回复 22# zhanghao001122 会不会是iptables有问题,计算节点需要配置iptables吗?
控制节点iptables:
root@hwnode1:/home/ubuntu# iptables-save -t nat
# Generated by iptables-save v1.4.21 on Wed May 20 16:19:33 2015
*nat
:PREROUTING ACCEPT [133143:41811752]
:INPUT ACCEPT [130199:41418480]
:OUTPUT ACCEPT [63379:3994496]
:POSTROUTING ACCEPT [67196:4405430]
:nova-api-OUTPUT - [0:0]
:nova-api-POSTROUTING - [0:0]
:nova-api-PREROUTING - [0:0]
:nova-api-float-snat - [0:0]
:nova-api-snat - [0:0]
:nova-compute-OUTPUT - [0:0]
:nova-compute-POSTROUTING - [0:0]
:nova-compute-PREROUTING - [0:0]
:nova-compute-float-snat - [0:0]
:nova-compute-snat - [0:0]
:nova-network-OUTPUT - [0:0]
:nova-network-POSTROUTING - [0:0]
:nova-network-PREROUTING - [0:0]
:nova-network-float-snat - [0:0]
:nova-network-snat - [0:0]
:nova-postrouting-bottom - [0:0]
-A PREROUTING -j nova-network-PREROUTING
-A PREROUTING -j nova-compute-PREROUTING
-A PREROUTING -j nova-api-PREROUTING
-A OUTPUT -j nova-network-OUTPUT
-A OUTPUT -j nova-compute-OUTPUT
-A OUTPUT -j nova-api-OUTPUT
-A POSTROUTING -j nova-network-POSTROUTING
-A POSTROUTING -j nova-compute-POSTROUTING
-A POSTROUTING -s 192.168.122.0/24 -d 224.0.0.0/24 -j RETURN
-A POSTROUTING -s 192.168.122.0/24 -d 255.255.255.255/32 -j RETURN
-A POSTROUTING -s 192.168.122.0/24 ! -d 192.168.122.0/24 -p tcp -j MASQUERADE --to-ports 1024-65535
-A POSTROUTING -s 192.168.122.0/24 ! -d 192.168.122.0/24 -p udp -j MASQUERADE --to-ports 1024-65535
-A POSTROUTING -s 192.168.122.0/24 ! -d 192.168.122.0/24 -j MASQUERADE
-A POSTROUTING -j nova-api-POSTROUTING
-A POSTROUTING -j nova-postrouting-bottom
-A nova-api-snat -j nova-api-float-snat
-A nova-compute-snat -j nova-compute-float-snat
-A nova-network-OUTPUT -d 110.1.20.41/32 -j DNAT --to-destination 192.168.200.3
-A nova-network-OUTPUT -d 110.1.20.47/32 -j DNAT --to-destination 192.168.200.7
-A nova-network-OUTPUT -d 110.1.20.70/32 -j DNAT --to-destination 192.168.200.4
-A nova-network-OUTPUT -d 110.1.20.69/32 -j DNAT --to-destination 192.168.200.6
-A nova-network-POSTROUTING -s 192.168.200.0/24 -d 127.0.0.1/32 -j ACCEPT
-A nova-network-POSTROUTING -s 192.168.200.0/24 -d 192.168.200.0/24 -m conntrack ! --ctstate DNAT -j ACCEPT
-A nova-network-POSTROUTING -s 192.168.200.3/32 -m conntrack --ctstate DNAT -j SNAT --to-source 110.1.20.41
-A nova-network-POSTROUTING -s 192.168.200.7/32 -m conntrack --ctstate DNAT -j SNAT --to-source 110.1.20.47
-A nova-network-POSTROUTING -s 192.168.200.4/32 -m conntrack --ctstate DNAT -j SNAT --to-source 110.1.20.70
-A nova-network-POSTROUTING -s 192.168.200.6/32 -m conntrack --ctstate DNAT -j SNAT --to-source 110.1.20.69
-A nova-network-PREROUTING -d 169.254.169.254/32 -p tcp -m tcp --dport 80 -j REDIRECT --to-ports 8775
-A nova-network-PREROUTING -d 110.1.20.41/32 -j DNAT --to-destination 192.168.200.3
-A nova-network-PREROUTING -d 110.1.20.47/32 -j DNAT --to-destination 192.168.200.7
-A nova-network-PREROUTING -d 110.1.20.70/32 -j DNAT --to-destination 192.168.200.4
-A nova-network-PREROUTING -d 110.1.20.69/32 -j DNAT --to-destination 192.168.200.6
-A nova-network-float-snat -s 192.168.200.3/32 -d 192.168.200.3/32 -j SNAT --to-source 110.1.20.41
-A nova-network-float-snat -s 192.168.200.3/32 -o br100 -j SNAT --to-source 110.1.20.41
-A nova-network-float-snat -s 192.168.200.7/32 -d 192.168.200.7/32 -j SNAT --to-source 110.1.20.47
-A nova-network-float-snat -s 192.168.200.7/32 -o br100 -j SNAT --to-source 110.1.20.47
-A nova-network-float-snat -s 192.168.200.4/32 -d 192.168.200.4/32 -j SNAT --to-source 110.1.20.70
-A nova-network-float-snat -s 192.168.200.4/32 -o br100 -j SNAT --to-source 110.1.20.70
-A nova-network-float-snat -s 192.168.200.6/32 -d 192.168.200.6/32 -j SNAT --to-source 110.1.20.69
-A nova-network-float-snat -s 192.168.200.6/32 -o br100 -j SNAT --to-source 110.1.20.69
-A nova-network-snat -j nova-network-float-snat
-A nova-network-snat -s 192.168.200.0/24 -o br100 -j SNAT --to-source 110.1.20.21
-A nova-postrouting-bottom -j nova-network-snat
-A nova-postrouting-bottom -j nova-compute-snat
-A nova-postrouting-bottom -j nova-api-snat
COMMIT
# Completed on Wed May 20 16:19:33 2015
计算节点iptables
root@hwnode2:/home/ubuntu# iptables-save -t nat
# Generated by iptables-save v1.4.21 on Wed May 20 16:20:36 2015
*nat
:PREROUTING ACCEPT [111:22279]
:INPUT ACCEPT [19:5930]
:OUTPUT ACCEPT [205:13563]
:POSTROUTING ACCEPT [273:28920]
:nova-compute-OUTPUT - [0:0]
:nova-compute-POSTROUTING - [0:0]
:nova-compute-PREROUTING - [0:0]
:nova-compute-float-snat - [0:0]
:nova-compute-snat - [0:0]
:nova-postrouting-bottom - [0:0]
-A PREROUTING -j nova-compute-PREROUTING
-A OUTPUT -j nova-compute-OUTPUT
-A POSTROUTING -j nova-compute-POSTROUTING
-A POSTROUTING -j nova-postrouting-bottom
-A POSTROUTING -s 192.168.122.0/24 -d 224.0.0.0/24 -j RETURN
-A POSTROUTING -s 192.168.122.0/24 -d 255.255.255.255/32 -j RETURN
-A POSTROUTING -s 192.168.122.0/24 ! -d 192.168.122.0/24 -p tcp -j MASQUERADE --to-ports 1024-65535
-A POSTROUTING -s 192.168.122.0/24 ! -d 192.168.122.0/24 -p udp -j MASQUERADE --to-ports 1024-65535
-A POSTROUTING -s 192.168.122.0/24 ! -d 192.168.122.0/24 -j MASQUERADE
-A nova-compute-snat -j nova-compute-float-snat
-A nova-postrouting-bottom -j nova-compute-snat
COMMIT
# Completed on Wed May 20 16:20:36 2015
root@hwnode2:/home/ubuntu#
收起