Guest User

Untitled

a guest
Sep 17th, 2014
346
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 29.12 KB | None | 0 0
  1. 2014-09-17 10:45:08.251 DEBUG neutron.agent.linux.utils [req-0217d659-2b0c-4077-8906-5a0535e2f2ba None None] Running command: ['sudo', '/usr/bin/neutron-rootwrap', '/etc/neutron/rootwrap.conf', 'iptables-save', '-c'] from (pid=3304) create_process /opt/openstack/neutron/neutron/agent/linux/utils.py:48
  2. 2014-09-17 10:45:08.300 DEBUG neutron.agent.linux.utils [req-0217d659-2b0c-4077-8906-5a0535e2f2ba None None] 
  3. Command: ['sudo', '/usr/bin/neutron-rootwrap', '/etc/neutron/rootwrap.conf', 'iptables-save', '-c']
  4. Exit code: 0
  5. Stdout: '# Generated by iptables-save v1.4.19.1 on Wed Sep 17 10:45:08 2014\n*nat\n:PREROUTING ACCEPT [65:7825]\n:INPUT ACCEPT [55:7192]\n:OUTPUT ACCEPT [132:8056]\n:POSTROUTING ACCEPT [132:8056]\n:OUTPUT_direct - [0:0]\n:POSTROUTING_ZONES - [0:0]\n:POSTROUTING_ZONES_SOURCE - [0:0]\n:POSTROUTING_direct - [0:0]\n:POST_public - [0:0]\n:POST_public_allow - [0:0]\n:POST_public_deny - [0:0]\n:POST_public_log - [0:0]\n:PREROUTING_ZONES - [0:0]\n:PREROUTING_ZONES_SOURCE - [0:0]\n:PREROUTING_direct - [0:0]\n:PRE_public - [0:0]\n:PRE_public_allow - [0:0]\n:PRE_public_deny - [0:0]\n:PRE_public_log - [0:0]\n:neutron-openvswi-OUTPUT - [0:0]\n:neutron-openvswi-POSTROUTING - [0:0]\n:neutron-openvswi-PREROUTING - [0:0]\n:neutron-openvswi-float-snat - [0:0]\n:neutron-openvswi-snat - [0:0]\n:neutron-postrouting-bottom - [0:0]\n:nova-api-OUTPUT - [0:0]\n:nova-api-POSTROUTING - [0:0]\n:nova-api-PREROUTING - [0:0]\n:nova-api-float-snat - [0:0]\n:nova-api-snat - [0:0]\n:nova-postrouting-bottom - [0:0]\n[4422:642549] -A PREROUTING -j neutron-openvswi-PREROUTING\n[4439:645349] -A PREROUTING -j nova-api-PREROUTING\n[4540:661459] -A PREROUTING -j PREROUTING_direct\n[4540:661459] -A PREROUTING -j PREROUTING_ZONES_SOURCE\n[4540:661459] -A PREROUTING -j PREROUTING_ZONES\n[2110:131360] -A OUTPUT -j neutron-openvswi-OUTPUT\n[2187:136016] -A OUTPUT -j nova-api-OUTPUT\n[2648:163884] -A OUTPUT -j OUTPUT_direct\n[2110:131360] -A POSTROUTING -j neutron-openvswi-POSTROUTING\n[2110:131360] -A POSTROUTING -j neutron-postrouting-bottom\n[2187:136016] -A POSTROUTING -j nova-api-POSTROUTING\n[2187:136016] -A POSTROUTING -j nova-postrouting-bottom\n[0:0] -A POSTROUTING -s 192.168.122.0/24 -d 224.0.0.0/24 -j RETURN\n[0:0] -A POSTROUTING -s 192.168.122.0/24 -d 255.255.255.255/32 -j RETURN\n[0:0] -A POSTROUTING -s 192.168.122.0/24 ! -d 192.168.122.0/24 -p tcp -j MASQUERADE --to-ports 1024-65535\n[0:0] -A POSTROUTING -s 192.168.122.0/24 ! -d 192.168.122.0/24 -p udp -j MASQUERADE --to-ports 1024-65535\n[0:0] -A POSTROUTING -s 192.168.122.0/24 ! -d 192.168.122.0/24 -j MASQUERADE\n[2648:163884] -A POSTROUTING -j POSTROUTING_direct\n[2648:163884] -A POSTROUTING -j POSTROUTING_ZONES_SOURCE\n[2648:163884] -A POSTROUTING -j POSTROUTING_ZONES\n[0:0] -A POSTROUTING_ZONES -o qvoa4fd6b6c-0a -g POST_public\n[0:0] -A POSTROUTING_ZONES -o qvba4fd6b6c-0a -g POST_public\n[0:0] -A POSTROUTING_ZONES -o veth2 -g POST_public\n[0:0] -A POSTROUTING_ZONES -o veth1 -g POST_public\n[2648:163884] -A POSTROUTING_ZONES -g POST_public\n[2648:163884] -A POST_public -j POST_public_log\n[2648:163884] -A POST_public -j POST_public_deny\n[2648:163884] -A POST_public -j POST_public_allow\n[1:328] -A PREROUTING_ZONES -i qvoa4fd6b6c-0a -g PRE_public\n[0:0] -A PREROUTING_ZONES -i qvba4fd6b6c-0a -g PRE_public\n[0:0] -A PREROUTING_ZONES -i veth2 -g PRE_public\n[0:0] -A PREROUTING_ZONES -i veth1 -g PRE_public\n[4538:660803] -A PREROUTING_ZONES -g PRE_public\n[4540:661459] -A PRE_public -j PRE_public_log\n[4540:661459] -A PRE_public -j PRE_public_deny\n[4540:661459] -A PRE_public -j PRE_public_allow\n[2110:131360] -A neutron-openvswi-snat -j neutron-openvswi-float-snat\n[2110:131360] -A neutron-postrouting-bottom -j neutron-openvswi-snat\n[2187:136016] -A nova-api-snat -j nova-api-float-snat\n[2187:136016] -A nova-postrouting-bottom -j nova-api-snat\nCOMMIT\n# Completed on Wed Sep 17 10:45:08 2014\n# Generated by iptables-save v1.4.19.1 on Wed Sep 17 10:45:08 2014\n*mangle\n:PREROUTING ACCEPT [28946:12630122]\n:INPUT ACCEPT [28936:12629489]\n:FORWARD ACCEPT [0:0]\n:OUTPUT ACCEPT [31035:17199715]\n:POSTROUTING ACCEPT [31035:17199715]\n:FORWARD_direct - [0:0]\n:INPUT_direct - [0:0]\n:OUTPUT_direct - [0:0]\n:POSTROUTING_direct - [0:0]\n:PREROUTING_ZONES - [0:0]\n:PREROUTING_ZONES_SOURCE - [0:0]\n:PREROUTING_direct - [0:0]\n:PRE_public - [0:0]\n:PRE_public_allow - [0:0]\n:PRE_public_deny - [0:0]\n:PRE_public_log - [0:0]\n:nova-api-POSTROUTING - [0:0]\n[594457:417853442] -A PREROUTING -j PREROUTING_direct\n[594457:417853442] -A PREROUTING -j PREROUTING_ZONES_SOURCE\n[594457:417853442] -A PREROUTING -j PREROUTING_ZONES\n[593796:417789767] -A INPUT -j INPUT_direct\n[0:0] -A FORWARD -j FORWARD_direct\n[632395:498066483] -A OUTPUT -j OUTPUT_direct\n[591325:251122469] -A POSTROUTING -j nova-api-POSTROUTING\n[0:0] -A POSTROUTING -o virbr0 -p udp -m udp --dport 68 -j CHECKSUM --checksum-fill\n[632395:498066483] -A POSTROUTING -j POSTROUTING_direct\n[1:328] -A PREROUTING_ZONES -i qvoa4fd6b6c-0a -g PRE_public\n[1:328] -A PREROUTING_ZONES -i qvba4fd6b6c-0a -g PRE_public\n[4:1312] -A PREROUTING_ZONES -i veth2 -g PRE_public\n[6:1968] -A PREROUTING_ZONES -i veth1 -g PRE_public\n[594441:417848194] -A PREROUTING_ZONES -g PRE_public\n[594457:417853442] -A PRE_public -j PRE_public_log\n[594457:417853442] -A PRE_public -j PRE_public_deny\n[594457:417853442] -A PRE_public -j PRE_public_allow\nCOMMIT\n# Completed on Wed Sep 17 10:45:08 2014\n# Generated by iptables-save v1.4.19.1 on Wed Sep 17 10:45:08 2014\n*security\n:INPUT ACCEPT [593095:417673709]\n:FORWARD ACCEPT [0:0]\n:OUTPUT ACCEPT [632404:498071559]\n:FORWARD_direct - [0:0]\n:INPUT_direct - [0:0]\n:OUTPUT_direct - [0:0]\n[593095:417673709] -A INPUT -j INPUT_direct\n[0:0] -A FORWARD -j FORWARD_direct\n[632404:498071559] -A OUTPUT -j OUTPUT_direct\nCOMMIT\n# Completed on Wed Sep 17 10:45:08 2014\n# Generated by iptables-save v1.4.19.1 on Wed Sep 17 10:45:08 2014\n*raw\n:PREROUTING ACCEPT [594467:417856265]\n:OUTPUT ACCEPT [632404:498071581]\n:OUTPUT_direct - [0:0]\n:PREROUTING_direct - [0:0]\n:neutron-openvswi-OUTPUT - [0:0]\n:neutron-openvswi-PREROUTING - [0:0]\n[545506:169203129] -A PREROUTING -j neutron-openvswi-PREROUTING\n[594467:417856265] -A PREROUTING -j PREROUTING_direct\n[583539:249414351] -A OUTPUT -j neutron-openvswi-OUTPUT\n[632404:498071581] -A OUTPUT -j OUTPUT_direct\nCOMMIT\n# Completed on Wed Sep 17 10:45:08 2014\n# Generated by iptables-save v1.4.19.1 on Wed Sep 17 10:45:08 2014\n*filter\n:INPUT ACCEPT [29759:12715662]\n:FORWARD ACCEPT [0:0]\n:OUTPUT ACCEPT [31989:18161832]\n:FORWARD_IN_ZONES - [0:0]\n:FORWARD_IN_ZONES_SOURCE - [0:0]\n:FORWARD_OUT_ZONES - [0:0]\n:FORWARD_OUT_ZONES_SOURCE - [0:0]\n:FORWARD_direct - [0:0]\n:FWDI_public - [0:0]\n:FWDI_public_allow - [0:0]\n:FWDI_public_deny - [0:0]\n:FWDI_public_log - [0:0]\n:FWDO_public - [0:0]\n:FWDO_public_allow - [0:0]\n:FWDO_public_deny - [0:0]\n:FWDO_public_log - [0:0]\n:INPUT_ZONES - [0:0]\n:INPUT_ZONES_SOURCE - [0:0]\n:INPUT_direct - [0:0]\n:IN_public - [0:0]\n:IN_public_allow - [0:0]\n:IN_public_deny - [0:0]\n:IN_public_log - [0:0]\n:OUTPUT_direct - [0:0]\n:neutron-filter-top - [0:0]\n:neutron-openvswi-FORWARD - [0:0]\n:neutron-openvswi-INPUT - [0:0]\n:neutron-openvswi-OUTPUT - [0:0]\n:neutron-openvswi-local - [0:0]\n:neutron-openvswi-sg-chain - [0:0]\n:neutron-openvswi-sg-fallback - [0:0]\n:nova-api-FORWARD - [0:0]\n:nova-api-INPUT - [0:0]\n:nova-api-OUTPUT - [0:0]\n:nova-api-local - [0:0]\n:nova-filter-top - [0:0]\n[496915:158441821] -A INPUT -j neutron-openvswi-INPUT\n[0:0] -A FORWARD -j neutron-filter-top\n[0:0] -A FORWARD -j neutron-openvswi-FORWARD\n[532715:237513554] -A OUTPUT -j neutron-filter-top\n[532715:237513554] -A OUTPUT -j neutron-openvswi-OUTPUT\n[0:0] -A FORWARD_IN_ZONES -i qvoa4fd6b6c-0a -g FWDI_public\n[0:0] -A FORWARD_IN_ZONES -i qvba4fd6b6c-0a -g FWDI_public\n[0:0] -A FORWARD_IN_ZONES -i veth2 -g FWDI_public\n[0:0] -A FORWARD_IN_ZONES -i veth1 -g FWDI_public\n[0:0] -A FORWARD_OUT_ZONES -o qvoa4fd6b6c-0a -g FWDO_public\n[0:0] -A FORWARD_OUT_ZONES -o qvba4fd6b6c-0a -g FWDO_public\n[0:0] -A FORWARD_OUT_ZONES -o veth2 -g FWDO_public\n[0:0] -A FORWARD_OUT_ZONES -o veth1 -g FWDO_public\n[0:0] -A INPUT_ZONES -i qvoa4fd6b6c-0a -g IN_public\n[0:0] -A INPUT_ZONES -i qvba4fd6b6c-0a -g IN_public\n[0:0] -A INPUT_ZONES -i veth2 -g IN_public\n[0:0] -A INPUT_ZONES -i veth1 -g IN_public\n[532715:237513554] -A neutron-filter-top -j neutron-openvswi-local\n[0:0] -A neutron-openvswi-sg-fallback -j DROP\nCOMMIT\n# Completed on Wed Sep 17 10:45:08 2014\n'
  6. Stderr: '' from (pid=3304) execute /opt/openstack/neutron/neutron/agent/linux/utils.py:78
  7. 2014-09-17 10:45:08.302 DEBUG neutron.agent.linux.utils [req-0217d659-2b0c-4077-8906-5a0535e2f2ba None None] Running command: ['sudo', '/usr/bin/neutron-rootwrap', '/etc/neutron/rootwrap.conf', 'iptables-restore', '-c'] from (pid=3304) create_process /opt/openstack/neutron/neutron/agent/linux/utils.py:48
  8. 2014-09-17 10:45:08.352 ERROR neutron.agent.linux.utils [req-0217d659-2b0c-4077-8906-5a0535e2f2ba None None] 
  9. Command: ['sudo', '/usr/bin/neutron-rootwrap', '/etc/neutron/rootwrap.conf', 'iptables-restore', '-c']
  10. Exit code: 2
  11. Stdout: ''
  12. Stderr: "iptables-restore v1.4.19.1: Set IPv43dedf87f-92a7-45e6-9 doesn't exist.\n\nError occurred at line: 193\nTry `iptables-restore -h' or 'iptables-restore --help' for more information.\n"
  13. 2014-09-17 10:45:08.353 ERROR neutron.agent.linux.iptables_manager [req-0217d659-2b0c-4077-8906-5a0535e2f2ba None None] IPTablesManager.apply failed to apply the following set of iptables rules:
  14. 1. # Generated by iptables-save v1.4.19.1 on Wed Sep 17 10:45:08 2014
  15. 2. *nat
  16. 3. :PREROUTING ACCEPT [65:7825]
  17. 4. :INPUT ACCEPT [55:7192]
  18. 5. :OUTPUT ACCEPT [132:8056]
  19. 6. :POSTROUTING ACCEPT [132:8056]
  20. 7. :OUTPUT_direct - [0:0]
  21. 8. :POSTROUTING_ZONES - [0:0]
  22. 9. :POSTROUTING_ZONES_SOURCE - [0:0]
  23. 10. :POSTROUTING_direct - [0:0]
  24. 11. :POST_public - [0:0]
  25. 12. :POST_public_allow - [0:0]
  26. 13. :POST_public_deny - [0:0]
  27. 14. :POST_public_log - [0:0]
  28. 15. :PREROUTING_ZONES - [0:0]
  29. 16. :PREROUTING_ZONES_SOURCE - [0:0]
  30. 17. :PREROUTING_direct - [0:0]
  31. 18. :PRE_public - [0:0]
  32. 19. :PRE_public_allow - [0:0]
  33. 20. :PRE_public_deny - [0:0]
  34. 21. :PRE_public_log - [0:0]
  35. 22. :nova-api-OUTPUT - [0:0]
  36. 23. :nova-api-POSTROUTING - [0:0]
  37. 24. :nova-api-PREROUTING - [0:0]
  38. 25. :nova-api-float-snat - [0:0]
  39. 26. :nova-api-snat - [0:0]
  40. 27. :nova-postrouting-bottom - [0:0]
  41. 28. :neutron-postrouting-bottom - [0:0]
  42. 29. :neutron-openvswi-OUTPUT - [0:0]
  43. 30. :neutron-openvswi-POSTROUTING - [0:0]
  44. 31. :neutron-openvswi-PREROUTING - [0:0]
  45. 32. :neutron-openvswi-float-snat - [0:0]
  46. 33. :neutron-openvswi-snat - [0:0]
  47. 34. [4422:642549] -A PREROUTING -j neutron-openvswi-PREROUTING
  48. 35. [2110:131360] -A OUTPUT -j neutron-openvswi-OUTPUT
  49. 36. [2110:131360] -A POSTROUTING -j neutron-openvswi-POSTROUTING
  50. 37. [2110:131360] -A POSTROUTING -j neutron-postrouting-bottom
  51. 38. [2110:131360] -A neutron-postrouting-bottom -j neutron-openvswi-snat
  52. 39. [2110:131360] -A neutron-openvswi-snat -j neutron-openvswi-float-snat
  53. 40. [4439:645349] -A PREROUTING -j nova-api-PREROUTING
  54. 41. [4540:661459] -A PREROUTING -j PREROUTING_direct
  55. 42. [4540:661459] -A PREROUTING -j PREROUTING_ZONES_SOURCE
  56. 43. [4540:661459] -A PREROUTING -j PREROUTING_ZONES
  57. 44. [2187:136016] -A OUTPUT -j nova-api-OUTPUT
  58. 45. [2648:163884] -A OUTPUT -j OUTPUT_direct
  59. 46. [2187:136016] -A POSTROUTING -j nova-api-POSTROUTING
  60. 47. [2187:136016] -A POSTROUTING -j nova-postrouting-bottom
  61. 48. [0:0] -A POSTROUTING -s 192.168.122.0/24 -d 224.0.0.0/24 -j RETURN
  62. 49. [0:0] -A POSTROUTING -s 192.168.122.0/24 -d 255.255.255.255/32 -j RETURN
  63. 50. [0:0] -A POSTROUTING -s 192.168.122.0/24 ! -d 192.168.122.0/24 -p tcp -j MASQUERADE --to-ports 1024-65535
  64. 51. [0:0] -A POSTROUTING -s 192.168.122.0/24 ! -d 192.168.122.0/24 -p udp -j MASQUERADE --to-ports 1024-65535
  65. 52. [0:0] -A POSTROUTING -s 192.168.122.0/24 ! -d 192.168.122.0/24 -j MASQUERADE
  66. 53. [2648:163884] -A POSTROUTING -j POSTROUTING_direct
  67. 54. [2648:163884] -A POSTROUTING -j POSTROUTING_ZONES_SOURCE
  68. 55. [2648:163884] -A POSTROUTING -j POSTROUTING_ZONES
  69. 56. [0:0] -A POSTROUTING_ZONES -o qvoa4fd6b6c-0a -g POST_public
  70. 57. [0:0] -A POSTROUTING_ZONES -o qvba4fd6b6c-0a -g POST_public
  71. 58. [0:0] -A POSTROUTING_ZONES -o veth2 -g POST_public
  72. 59. [0:0] -A POSTROUTING_ZONES -o veth1 -g POST_public
  73. 60. [2648:163884] -A POSTROUTING_ZONES -g POST_public
  74. 61. [2648:163884] -A POST_public -j POST_public_log
  75. 62. [2648:163884] -A POST_public -j POST_public_deny
  76. 63. [2648:163884] -A POST_public -j POST_public_allow
  77. 64. [1:328] -A PREROUTING_ZONES -i qvoa4fd6b6c-0a -g PRE_public
  78. 65. [0:0] -A PREROUTING_ZONES -i qvba4fd6b6c-0a -g PRE_public
  79. 66. [0:0] -A PREROUTING_ZONES -i veth2 -g PRE_public
  80. 67. [0:0] -A PREROUTING_ZONES -i veth1 -g PRE_public
  81. 68. [4538:660803] -A PREROUTING_ZONES -g PRE_public
  82. 69. [4540:661459] -A PRE_public -j PRE_public_log
  83. 70. [4540:661459] -A PRE_public -j PRE_public_deny
  84. 71. [4540:661459] -A PRE_public -j PRE_public_allow
  85. 72. [2187:136016] -A nova-api-snat -j nova-api-float-snat
  86. 73. [2187:136016] -A nova-postrouting-bottom -j nova-api-snat
  87. 74. COMMIT
  88. 75. # Completed on Wed Sep 17 10:45:08 2014
  89. 76. # Generated by iptables-save v1.4.19.1 on Wed Sep 17 10:45:08 2014
  90. 77. *mangle
  91. 78. :PREROUTING ACCEPT [28946:12630122]
  92. 79. :INPUT ACCEPT [28936:12629489]
  93. 80. :FORWARD ACCEPT [0:0]
  94. 81. :OUTPUT ACCEPT [31035:17199715]
  95. 82. :POSTROUTING ACCEPT [31035:17199715]
  96. 83. :FORWARD_direct - [0:0]
  97. 84. :INPUT_direct - [0:0]
  98. 85. :OUTPUT_direct - [0:0]
  99. 86. :POSTROUTING_direct - [0:0]
  100. 87. :PREROUTING_ZONES - [0:0]
  101. 88. :PREROUTING_ZONES_SOURCE - [0:0]
  102. 89. :PREROUTING_direct - [0:0]
  103. 90. :PRE_public - [0:0]
  104. 91. :PRE_public_allow - [0:0]
  105. 92. :PRE_public_deny - [0:0]
  106. 93. :PRE_public_log - [0:0]
  107. 94. :nova-api-POSTROUTING - [0:0]
  108. 95. [594457:417853442] -A PREROUTING -j PREROUTING_direct
  109. 96. [594457:417853442] -A PREROUTING -j PREROUTING_ZONES_SOURCE
  110. 97. [594457:417853442] -A PREROUTING -j PREROUTING_ZONES
  111. 98. [593796:417789767] -A INPUT -j INPUT_direct
  112. 99. [0:0] -A FORWARD -j FORWARD_direct
  113. 100. [632395:498066483] -A OUTPUT -j OUTPUT_direct
  114. 101. [591325:251122469] -A POSTROUTING -j nova-api-POSTROUTING
  115. 102. [0:0] -A POSTROUTING -o virbr0 -p udp -m udp --dport 68 -j CHECKSUM --checksum-fill
  116. 103. [632395:498066483] -A POSTROUTING -j POSTROUTING_direct
  117. 104. [1:328] -A PREROUTING_ZONES -i qvoa4fd6b6c-0a -g PRE_public
  118. 105. [1:328] -A PREROUTING_ZONES -i qvba4fd6b6c-0a -g PRE_public
  119. 106. [4:1312] -A PREROUTING_ZONES -i veth2 -g PRE_public
  120. 107. [6:1968] -A PREROUTING_ZONES -i veth1 -g PRE_public
  121. 108. [594441:417848194] -A PREROUTING_ZONES -g PRE_public
  122. 109. [594457:417853442] -A PRE_public -j PRE_public_log
  123. 110. [594457:417853442] -A PRE_public -j PRE_public_deny
  124. 111. [594457:417853442] -A PRE_public -j PRE_public_allow
  125. 112. COMMIT
  126. 113. # Completed on Wed Sep 17 10:45:08 2014
  127. 114. # Generated by iptables-save v1.4.19.1 on Wed Sep 17 10:45:08 2014
  128. 115. *security
  129. 116. :INPUT ACCEPT [593095:417673709]
  130. 117. :FORWARD ACCEPT [0:0]
  131. 118. :OUTPUT ACCEPT [632404:498071559]
  132. 119. :FORWARD_direct - [0:0]
  133. 120. :INPUT_direct - [0:0]
  134. 121. :OUTPUT_direct - [0:0]
  135. 122. [593095:417673709] -A INPUT -j INPUT_direct
  136. 123. [0:0] -A FORWARD -j FORWARD_direct
  137. 124. [632404:498071559] -A OUTPUT -j OUTPUT_direct
  138. 125. COMMIT
  139. 126. # Completed on Wed Sep 17 10:45:08 2014
  140. 127. # Generated by iptables-save v1.4.19.1 on Wed Sep 17 10:45:08 2014
  141. 128. *raw
  142. 129. :PREROUTING ACCEPT [594467:417856265]
  143. 130. :OUTPUT ACCEPT [632404:498071581]
  144. 131. :OUTPUT_direct - [0:0]
  145. 132. :PREROUTING_direct - [0:0]
  146. 133. :neutron-openvswi-OUTPUT - [0:0]
  147. 134. :neutron-openvswi-PREROUTING - [0:0]
  148. 135. [545506:169203129] -A PREROUTING -j neutron-openvswi-PREROUTING
  149. 136. [583539:249414351] -A OUTPUT -j neutron-openvswi-OUTPUT
  150. 137. [594467:417856265] -A PREROUTING -j PREROUTING_direct
  151. 138. [632404:498071581] -A OUTPUT -j OUTPUT_direct
  152. 139. COMMIT
  153. 140. # Completed on Wed Sep 17 10:45:08 2014
  154. 141. # Generated by iptables-save v1.4.19.1 on Wed Sep 17 10:45:08 2014
  155. 142. *filter
  156. 143. :INPUT ACCEPT [29759:12715662]
  157. 144. :FORWARD ACCEPT [0:0]
  158. 145. :OUTPUT ACCEPT [31989:18161832]
  159. 146. :FORWARD_IN_ZONES - [0:0]
  160. 147. :FORWARD_IN_ZONES_SOURCE - [0:0]
  161. 148. :FORWARD_OUT_ZONES - [0:0]
  162. 149. :FORWARD_OUT_ZONES_SOURCE - [0:0]
  163. 150. :FORWARD_direct - [0:0]
  164. 151. :FWDI_public - [0:0]
  165. 152. :FWDI_public_allow - [0:0]
  166. 153. :FWDI_public_deny - [0:0]
  167. 154. :FWDI_public_log - [0:0]
  168. 155. :FWDO_public - [0:0]
  169. 156. :FWDO_public_allow - [0:0]
  170. 157. :FWDO_public_deny - [0:0]
  171. 158. :FWDO_public_log - [0:0]
  172. 159. :INPUT_ZONES - [0:0]
  173. 160. :INPUT_ZONES_SOURCE - [0:0]
  174. 161. :INPUT_direct - [0:0]
  175. 162. :IN_public - [0:0]
  176. 163. :IN_public_allow - [0:0]
  177. 164. :IN_public_deny - [0:0]
  178. 165. :IN_public_log - [0:0]
  179. 166. :OUTPUT_direct - [0:0]
  180. 167. :nova-api-FORWARD - [0:0]
  181. 168. :nova-api-INPUT - [0:0]
  182. 169. :nova-api-OUTPUT - [0:0]
  183. 170. :nova-api-local - [0:0]
  184. 171. :neutron-filter-top - [0:0]
  185. 172. :neutron-openvswi-FORWARD - [0:0]
  186. 173. :neutron-openvswi-INPUT - [0:0]
  187. 174. :neutron-openvswi-OUTPUT - [0:0]
  188. 175. :neutron-openvswi-ia4fd6b6c-0 - [0:0]
  189. 176. :neutron-openvswi-local - [0:0]
  190. 177. :neutron-openvswi-oa4fd6b6c-0 - [0:0]
  191. 178. :neutron-openvswi-sa4fd6b6c-0 - [0:0]
  192. 179. :neutron-openvswi-sg-chain - [0:0]
  193. 180. :neutron-openvswi-sg-fallback - [0:0]
  194. 181. [0:0] -A FORWARD -j neutron-filter-top
  195. 182. [532715:237513554] -A OUTPUT -j neutron-filter-top
  196. 183. [532715:237513554] -A neutron-filter-top -j neutron-openvswi-local
  197. 184. [496915:158441821] -A INPUT -j neutron-openvswi-INPUT
  198. 185. [532715:237513554] -A OUTPUT -j neutron-openvswi-OUTPUT
  199. 186. [0:0] -A FORWARD -j neutron-openvswi-FORWARD
  200. 187. [0:0] -A neutron-openvswi-sg-fallback -j DROP
  201. 188. [0:0] -A neutron-openvswi-FORWARD -m physdev --physdev-out tapa4fd6b6c-0a --physdev-is-bridged -j neutron-openvswi-sg-chain
  202. 189. [0:0] -A neutron-openvswi-sg-chain -m physdev --physdev-out tapa4fd6b6c-0a --physdev-is-bridged -j neutron-openvswi-ia4fd6b6c-0
  203. 190. [0:0] -A neutron-openvswi-ia4fd6b6c-0 -m state --state INVALID -j DROP
  204. 191. [0:0] -A neutron-openvswi-ia4fd6b6c-0 -m state --state RELATED,ESTABLISHED -j RETURN
  205. 192. [0:0] -A neutron-openvswi-ia4fd6b6c-0 -s 10.0.0.3/32 -p udp -m udp --sport 67 --dport 68 -j RETURN
  206. 193. [0:0] -A neutron-openvswi-ia4fd6b6c-0 -m set --match-set IPv43dedf87f-92a7-45e6-9 src -j RETURN
  207. 194. [0:0] -A neutron-openvswi-ia4fd6b6c-0 -j neutron-openvswi-sg-fallback
  208. 195. [0:0] -A neutron-openvswi-FORWARD -m physdev --physdev-in tapa4fd6b6c-0a --physdev-is-bridged -j neutron-openvswi-sg-chain
  209. 196. [0:0] -A neutron-openvswi-sg-chain -m physdev --physdev-in tapa4fd6b6c-0a --physdev-is-bridged -j neutron-openvswi-oa4fd6b6c-0
  210. 197. [0:0] -A neutron-openvswi-INPUT -m physdev --physdev-in tapa4fd6b6c-0a --physdev-is-bridged -j neutron-openvswi-oa4fd6b6c-0
  211. 198. [0:0] -A neutron-openvswi-sa4fd6b6c-0 -m mac --mac-source fa:16:3e:0f:50:4d -s 10.0.0.4 -j RETURN
  212. 199. [0:0] -A neutron-openvswi-sa4fd6b6c-0 -j DROP
  213. 200. [0:0] -A neutron-openvswi-oa4fd6b6c-0 -p udp -m udp --sport 68 --dport 67 -j RETURN
  214. 201. [0:0] -A neutron-openvswi-oa4fd6b6c-0 -j neutron-openvswi-sa4fd6b6c-0
  215. 202. [0:0] -A neutron-openvswi-oa4fd6b6c-0 -p udp -m udp --sport 67 --dport 68 -j DROP
  216. 203. [0:0] -A neutron-openvswi-oa4fd6b6c-0 -m state --state INVALID -j DROP
  217. 204. [0:0] -A neutron-openvswi-oa4fd6b6c-0 -m state --state RELATED,ESTABLISHED -j RETURN
  218. 205. [0:0] -A neutron-openvswi-oa4fd6b6c-0 -j RETURN
  219. 206. [0:0] -A neutron-openvswi-oa4fd6b6c-0 -j neutron-openvswi-sg-fallback
  220. 207. [0:0] -A neutron-openvswi-sg-chain -j ACCEPT
  221. 208. :nova-filter-top - [0:0]
  222. 209. [0:0] -A FORWARD_IN_ZONES -i qvoa4fd6b6c-0a -g FWDI_public
  223. 210. [0:0] -A FORWARD_IN_ZONES -i qvba4fd6b6c-0a -g FWDI_public
  224. 211. [0:0] -A FORWARD_IN_ZONES -i veth2 -g FWDI_public
  225. 212. [0:0] -A FORWARD_IN_ZONES -i veth1 -g FWDI_public
  226. 213. [0:0] -A FORWARD_OUT_ZONES -o qvoa4fd6b6c-0a -g FWDO_public
  227. 214. [0:0] -A FORWARD_OUT_ZONES -o qvba4fd6b6c-0a -g FWDO_public
  228. 215. [0:0] -A FORWARD_OUT_ZONES -o veth2 -g FWDO_public
  229. 216. [0:0] -A FORWARD_OUT_ZONES -o veth1 -g FWDO_public
  230. 217. [0:0] -A INPUT_ZONES -i qvoa4fd6b6c-0a -g IN_public
  231. 218. [0:0] -A INPUT_ZONES -i qvba4fd6b6c-0a -g IN_public
  232. 219. [0:0] -A INPUT_ZONES -i veth2 -g IN_public
  233. 220. [0:0] -A INPUT_ZONES -i veth1 -g IN_public
  234. 221. COMMIT
  235. 222. # Completed on Wed Sep 17 10:45:08 2014
  236. 223. 
  237. 2014-09-17 10:45:08.355 DEBUG neutron.openstack.common.lockutils [req-0217d659-2b0c-4077-8906-5a0535e2f2ba None None] Released file lock "iptables" at /opt/openstack/data/neutron/lock/neutron-iptables from (pid=3304) lock /opt/openstack/neutron/neutron/openstack/common/lockutils.py:210
  238. 2014-09-17 10:45:08.355 DEBUG neutron.agent.linux.iptables_manager [req-0217d659-2b0c-4077-8906-5a0535e2f2ba None None] Semaphore / lock released "iptables" from (pid=3304) _apply /opt/openstack/neutron/neutron/agent/linux/iptables_manager.py:392
  239. 2014-09-17 10:45:08.356 ERROR neutron.plugins.openvswitch.agent.ovs_neutron_agent [req-0217d659-2b0c-4077-8906-5a0535e2f2ba None None] Error while processing VIF ports
  240. 2014-09-17 10:45:08.356 TRACE neutron.plugins.openvswitch.agent.ovs_neutron_agent Traceback (most recent call last):
  241. 2014-09-17 10:45:08.356 TRACE neutron.plugins.openvswitch.agent.ovs_neutron_agent  File "/opt/openstack/neutron/neutron/plugins/openvswitch/agent/ovs_neutron_agent.py", line 1403, in rpc_loop
  242. 2014-09-17 10:45:08.356 TRACE neutron.plugins.openvswitch.agent.ovs_neutron_agent  ovs_restarted)
  243. 2014-09-17 10:45:08.356 TRACE neutron.plugins.openvswitch.agent.ovs_neutron_agent  File "/opt/openstack/neutron/neutron/plugins/openvswitch/agent/ovs_neutron_agent.py", line 1202, in process_network_ports
  244. 2014-09-17 10:45:08.356 TRACE neutron.plugins.openvswitch.agent.ovs_neutron_agent  port_info.get('updated', set()))
  245. 2014-09-17 10:45:08.356 TRACE neutron.plugins.openvswitch.agent.ovs_neutron_agent  File "/opt/openstack/neutron/neutron/agent/securitygroups_rpc.py", line 316, in setup_port_filters
  246. 2014-09-17 10:45:08.356 TRACE neutron.plugins.openvswitch.agent.ovs_neutron_agent  self.prepare_devices_filter(new_devices)
  247. 2014-09-17 10:45:08.356 TRACE neutron.plugins.openvswitch.agent.ovs_neutron_agent  File "/opt/openstack/neutron/neutron/agent/securitygroups_rpc.py", line 211, in prepare_devices_filter
  248. 2014-09-17 10:45:08.356 TRACE neutron.plugins.openvswitch.agent.ovs_neutron_agent  security_groups, security_group_member_ips)
  249. 2014-09-17 10:45:08.356 TRACE neutron.plugins.openvswitch.agent.ovs_neutron_agent  File "/usr/lib64/python2.7/contextlib.py", line 24, in __exit__
  250. 2014-09-17 10:45:08.356 TRACE neutron.plugins.openvswitch.agent.ovs_neutron_agent  self.gen.next()
  251. 2014-09-17 10:45:08.356 TRACE neutron.plugins.openvswitch.agent.ovs_neutron_agent  File "/opt/openstack/neutron/neutron/agent/firewall.py", line 106, in defer_apply
  252. 2014-09-17 10:45:08.356 TRACE neutron.plugins.openvswitch.agent.ovs_neutron_agent  self.filter_defer_apply_off()
  253. 2014-09-17 10:45:08.356 TRACE neutron.plugins.openvswitch.agent.ovs_neutron_agent  File "/opt/openstack/neutron/neutron/agent/linux/iptables_firewall.py", line 557, in filter_defer_apply_off
  254. 2014-09-17 10:45:08.356 TRACE neutron.plugins.openvswitch.agent.ovs_neutron_agent  self.iptables.defer_apply_off()
  255. 2014-09-17 10:45:08.356 TRACE neutron.plugins.openvswitch.agent.ovs_neutron_agent  File "/opt/openstack/neutron/neutron/agent/linux/iptables_manager.py", line 374, in defer_apply_off
  256. 2014-09-17 10:45:08.356 TRACE neutron.plugins.openvswitch.agent.ovs_neutron_agent  self._apply()
  257. 2014-09-17 10:45:08.356 TRACE neutron.plugins.openvswitch.agent.ovs_neutron_agent  File "/opt/openstack/neutron/neutron/agent/linux/iptables_manager.py", line 390, in _apply
  258. 2014-09-17 10:45:08.356 TRACE neutron.plugins.openvswitch.agent.ovs_neutron_agent  return self._apply_synchronized()
  259. 2014-09-17 10:45:08.356 TRACE neutron.plugins.openvswitch.agent.ovs_neutron_agent  File "/opt/openstack/neutron/neutron/agent/linux/iptables_manager.py", line 445, in _apply_synchronized
  260. 2014-09-17 10:45:08.356 TRACE neutron.plugins.openvswitch.agent.ovs_neutron_agent  '\n'.join(log_lines))
  261. 2014-09-17 10:45:08.356 TRACE neutron.plugins.openvswitch.agent.ovs_neutron_agent  File "/opt/openstack/neutron/neutron/openstack/common/excutils.py", line 82, in __exit__
  262. 2014-09-17 10:45:08.356 TRACE neutron.plugins.openvswitch.agent.ovs_neutron_agent  six.reraise(self.type_, self.value, self.tb)
  263. 2014-09-17 10:45:08.356 TRACE neutron.plugins.openvswitch.agent.ovs_neutron_agent  File "/opt/openstack/neutron/neutron/agent/linux/iptables_manager.py", line 424, in _apply_synchronized
  264. 2014-09-17 10:45:08.356 TRACE neutron.plugins.openvswitch.agent.ovs_neutron_agent  root_helper=self.root_helper)
  265. 2014-09-17 10:45:08.356 TRACE neutron.plugins.openvswitch.agent.ovs_neutron_agent  File "/opt/openstack/neutron/neutron/agent/linux/utils.py", line 81, in execute
  266. 2014-09-17 10:45:08.356 TRACE neutron.plugins.openvswitch.agent.ovs_neutron_agent  raise RuntimeError(m)
  267. 2014-09-17 10:45:08.356 TRACE neutron.plugins.openvswitch.agent.ovs_neutron_agent RuntimeError:
  268. 2014-09-17 10:45:08.356 TRACE neutron.plugins.openvswitch.agent.ovs_neutron_agent Command: ['sudo', '/usr/bin/neutron-rootwrap', '/etc/neutron/rootwrap.conf', 'iptables-restore', '-c']
  269. 2014-09-17 10:45:08.356 TRACE neutron.plugins.openvswitch.agent.ovs_neutron_agent Exit code: 2
  270. 2014-09-17 10:45:08.356 TRACE neutron.plugins.openvswitch.agent.ovs_neutron_agent Stdout: ''
  271. 2014-09-17 10:45:08.356 TRACE neutron.plugins.openvswitch.agent.ovs_neutron_agent Stderr: "iptables-restore v1.4.19.1: Set IPv43dedf87f-92a7-45e6-9 doesn't exist.\n\nError occurred at line: 193\nTry `iptables-restore -h' or 'iptables-restore --help' for more information.\n"
  272. 2014-09-17 10:45:08.356 TRACE neutron.plugins.openvswitch.agent.ovs_neutron_agent 
  273. 2014-09-17 10:45:08.357 DEBUG neutron.plugins.openvswitch.agent.ovs_neutron_agent [req-0217d659-2b0c-4077-8906-5a0535e2f2ba None None] Agent rpc_loop - iteration:400 completed. Processed ports statistics: {'ancillary': {'removed': 0, 'added': 0}, 'regular': {'updated': 0, 'added': 0, 'removed': 0}}. Elapsed:0.449 from (pid=3304) rpc_loop /opt/openstack/neutron/neutron/plugins/openvswitch/agent/ovs_neutron_agent.py:1454
  274. ^C2014-09-17 10:45:08.495 DEBUG neutron.agent.linux.async_process [req-0217d659-2b0c-4077-8906-5a0535e2f2ba None None] Halting async process [['ovsdb-client', 'monitor', 'Interface', 'name,ofport', '--format=json']]. from (pid=3304) stop /opt/openstack/neutron/neutron/agent/linux/async_process.py:88
  275. 2014-09-17 10:45:08.496 DEBUG neutron.agent.linux.utils [req-0217d659-2b0c-4077-8906-5a0535e2f2ba None None] Running command: ['ps', '--ppid', '3452', '-o', 'pid='] from (pid=3304) create_process /opt/openstack/neutron/neutron/agent/linux/utils.py:48
  276. 2014-09-17 10:45:08.503 ERROR neutron.agent.linux.ovsdb_monitor [-] Error received from ovsdb monitor: Traceback (most recent call last):
  277. 2014-09-17 10:45:08.547 ERROR neutron.agent.linux.utils [req-0217d659-2b0c-4077-8906-5a0535e2f2ba None None] 
  278. Command: ['ps', '--ppid', '3452', '-o', 'pid=']
  279. Exit code: 1
  280. Stdout: ''
  281. Stderr: ''
Advertisement
Add Comment
Please, Sign In to add comment