New Question

v-magine installation - network issues [closed]

asked 2016-12-09 20:32:57 +0300

Nebukazar gravatar image


We've been installing v-magine on one of our hyperv node running windows 2012r2 std. So far, the installation worked, however, when we are trying to deploy VMs, networking is not working properly.

VMs are not able to reach the outside (eg: public network), however, VMs are able to see / ping each others.

The hyperv node has 2x NICs: - 1x OOB interface with public IP (no tagged vlan); - 1x external public network (no tagged vlan).

A /27 has been attributed to our public network, meaning we should be able to use that public subnet on any VMs running on that node.

The hyperv node has therefore 4x vswitches:

  • LOCAL (internal), previously created;
  • VRACK (external - should be the one being used by OpenStack), previously created;
  • v-magine-internal (internal), created by the vmagine installer;
  • v-magine-data (private), created by the vmagine installer.

Please note that VMs are getting the proper vswitch assigned:

PS C:\> Get-VM -Name instance-00000006,instance-00000007 | select -ExpandProperty NetworkAdapters | select VMName, SwitchName

VMName                                                      SwitchName
------                                                      ----------
instance-00000006                                           v-magine-data
instance-00000007                                           v-magine-data

The 2 VMs are using the subnet / network created by the vmagine installer.

The current network has the following values:

(neutron) net-show 612ebe38-47bd-454b-84d4-61de3db8638d
| Field                     | Value                                |
| admin_state_up            | True                                 |
| availability_zone_hints   |                                      |
| availability_zones        | nova                                 |
| created_at                | 2016-12-09T17:35:15                  |
| description               |                                      |
| id                        | 612ebe38-47bd-454b-84d4-61de3db8638d |
| ipv4_address_scope        |                                      |
| ipv6_address_scope        |                                      |
| is_default                | False                                |
| mtu                       | 1500                                 |
| name                      | public                               |
| provider:network_type     | vlan                                 |
| provider:physical_network | physnet1                             |
| provider:segmentation_id  | 535                                  |
| router:external           | True                                 |
| shared                    | False                                |
| status                    | ACTIVE                               |
| subnets                   | 7043c4ae-a7d7-40e1-8672-b0594e1f5e21 |
| tags                      |                                      |
| tenant_id                 | 3b512d5359764ea1b018e413b580f728     |
| updated_at                | 2016-12-09T17:35:15                  |

And the current subnet values (please note that I have masked sensitive data):

(neutron) subnet-show 7043c4ae-a7d7-40e1-8672-b0594e1f5e21
| Field             | Value                                            |
| allocation_pools  | {"start": "", "end": ""} |
| cidr              |                                  |
| created_at        | 2016-12-09T17:35:19                              |
| description       |                                                  |
| dns_nameservers   |                                                  |
| enable_dhcp       | True                                             |
| gateway_ip        |                                     |
| host_routes       |                                                  |
| id                | 7043c4ae-a7d7-40e1-8672-b0594e1f5e21             |
| ip_version        | 4                                                |
| ipv6_address_mode |                                                  |
| ipv6_ra_mode      |                                                  |
| name              | public_subnet                                    |
| network_id        | 612ebe38-47bd-454b-84d4-61de3db8638d             |
| subnetpool_id     |                                                  |
| tenant_id         | 3b512d5359764ea1b018e413b580f728                 |
| updated_at        | 2016-12-09T18:04:57                              |

I am not sure that I am missing, could you guys please help me out ? We are quite new to OpenStack and would definitely need some guidance.


edit retag flag offensive reopen merge delete

Closed for the following reason the question is answered, right answer was accepted by Nebukazar
close date 2017-01-23 23:18:23.683151


To begin with, let's ensure that the networking works as expected between VMs and Neutron: are the VMs getting an IP via DHCP? Can you ping the internal router IP from the VMs?

alexpilotti gravatar imagealexpilotti ( 2016-12-09 21:13:01 +0300 )edit

Hi Alex, Those VMs are getting the proper IPs assigned from the DHCP service. However, I don't seem to be able to ping the internal gateway (network:router_gateway). I can ping VMs from/to VMs fine tho. Please let me know if you need any further information / configuration snippets. Thanks!

Nebukazar gravatar imageNebukazar ( 2016-12-09 22:33:32 +0300 )edit

From inside the VMs, you should be able to ping the gateway and DHCP server (usually, can you please confirm if this is or not the case? Thanks

alexpilotti gravatar imagealexpilotti ( 2016-12-09 22:49:29 +0300 )edit

Actually, those VMs are getting a floating / route able IPs assigned, not the private 10.x.x.x subnet I'm still able to ping the DHPC service at x.x.x.38 (routeable IP) From neutron, I'm able to ping the router gateway: ip netns exec qrouter-5e279681-fd39-4f0b-9ecc-36a66abd246c ping x.x.x.34

Nebukazar gravatar imageNebukazar ( 2016-12-09 22:51:47 +0300 )edit

FYI: I'm deploying those VMs in the "admin" project for testing purpose. I'd like those VMs to use external IPs to reach the outside.

Nebukazar gravatar imageNebukazar ( 2016-12-09 22:57:44 +0300 )edit

That explains evertything: can you please login with the "demo" account and attach your VMs to the "private" network?

alexpilotti gravatar imagealexpilotti ( 2016-12-09 23:35:18 +0300 )edit

Can you please confirm if it is working as expected using the private network?

alexpilotti gravatar imagealexpilotti ( 2016-12-12 13:36:56 +0300 )edit

Hi Alex, so I've been creating a VM under the demo user. The VM is getting his local IP address (eg: as expected, however, I am unable to ping the outside. Please let me know if you need further information. -Thanks!

Nebukazar gravatar imageNebukazar ( 2016-12-13 23:13:34 +0300 )edit

First try to enable the ICMP Echo Request for ICMPv4 and ICMPv6, in the Hyper-v server as by default it is disable. Second, check your networks in the dashboard, say you created your private network under subnet details DNS Name Servers should be the IPs of your public network (NIC).

tahder gravatar imagetahder ( 2016-12-14 00:59:17 +0300 )edit

As per your config last table, you don't have the dns_nameservers pls do add (as this is your gateway), as this what I did in my configs (or use the DNS of your internet for sure). I assume you created a public network - same network range in your internet NIC

tahder gravatar imagetahder ( 2016-12-14 01:09:35 +0300 )edit

It doesn't seem to be working; I'm still unable to ping the gateway. Allow egress/ingress ICMP ACLs on the host are activated.

Nebukazar gravatar imageNebukazar ( 2016-12-14 16:31:18 +0300 )edit

Hi, just wondering if you guys had any other ideas as to what would might be the problem? Thanks!

Nebukazar gravatar imageNebukazar ( 2016-12-15 20:01:50 +0300 )edit

If the VM is getting a DHCP address, it means that VM to Neutron communication works. Let's proceed with the troubleshooting steps: can you ping (the internal gateway)?

alexpilotti gravatar imagealexpilotti ( 2016-12-15 20:08:21 +0300 )edit

Pinging the internal gateway doesn't seem to work; I'm getting no ICMP reply.

Nebukazar gravatar imageNebukazar ( 2016-12-15 21:58:18 +0300 )edit

can you show us in the controller node do login and issue the command 1) source ~/keystonerc_admin or ~/keystonerc_demo 2) neutron subnet-list 3) neutron subnet-show xxx where xxx is your network_name with an issue. 4) ifconfig 5) route -n. Maybe we can see it over there.

tahder gravatar imagetahder ( 2016-12-15 22:42:21 +0300 )edit

Sure, please find the following pastbin: Please note that I'm showing neutron's output for both subnet as I am unable to reach the GW on both subnet - not sure if that matter. I really appreciate the support and help you guys are giving so far. Thanks a lot!

Nebukazar gravatar imageNebukazar ( 2016-12-15 22:56:53 +0300 )edit

can you also ping from hyper-v to the controller node mgmt-int IP ( in your case)? If you can't the issue is here.

tahder gravatar imagetahder ( 2016-12-15 22:58:24 +0300 )edit

Yep; pinging the controller mgmt-int IP address from the hyperv node is working.

Nebukazar gravatar imageNebukazar ( 2016-12-15 23:09:17 +0300 )edit

as per mentioned by alex, you still can't you ping from your VMs and in the controller? is v-magine-data is a private network in hyperv? is your VRACK connected to External network?

tahder gravatar imagetahder ( 2016-12-15 23:19:07 +0300 )edit

1 answer

Sort by » oldest newest most voted

answered 2016-12-19 18:18:17 +0300

alexpilotti gravatar image

Please ensure that:

  • there's a router created in the tenant that owns the VMs (e.g. "demo")
  • the router is set to use the "public" network as gateway
  • the "private" subnet is connected to the router.

Note: if the router belongs to another tenant (e.g. "admin"), the demo user won't be able to associate floating IPs.

In Horizon, when logged in as "demo" you can check under "Project" -> "NETWORK" -> "Network Topology" as shown in the attached image:

image description

If the tenant does not have a router, just create a new one setting the proper external network (e.g. "public").

edit flag offensive delete link more


Thanks guys! You guys were very helpful and responsive. We are definately looking forward to do business with you guys. For those who are wondering how is the support... I'm telling you.. those guys know their stuff...!! Thanks once again, your products look promising :)

Nebukazar gravatar imageNebukazar ( 2016-12-19 20:07:18 +0300 )edit

Those guys ask only simple questions :)

semka_mesilov gravatar imagesemka_mesilov ( 2016-12-22 11:53:21 +0300 )edit

Question Tools



Asked: 2016-12-09 20:32:57 +0300

Seen: 344 times

Last updated: Dec 19 '16