*** skyraven has joined #openstack | 00:00 | |
*** skyraven has quit IRC | 00:08 | |
*** skyraven has joined #openstack | 00:09 | |
*** d34dh0r53 has quit IRC | 00:14 | |
*** skyraven has quit IRC | 00:14 | |
*** shokohsc has joined #openstack | 00:31 | |
*** imega has quit IRC | 00:48 | |
*** nurdie has joined #openstack | 00:55 | |
*** gyee has quit IRC | 00:58 | |
*** nurdie has quit IRC | 01:00 | |
*** brokencycle has quit IRC | 01:10 | |
*** wings has quit IRC | 01:31 | |
*** wings has joined #openstack | 01:33 | |
*** f0o has quit IRC | 01:37 | |
*** f0o has joined #openstack | 01:38 | |
*** spsurya has quit IRC | 02:03 | |
*** skyraven has joined #openstack | 02:10 | |
*** skyraven has quit IRC | 02:15 | |
*** k_mouza has quit IRC | 02:30 | |
*** d34dh0r53 has joined #openstack | 02:55 | |
*** Onionnion has joined #openstack | 02:59 | |
*** rvd has joined #openstack | 03:54 | |
*** idlemind has joined #openstack | 04:00 | |
*** skyraven has joined #openstack | 04:11 | |
*** Lucas_Gray has joined #openstack | 04:16 | |
*** skyraven has quit IRC | 04:16 | |
*** bobmel has joined #openstack | 04:50 | |
*** bobmel has quit IRC | 04:55 | |
*** pbing19 has joined #openstack | 05:04 | |
*** Lucas_Gray has quit IRC | 05:29 | |
*** links has joined #openstack | 05:30 | |
*** soniya29 has joined #openstack | 05:35 | |
*** surpatil has joined #openstack | 05:46 | |
*** pbing19 has quit IRC | 05:58 | |
*** pbing19 has joined #openstack | 05:58 | |
*** skyraven has joined #openstack | 06:12 | |
*** skyraven has quit IRC | 06:17 | |
*** shyamb has joined #openstack | 06:23 | |
*** sauvin has joined #openstack | 06:25 | |
*** pbing19 has quit IRC | 06:34 | |
*** pbing19 has joined #openstack | 06:36 | |
*** ymasson has quit IRC | 06:43 | |
*** nurdie has joined #openstack | 06:47 | |
*** nurdie has quit IRC | 06:51 | |
*** SurajPatil has joined #openstack | 06:59 | |
*** surpatil has quit IRC | 07:02 | |
*** surpatil has joined #openstack | 07:11 | |
*** pbing19 has quit IRC | 07:11 | |
*** pbing19 has joined #openstack | 07:12 | |
*** SurajPatil has quit IRC | 07:13 | |
*** shyamb has quit IRC | 07:17 | |
*** shyamb has joined #openstack | 07:19 | |
*** E1ephant has quit IRC | 07:28 | |
*** cah_link has joined #openstack | 07:29 | |
*** shyamb has quit IRC | 07:31 | |
*** mn3m has quit IRC | 07:49 | |
*** maddtux has joined #openstack | 07:51 | |
*** Domin has quit IRC | 07:53 | |
*** shyamb has joined #openstack | 08:01 | |
*** skyraven has joined #openstack | 08:03 | |
*** jtomasek has joined #openstack | 08:04 | |
*** shyamb has quit IRC | 08:05 | |
*** bengates has joined #openstack | 08:08 | |
*** ArchiFleKs has joined #openstack | 08:12 | |
*** tesseract has joined #openstack | 08:14 | |
*** shyamb has joined #openstack | 08:30 | |
*** Lucas_Gray has joined #openstack | 08:34 | |
*** pcaruana has joined #openstack | 08:35 | |
*** rpittau|afk is now known as rpittau | 08:41 | |
*** Lucas_Gray has quit IRC | 08:48 | |
*** Domin has joined #openstack | 08:51 | |
*** shyam89 has joined #openstack | 08:52 | |
*** shyamb has quit IRC | 08:52 | |
*** bobmel has joined #openstack | 08:52 | |
*** bl0m1 has quit IRC | 08:54 | |
*** bl0m1 has joined #openstack | 08:56 | |
*** bobmel has quit IRC | 08:57 | |
*** bl0m1 has quit IRC | 08:58 | |
*** Lucas_Gray has joined #openstack | 08:58 | |
*** bl0m1 has joined #openstack | 08:58 | |
*** wings has quit IRC | 09:15 | |
*** Lucas_Gray has quit IRC | 09:26 | |
*** alexmcleod has joined #openstack | 09:42 | |
*** Lucas_Gray has joined #openstack | 09:44 | |
*** SurajPatil has joined #openstack | 09:59 | |
*** arnoldoree has joined #openstack | 10:01 | |
*** surpatil has quit IRC | 10:02 | |
*** rohitsakala has joined #openstack | 10:11 | |
*** k_mouza has joined #openstack | 10:25 | |
*** pbing19 has quit IRC | 10:31 | |
*** surpatil has joined #openstack | 10:32 | |
*** pbing19 has joined #openstack | 10:32 | |
*** shyam89 has quit IRC | 10:34 | |
*** SurajPatil has quit IRC | 10:34 | |
*** imega has joined #openstack | 10:49 | |
*** rvd has quit IRC | 10:57 | |
*** SurajPatil has joined #openstack | 10:59 | |
*** surpatil has quit IRC | 11:02 | |
*** shyamb has joined #openstack | 11:06 | |
*** surpatil has joined #openstack | 11:09 | |
*** SurajPatil has quit IRC | 11:12 | |
*** Lucas_Gray has quit IRC | 11:13 | |
*** vxwarlock has joined #openstack | 11:18 | |
*** Lucas_Gray has joined #openstack | 11:26 | |
*** Lucas_Gray has quit IRC | 11:31 | |
*** Lucas_Gray has joined #openstack | 11:32 | |
*** Lucas_Gray has quit IRC | 11:34 | |
*** Lucas_Gray has joined #openstack | 11:34 | |
*** pbing19 has quit IRC | 11:44 | |
*** shyamb has quit IRC | 11:45 | |
*** bobmel has joined #openstack | 11:47 | |
*** Lucas_Gray has quit IRC | 11:58 | |
*** tonythomas has joined #openstack | 12:05 | |
*** devfaz has quit IRC | 12:08 | |
*** devfaz has joined #openstack | 12:09 | |
*** Lucas_Gray has joined #openstack | 12:11 | |
*** SurajPatil has joined #openstack | 12:12 | |
*** pbing19 has joined #openstack | 12:14 | |
*** surpatil has quit IRC | 12:14 | |
*** servagem has joined #openstack | 12:14 | |
*** SirNeo has quit IRC | 12:15 | |
*** Lucas_Gray has quit IRC | 12:20 | |
*** rohitsakala has quit IRC | 12:21 | |
*** slaweq has joined #openstack | 12:27 | |
*** shyamb has joined #openstack | 12:27 | |
*** dviroel has joined #openstack | 12:36 | |
*** cyclaw has quit IRC | 12:37 | |
*** gentoorax has joined #openstack | 12:38 | |
*** slaweq has quit IRC | 12:42 | |
*** slaweq has joined #openstack | 12:50 | |
*** surpatil has joined #openstack | 13:06 | |
*** slaweq has quit IRC | 13:06 | |
*** SurajPatil has quit IRC | 13:08 | |
*** bobmel has quit IRC | 13:11 | |
*** shyamb has quit IRC | 13:21 | |
*** pbing19 has quit IRC | 13:22 | |
*** slaweq has joined #openstack | 13:26 | |
*** pbing19 has joined #openstack | 13:28 | |
*** soniya29 has quit IRC | 13:31 | |
*** slaweq has quit IRC | 13:32 | |
*** slaweq has joined #openstack | 13:49 | |
*** slaweq has quit IRC | 13:53 | |
*** surpatil has quit IRC | 13:56 | |
*** links has quit IRC | 14:42 | |
*** pbing19 has quit IRC | 14:48 | |
*** henriqueof has joined #openstack | 14:57 | |
*** slaweq has joined #openstack | 14:57 | |
*** pbing19 has joined #openstack | 15:02 | |
*** henriqueof has quit IRC | 15:03 | |
*** henriqueof has joined #openstack | 15:03 | |
*** renich has joined #openstack | 15:24 | |
*** coboluxx has quit IRC | 15:27 | |
*** slaweq has quit IRC | 15:29 | |
*** renich has quit IRC | 15:33 | |
*** nurdie has joined #openstack | 15:37 | |
*** shortparry has joined #openstack | 15:42 | |
*** shortparry has quit IRC | 15:45 | |
*** shortparry has joined #openstack | 15:47 | |
*** pbing19 has quit IRC | 16:02 | |
*** shyamb has joined #openstack | 16:13 | |
*** bengates has quit IRC | 16:26 | |
*** bengates has joined #openstack | 16:27 | |
*** bengates has quit IRC | 16:27 | |
*** maddtux has quit IRC | 16:27 | |
*** pbing19 has joined #openstack | 16:27 | |
*** takamatsu has joined #openstack | 16:37 | |
*** k_mouza has quit IRC | 16:37 | |
*** Onionnion has quit IRC | 16:39 | |
*** gentoorax is now known as cyclaw | 16:39 | |
*** thorre has quit IRC | 16:41 | |
*** thorre has joined #openstack | 16:41 | |
*** shortparry has quit IRC | 16:43 | |
*** henriqueof has quit IRC | 16:44 | |
*** ymasson has joined #openstack | 16:46 | |
*** shyamb has quit IRC | 16:46 | |
*** imega has quit IRC | 16:54 | |
*** gyee has joined #openstack | 17:03 | |
*** links has joined #openstack | 17:06 | |
*** cah_link has quit IRC | 17:16 | |
*** rpittau is now known as rpittau|afk | 17:18 | |
*** jathan has joined #openstack | 17:28 | |
*** nurdie_ has joined #openstack | 17:31 | |
*** quantomworks has joined #openstack | 17:33 | |
*** pbing19 has quit IRC | 17:33 | |
*** pbing19 has joined #openstack | 17:33 | |
quantomworks | Confused. How would one go about blacklisting an IP Address when using octavia loadbalancer? Do security groups work? Last I tried, it didn't have any effect since the only address that needed to be whitelisted was the loadbalancer on the same private network. | 17:35 |
---|---|---|
*** nurdie has quit IRC | 17:35 | |
*** nurdie_ has quit IRC | 17:37 | |
*** jonaspaulo has joined #openstack | 17:38 | |
johnsom | quantomworks There are a few ways to do this. | 17:41 |
quantomworks | I'm all ears | 17:41 |
quantomworks | Currently using proxy protocl + nginx to yeild restrictions | 17:41 |
johnsom | quantomworks If you are running the Train release or newer, there is an ACL API available on the listener. | 17:41 |
quantomworks | protocol* | 17:41 |
quantomworks | We are unfortunentally on Stein right now | 17:41 |
*** spiral has joined #openstack | 17:44 | |
johnsom | quantomworks If not, then you can use a security group on a floating IP that points to the VIP or use TLS to block requests with no client certificate | 17:44 |
quantomworks | That's what I was afraid of. If I have to use a floating IP instead of a loadbalancer I have to made some heavy adjustments... | 17:44 |
johnsom | quantomworks Finally, you can use an L7 policy and rule to blacklist an address based on the HTTP header fields | 17:44 |
quantomworks | Ah that may be an option. Less adjustments. | 17:45 |
johnsom | quantomworks Oh, no, you would still use the load balancer, just point a floating IP at it | 17:45 |
*** pbing19 has quit IRC | 17:45 | |
quantomworks | Really? How would I apply a security group on a floating IP? | 17:45 |
quantomworks | I thought they were project wide/utilized by instance | 17:45 |
johnsom | quantomworks i.e. create a private network with no access for the load balancer VIP, then point a floating IP to that VIP | 17:45 |
quantomworks | Hmm. Last time I tried to put a lb on a different subnet than my instances I would get nothing but timeouts. I didn't investigate far though and was also trying to use an office network that was setup/had a tunnel attached. There may have been other factors... | 17:47 |
johnsom | quantomworks Well, maybe you didn't use Octavia before? With Octavia it is very common to have the VIP and members on different networks | 17:48 |
quantomworks | We are using Octavia at this time and the last I tried. I also tried it with a separate private network, but in both scenarios they did have a gateway on the network/subnet so they did have access. I wonder if thats a factor... | 17:49 |
*** alexmcleod has quit IRC | 17:50 | |
johnsom | quantomworks member server networks don't require a gateway for load balancers to access them. Did you specify a subnet when you created the members? If you didn't do that you required them to be on the VIP subnet. | 17:51 |
quantomworks | When I created the LB I specified a subnet last I tested. If all I need is the network then I will attempt it this way during our down time. | 17:56 |
johnsom | Well, you specify a subnet at both LB creation time, then optionally at member create time if the member is not located on the VIP subnet. | 17:57 |
quantomworks | What do you mean? | 17:59 |
quantomworks | Ah nevermind I see | 17:59 |
quantomworks | Thank you for the information you provided. I will weigh these options and do some testing and adjustments. | 18:02 |
johnsom | Sure, NP. Also, there is a #openstack-lbaas channel where the load balancing folks hang out, so if you have further questions it is a good resource. | 18:04 |
quantomworks | Awesome, thanks for that! | 18:10 |
*** tomgray has joined #openstack | 18:24 | |
*** bobmel has joined #openstack | 18:46 | |
*** bobmel has quit IRC | 18:46 | |
*** bobmel has joined #openstack | 18:46 | |
*** Lucas_Gray has joined #openstack | 18:48 | |
*** tonythomas has quit IRC | 18:53 | |
*** nurdie has joined #openstack | 18:55 | |
*** brokencycle has joined #openstack | 18:59 | |
quantomworks | @johnsom regarding the security group method, Is this equivalent to editing the port's security groups assigned to the loadbalancer? | 19:00 |
quantomworks | It is odd because currently, under horizon, the port status is showing down for the VIP. However these are the current settings/its on the same network. | 19:01 |
quantomworks | There is another port prefixed with vrrp though that appers to be the octavia instance and is enabled. | 19:02 |
quantomworks | I cant edit that port though | 19:02 |
*** nurdie_ has joined #openstack | 19:02 | |
*** nurdie has quit IRC | 19:06 | |
*** nurdie_ has quit IRC | 19:07 | |
*** paladox has quit IRC | 19:10 | |
*** jraju__ has joined #openstack | 19:12 | |
*** links has quit IRC | 19:13 | |
*** cah_link has joined #openstack | 19:17 | |
*** iniazi has quit IRC | 19:18 | |
*** iniazi has joined #openstack | 19:18 | |
*** jraju__ has quit IRC | 19:19 | |
*** henriqueof has joined #openstack | 19:21 | |
*** dtrainor_ has joined #openstack | 19:21 | |
*** pck has quit IRC | 19:22 | |
*** dtrainor has quit IRC | 19:24 | |
*** dayou has quit IRC | 19:26 | |
*** dayou has joined #openstack | 19:26 | |
*** sauvin has quit IRC | 19:29 | |
*** paladox has joined #openstack | 19:34 | |
*** paladox has quit IRC | 19:35 | |
*** paladox has joined #openstack | 19:35 | |
*** khyr0n has joined #openstack | 19:45 | |
*** Lucas_Gray has quit IRC | 20:00 | |
*** quantomworks has quit IRC | 20:05 | |
*** cah_link has quit IRC | 20:12 | |
*** random_yanek has quit IRC | 20:16 | |
*** random_yanek has joined #openstack | 20:23 | |
*** vxwarlock has quit IRC | 20:48 | |
*** takamatsu has quit IRC | 20:51 | |
*** rav3n has joined #openstack | 21:23 | |
*** sshnaidm has joined #openstack | 21:28 | |
*** shibboleth has joined #openstack | 21:45 | |
*** servagem has quit IRC | 21:52 | |
*** cah_link has joined #openstack | 21:55 | |
*** bobmel has quit IRC | 22:05 | |
*** cah_link has quit IRC | 22:07 | |
*** stewie925 has joined #openstack | 22:34 | |
*** TxGirlGeek has joined #openstack | 22:35 | |
*** dviroel has quit IRC | 22:48 | |
*** tesseract has quit IRC | 22:54 | |
*** pcaruana has quit IRC | 22:59 | |
*** factor has quit IRC | 23:14 | |
*** factor has joined #openstack | 23:15 | |
*** TxGirlGeek has quit IRC | 23:28 | |
*** arnoldoree has quit IRC | 23:30 | |
*** jathan has quit IRC | 23:31 | |
*** shibboleth has quit IRC | 23:52 | |
*** gyee has quit IRC | 23:58 |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!