Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- Control Node (as tenant user)
- ==============================
- root@kcon-cs-gen-01i:~# nova list
- +--------------------------------------+--------------+--------+-----------------------------------------+
- | ID | Name | Status | Networks |
- +--------------------------------------+--------------+--------+-----------------------------------------+
- | e885f58b-290d-4d02-abd5-95768cf3d1be | my_fourth_vm | ACTIVE | net_proj_one=192.168.252.3, 10.21.166.2 |
- +--------------------------------------+--------------+--------+-----------------------------------------+
- root@kcon-cs-gen-01i:~# quantum floatingip-list
- +--------------------------------------+------------------+---------------------+--------------------------------------+
- | id | fixed_ip_address | floating_ip_address | port_id |
- +--------------------------------------+------------------+---------------------+--------------------------------------+
- | 8ed3ce4d-f8ff-4232-80d5-25446428173b | 192.168.252.3 | 10.21.166.2 | 5b0e7933-2105-4eb0-9074-8ec4e65cb81c |
- +--------------------------------------+------------------+---------------------+--------------------------------------+
- root@kcon-cs-gen-01i:~# nova secgroup-list-rules default
- +-------------+-----------+---------+------------+--------------+
- | IP Protocol | From Port | To Port | IP Range | Source Group |
- +-------------+-----------+---------+------------+--------------+
- | icmp | -1 | -1 | 0.0.0.0/24 | |
- | tcp | 22 | 22 | 0.0.0.0/24 | |
- +-------------+-----------+---------+------------+--------------+
- root@kcon-cs-gen-01i:~# nova show my_fourth_vm
- +-----------------------------+----------------------------------------------------------+
- | Property | Value |
- +-----------------------------+----------------------------------------------------------+
- | status | ACTIVE |
- | updated | 2013-05-02T21:50:54Z |
- | OS-EXT-STS:task_state | None |
- | key_name | None |
- | image | myFirstImage (f0a92447-ede8-4715-b319-b418ef824962) |
- | hostId | a5d683856975990163b8f23fab517db89a5a2fc79ba738e98b4989d2 |
- | OS-EXT-STS:vm_state | active |
- | flavor | m1.tiny (1) |
- | id | e885f58b-290d-4d02-abd5-95768cf3d1be |
- | security_groups | [{u'name': u'default'}] |
- | user_id | 0fd82892836547e29df9f59a5a75a731 |
- | name | my_fourth_vm |
- | net_proj_one network | 192.168.252.3, 10.21.166.2 |
- | created | 2013-05-02T21:09:41Z |
- | tenant_id | 22710edfb163438ca87d8064b25dddf4 |
- | OS-DCF:diskConfig | MANUAL |
- | metadata | {} |
- | accessIPv4 | |
- | accessIPv6 | |
- | progress | 0 |
- | OS-EXT-STS:power_state | 1 |
- | OS-EXT-AZ:availability_zone | nova |
- | config_drive | |
- +-----------------------------+----------------------------------------------------------+
- root@kcon-cs-gen-01i:~# quantum port-list
- +--------------------------------------+------+-------------------+--------------------------------------------------------------------------------------+
- | id | name | mac_address | fixed_ips |
- +--------------------------------------+------+-------------------+--------------------------------------------------------------------------------------+
- | 14301d16-5dca-4a6b-bcfa-7d684efbec86 | | fa:16:3e:de:6d:16 | {"subnet_id": "26f55d4c-e295-4d9c-b10d-be811b7bf841", "ip_address": "192.168.252.2"} |
- | 5b0e7933-2105-4eb0-9074-8ec4e65cb81c | | fa:16:3e:8a:02:78 | {"subnet_id": "26f55d4c-e295-4d9c-b10d-be811b7bf841", "ip_address": "192.168.252.3"} |
- | 9ae4cc80-c749-4320-842e-de23e367fd22 | | fa:16:3e:f8:a4:54 | {"subnet_id": "26f55d4c-e295-4d9c-b10d-be811b7bf841", "ip_address": "192.168.252.1"} |
- +--------------------------------------+------+-------------------+--------------------------------------------------------------------------------------+
- root@kcon-cs-gen-01i:~# quantum port-show 5b0e7933-2105-4eb0-9074-8ec4e65cb81c
- +----------------+--------------------------------------------------------------------------------------+
- | Field | Value |
- +----------------+--------------------------------------------------------------------------------------+
- | admin_state_up | True |
- | device_id | e885f58b-290d-4d02-abd5-95768cf3d1be |
- | device_owner | compute:None |
- | fixed_ips | {"subnet_id": "26f55d4c-e295-4d9c-b10d-be811b7bf841", "ip_address": "192.168.252.3"} |
- | id | 5b0e7933-2105-4eb0-9074-8ec4e65cb81c |
- | mac_address | fa:16:3e:8a:02:78 |
- | name | |
- | network_id | af224f3f-8de6-4e0d-b043-6bcd5cb014c5 |
- | status | ACTIVE |
- | tenant_id | 22710edfb163438ca87d8064b25dddf4 |
- +----------------+--------------------------------------------------------------------------------------+
- Compute Node
- ============
- iptables FILTER
- ---------------
- root@kvm-cs-sn-15i:/etc/init.d# iptables -nvL
- Chain INPUT (policy ACCEPT 386K packets, 65M bytes)
- pkts bytes target prot opt in out source destination
- 12676 2417K nova-compute-INPUT all -- * * 0.0.0.0/0 0.0.0.0/0
- 0 0 ACCEPT udp -- virbr0 * 0.0.0.0/0 0.0.0.0/0 udp dpt:53
- 0 0 ACCEPT tcp -- virbr0 * 0.0.0.0/0 0.0.0.0/0 tcp dpt:53
- 0 0 ACCEPT udp -- virbr0 * 0.0.0.0/0 0.0.0.0/0 udp dpt:67
- 0 0 ACCEPT tcp -- virbr0 * 0.0.0.0/0 0.0.0.0/0 tcp dpt:67
- Chain FORWARD (policy ACCEPT 1724 packets, 220K bytes)
- pkts bytes target prot opt in out source destination
- 4335 709K nova-filter-top all -- * * 0.0.0.0/0 0.0.0.0/0
- 109 30703 nova-compute-FORWARD all -- * * 0.0.0.0/0 0.0.0.0/0
- 0 0 ACCEPT all -- * virbr0 0.0.0.0/0 192.168.122.0/24 state RELATED,ESTABLISHED
- 0 0 ACCEPT all -- virbr0 * 192.168.122.0/24 0.0.0.0/0
- 0 0 ACCEPT all -- virbr0 virbr0 0.0.0.0/0 0.0.0.0/0
- 0 0 REJECT all -- * virbr0 0.0.0.0/0 0.0.0.0/0 reject-with icmp-port-unreachable
- 0 0 REJECT all -- virbr0 * 0.0.0.0/0 0.0.0.0/0 reject-with icmp-port-unreachable
- Chain OUTPUT (policy ACCEPT 510K packets, 81M bytes)
- pkts bytes target prot opt in out source destination
- 195K 37M nova-filter-top all -- * * 0.0.0.0/0 0.0.0.0/0
- 16050 2977K nova-compute-OUTPUT all -- * * 0.0.0.0/0 0.0.0.0/0
- Chain nova-compute-FORWARD (1 references)
- pkts bytes target prot opt in out source destination
- 58 17864 ACCEPT udp -- * * 0.0.0.0 255.255.255.255 udp spt:68 dpt:67
- Chain nova-compute-INPUT (1 references)
- pkts bytes target prot opt in out source destination
- 29 8932 ACCEPT udp -- * * 0.0.0.0 255.255.255.255 udp spt:68 dpt:67
- Chain nova-compute-OUTPUT (1 references)
- pkts bytes target prot opt in out source destination
- Chain nova-compute-inst-4 (1 references)
- pkts bytes target prot opt in out source destination
- 0 0 DROP all -- * * 0.0.0.0/0 0.0.0.0/0 state INVALID
- 22 1848 ACCEPT all -- * * 0.0.0.0/0 0.0.0.0/0 state RELATED,ESTABLISHED
- 84 14775 nova-compute-provider all -- * * 0.0.0.0/0 0.0.0.0/0
- 29 10179 ACCEPT udp -- * * 192.168.252.2 0.0.0.0/0 udp spt:67 dpt:68
- 0 0 ACCEPT all -- * * 192.168.252.0/23 0.0.0.0/0
- 0 0 ACCEPT tcp -- * * 0.0.0.0/24 0.0.0.0/0 tcp dpt:22
- 0 0 ACCEPT icmp -- * * 0.0.0.0/24 0.0.0.0/0
- 55 4596 nova-compute-sg-fallback all -- * * 0.0.0.0/0 0.0.0.0/0
- Chain nova-compute-local (1 references)
- pkts bytes target prot opt in out source destination
- 106 16623 nova-compute-inst-4 all -- * * 0.0.0.0/0 192.168.252.3
- Chain nova-compute-provider (1 references)
- pkts bytes target prot opt in out source destination
- Chain nova-compute-sg-fallback (1 references)
- pkts bytes target prot opt in out source destination
- 55 4596 DROP all -- * * 0.0.0.0/0 0.0.0.0/0
- Chain nova-filter-top (2 references)
- pkts bytes target prot opt in out source destination
- 16265 3025K nova-compute-local all -- * * 0.0.0.0/0 0.0.0.0/0
- iptables NAT
- ------------
- root@kvm-cs-sn-15i:/etc/init.d# iptables -nvL -t nat
- Chain PREROUTING (policy ACCEPT 1079 packets, 217K bytes)
- pkts bytes target prot opt in out source destination
- 173 28333 nova-compute-PREROUTING all -- * * 0.0.0.0/0 0.0.0.0/0
- Chain INPUT (policy ACCEPT 174 packets, 29121 bytes)
- pkts bytes target prot opt in out source destination
- Chain OUTPUT (policy ACCEPT 2470 packets, 151K bytes)
- pkts bytes target prot opt in out source destination
- 234 14238 nova-compute-OUTPUT all -- * * 0.0.0.0/0 0.0.0.0/0
- Chain POSTROUTING (policy ACCEPT 3219 packets, 326K bytes)
- pkts bytes target prot opt in out source destination
- 295 34092 nova-compute-POSTROUTING all -- * * 0.0.0.0/0 0.0.0.0/0
- 3135 320K nova-postrouting-bottom all -- * * 0.0.0.0/0 0.0.0.0/0
- 0 0 MASQUERADE tcp -- * * 192.168.122.0/24 !192.168.122.0/24 masq ports: 1024-65535
- 0 0 MASQUERADE udp -- * * 192.168.122.0/24 !192.168.122.0/24 masq ports: 1024-65535
- 0 0 MASQUERADE all -- * * 192.168.122.0/24 !192.168.122.0/24
- Chain nova-compute-OUTPUT (1 references)
- pkts bytes target prot opt in out source destination
- Chain nova-compute-POSTROUTING (1 references)
- pkts bytes target prot opt in out source destination
- Chain nova-compute-PREROUTING (1 references)
- pkts bytes target prot opt in out source destination
- Chain nova-compute-float-snat (1 references)
- pkts bytes target prot opt in out source destination
- Chain nova-compute-snat (1 references)
- pkts bytes target prot opt in out source destination
- 295 34092 nova-compute-float-snat all -- * * 0.0.0.0/0 0.0.0.0/0
- Chain nova-postrouting-bottom (1 references)
- pkts bytes target prot opt in out source destination
- 295 34092 nova-compute-snat all -- * * 0.0.0.0/0 0.0.0.0/0
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement