Re: Help/Advice needed - some traffic don't reach VNET / VM

2017-10-13 Thread Wei ZHOU
Hi Andrija, Good to see your update and know you found the root cause. -Wei 2017-10-13 22:16 GMT+02:00 Andrija Panic : > Hi all, > > I feel obligated to share update, to close the issue: > > Nothing to do with kernel/qemu etc.. Seem that hidden Docker NAT/Masquerade > rules don't play nice with

Re: Help/Advice needed - some traffic don't reach VNET / VM

2017-10-13 Thread Andrija Panic
Hi all, I feel obligated to share update, to close the issue: Nothing to do with kernel/qemu etc.. Seem that hidden Docker NAT/Masquerade rules don't play nice with VNET... Description of the problem as given originally still is valid, but root cause is as above... Apologies for wasting everyon

Re: Help/Advice needed - some traffic don't reach VNET / VM

2017-10-10 Thread Wei ZHOU
Andrija, We had similar issue before. However, we use advanced zone with security groups, and the issue is because some security groups rules (iptables rules) are not applied by security_group.py successfully. is there any iptables rules on the hypervisors ? -Wei 2017-10-10 11:23 GMT+02:00 Andri

Re: Help/Advice needed - some traffic don't reach VNET / VM

2017-10-10 Thread Andrija Panic
Hi, @Wei, no we are using VXLAN, advanced networking... problem is that packet not passed from bridge to the VNET - that is "all"... @Ivan, we did upgrade few hosts to kernel, 4.4 (made available from Ubuntu 16.04 to Ubuntu 14.04), but again we there had some issues with FortiOS (some special OS,

Re: Help/Advice needed - some traffic don't reach VNET / VM

2017-10-10 Thread Ivan Kudryavtsev
Andrija, I saw it in the past. Problem might be coolnnected with kernel version and vnet itself. Try to look for it. I don't remember how we overcame it in the past... 10 окт. 2017 г. 8:07 ДП пользователь "Wei ZHOU" написал: > Hi Andrija, > > Are using advanced zone with isolated network or secu

Re: Help/Advice needed - some traffic don't reach VNET / VM

2017-10-10 Thread Wei ZHOU
Hi Andrija, Are using advanced zone with isolated network or security groups ? -Wei 2017-10-09 22:52 GMT+02:00 Andrija Panic : > Hi guys, > > we have occasional but serious problem, that starts happening as it seems > randomly (i.e. NOT under high load) - not ACS related afaik, purely KVM, >

RE: Help/Advice needed - some traffic don't reach VNET / VM

2017-10-09 Thread Andrija Panic
il.com] > Sent: Tuesday, October 10, 2017 2:37 AM > To: us...@cloudstack.apache.org > Cc: dev@cloudstack.apache.org > Subject: Re: Help/Advice needed - some traffic don't reach VNET / VM > > Hi guys, > > thanks for quick reply: > > - VM issue happens on Windows mostly

Re: Help/Advice needed - some traffic don't reach VNET / VM

2017-10-09 Thread Andrija Panic
Hi guys, thanks for quick reply: - VM issue happens on Windows mostly (one customer is of particularly bad luck as it seems), but afaik also happens on Linux, and FortiOS (some FW stuff, not pure linux) - both are running PV stuff (Windows PV, or CentOS 6.5 x64 OS type) - we are actually using LA

Re: Help/Advice needed - some traffic don't reach VNET / VM

2017-10-09 Thread Dag Sonstebo
Hi Andrija, Do you use NIC bonds? I have seen this before when using active-active bonds, and as you say it can be very difficult to troubleshoot and the behaviour makes little sense. What can happen is network traffic is load balanced between the two NICs, however the update frequency of the M

Re: Help/Advice needed - some traffic don't reach VNET / VM

2017-10-09 Thread Simon Weller
Andrija, What is the guest OS for this VM, or does this issue not discriminate? - Si From: Andrija Panic Sent: Monday, October 9, 2017 3:52 PM To: dev@cloudstack.apache.org; us...@cloudstack.apache.org Subject: Help/Advice needed - some traffic don't reach VNET