OpenStack RDO 部署流程 - 4(Neutron安全组)
Neutron安全组的配置需要仔细。
需要在所有计算节点上配置:
/etc/nova/nova.conf:
# 该配置项有时候会遗漏,导致iptables策略无法生效
libvirt_vif_driver = nova.virt.libvirt.vif.LibvirtHybridOVSBridgeDriver
linuxnet_interface_driver =nova.network.linux_net.LinuxOVSInterfaceDriver
# 让Nova在调用安全组API时,直接通知neutron处理
security_group_api = neutron
# 配置Nova禁用firewalldriver
firewall_driver = nova.virt.firewall.NoopFirewallDriver
/etc/neutron/ovs_neutron_plugin.ini:
firewall_driver = neutron.agent.linux.iptables_firewall.OVSHybridIptablesFirewallDriver