a lot of conntrack connections? | 18:29 |
shewless | Is there any case where that is not true? | 18:29 |
admin0 | it does not :) | 18:30 |
admin0 | lots of connects = not lots of traffic | 18:30 |
admin0 | i can use iperf, 5 -10 connections and choke the traffic out | 18:31 |
shewless | admin0: ah I see.. lots of connections.. got it | 18:31 |
admin0 | in a while true loop .. | 18:31 |
yankcrime | yup, the problem here is not throughput - it's the number of connections and their states that need to be tracked | 18:31 |
yankcrime | "a lot of traffic" can mean a variety of things ;) | 18:31 |
yankcrime | dunno about that firewall driver offhand, i'd have to check | 18:32 |
shewless | yankcrime, admin0: I see this: | 18:35 |
shewless | tcp 6 428035 ESTABLISHED src=10.0.3.88 dst=10.0.6.148 sport=42730 dport=1723 src=10.0.6.148 dst=10.0.3.88 sport=1723 dport=42730 [ASSURED] mark=0 use=1 tcp 6 427137 ESTABLISHED src=10.0.3.3 dst=10.0.4.185 sport=27763 dport=56649 src=10.0.4.185 dst=10.0.3.3 sport=56649 dport=27763 [ASSURED] mark=0 use=1 tcp 6 426106 ESTABLISHED src=10.0.1.156 dst=10.0.2.246 sport=52167 dport=1723 src=10.0.2.246 dst=10.0.1.1 | 18:35 |
shewless | any idea how I can track down what's using 10.0.X.X? | 18:35 |
*** dtrainor has joined #openstack-operators | 18:38 | |
*** shashank_t_ has quit IRC | 18:40 | |
*** racedo has quit IRC | 18:41 | |
*** arnewiebalck_ has joined #openstack-operators | 18:45 | |
*** dtrainor has quit IRC | 18:46 | |
*** shashank_t_ has joined #openstack-operators | 18:50 | |
*** racedo has joined #openstack-operators | 18:51 | |
*** dtrainor has joined #openstack-operators | 18:52 | |
shewless | yankcrime, admin0: do you know what the repercussions would be if I completely disable/blacklist conntrack? | 18:55 |
*** rebase has quit IRC | 18:58 | |
shewless | also. is it possible to flag a network in openstack to use the NOTRACK option? | 19:14 |
shewless | something like iptables -t raw -A PREROUTING -d 22.33.44.55 -p tcp --dport 80 -j NOTRACK | 19:14 |
shewless | could I manually add some raw PREROUTING entries to my computes? | 19:17 |
shewless | something like | 19:17 |
shewless | iptables -t raw -A PREROUTING -s 172.20.0.0/16 -d 172.20.0.0/16 -j NOTRACK | 19:18 |
*** arnewiebalck_ has quit IRC | 19:20 | |
*** erhudy has joined #openstack-operators | 19:20 | |
*** racedo has quit IRC | 19:22 | |
*** racedo has joined #openstack-operators | 19:25 | |
*** shashank_t_ has quit IRC | 19:27 | |
*** shashank_t_ has joined #openstack-operators | 19:27 | |
*** shashank_t_ has quit IRC | 19:31 | |
klindgren | So the issue with using notrack is that you have to portit both the inbound and outbound (related connection) via notrack | 19:31 |
klindgren | most firewall rules permit either the inbound or the outbound part then uses --state established, related | 19:32 |
klindgren | or something similar. But we notrack ssh, and other important for the compute node to work connections | 19:32 |
klindgren | You can also adjust the number of tables and the size of the top level hash in real time. as well. | 19:33 |
klindgren | you have to specifically allow intbound/outbound. | 19:34 |
*** arnewiebalck_ has joined #openstack-operators | 19:34 | |
klindgren | IE doing: iptables -t raw -A PREROUTING -s 172.20.0.0/16 -d 172.20.0.0/16 -j NOTRACK will notrack the connections | 19:34 |
admin0 | back .. was driving | 19:34 |
admin0 | you can opt to not track, but you will then be unable to detect abusers until too late .. or you will suddenly find a lot of cpu usage, but no visible proces, because the CPUs are busy with interrupts and context switches | 19:35 |
klindgren | but if you are relying on established,related, such as iptables -I INPUT -s 172.20.0.0./16 --dport 22 -j ACCEPT, iirc y also need to add the iptables -O OUTPUT -d 172.20.0.0/16 --sport 22 -j ACCEPT | 19:38 |
shewless | hmm. | 19:38 |
klindgren | because connection tracking job is to make it easier to allow both sides of connections through. | 19:39 |
shewless | My problem is that I am providing stacks that utilize traffic simulation tools to send traffic over a private network to other instances | 19:40 |
shewless | the private network has port security disabled completely | 19:40 |
shewless | the traffic tools may simulate hundreds of connections.. | 19:40 |
klindgren | pretty sure it still has anti-spoofing rules enabled? | 19:40 |
shewless | klindgren: probably.. not sure exactly what that means but it seems to be going through conntrack | 19:41 |
klindgren | iptables-save | grep magic | 19:41 |
klindgren | look for neutron-s(some-id) | 19:41 |
klindgren | is anti spoofing | 19:42 |
klindgren | neutron-o(some-id) is outbound | 19:42 |
klindgren | neutron-i(some-id) is inbound | 19:42 |
klindgren | also tap(some-id-with-one-more-digit) is the vm's tap device | 19:44 |
shewless | lots of "neutron-openvswi-" entries.. no neutron-s or neutron-i | 19:44 |
shewless | klindgren: lots of neutron-openvswi-o, -s, and -i | 19:46 |
klindgren | ah | 19:46 |
shewless | not sure what that means though.. I guess it means antispoof? | 19:46 |
klindgren | so if you grep for the vm ip | 19:46 |
klindgren | you should find -s rules | 19:47 |
klindgren | which try to make sure it has the correct mac address | 19:47 |
shewless | is that why conntrack is needed? | 19:47 |
shewless | klindgren: actually there are no rules in iptables-save for my "dataplane" Ip range | 19:50 |
*** slaweq has quit IRC | 19:52 | |
klindgren | yea thts why contrack is needed. because of the established,related allows in the -i rules for vm's | 19:52 |
klindgren | once its enabled all connections by default are tracked. | 19:53 |
*** slaweq has joined #openstack-operators | 19:53 | |
shewless | so in my case.. where I don't really need anything special on this private network, should i just increase the conntrack limit to a huge number or should I try and notrack certain ranges? | 19:54 |
*** liverpooler has quit IRC | 19:55 | |
*** slaweq has quit IRC | 19:58 | |
*** racedo has quit IRC | 20:05 | |
*** slaweq has joined #openstack-operators | 20:06 | |
*** aojea has joined #openstack-operators | 20:18 | |
*** arnewiebalck_ has quit IRC | 20:26 | |
*** armax has joined #openstack-operators | 20:29 | |
*** kstev has quit IRC | 20:38 | |
*** jamesdenton has quit IRC | 21:01 | |
klindgren | sorry - just coming back to this. Thats what I would do. | 21:03 |
klindgren | You can also adjust the connection tracking tables timeouts for things as well | 21:04 |
klindgren | so that some rules stick around for less time. | 21:04 |
klindgren | like syn sent and the like | 21:04 |
*** aojea has quit IRC | 21:06 | |
*** rebase has joined #openstack-operators | 21:07 | |
*** beddari has quit IRC | 21:14 | |
*** shasha_t_ has quit IRC | 21:21 | |
*** aojea has joined #openstack-operators | 21:22 | |
*** fragatina has joined #openstack-operators | 21:29 | |
*** rebase has quit IRC | 22:11 | |
*** rebase has joined #openstack-operators | 22:12 | |
*** emerson has joined #openstack-operators | 22:37 | |
*** simon-AS5591 has quit IRC | 22:38 | |
*** arnewiebalck_ has joined #openstack-operators | 22:52 | |
*** aojea has quit IRC | 22:59 | |
*** erhudy has quit IRC | 23:00 | |
*** arnewiebalck_ has quit IRC | 23:11 | |
*** VW_ has joined #openstack-operators | 23:11 | |
*** VW has quit IRC | 23:14 | |
*** VW_ has quit IRC | 23:15 | |
zioproto | shewless: just to check the obvious things. Read about conntrack kernel tunables here https://wiki.openstack.org/wiki/Documentation/HypervisorTuningGuide - do you have reasonable settings ? | 23:23 |
*** markvoelker has quit IRC | 23:24 | |
*** jamesden_ has joined #openstack-operators | 23:35 | |
*** racedo has joined #openstack-operators | 23:37 | |
*** racedo has quit IRC | 23:42 | |
*** jamesden_ has quit IRC | 23:53 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!