1"use strict";(self.webpackChunktigera_docs=self.webpackChunktigera_docs||[]).push([[3577],{15680:(e,t,n)=>{n.d(t,{xA:()=>c,yg:()=>d});var a=n(96540);function r(e,t,n){return t in e?Object.defineProperty(e,t,{value:n,enumerable:!0,configurable:!0,writable:!0}):e[t]=n,e}function o(e,t){var n=Object.keys(e);if(Object.getOwnPropertySymbols){var a=Object.getOwnPropertySymbols(e);t&&(a=a.filter((function(t){return Object.getOwnPropertyDescriptor(e,t).enumerable}))),n.push.apply(n,a)}return n}function i(e){for(var t=1;t<arguments.length;t++){var n=null!=arguments[t]?arguments[t]:{};t%2?o(Object(n),!0).forEach((function(t){r(e,t,n[t])})):Object.getOwnPropertyDescriptors?Object.defineProperties(e,Object.getOwnPropertyDescriptors(n)):o(Object(n)).forEach((function(t){Object.defineProperty(e,t,Object.getOwnPropertyDescriptor(n,t))}))}return e}function l(e,t){if(null==e)return{};var n,a,r=function(e,t){if(null==e)return{};var n,a,r={},o=Object.keys(e);for(a=0;a<o.length;a++)n=o[a],t.indexOf(n)>=0||(r[n]=e[n]);return r}(e,t);if(Object.getOwnPropertySymbols){var o=Object.getOwnPropertySymbols(e);for(a=0;a<o.length;a++)n=o[a],t.indexOf(n)>=0||Object.prototype.propertyIsEnumerable.call(e,n)&&(r[n]=e[n])}return r}var p=a.createContext({}),s=function(e){var t=a.useContext(p),n=t;return e&&(n="function"==typeof e?e(t):i(i({},t),e)),n},c=function(e){var t=s(e.components);return a.createElement(p.Provider,{value:t},e.children)},g="mdxType",u={inlineCode:"code",wrapper:function(e){var t=e.children;return a.createElement(a.Fragment,{},t)}},m=a.forwardRef((function(e,t){var n=e.components,r=e.mdxType,o=e.originalType,p=e.parentName,c=l(e,["components","mdxType","originalType","parentName"]),g=s(n),m=r,d=g["".concat(p,".").concat(m)]||g[m]||u[m]||o;return n?a.createElement(d,i(i({ref:t},c),{},{components:n})):a.createElement(d,i({ref:t},c))}));function d(e,t){var n=arguments,r=t&&t.mdxType;if("string"==typeof e||r){var o=n.length,i=new Array(o);i[0]=m;var l={};for(var p in t)hasOwnProperty.call(t,p)&&(l[p]=t[p]);l.originalType=e,l[g]="string"==typeof e?e:r,i[1]=l;for(var s=2;s<o;s++)i[s]=n[s];return a.createElement.apply(null,i)}return a.createElement.apply(null,n)}m.displayName="MDXCreateElement"},18512:(e,t,n)=>{n.r(t),n.d(t,{assets:()=>p,contentTitle:()=>i,default:()=>u,frontMatter:()=>o,metadata:()=>l,toc:()=>s});var a=n(58168),r=(n(96540),n(15680));const o={description:"Configure floating IPs in Calico for OpenStack."},i="Floating IPs",l={unversionedId:"networking/openstack/floating-ips",id:"version-3.26/networking/openstack/floating-ips",title:"Floating IPs",description:"Configure floating IPs in Calico for OpenStack.",source:"@site/calico_versioned_docs/version-3.26/networking/openstack/floating-ips.mdx",sourceDirName:"networking/openstack",slug:"/networking/openstack/floating-ips",permalink:"/calico/3.26/networking/openstack/floating-ips",draft:!1,editUrl:"https://github.com/tigera/docs/edit/main/calico_versioned_docs/version-3.26/networking/openstack/floating-ips.mdx",tags:[],version:"3.26",frontMatter:{description:"Configure floating IPs in Calico for OpenStack."},sidebar:"calicoSidebar",previous:{title:"Detailed semantics",permalink:"/calico/3.26/networking/openstack/semantics"},next:{title:"Service IPs",permalink:"/calico/3.26/networking/openstack/service-ips"}},p={},s=[],c={toc:s},g="wrapper";
1function u(e){let{components:t,...n}=e;return(0,r.yg)(g,(0,a.A)({},c,n,{components:t,mdxType:"MDXLayout"}),(0,r.yg)("h1",{id:"floating-ips"},"Floating IPs"),(0,r.yg)("p",null,"networking-calico includes beta support for floating IPs. Currently this\nrequires running Calico as a Neutron core plugin (i.e. ",(0,r.yg)("inlineCode",{parentName:"p"},"core_plugin = calico"),") instead of as an ML2 mechanism driver."),(0,r.yg)("admonition",{type:"note"},(0,r.yg)("p",{parentName:"admonition"},"We would like it to work as an ML2 mechanism driver too\u2014patches\nand/or advice welcome!")),(0,r.yg)("p",null,"To set up a floating IP, you need the same pattern of Neutron data model\nobjects as you do for Neutron in general, which means:"),(0,r.yg)("ul",null,(0,r.yg)("li",{parentName:"ul"},(0,r.yg)("p",{parentName:"li"},"a tenant network, with an instance attached to it, that will be the target of\nthe floating IP")),(0,r.yg)("li",{parentName:"ul"},(0,r.yg)("p",{parentName:"li"},"a Neutron router, with the tenant network connected to it")),(0,r.yg)("li",{parentName:"ul"},(0,r.yg)("p",{parentName:"li"},"a provider network with ",(0,r.yg)("inlineCode",{parentName:"p"},"router:external True")," that is set as the\nrouter's gateway (e.g. with ",(0,r.yg)("inlineCode",{parentName:"p"},"neutron router-gateway-set"),"), and with a\nsubnet with a CIDR that floating IPs will be allocated from")),(0,r.yg)("li",{parentName:"ul"},(0,r.yg)("p",{parentName:"li"},"a floating IP, allocated from the provider network subnet, that maps onto the\ninstance attached to the tenant network."))),(0,r.yg)("p",null,"For example:"),(0,r.yg)("ol",null,(0,r.yg)("li",{parentName:"ol"},(0,r.yg)("p",{parentName:"li"},"Create tenant network and subnet."),(0,r.yg)("pre",{parentName:"li"},(0,r.yg)("code",{parentName:"pre",className:"language-bash"},"neutron net-create --shared calico\nneutron subnet-create --gateway 10.65.0.1 --enable-dhcp --ip-version 4 --name calico-v4 calico 10.65.0.0/24\n"))),(0,r.yg)("li",{parentName:"ol"},(0,r.yg)("p",{parentName:"li"},"Boot a VM on that network."),(0,r.yg)("pre",{parentName:"li"},(0,r.yg)("code",{parentName:"pre",className:"language-bash"},"nova boot [...]\n"))),(0,r.yg)("li",{parentName:"ol"},(0,r.yg)("p",{parentName:"li"},"Find its Neutron port ID."),(0,r.yg)("pre",{parentName:"li"},(0,r.yg)("code",{parentName:"pre",className:"language-bash"},"neutron port-list\n"))),(0,r.yg)("li",{parentName:"ol"},(0,r.yg)("p",{parentName:"li"},"Create an external network and subnet; this is where floating\nIPs will be allocated from."),(0,r.yg)("pre",{parentName:"li"},(0,r.yg)("code",{parentName:"pre",className:"language-bash"},"neutron net-create public --router:external True\nneutron subnet-create public 172.16.1.0/24\n"))),(0,r.yg)("li",{parentName:"ol"},(0,r.yg)("p",{parentName:"li"},"Create a router connecting the tenant and external networks."),(0,r.yg)("pre",{parentName:"li"},(0,r.yg)("code",{parentName:"pre",className:"language-bash"},"neutron router-create router1\nneutron router-interface-add router1 <tenant-subnet-id>\nneutron router-gateway-set router1 public\n"))),(0,r.yg)("li",{parentName:"ol"},(0,r.yg)("p",{parentName:"li"},"Create a floating IP and associate it with the target VM."),(0,r.yg)("pre",{parentName:"li"},(0,r.yg)("code",{parentName:"pre",className:"language-bash"},"neutron floatingip-create public\nneutron floatingip-associate <floatingip-id> <target-VM-port-id>\n")),(0,r.yg)("p",{parentName:"li"},"Then the Calico agents will arrange that the floating IP is routed to the\ninstance's compute host, and then DNAT'd to the instance's fixed IP address.")),(0,r.yg)("li",{parentName:"ol"},(0,r.yg)("p",{parentName:"li"},"From a compute node, issue the following command."),(0,r.yg)("pre",{parentName:"li"},(0,r.yg)("code",{parentName:"pre",className:"language-bash"},"ip r\n")),(0,r.yg)("p",{parentName:"li"},"It should return the routing table."),(0,r.yg)("pre",{parentName:"li"},(0,r.yg)("code",{parentName:"pre"},"default via 10.240.0.1 dev eth0\n10.65.0.13 dev tap9a7e0868-da scope link\n10.65.0.14 via 192.168.8.4 dev l2tpeth8-3 proto bird\n10.65.0.23 via 192.168.8.4 dev l2tpeth8-3 proto bird\n10.240.0.1 dev eth0 scope link\n172.16.
11.3 dev tap9a7e0868-da scope link\n192.168.8.0/24 dev l2tpeth8-3 proto kernel scope link src 192.168.8.3\n192.168.122.0/24 dev virbr0 proto kernel scope link src 192.168.122.1\n"))),(0,r.yg)("li",{parentName:"ol"},(0,r.yg)("p",{parentName:"li"},"Issue the following command to review iptables."),(0,r.yg)("pre",{parentName:"li"},(0,r.yg)("code",{parentName:"pre",className:"language-bash"},"sudo iptables -L -n -v -t nat\n")),(0,r.yg)("p",{parentName:"li"},"It should return something like the following."),(0,r.yg)("pre",{parentName:"li"},(0,r.yg)("code",{parentName:"pre"},"[...]\nChain felix-FIP-DNAT (2 references)\n pkts bytes target prot opt in out source destination\n 0 0 DNAT all -- * * 0.0.0.0/0 172.16.1.3 to:10.65.0.13\n\nChain felix-FIP-SNAT (1 references)\n pkts bytes target prot opt in out source destination\n 0 0 SNAT all -- * * 10.65.0.13 10.65.0.13 to:172.16.1.3\n\nChain felix-OUTPUT (1 references)\n pkts bytes target prot opt in out source destination\n 1 60 felix-FIP-DNAT all -- * * 0.0.0.0/0 0.0.0.0/0\n\nChain felix-POSTROUTING (1 references)\n pkts bytes target prot opt in out source destination\n 1 60 felix-FIP-SNAT all -- * * 0.0.0.0/0 0.0.0.0/0\n\nChain felix-PREROUTING (1 references)\n pkts bytes target prot opt in out source destination\n 0 0 felix-FIP-DNAT all -- * * 0.0.0.0/0 0.0.0.0/0\n 0 0 DNAT tcp -- * * 0.0.0.0/0 169.254.169.254 tcp dpt:80 to:127.0.0.1:8775\n[...]\n")))))}u.isMDXComponent=!0}}]);
Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.