Apr 18 13:28:21 cloudvirt2001-dev nova-compute[1374]: /usr/lib/python3/dist-packages/oslo_policy/policy.py:722: UserWarning: Policy "admin_or_owner":"is_admin:True or project_id:%(project_id)s" was deprecated for removal in 21.0.0. Reason:
Apr 18 13:28:21 cloudvirt2001-dev nova-compute[1374]: Nova API policies are introducing new default roles with scope_type
Apr 18 13:28:21 cloudvirt2001-dev nova-compute[1374]: capabilities. Old policies are deprecated and silently going to be ignored
Apr 18 13:28:21 cloudvirt2001-dev nova-compute[1374]: in nova 23.0.0 release.
Apr 18 13:28:21 cloudvirt2001-dev nova-compute[1374]: . Its value may be silently ignored in the future.
Apr 18 13:28:24 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:24.670 8372 ERROR neutron.agent.linux.iptables_manager [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] IPTablesManager.apply failed to apply the following set of iptables rules:
1. # Generated by iptables_manager
2. *filter
3. :neutron-openvswi-i355ee-9aee - [0:0]
4. :neutron-openvswi-o355ee-9aee - [0:0]
5. :neutron-openvswi-s355ee-9aee - [0:0]
6. -I neutron-openvswi-FORWARD 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
7. -I neutron-openvswi-FORWARD 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
8. -I neutron-openvswi-FORWARD 3 -m physdev --physdev-out 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
9. -I neutron-openvswi-FORWARD 4 -m physdev --physdev-in 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
10. -I neutron-openvswi-INPUT 1 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct incoming traffic from VM to the security group chain." -j neutron-openvswi-o355ee-9aee
11. -I neutron-openvswi-i355ee-9aee 1 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
15. -I neutron-openvswi-i355ee-9aee 5 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
16. -I neutron-openvswi-i355ee-9aee 6 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
21. -I neutron-openvswi-o355ee-9aee 5 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
22. -I neutron-openvswi-o355ee-9aee 6 -j RETURN
23. -I neutron-openvswi-o355ee-9aee 7 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
24. -I neutron-openvswi-o355ee-9aee 8 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
25. -I neutron-openvswi-s355ee-9aee 1 -s 172.16.129.142/32 -m mac --mac-source FA:16:3E:07:C5:CB -m comment --comment "Allow traffic from defined IP/MAC pairs." -j RETURN
26. -I neutron-openvswi-s355ee-9aee 2 -m comment --comment "Drop traffic without an IP/MAC allow rule." -j DROP
27. -I neutron-openvswi-sg-chain 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-i355ee-9aee
28. -I neutron-openvswi-sg-chain 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-o355ee-9aee
29. COMMIT
30. # Completed by iptables_manager
31. # Generated by iptables_manager
32. *raw
33. -I neutron-openvswi-PREROUTING 1 -m physdev --physdev-in brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
34. -I neutron-openvswi-PREROUTING 2 -i brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
35. -I neutron-openvswi-PREROUTING 3 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
-I neutron-openvswi-FORWARD 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
-I neutron-openvswi-FORWARD 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
-I neutron-openvswi-FORWARD 3 -m physdev --physdev-out 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
-I neutron-openvswi-FORWARD 4 -m physdev --physdev-in 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
-I neutron-openvswi-INPUT 1 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct incoming traffic from VM to the security group chain." -j neutron-openvswi-o355ee-9aee
-I neutron-openvswi-i355ee-9aee 1 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
-I neutron-openvswi-i355ee-9aee 4 -m set --match-set NIPv44c29a64f-b883-4622-893c- src -j RETURN
-I neutron-openvswi-i355ee-9aee 5 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
-I neutron-openvswi-i355ee-9aee 6 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
-I neutron-openvswi-o355ee-9aee 5 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
-I neutron-openvswi-o355ee-9aee 6 -j RETURN
-I neutron-openvswi-o355ee-9aee 7 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
-I neutron-openvswi-o355ee-9aee 8 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
-I neutron-openvswi-s355ee-9aee 1 -s 172.16.129.142/32 -m mac --mac-source FA:16:3E:07:C5:CB -m comment --comment "Allow traffic from defined IP/MAC pairs." -j RETURN
-I neutron-openvswi-s355ee-9aee 2 -m comment --comment "Drop traffic without an IP/MAC allow rule." -j DROP
-I neutron-openvswi-sg-chain 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-i355ee-9aee
-I neutron-openvswi-sg-chain 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-o355ee-9aee
COMMIT
# Completed by iptables_manager
# Generated by iptables_manager
*raw
-I neutron-openvswi-PREROUTING 1 -m physdev --physdev-in brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
-I neutron-openvswi-PREROUTING 2 -i brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
-I neutron-openvswi-PREROUTING 3 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
COMMIT
# Completed by iptables_manager
; Stdout: ; Stderr: iptables-restore v1.8.9 (nf_tables): interface name `de8355ee-9aee-4de4-9df9-513d9d62c08c' must be shorter than IFNAMSIZ (15)
Error occurred at line: 6
Try `iptables-restore -h' or 'iptables-restore --help' for more information.
2024-04-18 13:28:24.671 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-FORWARD 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
2024-04-18 13:28:24.671 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-FORWARD 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
2024-04-18 13:28:24.671 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-FORWARD 3 -m physdev --physdev-out 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
2024-04-18 13:28:24.671 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-FORWARD 4 -m physdev --physdev-in 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
2024-04-18 13:28:24.671 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-INPUT 1 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct incoming traffic from VM to the security group chain." -j neutron-openvswi-o355ee-9aee
2024-04-18 13:28:24.671 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-i355ee-9aee 1 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
2024-04-18 13:28:24.671 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-i355ee-9aee 5 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
2024-04-18 13:28:24.671 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-i355ee-9aee 6 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
2024-04-18 13:28:24.671 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 5 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
2024-04-18 13:28:24.671 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 7 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
2024-04-18 13:28:24.671 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 8 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
2024-04-18 13:28:24.671 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-s355ee-9aee 1 -s 172.16.129.142/32 -m mac --mac-source FA:16:3E:07:C5:CB -m comment --comment "Allow traffic from defined IP/MAC pairs." -j RETURN
2024-04-18 13:28:24.671 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-s355ee-9aee 2 -m comment --comment "Drop traffic without an IP/MAC allow rule." -j DROP
2024-04-18 13:28:24.671 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-sg-chain 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-i355ee-9aee
2024-04-18 13:28:24.671 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-sg-chain 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-o355ee-9aee
2024-04-18 13:28:24.671 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent # Completed by iptables_manager
2024-04-18 13:28:24.671 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent ; Stdout: ; Stderr: iptables-restore v1.8.9 (nf_tables): interface name `de8355ee-9aee-4de4-9df9-513d9d62c08c' must be shorter than IFNAMSIZ (15)
2024-04-18 13:28:24.671 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent Error occurred at line: 6
2024-04-18 13:28:24.671 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent Try `iptables-restore -h' or 'iptables-restore --help' for more information.
Apr 18 13:28:26 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:26.623 8372 ERROR neutron.agent.linux.iptables_manager [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] IPTablesManager.apply failed to apply the following set of iptables rules:
1. # Generated by iptables_manager
2. *filter
3. :neutron-openvswi-i355ee-9aee - [0:0]
4. :neutron-openvswi-o355ee-9aee - [0:0]
5. :neutron-openvswi-s355ee-9aee - [0:0]
6. -I neutron-openvswi-FORWARD 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
7. -I neutron-openvswi-FORWARD 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
8. -I neutron-openvswi-FORWARD 3 -m physdev --physdev-out 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
9. -I neutron-openvswi-FORWARD 4 -m physdev --physdev-in 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
10. -I neutron-openvswi-INPUT 1 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct incoming traffic from VM to the security group chain." -j neutron-openvswi-o355ee-9aee
11. -I neutron-openvswi-i355ee-9aee 1 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
15. -I neutron-openvswi-i355ee-9aee 5 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
16. -I neutron-openvswi-i355ee-9aee 6 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
21. -I neutron-openvswi-o355ee-9aee 5 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
22. -I neutron-openvswi-o355ee-9aee 6 -j RETURN
23. -I neutron-openvswi-o355ee-9aee 7 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
24. -I neutron-openvswi-o355ee-9aee 8 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
25. -I neutron-openvswi-s355ee-9aee 1 -s 172.16.129.142/32 -m mac --mac-source FA:16:3E:07:C5:CB -m comment --comment "Allow traffic from defined IP/MAC pairs." -j RETURN
26. -I neutron-openvswi-s355ee-9aee 2 -m comment --comment "Drop traffic without an IP/MAC allow rule." -j DROP
27. -I neutron-openvswi-sg-chain 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-i355ee-9aee
28. -I neutron-openvswi-sg-chain 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-o355ee-9aee
29. COMMIT
30. # Completed by iptables_manager
31. # Generated by iptables_manager
32. *raw
33. -I neutron-openvswi-PREROUTING 1 -m physdev --physdev-in brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
34. -I neutron-openvswi-PREROUTING 2 -i brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
35. -I neutron-openvswi-PREROUTING 3 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
-I neutron-openvswi-FORWARD 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
-I neutron-openvswi-FORWARD 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
-I neutron-openvswi-FORWARD 3 -m physdev --physdev-out 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
-I neutron-openvswi-FORWARD 4 -m physdev --physdev-in 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
-I neutron-openvswi-INPUT 1 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct incoming traffic from VM to the security group chain." -j neutron-openvswi-o355ee-9aee
-I neutron-openvswi-i355ee-9aee 1 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
-I neutron-openvswi-i355ee-9aee 4 -m set --match-set NIPv44c29a64f-b883-4622-893c- src -j RETURN
-I neutron-openvswi-i355ee-9aee 5 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
-I neutron-openvswi-i355ee-9aee 6 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
-I neutron-openvswi-o355ee-9aee 5 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
-I neutron-openvswi-o355ee-9aee 6 -j RETURN
-I neutron-openvswi-o355ee-9aee 7 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
-I neutron-openvswi-o355ee-9aee 8 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
-I neutron-openvswi-s355ee-9aee 1 -s 172.16.129.142/32 -m mac --mac-source FA:16:3E:07:C5:CB -m comment --comment "Allow traffic from defined IP/MAC pairs." -j RETURN
-I neutron-openvswi-s355ee-9aee 2 -m comment --comment "Drop traffic without an IP/MAC allow rule." -j DROP
-I neutron-openvswi-sg-chain 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-i355ee-9aee
-I neutron-openvswi-sg-chain 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-o355ee-9aee
COMMIT
# Completed by iptables_manager
# Generated by iptables_manager
*raw
-I neutron-openvswi-PREROUTING 1 -m physdev --physdev-in brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
-I neutron-openvswi-PREROUTING 2 -i brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
-I neutron-openvswi-PREROUTING 3 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
COMMIT
# Completed by iptables_manager
; Stdout: ; Stderr: iptables-restore v1.8.9 (nf_tables): interface name `de8355ee-9aee-4de4-9df9-513d9d62c08c' must be shorter than IFNAMSIZ (15)
Error occurred at line: 6
Try `iptables-restore -h' or 'iptables-restore --help' for more information.
2024-04-18 13:28:26.624 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-FORWARD 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
2024-04-18 13:28:26.624 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-FORWARD 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
2024-04-18 13:28:26.624 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-FORWARD 3 -m physdev --physdev-out 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
2024-04-18 13:28:26.624 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-FORWARD 4 -m physdev --physdev-in 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
2024-04-18 13:28:26.624 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-INPUT 1 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct incoming traffic from VM to the security group chain." -j neutron-openvswi-o355ee-9aee
2024-04-18 13:28:26.624 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-i355ee-9aee 1 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
2024-04-18 13:28:26.624 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-i355ee-9aee 5 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
2024-04-18 13:28:26.624 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-i355ee-9aee 6 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
2024-04-18 13:28:26.624 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 5 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
2024-04-18 13:28:26.624 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 7 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
2024-04-18 13:28:26.624 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 8 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
2024-04-18 13:28:26.624 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-s355ee-9aee 1 -s 172.16.129.142/32 -m mac --mac-source FA:16:3E:07:C5:CB -m comment --comment "Allow traffic from defined IP/MAC pairs." -j RETURN
2024-04-18 13:28:26.624 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-s355ee-9aee 2 -m comment --comment "Drop traffic without an IP/MAC allow rule." -j DROP
2024-04-18 13:28:26.624 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-sg-chain 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-i355ee-9aee
2024-04-18 13:28:26.624 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-sg-chain 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-o355ee-9aee
2024-04-18 13:28:26.624 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent # Completed by iptables_manager
2024-04-18 13:28:26.624 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent ; Stdout: ; Stderr: iptables-restore v1.8.9 (nf_tables): interface name `de8355ee-9aee-4de4-9df9-513d9d62c08c' must be shorter than IFNAMSIZ (15)
2024-04-18 13:28:26.624 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent Error occurred at line: 6
2024-04-18 13:28:26.624 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent Try `iptables-restore -h' or 'iptables-restore --help' for more information.
Apr 18 13:28:28 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:28.626 8372 ERROR neutron.agent.linux.iptables_manager [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] IPTablesManager.apply failed to apply the following set of iptables rules:
1. # Generated by iptables_manager
2. *filter
3. :neutron-openvswi-i355ee-9aee - [0:0]
4. :neutron-openvswi-o355ee-9aee - [0:0]
5. :neutron-openvswi-s355ee-9aee - [0:0]
6. -I neutron-openvswi-FORWARD 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
7. -I neutron-openvswi-FORWARD 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
8. -I neutron-openvswi-FORWARD 3 -m physdev --physdev-out 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
9. -I neutron-openvswi-FORWARD 4 -m physdev --physdev-in 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
10. -I neutron-openvswi-INPUT 1 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct incoming traffic from VM to the security group chain." -j neutron-openvswi-o355ee-9aee
11. -I neutron-openvswi-i355ee-9aee 1 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
15. -I neutron-openvswi-i355ee-9aee 5 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
16. -I neutron-openvswi-i355ee-9aee 6 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
21. -I neutron-openvswi-o355ee-9aee 5 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
22. -I neutron-openvswi-o355ee-9aee 6 -j RETURN
23. -I neutron-openvswi-o355ee-9aee 7 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
24. -I neutron-openvswi-o355ee-9aee 8 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
25. -I neutron-openvswi-s355ee-9aee 1 -s 172.16.129.142/32 -m mac --mac-source FA:16:3E:07:C5:CB -m comment --comment "Allow traffic from defined IP/MAC pairs." -j RETURN
26. -I neutron-openvswi-s355ee-9aee 2 -m comment --comment "Drop traffic without an IP/MAC allow rule." -j DROP
27. -I neutron-openvswi-sg-chain 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-i355ee-9aee
28. -I neutron-openvswi-sg-chain 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-o355ee-9aee
29. COMMIT
30. # Completed by iptables_manager
31. # Generated by iptables_manager
32. *raw
33. -I neutron-openvswi-PREROUTING 1 -m physdev --physdev-in brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
34. -I neutron-openvswi-PREROUTING 2 -i brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
35. -I neutron-openvswi-PREROUTING 3 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
-I neutron-openvswi-FORWARD 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
-I neutron-openvswi-FORWARD 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
-I neutron-openvswi-FORWARD 3 -m physdev --physdev-out 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
-I neutron-openvswi-FORWARD 4 -m physdev --physdev-in 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
-I neutron-openvswi-INPUT 1 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct incoming traffic from VM to the security group chain." -j neutron-openvswi-o355ee-9aee
-I neutron-openvswi-i355ee-9aee 1 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
-I neutron-openvswi-i355ee-9aee 4 -m set --match-set NIPv44c29a64f-b883-4622-893c- src -j RETURN
-I neutron-openvswi-i355ee-9aee 5 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
-I neutron-openvswi-i355ee-9aee 6 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
-I neutron-openvswi-o355ee-9aee 5 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
-I neutron-openvswi-o355ee-9aee 6 -j RETURN
-I neutron-openvswi-o355ee-9aee 7 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
-I neutron-openvswi-o355ee-9aee 8 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
-I neutron-openvswi-s355ee-9aee 1 -s 172.16.129.142/32 -m mac --mac-source FA:16:3E:07:C5:CB -m comment --comment "Allow traffic from defined IP/MAC pairs." -j RETURN
-I neutron-openvswi-s355ee-9aee 2 -m comment --comment "Drop traffic without an IP/MAC allow rule." -j DROP
-I neutron-openvswi-sg-chain 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-i355ee-9aee
-I neutron-openvswi-sg-chain 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-o355ee-9aee
COMMIT
# Completed by iptables_manager
# Generated by iptables_manager
*raw
-I neutron-openvswi-PREROUTING 1 -m physdev --physdev-in brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
-I neutron-openvswi-PREROUTING 2 -i brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
-I neutron-openvswi-PREROUTING 3 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
COMMIT
# Completed by iptables_manager
; Stdout: ; Stderr: iptables-restore v1.8.9 (nf_tables): interface name `de8355ee-9aee-4de4-9df9-513d9d62c08c' must be shorter than IFNAMSIZ (15)
Error occurred at line: 6
Try `iptables-restore -h' or 'iptables-restore --help' for more information.
2024-04-18 13:28:28.627 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-FORWARD 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
2024-04-18 13:28:28.627 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-FORWARD 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
2024-04-18 13:28:28.627 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-FORWARD 3 -m physdev --physdev-out 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
2024-04-18 13:28:28.627 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-FORWARD 4 -m physdev --physdev-in 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
2024-04-18 13:28:28.627 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-INPUT 1 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct incoming traffic from VM to the security group chain." -j neutron-openvswi-o355ee-9aee
2024-04-18 13:28:28.627 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-i355ee-9aee 1 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
2024-04-18 13:28:28.627 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-i355ee-9aee 5 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
2024-04-18 13:28:28.627 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-i355ee-9aee 6 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
2024-04-18 13:28:28.627 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 5 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
2024-04-18 13:28:28.627 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 7 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
2024-04-18 13:28:28.627 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 8 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
2024-04-18 13:28:28.627 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-s355ee-9aee 1 -s 172.16.129.142/32 -m mac --mac-source FA:16:3E:07:C5:CB -m comment --comment "Allow traffic from defined IP/MAC pairs." -j RETURN
2024-04-18 13:28:28.627 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-s355ee-9aee 2 -m comment --comment "Drop traffic without an IP/MAC allow rule." -j DROP
2024-04-18 13:28:28.627 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-sg-chain 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-i355ee-9aee
2024-04-18 13:28:28.627 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-sg-chain 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-o355ee-9aee
2024-04-18 13:28:28.627 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent # Completed by iptables_manager
2024-04-18 13:28:28.627 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent ; Stdout: ; Stderr: iptables-restore v1.8.9 (nf_tables): interface name `de8355ee-9aee-4de4-9df9-513d9d62c08c' must be shorter than IFNAMSIZ (15)
2024-04-18 13:28:28.627 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent Error occurred at line: 6
2024-04-18 13:28:28.627 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent Try `iptables-restore -h' or 'iptables-restore --help' for more information.
Apr 18 13:28:30 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:30.627 8372 ERROR neutron.agent.linux.iptables_manager [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] IPTablesManager.apply failed to apply the following set of iptables rules:
1. # Generated by iptables_manager
2. *filter
3. :neutron-openvswi-i355ee-9aee - [0:0]
4. :neutron-openvswi-o355ee-9aee - [0:0]
5. :neutron-openvswi-s355ee-9aee - [0:0]
6. -I neutron-openvswi-FORWARD 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
7. -I neutron-openvswi-FORWARD 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
8. -I neutron-openvswi-FORWARD 3 -m physdev --physdev-out 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
9. -I neutron-openvswi-FORWARD 4 -m physdev --physdev-in 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
10. -I neutron-openvswi-INPUT 1 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct incoming traffic from VM to the security group chain." -j neutron-openvswi-o355ee-9aee
11. -I neutron-openvswi-i355ee-9aee 1 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
15. -I neutron-openvswi-i355ee-9aee 5 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
16. -I neutron-openvswi-i355ee-9aee 6 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
21. -I neutron-openvswi-o355ee-9aee 5 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
22. -I neutron-openvswi-o355ee-9aee 6 -j RETURN
23. -I neutron-openvswi-o355ee-9aee 7 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
24. -I neutron-openvswi-o355ee-9aee 8 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
25. -I neutron-openvswi-s355ee-9aee 1 -s 172.16.129.142/32 -m mac --mac-source FA:16:3E:07:C5:CB -m comment --comment "Allow traffic from defined IP/MAC pairs." -j RETURN
26. -I neutron-openvswi-s355ee-9aee 2 -m comment --comment "Drop traffic without an IP/MAC allow rule." -j DROP
27. -I neutron-openvswi-sg-chain 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-i355ee-9aee
28. -I neutron-openvswi-sg-chain 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-o355ee-9aee
29. COMMIT
30. # Completed by iptables_manager
31. # Generated by iptables_manager
32. *raw
33. -I neutron-openvswi-PREROUTING 1 -m physdev --physdev-in brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
34. -I neutron-openvswi-PREROUTING 2 -i brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
35. -I neutron-openvswi-PREROUTING 3 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
-I neutron-openvswi-FORWARD 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
-I neutron-openvswi-FORWARD 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
-I neutron-openvswi-FORWARD 3 -m physdev --physdev-out 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
-I neutron-openvswi-FORWARD 4 -m physdev --physdev-in 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
-I neutron-openvswi-INPUT 1 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct incoming traffic from VM to the security group chain." -j neutron-openvswi-o355ee-9aee
-I neutron-openvswi-i355ee-9aee 1 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
-I neutron-openvswi-i355ee-9aee 4 -m set --match-set NIPv44c29a64f-b883-4622-893c- src -j RETURN
-I neutron-openvswi-i355ee-9aee 5 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
-I neutron-openvswi-i355ee-9aee 6 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
-I neutron-openvswi-o355ee-9aee 5 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
-I neutron-openvswi-o355ee-9aee 6 -j RETURN
-I neutron-openvswi-o355ee-9aee 7 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
-I neutron-openvswi-o355ee-9aee 8 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
-I neutron-openvswi-s355ee-9aee 1 -s 172.16.129.142/32 -m mac --mac-source FA:16:3E:07:C5:CB -m comment --comment "Allow traffic from defined IP/MAC pairs." -j RETURN
-I neutron-openvswi-s355ee-9aee 2 -m comment --comment "Drop traffic without an IP/MAC allow rule." -j DROP
-I neutron-openvswi-sg-chain 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-i355ee-9aee
-I neutron-openvswi-sg-chain 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-o355ee-9aee
COMMIT
# Completed by iptables_manager
# Generated by iptables_manager
*raw
-I neutron-openvswi-PREROUTING 1 -m physdev --physdev-in brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
-I neutron-openvswi-PREROUTING 2 -i brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
-I neutron-openvswi-PREROUTING 3 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
COMMIT
# Completed by iptables_manager
; Stdout: ; Stderr: iptables-restore v1.8.9 (nf_tables): interface name `de8355ee-9aee-4de4-9df9-513d9d62c08c' must be shorter than IFNAMSIZ (15)
Error occurred at line: 6
Try `iptables-restore -h' or 'iptables-restore --help' for more information.
2024-04-18 13:28:30.628 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-FORWARD 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
2024-04-18 13:28:30.628 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-FORWARD 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
2024-04-18 13:28:30.628 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-FORWARD 3 -m physdev --physdev-out 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
2024-04-18 13:28:30.628 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-FORWARD 4 -m physdev --physdev-in 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
2024-04-18 13:28:30.628 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-INPUT 1 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct incoming traffic from VM to the security group chain." -j neutron-openvswi-o355ee-9aee
2024-04-18 13:28:30.628 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-i355ee-9aee 1 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
2024-04-18 13:28:30.628 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-i355ee-9aee 5 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
2024-04-18 13:28:30.628 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-i355ee-9aee 6 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
2024-04-18 13:28:30.628 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 5 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
2024-04-18 13:28:30.628 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 7 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
2024-04-18 13:28:30.628 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 8 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
2024-04-18 13:28:30.628 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-s355ee-9aee 1 -s 172.16.129.142/32 -m mac --mac-source FA:16:3E:07:C5:CB -m comment --comment "Allow traffic from defined IP/MAC pairs." -j RETURN
2024-04-18 13:28:30.628 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-s355ee-9aee 2 -m comment --comment "Drop traffic without an IP/MAC allow rule." -j DROP
2024-04-18 13:28:30.628 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-sg-chain 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-i355ee-9aee
2024-04-18 13:28:30.628 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-sg-chain 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-o355ee-9aee
2024-04-18 13:28:30.628 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent # Completed by iptables_manager
2024-04-18 13:28:30.628 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent ; Stdout: ; Stderr: iptables-restore v1.8.9 (nf_tables): interface name `de8355ee-9aee-4de4-9df9-513d9d62c08c' must be shorter than IFNAMSIZ (15)
2024-04-18 13:28:30.628 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent Error occurred at line: 6
2024-04-18 13:28:30.628 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent Try `iptables-restore -h' or 'iptables-restore --help' for more information.
Apr 18 13:28:32 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:32.628 8372 ERROR neutron.agent.linux.iptables_manager [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] IPTablesManager.apply failed to apply the following set of iptables rules:
1. # Generated by iptables_manager
2. *filter
3. :neutron-openvswi-i355ee-9aee - [0:0]
4. :neutron-openvswi-o355ee-9aee - [0:0]
5. :neutron-openvswi-s355ee-9aee - [0:0]
6. -I neutron-openvswi-FORWARD 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
7. -I neutron-openvswi-FORWARD 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
8. -I neutron-openvswi-FORWARD 3 -m physdev --physdev-out 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
9. -I neutron-openvswi-FORWARD 4 -m physdev --physdev-in 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
10. -I neutron-openvswi-INPUT 1 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct incoming traffic from VM to the security group chain." -j neutron-openvswi-o355ee-9aee
11. -I neutron-openvswi-i355ee-9aee 1 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
15. -I neutron-openvswi-i355ee-9aee 5 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
16. -I neutron-openvswi-i355ee-9aee 6 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
21. -I neutron-openvswi-o355ee-9aee 5 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
22. -I neutron-openvswi-o355ee-9aee 6 -j RETURN
23. -I neutron-openvswi-o355ee-9aee 7 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
24. -I neutron-openvswi-o355ee-9aee 8 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
25. -I neutron-openvswi-s355ee-9aee 1 -s 172.16.129.142/32 -m mac --mac-source FA:16:3E:07:C5:CB -m comment --comment "Allow traffic from defined IP/MAC pairs." -j RETURN
26. -I neutron-openvswi-s355ee-9aee 2 -m comment --comment "Drop traffic without an IP/MAC allow rule." -j DROP
27. -I neutron-openvswi-sg-chain 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-i355ee-9aee
28. -I neutron-openvswi-sg-chain 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-o355ee-9aee
29. COMMIT
30. # Completed by iptables_manager
31. # Generated by iptables_manager
32. *raw
33. -I neutron-openvswi-PREROUTING 1 -m physdev --physdev-in brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
34. -I neutron-openvswi-PREROUTING 2 -i brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
35. -I neutron-openvswi-PREROUTING 3 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
-I neutron-openvswi-FORWARD 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
-I neutron-openvswi-FORWARD 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
-I neutron-openvswi-FORWARD 3 -m physdev --physdev-out 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
-I neutron-openvswi-FORWARD 4 -m physdev --physdev-in 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
-I neutron-openvswi-INPUT 1 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct incoming traffic from VM to the security group chain." -j neutron-openvswi-o355ee-9aee
-I neutron-openvswi-i355ee-9aee 1 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
-I neutron-openvswi-i355ee-9aee 4 -m set --match-set NIPv44c29a64f-b883-4622-893c- src -j RETURN
-I neutron-openvswi-i355ee-9aee 5 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
-I neutron-openvswi-i355ee-9aee 6 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
-I neutron-openvswi-o355ee-9aee 5 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
-I neutron-openvswi-o355ee-9aee 6 -j RETURN
-I neutron-openvswi-o355ee-9aee 7 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
-I neutron-openvswi-o355ee-9aee 8 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
-I neutron-openvswi-s355ee-9aee 1 -s 172.16.129.142/32 -m mac --mac-source FA:16:3E:07:C5:CB -m comment --comment "Allow traffic from defined IP/MAC pairs." -j RETURN
-I neutron-openvswi-s355ee-9aee 2 -m comment --comment "Drop traffic without an IP/MAC allow rule." -j DROP
-I neutron-openvswi-sg-chain 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-i355ee-9aee
-I neutron-openvswi-sg-chain 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-o355ee-9aee
COMMIT
# Completed by iptables_manager
# Generated by iptables_manager
*raw
-I neutron-openvswi-PREROUTING 1 -m physdev --physdev-in brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
-I neutron-openvswi-PREROUTING 2 -i brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
-I neutron-openvswi-PREROUTING 3 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
COMMIT
# Completed by iptables_manager
; Stdout: ; Stderr: iptables-restore v1.8.9 (nf_tables): interface name `de8355ee-9aee-4de4-9df9-513d9d62c08c' must be shorter than IFNAMSIZ (15)
Error occurred at line: 6
Try `iptables-restore -h' or 'iptables-restore --help' for more information.
2024-04-18 13:28:32.629 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-FORWARD 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
2024-04-18 13:28:32.629 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-FORWARD 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
2024-04-18 13:28:32.629 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-FORWARD 3 -m physdev --physdev-out 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
2024-04-18 13:28:32.629 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-FORWARD 4 -m physdev --physdev-in 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
2024-04-18 13:28:32.629 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-INPUT 1 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct incoming traffic from VM to the security group chain." -j neutron-openvswi-o355ee-9aee
2024-04-18 13:28:32.629 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-i355ee-9aee 1 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
2024-04-18 13:28:32.629 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-i355ee-9aee 5 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
2024-04-18 13:28:32.629 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-i355ee-9aee 6 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
2024-04-18 13:28:32.629 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 5 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
2024-04-18 13:28:32.629 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 7 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
2024-04-18 13:28:32.629 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 8 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
2024-04-18 13:28:32.629 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-s355ee-9aee 1 -s 172.16.129.142/32 -m mac --mac-source FA:16:3E:07:C5:CB -m comment --comment "Allow traffic from defined IP/MAC pairs." -j RETURN
2024-04-18 13:28:32.629 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-s355ee-9aee 2 -m comment --comment "Drop traffic without an IP/MAC allow rule." -j DROP
2024-04-18 13:28:32.629 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-sg-chain 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-i355ee-9aee
2024-04-18 13:28:32.629 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-sg-chain 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-o355ee-9aee
2024-04-18 13:28:32.629 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent # Completed by iptables_manager
2024-04-18 13:28:32.629 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent ; Stdout: ; Stderr: iptables-restore v1.8.9 (nf_tables): interface name `de8355ee-9aee-4de4-9df9-513d9d62c08c' must be shorter than IFNAMSIZ (15)
2024-04-18 13:28:32.629 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent Error occurred at line: 6
2024-04-18 13:28:32.629 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent Try `iptables-restore -h' or 'iptables-restore --help' for more information.
Apr 18 13:28:34 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:34.630 8372 ERROR neutron.agent.linux.iptables_manager [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] IPTablesManager.apply failed to apply the following set of iptables rules:
1. # Generated by iptables_manager
2. *filter
3. :neutron-openvswi-i355ee-9aee - [0:0]
4. :neutron-openvswi-o355ee-9aee - [0:0]
5. :neutron-openvswi-s355ee-9aee - [0:0]
6. -I neutron-openvswi-FORWARD 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
7. -I neutron-openvswi-FORWARD 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
8. -I neutron-openvswi-FORWARD 3 -m physdev --physdev-out 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
9. -I neutron-openvswi-FORWARD 4 -m physdev --physdev-in 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
10. -I neutron-openvswi-INPUT 1 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct incoming traffic from VM to the security group chain." -j neutron-openvswi-o355ee-9aee
11. -I neutron-openvswi-i355ee-9aee 1 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
15. -I neutron-openvswi-i355ee-9aee 5 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
16. -I neutron-openvswi-i355ee-9aee 6 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
21. -I neutron-openvswi-o355ee-9aee 5 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
22. -I neutron-openvswi-o355ee-9aee 6 -j RETURN
23. -I neutron-openvswi-o355ee-9aee 7 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
24. -I neutron-openvswi-o355ee-9aee 8 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
25. -I neutron-openvswi-s355ee-9aee 1 -s 172.16.129.142/32 -m mac --mac-source FA:16:3E:07:C5:CB -m comment --comment "Allow traffic from defined IP/MAC pairs." -j RETURN
26. -I neutron-openvswi-s355ee-9aee 2 -m comment --comment "Drop traffic without an IP/MAC allow rule." -j DROP
27. -I neutron-openvswi-sg-chain 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-i355ee-9aee
28. -I neutron-openvswi-sg-chain 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-o355ee-9aee
29. COMMIT
30. # Completed by iptables_manager
31. # Generated by iptables_manager
32. *raw
33. -I neutron-openvswi-PREROUTING 1 -m physdev --physdev-in brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
34. -I neutron-openvswi-PREROUTING 2 -i brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
35. -I neutron-openvswi-PREROUTING 3 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
-I neutron-openvswi-FORWARD 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
-I neutron-openvswi-FORWARD 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
-I neutron-openvswi-FORWARD 3 -m physdev --physdev-out 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
-I neutron-openvswi-FORWARD 4 -m physdev --physdev-in 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
-I neutron-openvswi-INPUT 1 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct incoming traffic from VM to the security group chain." -j neutron-openvswi-o355ee-9aee
-I neutron-openvswi-i355ee-9aee 1 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
-I neutron-openvswi-i355ee-9aee 4 -m set --match-set NIPv44c29a64f-b883-4622-893c- src -j RETURN
-I neutron-openvswi-i355ee-9aee 5 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
-I neutron-openvswi-i355ee-9aee 6 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
-I neutron-openvswi-o355ee-9aee 5 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
-I neutron-openvswi-o355ee-9aee 6 -j RETURN
-I neutron-openvswi-o355ee-9aee 7 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
-I neutron-openvswi-o355ee-9aee 8 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
-I neutron-openvswi-s355ee-9aee 1 -s 172.16.129.142/32 -m mac --mac-source FA:16:3E:07:C5:CB -m comment --comment "Allow traffic from defined IP/MAC pairs." -j RETURN
-I neutron-openvswi-s355ee-9aee 2 -m comment --comment "Drop traffic without an IP/MAC allow rule." -j DROP
-I neutron-openvswi-sg-chain 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-i355ee-9aee
-I neutron-openvswi-sg-chain 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-o355ee-9aee
COMMIT
# Completed by iptables_manager
# Generated by iptables_manager
*raw
-I neutron-openvswi-PREROUTING 1 -m physdev --physdev-in brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
-I neutron-openvswi-PREROUTING 2 -i brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
-I neutron-openvswi-PREROUTING 3 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
COMMIT
# Completed by iptables_manager
; Stdout: ; Stderr: iptables-restore v1.8.9 (nf_tables): interface name `de8355ee-9aee-4de4-9df9-513d9d62c08c' must be shorter than IFNAMSIZ (15)
Error occurred at line: 6
Try `iptables-restore -h' or 'iptables-restore --help' for more information.
2024-04-18 13:28:34.631 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-FORWARD 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
2024-04-18 13:28:34.631 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-FORWARD 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
2024-04-18 13:28:34.631 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-FORWARD 3 -m physdev --physdev-out 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
2024-04-18 13:28:34.631 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-FORWARD 4 -m physdev --physdev-in 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
2024-04-18 13:28:34.631 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-INPUT 1 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct incoming traffic from VM to the security group chain." -j neutron-openvswi-o355ee-9aee
2024-04-18 13:28:34.631 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-i355ee-9aee 1 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
2024-04-18 13:28:34.631 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-i355ee-9aee 5 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
2024-04-18 13:28:34.631 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-i355ee-9aee 6 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
2024-04-18 13:28:34.631 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 5 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
2024-04-18 13:28:34.631 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 7 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
2024-04-18 13:28:34.631 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 8 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
2024-04-18 13:28:34.631 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-s355ee-9aee 1 -s 172.16.129.142/32 -m mac --mac-source FA:16:3E:07:C5:CB -m comment --comment "Allow traffic from defined IP/MAC pairs." -j RETURN
2024-04-18 13:28:34.631 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-s355ee-9aee 2 -m comment --comment "Drop traffic without an IP/MAC allow rule." -j DROP
2024-04-18 13:28:34.631 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-sg-chain 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-i355ee-9aee
2024-04-18 13:28:34.631 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-sg-chain 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-o355ee-9aee
2024-04-18 13:28:34.631 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent # Completed by iptables_manager
2024-04-18 13:28:34.631 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent ; Stdout: ; Stderr: iptables-restore v1.8.9 (nf_tables): interface name `de8355ee-9aee-4de4-9df9-513d9d62c08c' must be shorter than IFNAMSIZ (15)
2024-04-18 13:28:34.631 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent Error occurred at line: 6
2024-04-18 13:28:34.631 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent Try `iptables-restore -h' or 'iptables-restore --help' for more information.
Apr 18 13:28:36 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:36.629 8372 ERROR neutron.agent.linux.iptables_manager [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] IPTablesManager.apply failed to apply the following set of iptables rules:
1. # Generated by iptables_manager
2. *filter
3. :neutron-openvswi-i355ee-9aee - [0:0]
4. :neutron-openvswi-o355ee-9aee - [0:0]
5. :neutron-openvswi-s355ee-9aee - [0:0]
6. -I neutron-openvswi-FORWARD 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
7. -I neutron-openvswi-FORWARD 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
8. -I neutron-openvswi-FORWARD 3 -m physdev --physdev-out 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
9. -I neutron-openvswi-FORWARD 4 -m physdev --physdev-in 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
10. -I neutron-openvswi-INPUT 1 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct incoming traffic from VM to the security group chain." -j neutron-openvswi-o355ee-9aee
11. -I neutron-openvswi-i355ee-9aee 1 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
15. -I neutron-openvswi-i355ee-9aee 5 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
16. -I neutron-openvswi-i355ee-9aee 6 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
21. -I neutron-openvswi-o355ee-9aee 5 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
22. -I neutron-openvswi-o355ee-9aee 6 -j RETURN
23. -I neutron-openvswi-o355ee-9aee 7 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
24. -I neutron-openvswi-o355ee-9aee 8 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
25. -I neutron-openvswi-s355ee-9aee 1 -s 172.16.129.142/32 -m mac --mac-source FA:16:3E:07:C5:CB -m comment --comment "Allow traffic from defined IP/MAC pairs." -j RETURN
26. -I neutron-openvswi-s355ee-9aee 2 -m comment --comment "Drop traffic without an IP/MAC allow rule." -j DROP
27. -I neutron-openvswi-sg-chain 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-i355ee-9aee
28. -I neutron-openvswi-sg-chain 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-o355ee-9aee
29. COMMIT
30. # Completed by iptables_manager
31. # Generated by iptables_manager
32. *raw
33. -I neutron-openvswi-PREROUTING 1 -m physdev --physdev-in brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
34. -I neutron-openvswi-PREROUTING 2 -i brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
35. -I neutron-openvswi-PREROUTING 3 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
-I neutron-openvswi-FORWARD 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
-I neutron-openvswi-FORWARD 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
-I neutron-openvswi-FORWARD 3 -m physdev --physdev-out 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
-I neutron-openvswi-FORWARD 4 -m physdev --physdev-in 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
-I neutron-openvswi-INPUT 1 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct incoming traffic from VM to the security group chain." -j neutron-openvswi-o355ee-9aee
-I neutron-openvswi-i355ee-9aee 1 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
-I neutron-openvswi-i355ee-9aee 4 -m set --match-set NIPv44c29a64f-b883-4622-893c- src -j RETURN
-I neutron-openvswi-i355ee-9aee 5 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
-I neutron-openvswi-i355ee-9aee 6 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
-I neutron-openvswi-o355ee-9aee 5 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
-I neutron-openvswi-o355ee-9aee 6 -j RETURN
-I neutron-openvswi-o355ee-9aee 7 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
-I neutron-openvswi-o355ee-9aee 8 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
-I neutron-openvswi-s355ee-9aee 1 -s 172.16.129.142/32 -m mac --mac-source FA:16:3E:07:C5:CB -m comment --comment "Allow traffic from defined IP/MAC pairs." -j RETURN
-I neutron-openvswi-s355ee-9aee 2 -m comment --comment "Drop traffic without an IP/MAC allow rule." -j DROP
-I neutron-openvswi-sg-chain 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-i355ee-9aee
-I neutron-openvswi-sg-chain 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-o355ee-9aee
COMMIT
# Completed by iptables_manager
# Generated by iptables_manager
*raw
-I neutron-openvswi-PREROUTING 1 -m physdev --physdev-in brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
-I neutron-openvswi-PREROUTING 2 -i brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
-I neutron-openvswi-PREROUTING 3 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
COMMIT
# Completed by iptables_manager
; Stdout: ; Stderr: iptables-restore v1.8.9 (nf_tables): interface name `de8355ee-9aee-4de4-9df9-513d9d62c08c' must be shorter than IFNAMSIZ (15)
Error occurred at line: 6
Try `iptables-restore -h' or 'iptables-restore --help' for more information.
2024-04-18 13:28:36.630 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-FORWARD 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
2024-04-18 13:28:36.630 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-FORWARD 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
2024-04-18 13:28:36.630 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-FORWARD 3 -m physdev --physdev-out 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
2024-04-18 13:28:36.630 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-FORWARD 4 -m physdev --physdev-in 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
2024-04-18 13:28:36.630 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-INPUT 1 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct incoming traffic from VM to the security group chain." -j neutron-openvswi-o355ee-9aee
2024-04-18 13:28:36.630 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-i355ee-9aee 1 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
2024-04-18 13:28:36.630 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-i355ee-9aee 5 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
2024-04-18 13:28:36.630 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-i355ee-9aee 6 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
2024-04-18 13:28:36.630 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 5 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
2024-04-18 13:28:36.630 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 7 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
2024-04-18 13:28:36.630 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 8 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
2024-04-18 13:28:36.630 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-s355ee-9aee 1 -s 172.16.129.142/32 -m mac --mac-source FA:16:3E:07:C5:CB -m comment --comment "Allow traffic from defined IP/MAC pairs." -j RETURN
2024-04-18 13:28:36.630 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-s355ee-9aee 2 -m comment --comment "Drop traffic without an IP/MAC allow rule." -j DROP
2024-04-18 13:28:36.630 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-sg-chain 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-i355ee-9aee
2024-04-18 13:28:36.630 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-sg-chain 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-o355ee-9aee
2024-04-18 13:28:36.630 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent # Completed by iptables_manager
2024-04-18 13:28:36.630 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent ; Stdout: ; Stderr: iptables-restore v1.8.9 (nf_tables): interface name `de8355ee-9aee-4de4-9df9-513d9d62c08c' must be shorter than IFNAMSIZ (15)
2024-04-18 13:28:36.630 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent Error occurred at line: 6
2024-04-18 13:28:36.630 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent Try `iptables-restore -h' or 'iptables-restore --help' for more information.
Apr 18 13:28:38 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:38.631 8372 ERROR neutron.agent.linux.iptables_manager [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] IPTablesManager.apply failed to apply the following set of iptables rules:
1. # Generated by iptables_manager
2. *filter
3. :neutron-openvswi-i355ee-9aee - [0:0]
4. :neutron-openvswi-o355ee-9aee - [0:0]
5. :neutron-openvswi-s355ee-9aee - [0:0]
6. -I neutron-openvswi-FORWARD 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
7. -I neutron-openvswi-FORWARD 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
8. -I neutron-openvswi-FORWARD 3 -m physdev --physdev-out 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
9. -I neutron-openvswi-FORWARD 4 -m physdev --physdev-in 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
10. -I neutron-openvswi-INPUT 1 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct incoming traffic from VM to the security group chain." -j neutron-openvswi-o355ee-9aee
11. -I neutron-openvswi-i355ee-9aee 1 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
15. -I neutron-openvswi-i355ee-9aee 5 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
16. -I neutron-openvswi-i355ee-9aee 6 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
21. -I neutron-openvswi-o355ee-9aee 5 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
22. -I neutron-openvswi-o355ee-9aee 6 -j RETURN
23. -I neutron-openvswi-o355ee-9aee 7 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
24. -I neutron-openvswi-o355ee-9aee 8 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
25. -I neutron-openvswi-s355ee-9aee 1 -s 172.16.129.142/32 -m mac --mac-source FA:16:3E:07:C5:CB -m comment --comment "Allow traffic from defined IP/MAC pairs." -j RETURN
26. -I neutron-openvswi-s355ee-9aee 2 -m comment --comment "Drop traffic without an IP/MAC allow rule." -j DROP
27. -I neutron-openvswi-sg-chain 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-i355ee-9aee
28. -I neutron-openvswi-sg-chain 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-o355ee-9aee
29. COMMIT
30. # Completed by iptables_manager
31. # Generated by iptables_manager
32. *raw
33. -I neutron-openvswi-PREROUTING 1 -m physdev --physdev-in brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
34. -I neutron-openvswi-PREROUTING 2 -i brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
35. -I neutron-openvswi-PREROUTING 3 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
-I neutron-openvswi-FORWARD 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
-I neutron-openvswi-FORWARD 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
-I neutron-openvswi-FORWARD 3 -m physdev --physdev-out 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
-I neutron-openvswi-FORWARD 4 -m physdev --physdev-in 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
-I neutron-openvswi-INPUT 1 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct incoming traffic from VM to the security group chain." -j neutron-openvswi-o355ee-9aee
-I neutron-openvswi-i355ee-9aee 1 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
-I neutron-openvswi-i355ee-9aee 4 -m set --match-set NIPv44c29a64f-b883-4622-893c- src -j RETURN
-I neutron-openvswi-i355ee-9aee 5 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
-I neutron-openvswi-i355ee-9aee 6 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
-I neutron-openvswi-o355ee-9aee 5 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
-I neutron-openvswi-o355ee-9aee 6 -j RETURN
-I neutron-openvswi-o355ee-9aee 7 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
-I neutron-openvswi-o355ee-9aee 8 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
-I neutron-openvswi-s355ee-9aee 1 -s 172.16.129.142/32 -m mac --mac-source FA:16:3E:07:C5:CB -m comment --comment "Allow traffic from defined IP/MAC pairs." -j RETURN
-I neutron-openvswi-s355ee-9aee 2 -m comment --comment "Drop traffic without an IP/MAC allow rule." -j DROP
-I neutron-openvswi-sg-chain 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-i355ee-9aee
-I neutron-openvswi-sg-chain 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-o355ee-9aee
COMMIT
# Completed by iptables_manager
# Generated by iptables_manager
*raw
-I neutron-openvswi-PREROUTING 1 -m physdev --physdev-in brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
-I neutron-openvswi-PREROUTING 2 -i brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
-I neutron-openvswi-PREROUTING 3 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
COMMIT
# Completed by iptables_manager
; Stdout: ; Stderr: iptables-restore v1.8.9 (nf_tables): interface name `de8355ee-9aee-4de4-9df9-513d9d62c08c' must be shorter than IFNAMSIZ (15)
Error occurred at line: 6
Try `iptables-restore -h' or 'iptables-restore --help' for more information.
2024-04-18 13:28:38.632 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-FORWARD 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
2024-04-18 13:28:38.632 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-FORWARD 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
2024-04-18 13:28:38.632 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-FORWARD 3 -m physdev --physdev-out 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
2024-04-18 13:28:38.632 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-FORWARD 4 -m physdev --physdev-in 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
2024-04-18 13:28:38.632 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-INPUT 1 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct incoming traffic from VM to the security group chain." -j neutron-openvswi-o355ee-9aee
2024-04-18 13:28:38.632 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-i355ee-9aee 1 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
2024-04-18 13:28:38.632 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-i355ee-9aee 5 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
2024-04-18 13:28:38.632 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-i355ee-9aee 6 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
2024-04-18 13:28:38.632 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 5 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
2024-04-18 13:28:38.632 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 7 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
2024-04-18 13:28:38.632 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 8 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
2024-04-18 13:28:38.632 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-s355ee-9aee 1 -s 172.16.129.142/32 -m mac --mac-source FA:16:3E:07:C5:CB -m comment --comment "Allow traffic from defined IP/MAC pairs." -j RETURN
2024-04-18 13:28:38.632 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-s355ee-9aee 2 -m comment --comment "Drop traffic without an IP/MAC allow rule." -j DROP
2024-04-18 13:28:38.632 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-sg-chain 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-i355ee-9aee
2024-04-18 13:28:38.632 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-sg-chain 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-o355ee-9aee
2024-04-18 13:28:38.632 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent # Completed by iptables_manager
2024-04-18 13:28:38.632 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent ; Stdout: ; Stderr: iptables-restore v1.8.9 (nf_tables): interface name `de8355ee-9aee-4de4-9df9-513d9d62c08c' must be shorter than IFNAMSIZ (15)
2024-04-18 13:28:38.632 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent Error occurred at line: 6
2024-04-18 13:28:38.632 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent Try `iptables-restore -h' or 'iptables-restore --help' for more information.
Apr 18 13:28:40 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:40.633 8372 ERROR neutron.agent.linux.iptables_manager [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] IPTablesManager.apply failed to apply the following set of iptables rules:
1. # Generated by iptables_manager
2. *filter
3. :neutron-openvswi-i355ee-9aee - [0:0]
4. :neutron-openvswi-o355ee-9aee - [0:0]
5. :neutron-openvswi-s355ee-9aee - [0:0]
6. -I neutron-openvswi-FORWARD 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
7. -I neutron-openvswi-FORWARD 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
8. -I neutron-openvswi-FORWARD 3 -m physdev --physdev-out 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
9. -I neutron-openvswi-FORWARD 4 -m physdev --physdev-in 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
10. -I neutron-openvswi-INPUT 1 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct incoming traffic from VM to the security group chain." -j neutron-openvswi-o355ee-9aee
11. -I neutron-openvswi-i355ee-9aee 1 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
15. -I neutron-openvswi-i355ee-9aee 5 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
16. -I neutron-openvswi-i355ee-9aee 6 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
21. -I neutron-openvswi-o355ee-9aee 5 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
22. -I neutron-openvswi-o355ee-9aee 6 -j RETURN
23. -I neutron-openvswi-o355ee-9aee 7 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
24. -I neutron-openvswi-o355ee-9aee 8 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
25. -I neutron-openvswi-s355ee-9aee 1 -s 172.16.129.142/32 -m mac --mac-source FA:16:3E:07:C5:CB -m comment --comment "Allow traffic from defined IP/MAC pairs." -j RETURN
26. -I neutron-openvswi-s355ee-9aee 2 -m comment --comment "Drop traffic without an IP/MAC allow rule." -j DROP
27. -I neutron-openvswi-sg-chain 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-i355ee-9aee
28. -I neutron-openvswi-sg-chain 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-o355ee-9aee
29. COMMIT
30. # Completed by iptables_manager
31. # Generated by iptables_manager
32. *raw
33. -I neutron-openvswi-PREROUTING 1 -m physdev --physdev-in brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
34. -I neutron-openvswi-PREROUTING 2 -i brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
35. -I neutron-openvswi-PREROUTING 3 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
-I neutron-openvswi-FORWARD 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
-I neutron-openvswi-FORWARD 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
-I neutron-openvswi-FORWARD 3 -m physdev --physdev-out 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
-I neutron-openvswi-FORWARD 4 -m physdev --physdev-in 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
-I neutron-openvswi-INPUT 1 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct incoming traffic from VM to the security group chain." -j neutron-openvswi-o355ee-9aee
-I neutron-openvswi-i355ee-9aee 1 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
-I neutron-openvswi-i355ee-9aee 4 -m set --match-set NIPv44c29a64f-b883-4622-893c- src -j RETURN
-I neutron-openvswi-i355ee-9aee 5 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
-I neutron-openvswi-i355ee-9aee 6 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
-I neutron-openvswi-o355ee-9aee 5 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
-I neutron-openvswi-o355ee-9aee 6 -j RETURN
-I neutron-openvswi-o355ee-9aee 7 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
-I neutron-openvswi-o355ee-9aee 8 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
-I neutron-openvswi-s355ee-9aee 1 -s 172.16.129.142/32 -m mac --mac-source FA:16:3E:07:C5:CB -m comment --comment "Allow traffic from defined IP/MAC pairs." -j RETURN
-I neutron-openvswi-s355ee-9aee 2 -m comment --comment "Drop traffic without an IP/MAC allow rule." -j DROP
-I neutron-openvswi-sg-chain 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-i355ee-9aee
-I neutron-openvswi-sg-chain 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-o355ee-9aee
COMMIT
# Completed by iptables_manager
# Generated by iptables_manager
*raw
-I neutron-openvswi-PREROUTING 1 -m physdev --physdev-in brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
-I neutron-openvswi-PREROUTING 2 -i brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
-I neutron-openvswi-PREROUTING 3 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
COMMIT
# Completed by iptables_manager
; Stdout: ; Stderr: iptables-restore v1.8.9 (nf_tables): interface name `de8355ee-9aee-4de4-9df9-513d9d62c08c' must be shorter than IFNAMSIZ (15)
Error occurred at line: 6
Try `iptables-restore -h' or 'iptables-restore --help' for more information.
2024-04-18 13:28:40.633 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-FORWARD 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
2024-04-18 13:28:40.633 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-FORWARD 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
2024-04-18 13:28:40.633 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-FORWARD 3 -m physdev --physdev-out 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
2024-04-18 13:28:40.633 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-FORWARD 4 -m physdev --physdev-in 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
2024-04-18 13:28:40.633 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-INPUT 1 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct incoming traffic from VM to the security group chain." -j neutron-openvswi-o355ee-9aee
2024-04-18 13:28:40.633 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-i355ee-9aee 1 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
2024-04-18 13:28:40.633 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-i355ee-9aee 5 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
2024-04-18 13:28:40.633 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-i355ee-9aee 6 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
2024-04-18 13:28:40.633 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 5 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
2024-04-18 13:28:40.633 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 7 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
2024-04-18 13:28:40.633 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 8 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
2024-04-18 13:28:40.633 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-s355ee-9aee 1 -s 172.16.129.142/32 -m mac --mac-source FA:16:3E:07:C5:CB -m comment --comment "Allow traffic from defined IP/MAC pairs." -j RETURN
2024-04-18 13:28:40.633 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-s355ee-9aee 2 -m comment --comment "Drop traffic without an IP/MAC allow rule." -j DROP
2024-04-18 13:28:40.633 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-sg-chain 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-i355ee-9aee
2024-04-18 13:28:40.633 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-sg-chain 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-o355ee-9aee
2024-04-18 13:28:40.633 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent # Completed by iptables_manager
2024-04-18 13:28:40.633 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent ; Stdout: ; Stderr: iptables-restore v1.8.9 (nf_tables): interface name `de8355ee-9aee-4de4-9df9-513d9d62c08c' must be shorter than IFNAMSIZ (15)
2024-04-18 13:28:40.633 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent Error occurred at line: 6
2024-04-18 13:28:40.633 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent Try `iptables-restore -h' or 'iptables-restore --help' for more information.
Apr 18 13:28:42 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:42.635 8372 ERROR neutron.agent.linux.iptables_manager [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] IPTablesManager.apply failed to apply the following set of iptables rules:
1. # Generated by iptables_manager
2. *filter
3. :neutron-openvswi-i355ee-9aee - [0:0]
4. :neutron-openvswi-o355ee-9aee - [0:0]
5. :neutron-openvswi-s355ee-9aee - [0:0]
6. -I neutron-openvswi-FORWARD 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
7. -I neutron-openvswi-FORWARD 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
8. -I neutron-openvswi-FORWARD 3 -m physdev --physdev-out 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
9. -I neutron-openvswi-FORWARD 4 -m physdev --physdev-in 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
10. -I neutron-openvswi-INPUT 1 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct incoming traffic from VM to the security group chain." -j neutron-openvswi-o355ee-9aee
11. -I neutron-openvswi-i355ee-9aee 1 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
15. -I neutron-openvswi-i355ee-9aee 5 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
16. -I neutron-openvswi-i355ee-9aee 6 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
21. -I neutron-openvswi-o355ee-9aee 5 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
22. -I neutron-openvswi-o355ee-9aee 6 -j RETURN
23. -I neutron-openvswi-o355ee-9aee 7 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
24. -I neutron-openvswi-o355ee-9aee 8 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
25. -I neutron-openvswi-s355ee-9aee 1 -s 172.16.129.142/32 -m mac --mac-source FA:16:3E:07:C5:CB -m comment --comment "Allow traffic from defined IP/MAC pairs." -j RETURN
26. -I neutron-openvswi-s355ee-9aee 2 -m comment --comment "Drop traffic without an IP/MAC allow rule." -j DROP
27. -I neutron-openvswi-sg-chain 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-i355ee-9aee
28. -I neutron-openvswi-sg-chain 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-o355ee-9aee
29. COMMIT
30. # Completed by iptables_manager
31. # Generated by iptables_manager
32. *raw
33. -I neutron-openvswi-PREROUTING 1 -m physdev --physdev-in brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
34. -I neutron-openvswi-PREROUTING 2 -i brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
35. -I neutron-openvswi-PREROUTING 3 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
-I neutron-openvswi-FORWARD 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
-I neutron-openvswi-FORWARD 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
-I neutron-openvswi-FORWARD 3 -m physdev --physdev-out 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
-I neutron-openvswi-FORWARD 4 -m physdev --physdev-in 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
-I neutron-openvswi-INPUT 1 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct incoming traffic from VM to the security group chain." -j neutron-openvswi-o355ee-9aee
-I neutron-openvswi-i355ee-9aee 1 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
-I neutron-openvswi-i355ee-9aee 4 -m set --match-set NIPv44c29a64f-b883-4622-893c- src -j RETURN
-I neutron-openvswi-i355ee-9aee 5 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
-I neutron-openvswi-i355ee-9aee 6 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
-I neutron-openvswi-o355ee-9aee 5 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
-I neutron-openvswi-o355ee-9aee 6 -j RETURN
-I neutron-openvswi-o355ee-9aee 7 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
-I neutron-openvswi-o355ee-9aee 8 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
-I neutron-openvswi-s355ee-9aee 1 -s 172.16.129.142/32 -m mac --mac-source FA:16:3E:07:C5:CB -m comment --comment "Allow traffic from defined IP/MAC pairs." -j RETURN
-I neutron-openvswi-s355ee-9aee 2 -m comment --comment "Drop traffic without an IP/MAC allow rule." -j DROP
-I neutron-openvswi-sg-chain 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-i355ee-9aee
-I neutron-openvswi-sg-chain 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-o355ee-9aee
COMMIT
# Completed by iptables_manager
# Generated by iptables_manager
*raw
-I neutron-openvswi-PREROUTING 1 -m physdev --physdev-in brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
-I neutron-openvswi-PREROUTING 2 -i brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
-I neutron-openvswi-PREROUTING 3 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
COMMIT
# Completed by iptables_manager
; Stdout: ; Stderr: iptables-restore v1.8.9 (nf_tables): interface name `de8355ee-9aee-4de4-9df9-513d9d62c08c' must be shorter than IFNAMSIZ (15)
Error occurred at line: 6
Try `iptables-restore -h' or 'iptables-restore --help' for more information.
2024-04-18 13:28:42.636 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-FORWARD 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
2024-04-18 13:28:42.636 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-FORWARD 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
2024-04-18 13:28:42.636 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-FORWARD 3 -m physdev --physdev-out 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
2024-04-18 13:28:42.636 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-FORWARD 4 -m physdev --physdev-in 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
2024-04-18 13:28:42.636 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-INPUT 1 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct incoming traffic from VM to the security group chain." -j neutron-openvswi-o355ee-9aee
2024-04-18 13:28:42.636 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-i355ee-9aee 1 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
2024-04-18 13:28:42.636 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-i355ee-9aee 5 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
2024-04-18 13:28:42.636 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-i355ee-9aee 6 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
2024-04-18 13:28:42.636 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 5 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
2024-04-18 13:28:42.636 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 7 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
2024-04-18 13:28:42.636 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 8 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
2024-04-18 13:28:42.636 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-s355ee-9aee 1 -s 172.16.129.142/32 -m mac --mac-source FA:16:3E:07:C5:CB -m comment --comment "Allow traffic from defined IP/MAC pairs." -j RETURN
2024-04-18 13:28:42.636 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-s355ee-9aee 2 -m comment --comment "Drop traffic without an IP/MAC allow rule." -j DROP
2024-04-18 13:28:42.636 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-sg-chain 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-i355ee-9aee
2024-04-18 13:28:42.636 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-sg-chain 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-o355ee-9aee
2024-04-18 13:28:42.636 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent # Completed by iptables_manager
2024-04-18 13:28:42.636 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent ; Stdout: ; Stderr: iptables-restore v1.8.9 (nf_tables): interface name `de8355ee-9aee-4de4-9df9-513d9d62c08c' must be shorter than IFNAMSIZ (15)
2024-04-18 13:28:42.636 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent Error occurred at line: 6
2024-04-18 13:28:42.636 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent Try `iptables-restore -h' or 'iptables-restore --help' for more information.
Apr 18 13:28:44 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:44.638 8372 ERROR neutron.agent.linux.iptables_manager [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] IPTablesManager.apply failed to apply the following set of iptables rules:
1. # Generated by iptables_manager
2. *filter
3. :neutron-openvswi-i355ee-9aee - [0:0]
4. :neutron-openvswi-o355ee-9aee - [0:0]
5. :neutron-openvswi-s355ee-9aee - [0:0]
6. -I neutron-openvswi-FORWARD 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
7. -I neutron-openvswi-FORWARD 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
8. -I neutron-openvswi-FORWARD 3 -m physdev --physdev-out 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
9. -I neutron-openvswi-FORWARD 4 -m physdev --physdev-in 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
10. -I neutron-openvswi-INPUT 1 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct incoming traffic from VM to the security group chain." -j neutron-openvswi-o355ee-9aee
11. -I neutron-openvswi-i355ee-9aee 1 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
15. -I neutron-openvswi-i355ee-9aee 5 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
16. -I neutron-openvswi-i355ee-9aee 6 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
21. -I neutron-openvswi-o355ee-9aee 5 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
22. -I neutron-openvswi-o355ee-9aee 6 -j RETURN
23. -I neutron-openvswi-o355ee-9aee 7 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
24. -I neutron-openvswi-o355ee-9aee 8 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
25. -I neutron-openvswi-s355ee-9aee 1 -s 172.16.129.142/32 -m mac --mac-source FA:16:3E:07:C5:CB -m comment --comment "Allow traffic from defined IP/MAC pairs." -j RETURN
26. -I neutron-openvswi-s355ee-9aee 2 -m comment --comment "Drop traffic without an IP/MAC allow rule." -j DROP
27. -I neutron-openvswi-sg-chain 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-i355ee-9aee
28. -I neutron-openvswi-sg-chain 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-o355ee-9aee
29. COMMIT
30. # Completed by iptables_manager
31. # Generated by iptables_manager
32. *raw
33. -I neutron-openvswi-PREROUTING 1 -m physdev --physdev-in brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
34. -I neutron-openvswi-PREROUTING 2 -i brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
35. -I neutron-openvswi-PREROUTING 3 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
-I neutron-openvswi-FORWARD 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
-I neutron-openvswi-FORWARD 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
-I neutron-openvswi-FORWARD 3 -m physdev --physdev-out 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
-I neutron-openvswi-FORWARD 4 -m physdev --physdev-in 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
-I neutron-openvswi-INPUT 1 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct incoming traffic from VM to the security group chain." -j neutron-openvswi-o355ee-9aee
-I neutron-openvswi-i355ee-9aee 1 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
-I neutron-openvswi-i355ee-9aee 4 -m set --match-set NIPv44c29a64f-b883-4622-893c- src -j RETURN
-I neutron-openvswi-i355ee-9aee 5 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
-I neutron-openvswi-i355ee-9aee 6 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
-I neutron-openvswi-o355ee-9aee 5 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
-I neutron-openvswi-o355ee-9aee 6 -j RETURN
-I neutron-openvswi-o355ee-9aee 7 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
-I neutron-openvswi-o355ee-9aee 8 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
-I neutron-openvswi-s355ee-9aee 1 -s 172.16.129.142/32 -m mac --mac-source FA:16:3E:07:C5:CB -m comment --comment "Allow traffic from defined IP/MAC pairs." -j RETURN
-I neutron-openvswi-s355ee-9aee 2 -m comment --comment "Drop traffic without an IP/MAC allow rule." -j DROP
-I neutron-openvswi-sg-chain 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-i355ee-9aee
-I neutron-openvswi-sg-chain 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-o355ee-9aee
COMMIT
# Completed by iptables_manager
# Generated by iptables_manager
*raw
-I neutron-openvswi-PREROUTING 1 -m physdev --physdev-in brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
-I neutron-openvswi-PREROUTING 2 -i brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
-I neutron-openvswi-PREROUTING 3 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
COMMIT
# Completed by iptables_manager
; Stdout: ; Stderr: iptables-restore v1.8.9 (nf_tables): interface name `de8355ee-9aee-4de4-9df9-513d9d62c08c' must be shorter than IFNAMSIZ (15)
Error occurred at line: 6
Try `iptables-restore -h' or 'iptables-restore --help' for more information.
2024-04-18 13:28:44.639 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-FORWARD 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
2024-04-18 13:28:44.639 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-FORWARD 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
2024-04-18 13:28:44.639 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-FORWARD 3 -m physdev --physdev-out 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
2024-04-18 13:28:44.639 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-FORWARD 4 -m physdev --physdev-in 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
2024-04-18 13:28:44.639 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-INPUT 1 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct incoming traffic from VM to the security group chain." -j neutron-openvswi-o355ee-9aee
2024-04-18 13:28:44.639 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-i355ee-9aee 1 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
2024-04-18 13:28:44.639 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-i355ee-9aee 5 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
2024-04-18 13:28:44.639 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-i355ee-9aee 6 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
2024-04-18 13:28:44.639 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 5 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
2024-04-18 13:28:44.639 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 7 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
2024-04-18 13:28:44.639 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 8 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
2024-04-18 13:28:44.639 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-s355ee-9aee 1 -s 172.16.129.142/32 -m mac --mac-source FA:16:3E:07:C5:CB -m comment --comment "Allow traffic from defined IP/MAC pairs." -j RETURN
2024-04-18 13:28:44.639 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-s355ee-9aee 2 -m comment --comment "Drop traffic without an IP/MAC allow rule." -j DROP
2024-04-18 13:28:44.639 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-sg-chain 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-i355ee-9aee
2024-04-18 13:28:44.639 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-sg-chain 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-o355ee-9aee
2024-04-18 13:28:44.639 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent # Completed by iptables_manager
2024-04-18 13:28:44.639 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent ; Stdout: ; Stderr: iptables-restore v1.8.9 (nf_tables): interface name `de8355ee-9aee-4de4-9df9-513d9d62c08c' must be shorter than IFNAMSIZ (15)
2024-04-18 13:28:44.639 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent Error occurred at line: 6
2024-04-18 13:28:44.639 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent Try `iptables-restore -h' or 'iptables-restore --help' for more information.
Apr 18 13:28:46 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:46.639 8372 ERROR neutron.agent.linux.iptables_manager [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] IPTablesManager.apply failed to apply the following set of iptables rules:
1. # Generated by iptables_manager
2. *filter
3. :neutron-openvswi-i355ee-9aee - [0:0]
4. :neutron-openvswi-o355ee-9aee - [0:0]
5. :neutron-openvswi-s355ee-9aee - [0:0]
6. -I neutron-openvswi-FORWARD 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
7. -I neutron-openvswi-FORWARD 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
8. -I neutron-openvswi-FORWARD 3 -m physdev --physdev-out 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
9. -I neutron-openvswi-FORWARD 4 -m physdev --physdev-in 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
10. -I neutron-openvswi-INPUT 1 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct incoming traffic from VM to the security group chain." -j neutron-openvswi-o355ee-9aee
11. -I neutron-openvswi-i355ee-9aee 1 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
15. -I neutron-openvswi-i355ee-9aee 5 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
16. -I neutron-openvswi-i355ee-9aee 6 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
21. -I neutron-openvswi-o355ee-9aee 5 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
22. -I neutron-openvswi-o355ee-9aee 6 -j RETURN
23. -I neutron-openvswi-o355ee-9aee 7 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
24. -I neutron-openvswi-o355ee-9aee 8 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
25. -I neutron-openvswi-s355ee-9aee 1 -s 172.16.129.142/32 -m mac --mac-source FA:16:3E:07:C5:CB -m comment --comment "Allow traffic from defined IP/MAC pairs." -j RETURN
26. -I neutron-openvswi-s355ee-9aee 2 -m comment --comment "Drop traffic without an IP/MAC allow rule." -j DROP
27. -I neutron-openvswi-sg-chain 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-i355ee-9aee
28. -I neutron-openvswi-sg-chain 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-o355ee-9aee
29. COMMIT
30. # Completed by iptables_manager
31. # Generated by iptables_manager
32. *raw
33. -I neutron-openvswi-PREROUTING 1 -m physdev --physdev-in brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
34. -I neutron-openvswi-PREROUTING 2 -i brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
35. -I neutron-openvswi-PREROUTING 3 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
-I neutron-openvswi-FORWARD 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
-I neutron-openvswi-FORWARD 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
-I neutron-openvswi-FORWARD 3 -m physdev --physdev-out 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
-I neutron-openvswi-FORWARD 4 -m physdev --physdev-in 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
-I neutron-openvswi-INPUT 1 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct incoming traffic from VM to the security group chain." -j neutron-openvswi-o355ee-9aee
-I neutron-openvswi-i355ee-9aee 1 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
-I neutron-openvswi-i355ee-9aee 4 -m set --match-set NIPv44c29a64f-b883-4622-893c- src -j RETURN
-I neutron-openvswi-i355ee-9aee 5 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
-I neutron-openvswi-i355ee-9aee 6 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
-I neutron-openvswi-o355ee-9aee 5 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
-I neutron-openvswi-o355ee-9aee 6 -j RETURN
-I neutron-openvswi-o355ee-9aee 7 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
-I neutron-openvswi-o355ee-9aee 8 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
-I neutron-openvswi-s355ee-9aee 1 -s 172.16.129.142/32 -m mac --mac-source FA:16:3E:07:C5:CB -m comment --comment "Allow traffic from defined IP/MAC pairs." -j RETURN
-I neutron-openvswi-s355ee-9aee 2 -m comment --comment "Drop traffic without an IP/MAC allow rule." -j DROP
-I neutron-openvswi-sg-chain 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-i355ee-9aee
-I neutron-openvswi-sg-chain 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-o355ee-9aee
COMMIT
# Completed by iptables_manager
# Generated by iptables_manager
*raw
-I neutron-openvswi-PREROUTING 1 -m physdev --physdev-in brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
-I neutron-openvswi-PREROUTING 2 -i brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
-I neutron-openvswi-PREROUTING 3 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
COMMIT
# Completed by iptables_manager
; Stdout: ; Stderr: iptables-restore v1.8.9 (nf_tables): interface name `de8355ee-9aee-4de4-9df9-513d9d62c08c' must be shorter than IFNAMSIZ (15)
Error occurred at line: 6
Try `iptables-restore -h' or 'iptables-restore --help' for more information.
2024-04-18 13:28:46.640 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-FORWARD 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
2024-04-18 13:28:46.640 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-FORWARD 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
2024-04-18 13:28:46.640 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-FORWARD 3 -m physdev --physdev-out 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
2024-04-18 13:28:46.640 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-FORWARD 4 -m physdev --physdev-in 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
2024-04-18 13:28:46.640 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-INPUT 1 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct incoming traffic from VM to the security group chain." -j neutron-openvswi-o355ee-9aee
2024-04-18 13:28:46.640 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-i355ee-9aee 1 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
2024-04-18 13:28:46.640 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-i355ee-9aee 5 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
2024-04-18 13:28:46.640 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-i355ee-9aee 6 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
2024-04-18 13:28:46.640 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 5 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
2024-04-18 13:28:46.640 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 7 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
2024-04-18 13:28:46.640 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 8 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
2024-04-18 13:28:46.640 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-s355ee-9aee 1 -s 172.16.129.142/32 -m mac --mac-source FA:16:3E:07:C5:CB -m comment --comment "Allow traffic from defined IP/MAC pairs." -j RETURN
2024-04-18 13:28:46.640 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-s355ee-9aee 2 -m comment --comment "Drop traffic without an IP/MAC allow rule." -j DROP
2024-04-18 13:28:46.640 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-sg-chain 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-i355ee-9aee
2024-04-18 13:28:46.640 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-sg-chain 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-o355ee-9aee
2024-04-18 13:28:46.640 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent # Completed by iptables_manager
2024-04-18 13:28:46.640 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent ; Stdout: ; Stderr: iptables-restore v1.8.9 (nf_tables): interface name `de8355ee-9aee-4de4-9df9-513d9d62c08c' must be shorter than IFNAMSIZ (15)
2024-04-18 13:28:46.640 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent Error occurred at line: 6
2024-04-18 13:28:46.640 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent Try `iptables-restore -h' or 'iptables-restore --help' for more information.
Apr 18 13:28:48 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:48.641 8372 ERROR neutron.agent.linux.iptables_manager [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] IPTablesManager.apply failed to apply the following set of iptables rules:
1. # Generated by iptables_manager
2. *filter
3. :neutron-openvswi-i355ee-9aee - [0:0]
4. :neutron-openvswi-o355ee-9aee - [0:0]
5. :neutron-openvswi-s355ee-9aee - [0:0]
6. -I neutron-openvswi-FORWARD 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
7. -I neutron-openvswi-FORWARD 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
8. -I neutron-openvswi-FORWARD 3 -m physdev --physdev-out 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
9. -I neutron-openvswi-FORWARD 4 -m physdev --physdev-in 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
10. -I neutron-openvswi-INPUT 1 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct incoming traffic from VM to the security group chain." -j neutron-openvswi-o355ee-9aee
11. -I neutron-openvswi-i355ee-9aee 1 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
15. -I neutron-openvswi-i355ee-9aee 5 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
16. -I neutron-openvswi-i355ee-9aee 6 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
21. -I neutron-openvswi-o355ee-9aee 5 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
22. -I neutron-openvswi-o355ee-9aee 6 -j RETURN
23. -I neutron-openvswi-o355ee-9aee 7 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
24. -I neutron-openvswi-o355ee-9aee 8 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
25. -I neutron-openvswi-s355ee-9aee 1 -s 172.16.129.142/32 -m mac --mac-source FA:16:3E:07:C5:CB -m comment --comment "Allow traffic from defined IP/MAC pairs." -j RETURN
26. -I neutron-openvswi-s355ee-9aee 2 -m comment --comment "Drop traffic without an IP/MAC allow rule." -j DROP
27. -I neutron-openvswi-sg-chain 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-i355ee-9aee
28. -I neutron-openvswi-sg-chain 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-o355ee-9aee
29. COMMIT
30. # Completed by iptables_manager
31. # Generated by iptables_manager
32. *raw
33. -I neutron-openvswi-PREROUTING 1 -m physdev --physdev-in brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
34. -I neutron-openvswi-PREROUTING 2 -i brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
35. -I neutron-openvswi-PREROUTING 3 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
-I neutron-openvswi-FORWARD 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
-I neutron-openvswi-FORWARD 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
-I neutron-openvswi-FORWARD 3 -m physdev --physdev-out 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
-I neutron-openvswi-FORWARD 4 -m physdev --physdev-in 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
-I neutron-openvswi-INPUT 1 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct incoming traffic from VM to the security group chain." -j neutron-openvswi-o355ee-9aee
-I neutron-openvswi-i355ee-9aee 1 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
-I neutron-openvswi-i355ee-9aee 4 -m set --match-set NIPv44c29a64f-b883-4622-893c- src -j RETURN
-I neutron-openvswi-i355ee-9aee 5 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
-I neutron-openvswi-i355ee-9aee 6 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
-I neutron-openvswi-o355ee-9aee 5 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
-I neutron-openvswi-o355ee-9aee 6 -j RETURN
-I neutron-openvswi-o355ee-9aee 7 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
-I neutron-openvswi-o355ee-9aee 8 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
-I neutron-openvswi-s355ee-9aee 1 -s 172.16.129.142/32 -m mac --mac-source FA:16:3E:07:C5:CB -m comment --comment "Allow traffic from defined IP/MAC pairs." -j RETURN
-I neutron-openvswi-s355ee-9aee 2 -m comment --comment "Drop traffic without an IP/MAC allow rule." -j DROP
-I neutron-openvswi-sg-chain 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-i355ee-9aee
-I neutron-openvswi-sg-chain 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-o355ee-9aee
COMMIT
# Completed by iptables_manager
# Generated by iptables_manager
*raw
-I neutron-openvswi-PREROUTING 1 -m physdev --physdev-in brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
-I neutron-openvswi-PREROUTING 2 -i brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
-I neutron-openvswi-PREROUTING 3 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
COMMIT
# Completed by iptables_manager
; Stdout: ; Stderr: iptables-restore v1.8.9 (nf_tables): interface name `de8355ee-9aee-4de4-9df9-513d9d62c08c' must be shorter than IFNAMSIZ (15)
Error occurred at line: 6
Try `iptables-restore -h' or 'iptables-restore --help' for more information.
2024-04-18 13:28:48.642 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-FORWARD 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
2024-04-18 13:28:48.642 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-FORWARD 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
2024-04-18 13:28:48.642 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-FORWARD 3 -m physdev --physdev-out 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
2024-04-18 13:28:48.642 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-FORWARD 4 -m physdev --physdev-in 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
2024-04-18 13:28:48.642 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-INPUT 1 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct incoming traffic from VM to the security group chain." -j neutron-openvswi-o355ee-9aee
2024-04-18 13:28:48.642 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-i355ee-9aee 1 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
2024-04-18 13:28:48.642 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-i355ee-9aee 5 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
2024-04-18 13:28:48.642 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-i355ee-9aee 6 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
2024-04-18 13:28:48.642 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 5 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
2024-04-18 13:28:48.642 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 7 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
2024-04-18 13:28:48.642 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 8 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
2024-04-18 13:28:48.642 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-s355ee-9aee 1 -s 172.16.129.142/32 -m mac --mac-source FA:16:3E:07:C5:CB -m comment --comment "Allow traffic from defined IP/MAC pairs." -j RETURN
2024-04-18 13:28:48.642 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-s355ee-9aee 2 -m comment --comment "Drop traffic without an IP/MAC allow rule." -j DROP
2024-04-18 13:28:48.642 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-sg-chain 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-i355ee-9aee
2024-04-18 13:28:48.642 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-sg-chain 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-o355ee-9aee
2024-04-18 13:28:48.642 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent # Completed by iptables_manager
2024-04-18 13:28:48.642 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent ; Stdout: ; Stderr: iptables-restore v1.8.9 (nf_tables): interface name `de8355ee-9aee-4de4-9df9-513d9d62c08c' must be shorter than IFNAMSIZ (15)
2024-04-18 13:28:48.642 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent Error occurred at line: 6
2024-04-18 13:28:48.642 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent Try `iptables-restore -h' or 'iptables-restore --help' for more information.
Apr 18 13:28:50 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:50.643 8372 ERROR neutron.agent.linux.iptables_manager [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] IPTablesManager.apply failed to apply the following set of iptables rules:
1. # Generated by iptables_manager
2. *filter
3. :neutron-openvswi-i355ee-9aee - [0:0]
4. :neutron-openvswi-o355ee-9aee - [0:0]
5. :neutron-openvswi-s355ee-9aee - [0:0]
6. -I neutron-openvswi-FORWARD 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
7. -I neutron-openvswi-FORWARD 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
8. -I neutron-openvswi-FORWARD 3 -m physdev --physdev-out 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
9. -I neutron-openvswi-FORWARD 4 -m physdev --physdev-in 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
10. -I neutron-openvswi-INPUT 1 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct incoming traffic from VM to the security group chain." -j neutron-openvswi-o355ee-9aee
11. -I neutron-openvswi-i355ee-9aee 1 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
15. -I neutron-openvswi-i355ee-9aee 5 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
16. -I neutron-openvswi-i355ee-9aee 6 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
21. -I neutron-openvswi-o355ee-9aee 5 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
22. -I neutron-openvswi-o355ee-9aee 6 -j RETURN
23. -I neutron-openvswi-o355ee-9aee 7 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
24. -I neutron-openvswi-o355ee-9aee 8 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
25. -I neutron-openvswi-s355ee-9aee 1 -s 172.16.129.142/32 -m mac --mac-source FA:16:3E:07:C5:CB -m comment --comment "Allow traffic from defined IP/MAC pairs." -j RETURN
26. -I neutron-openvswi-s355ee-9aee 2 -m comment --comment "Drop traffic without an IP/MAC allow rule." -j DROP
27. -I neutron-openvswi-sg-chain 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-i355ee-9aee
28. -I neutron-openvswi-sg-chain 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-o355ee-9aee
29. COMMIT
30. # Completed by iptables_manager
31. # Generated by iptables_manager
32. *raw
33. -I neutron-openvswi-PREROUTING 1 -m physdev --physdev-in brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
34. -I neutron-openvswi-PREROUTING 2 -i brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
35. -I neutron-openvswi-PREROUTING 3 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
-I neutron-openvswi-FORWARD 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
-I neutron-openvswi-FORWARD 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
-I neutron-openvswi-FORWARD 3 -m physdev --physdev-out 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
-I neutron-openvswi-FORWARD 4 -m physdev --physdev-in 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
-I neutron-openvswi-INPUT 1 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct incoming traffic from VM to the security group chain." -j neutron-openvswi-o355ee-9aee
-I neutron-openvswi-i355ee-9aee 1 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
-I neutron-openvswi-i355ee-9aee 4 -m set --match-set NIPv44c29a64f-b883-4622-893c- src -j RETURN
-I neutron-openvswi-i355ee-9aee 5 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
-I neutron-openvswi-i355ee-9aee 6 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
-I neutron-openvswi-o355ee-9aee 5 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
-I neutron-openvswi-o355ee-9aee 6 -j RETURN
-I neutron-openvswi-o355ee-9aee 7 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
-I neutron-openvswi-o355ee-9aee 8 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
-I neutron-openvswi-s355ee-9aee 1 -s 172.16.129.142/32 -m mac --mac-source FA:16:3E:07:C5:CB -m comment --comment "Allow traffic from defined IP/MAC pairs." -j RETURN
-I neutron-openvswi-s355ee-9aee 2 -m comment --comment "Drop traffic without an IP/MAC allow rule." -j DROP
-I neutron-openvswi-sg-chain 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-i355ee-9aee
-I neutron-openvswi-sg-chain 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-o355ee-9aee
COMMIT
# Completed by iptables_manager
# Generated by iptables_manager
*raw
-I neutron-openvswi-PREROUTING 1 -m physdev --physdev-in brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
-I neutron-openvswi-PREROUTING 2 -i brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
-I neutron-openvswi-PREROUTING 3 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
COMMIT
# Completed by iptables_manager
; Stdout: ; Stderr: iptables-restore v1.8.9 (nf_tables): interface name `de8355ee-9aee-4de4-9df9-513d9d62c08c' must be shorter than IFNAMSIZ (15)
Error occurred at line: 6
Try `iptables-restore -h' or 'iptables-restore --help' for more information.
2024-04-18 13:28:50.644 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-FORWARD 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
2024-04-18 13:28:50.644 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-FORWARD 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
2024-04-18 13:28:50.644 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-FORWARD 3 -m physdev --physdev-out 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
2024-04-18 13:28:50.644 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-FORWARD 4 -m physdev --physdev-in 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
2024-04-18 13:28:50.644 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-INPUT 1 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct incoming traffic from VM to the security group chain." -j neutron-openvswi-o355ee-9aee
2024-04-18 13:28:50.644 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-i355ee-9aee 1 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
2024-04-18 13:28:50.644 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-i355ee-9aee 5 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
2024-04-18 13:28:50.644 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-i355ee-9aee 6 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
2024-04-18 13:28:50.644 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 5 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
2024-04-18 13:28:50.644 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 7 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
2024-04-18 13:28:50.644 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 8 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
2024-04-18 13:28:50.644 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-s355ee-9aee 1 -s 172.16.129.142/32 -m mac --mac-source FA:16:3E:07:C5:CB -m comment --comment "Allow traffic from defined IP/MAC pairs." -j RETURN
2024-04-18 13:28:50.644 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-s355ee-9aee 2 -m comment --comment "Drop traffic without an IP/MAC allow rule." -j DROP
2024-04-18 13:28:50.644 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-sg-chain 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-i355ee-9aee
2024-04-18 13:28:50.644 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-sg-chain 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-o355ee-9aee
2024-04-18 13:28:50.644 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent # Completed by iptables_manager
2024-04-18 13:28:50.644 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent ; Stdout: ; Stderr: iptables-restore v1.8.9 (nf_tables): interface name `de8355ee-9aee-4de4-9df9-513d9d62c08c' must be shorter than IFNAMSIZ (15)
2024-04-18 13:28:50.644 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent Error occurred at line: 6
2024-04-18 13:28:50.644 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent Try `iptables-restore -h' or 'iptables-restore --help' for more information.
Apr 18 13:28:52 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:52.644 8372 ERROR neutron.agent.linux.iptables_manager [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] IPTablesManager.apply failed to apply the following set of iptables rules:
1. # Generated by iptables_manager
2. *filter
3. :neutron-openvswi-i355ee-9aee - [0:0]
4. :neutron-openvswi-o355ee-9aee - [0:0]
5. :neutron-openvswi-s355ee-9aee - [0:0]
6. -I neutron-openvswi-FORWARD 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
7. -I neutron-openvswi-FORWARD 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
8. -I neutron-openvswi-FORWARD 3 -m physdev --physdev-out 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
9. -I neutron-openvswi-FORWARD 4 -m physdev --physdev-in 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
10. -I neutron-openvswi-INPUT 1 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct incoming traffic from VM to the security group chain." -j neutron-openvswi-o355ee-9aee
11. -I neutron-openvswi-i355ee-9aee 1 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
15. -I neutron-openvswi-i355ee-9aee 5 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
16. -I neutron-openvswi-i355ee-9aee 6 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
21. -I neutron-openvswi-o355ee-9aee 5 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
22. -I neutron-openvswi-o355ee-9aee 6 -j RETURN
23. -I neutron-openvswi-o355ee-9aee 7 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
24. -I neutron-openvswi-o355ee-9aee 8 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
25. -I neutron-openvswi-s355ee-9aee 1 -s 172.16.129.142/32 -m mac --mac-source FA:16:3E:07:C5:CB -m comment --comment "Allow traffic from defined IP/MAC pairs." -j RETURN
26. -I neutron-openvswi-s355ee-9aee 2 -m comment --comment "Drop traffic without an IP/MAC allow rule." -j DROP
27. -I neutron-openvswi-sg-chain 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-i355ee-9aee
28. -I neutron-openvswi-sg-chain 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-o355ee-9aee
29. COMMIT
30. # Completed by iptables_manager
31. # Generated by iptables_manager
32. *raw
33. -I neutron-openvswi-PREROUTING 1 -m physdev --physdev-in brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
34. -I neutron-openvswi-PREROUTING 2 -i brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
35. -I neutron-openvswi-PREROUTING 3 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
-I neutron-openvswi-FORWARD 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
-I neutron-openvswi-FORWARD 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
-I neutron-openvswi-FORWARD 3 -m physdev --physdev-out 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
-I neutron-openvswi-FORWARD 4 -m physdev --physdev-in 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
-I neutron-openvswi-INPUT 1 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct incoming traffic from VM to the security group chain." -j neutron-openvswi-o355ee-9aee
-I neutron-openvswi-i355ee-9aee 1 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
-I neutron-openvswi-i355ee-9aee 4 -m set --match-set NIPv44c29a64f-b883-4622-893c- src -j RETURN
-I neutron-openvswi-i355ee-9aee 5 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
-I neutron-openvswi-i355ee-9aee 6 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
-I neutron-openvswi-o355ee-9aee 5 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
-I neutron-openvswi-o355ee-9aee 6 -j RETURN
-I neutron-openvswi-o355ee-9aee 7 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
-I neutron-openvswi-o355ee-9aee 8 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
-I neutron-openvswi-s355ee-9aee 1 -s 172.16.129.142/32 -m mac --mac-source FA:16:3E:07:C5:CB -m comment --comment "Allow traffic from defined IP/MAC pairs." -j RETURN
-I neutron-openvswi-s355ee-9aee 2 -m comment --comment "Drop traffic without an IP/MAC allow rule." -j DROP
-I neutron-openvswi-sg-chain 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-i355ee-9aee
-I neutron-openvswi-sg-chain 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-o355ee-9aee
COMMIT
# Completed by iptables_manager
# Generated by iptables_manager
*raw
-I neutron-openvswi-PREROUTING 1 -m physdev --physdev-in brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
-I neutron-openvswi-PREROUTING 2 -i brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
-I neutron-openvswi-PREROUTING 3 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
COMMIT
# Completed by iptables_manager
; Stdout: ; Stderr: iptables-restore v1.8.9 (nf_tables): interface name `de8355ee-9aee-4de4-9df9-513d9d62c08c' must be shorter than IFNAMSIZ (15)
Error occurred at line: 6
Try `iptables-restore -h' or 'iptables-restore --help' for more information.
2024-04-18 13:28:52.645 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-FORWARD 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
2024-04-18 13:28:52.645 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-FORWARD 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
2024-04-18 13:28:52.645 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-FORWARD 3 -m physdev --physdev-out 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
2024-04-18 13:28:52.645 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-FORWARD 4 -m physdev --physdev-in 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
2024-04-18 13:28:52.645 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-INPUT 1 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct incoming traffic from VM to the security group chain." -j neutron-openvswi-o355ee-9aee
2024-04-18 13:28:52.645 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-i355ee-9aee 1 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
2024-04-18 13:28:52.645 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-i355ee-9aee 5 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
2024-04-18 13:28:52.645 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-i355ee-9aee 6 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
2024-04-18 13:28:52.645 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 5 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
2024-04-18 13:28:52.645 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 7 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
2024-04-18 13:28:52.645 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 8 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
2024-04-18 13:28:52.645 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-s355ee-9aee 1 -s 172.16.129.142/32 -m mac --mac-source FA:16:3E:07:C5:CB -m comment --comment "Allow traffic from defined IP/MAC pairs." -j RETURN
2024-04-18 13:28:52.645 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-s355ee-9aee 2 -m comment --comment "Drop traffic without an IP/MAC allow rule." -j DROP
2024-04-18 13:28:52.645 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-sg-chain 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-i355ee-9aee
2024-04-18 13:28:52.645 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-sg-chain 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-o355ee-9aee
2024-04-18 13:28:52.645 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent # Completed by iptables_manager
2024-04-18 13:28:52.645 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent ; Stdout: ; Stderr: iptables-restore v1.8.9 (nf_tables): interface name `de8355ee-9aee-4de4-9df9-513d9d62c08c' must be shorter than IFNAMSIZ (15)
2024-04-18 13:28:52.645 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent Error occurred at line: 6
2024-04-18 13:28:52.645 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent Try `iptables-restore -h' or 'iptables-restore --help' for more information.
Apr 18 13:28:54 cloudvirt2001-dev systemd-journald[577]: Data hash table of /var/log/journal/62693336befd45e4abc6fcb349d9135e/system.journal has a fill level at 75.0 (174763 of 233016 items, 67108864 file size, 383 bytes per hash table item), suggesting rotation.
Apr 18 13:28:54 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:54.648 8372 ERROR neutron.agent.linux.iptables_manager [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] IPTablesManager.apply failed to apply the following set of iptables rules:
1. # Generated by iptables_manager
2. *filter
3. :neutron-openvswi-i355ee-9aee - [0:0]
4. :neutron-openvswi-o355ee-9aee - [0:0]
5. :neutron-openvswi-s355ee-9aee - [0:0]
6. -I neutron-openvswi-FORWARD 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
7. -I neutron-openvswi-FORWARD 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
8. -I neutron-openvswi-FORWARD 3 -m physdev --physdev-out 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
9. -I neutron-openvswi-FORWARD 4 -m physdev --physdev-in 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
10. -I neutron-openvswi-INPUT 1 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct incoming traffic from VM to the security group chain." -j neutron-openvswi-o355ee-9aee
11. -I neutron-openvswi-i355ee-9aee 1 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
15. -I neutron-openvswi-i355ee-9aee 5 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
16. -I neutron-openvswi-i355ee-9aee 6 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
21. -I neutron-openvswi-o355ee-9aee 5 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
22. -I neutron-openvswi-o355ee-9aee 6 -j RETURN
23. -I neutron-openvswi-o355ee-9aee 7 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
24. -I neutron-openvswi-o355ee-9aee 8 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
25. -I neutron-openvswi-s355ee-9aee 1 -s 172.16.129.142/32 -m mac --mac-source FA:16:3E:07:C5:CB -m comment --comment "Allow traffic from defined IP/MAC pairs." -j RETURN
26. -I neutron-openvswi-s355ee-9aee 2 -m comment --comment "Drop traffic without an IP/MAC allow rule." -j DROP
27. -I neutron-openvswi-sg-chain 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-i355ee-9aee
28. -I neutron-openvswi-sg-chain 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-o355ee-9aee
29. COMMIT
30. # Completed by iptables_manager
31. # Generated by iptables_manager
32. *raw
33. -I neutron-openvswi-PREROUTING 1 -m physdev --physdev-in brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
34. -I neutron-openvswi-PREROUTING 2 -i brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
35. -I neutron-openvswi-PREROUTING 3 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
-I neutron-openvswi-FORWARD 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
-I neutron-openvswi-FORWARD 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
-I neutron-openvswi-FORWARD 3 -m physdev --physdev-out 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
-I neutron-openvswi-FORWARD 4 -m physdev --physdev-in 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
-I neutron-openvswi-INPUT 1 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct incoming traffic from VM to the security group chain." -j neutron-openvswi-o355ee-9aee
-I neutron-openvswi-i355ee-9aee 1 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
-I neutron-openvswi-i355ee-9aee 4 -m set --match-set NIPv44c29a64f-b883-4622-893c- src -j RETURN
-I neutron-openvswi-i355ee-9aee 5 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
-I neutron-openvswi-i355ee-9aee 6 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
-I neutron-openvswi-o355ee-9aee 5 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
-I neutron-openvswi-o355ee-9aee 6 -j RETURN
-I neutron-openvswi-o355ee-9aee 7 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
-I neutron-openvswi-o355ee-9aee 8 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
-I neutron-openvswi-s355ee-9aee 1 -s 172.16.129.142/32 -m mac --mac-source FA:16:3E:07:C5:CB -m comment --comment "Allow traffic from defined IP/MAC pairs." -j RETURN
-I neutron-openvswi-s355ee-9aee 2 -m comment --comment "Drop traffic without an IP/MAC allow rule." -j DROP
-I neutron-openvswi-sg-chain 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-i355ee-9aee
-I neutron-openvswi-sg-chain 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-o355ee-9aee
COMMIT
# Completed by iptables_manager
# Generated by iptables_manager
*raw
-I neutron-openvswi-PREROUTING 1 -m physdev --physdev-in brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
-I neutron-openvswi-PREROUTING 2 -i brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
-I neutron-openvswi-PREROUTING 3 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
COMMIT
# Completed by iptables_manager
; Stdout: ; Stderr: iptables-restore v1.8.9 (nf_tables): interface name `de8355ee-9aee-4de4-9df9-513d9d62c08c' must be shorter than IFNAMSIZ (15)
Error occurred at line: 6
Try `iptables-restore -h' or 'iptables-restore --help' for more information.
2024-04-18 13:28:54.649 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-FORWARD 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
2024-04-18 13:28:54.649 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-FORWARD 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
2024-04-18 13:28:54.649 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-FORWARD 3 -m physdev --physdev-out 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
2024-04-18 13:28:54.649 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-FORWARD 4 -m physdev --physdev-in 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
2024-04-18 13:28:54.649 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-INPUT 1 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct incoming traffic from VM to the security group chain." -j neutron-openvswi-o355ee-9aee
2024-04-18 13:28:54.649 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-i355ee-9aee 1 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
2024-04-18 13:28:54.649 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-i355ee-9aee 5 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
2024-04-18 13:28:54.649 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-i355ee-9aee 6 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
2024-04-18 13:28:54.649 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 5 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
2024-04-18 13:28:54.649 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 7 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
2024-04-18 13:28:54.649 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 8 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
2024-04-18 13:28:54.649 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-s355ee-9aee 1 -s 172.16.129.142/32 -m mac --mac-source FA:16:3E:07:C5:CB -m comment --comment "Allow traffic from defined IP/MAC pairs." -j RETURN
2024-04-18 13:28:54.649 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-s355ee-9aee 2 -m comment --comment "Drop traffic without an IP/MAC allow rule." -j DROP
2024-04-18 13:28:54.649 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-sg-chain 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-i355ee-9aee
2024-04-18 13:28:54.649 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-sg-chain 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-o355ee-9aee
2024-04-18 13:28:54.649 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent # Completed by iptables_manager
2024-04-18 13:28:54.649 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent ; Stdout: ; Stderr: iptables-restore v1.8.9 (nf_tables): interface name `de8355ee-9aee-4de4-9df9-513d9d62c08c' must be shorter than IFNAMSIZ (15)
2024-04-18 13:28:54.649 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent Error occurred at line: 6
2024-04-18 13:28:54.649 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent Try `iptables-restore -h' or 'iptables-restore --help' for more information.
Apr 18 13:28:56 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:56.646 8372 ERROR neutron.agent.linux.iptables_manager [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] IPTablesManager.apply failed to apply the following set of iptables rules:
1. # Generated by iptables_manager
2. *filter
3. :neutron-openvswi-i355ee-9aee - [0:0]
4. :neutron-openvswi-o355ee-9aee - [0:0]
5. :neutron-openvswi-s355ee-9aee - [0:0]
6. -I neutron-openvswi-FORWARD 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
7. -I neutron-openvswi-FORWARD 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
8. -I neutron-openvswi-FORWARD 3 -m physdev --physdev-out 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
9. -I neutron-openvswi-FORWARD 4 -m physdev --physdev-in 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
10. -I neutron-openvswi-INPUT 1 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct incoming traffic from VM to the security group chain." -j neutron-openvswi-o355ee-9aee
11. -I neutron-openvswi-i355ee-9aee 1 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
15. -I neutron-openvswi-i355ee-9aee 5 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
16. -I neutron-openvswi-i355ee-9aee 6 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
21. -I neutron-openvswi-o355ee-9aee 5 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
22. -I neutron-openvswi-o355ee-9aee 6 -j RETURN
23. -I neutron-openvswi-o355ee-9aee 7 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
24. -I neutron-openvswi-o355ee-9aee 8 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
25. -I neutron-openvswi-s355ee-9aee 1 -s 172.16.129.142/32 -m mac --mac-source FA:16:3E:07:C5:CB -m comment --comment "Allow traffic from defined IP/MAC pairs." -j RETURN
26. -I neutron-openvswi-s355ee-9aee 2 -m comment --comment "Drop traffic without an IP/MAC allow rule." -j DROP
27. -I neutron-openvswi-sg-chain 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-i355ee-9aee
28. -I neutron-openvswi-sg-chain 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-o355ee-9aee
29. COMMIT
30. # Completed by iptables_manager
31. # Generated by iptables_manager
32. *raw
33. -I neutron-openvswi-PREROUTING 1 -m physdev --physdev-in brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
34. -I neutron-openvswi-PREROUTING 2 -i brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
35. -I neutron-openvswi-PREROUTING 3 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
-I neutron-openvswi-FORWARD 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
-I neutron-openvswi-FORWARD 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
-I neutron-openvswi-FORWARD 3 -m physdev --physdev-out 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
-I neutron-openvswi-FORWARD 4 -m physdev --physdev-in 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
-I neutron-openvswi-INPUT 1 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct incoming traffic from VM to the security group chain." -j neutron-openvswi-o355ee-9aee
-I neutron-openvswi-i355ee-9aee 1 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
-I neutron-openvswi-i355ee-9aee 4 -m set --match-set NIPv44c29a64f-b883-4622-893c- src -j RETURN
-I neutron-openvswi-i355ee-9aee 5 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
-I neutron-openvswi-i355ee-9aee 6 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
-I neutron-openvswi-o355ee-9aee 5 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
-I neutron-openvswi-o355ee-9aee 6 -j RETURN
-I neutron-openvswi-o355ee-9aee 7 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
-I neutron-openvswi-o355ee-9aee 8 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
-I neutron-openvswi-s355ee-9aee 1 -s 172.16.129.142/32 -m mac --mac-source FA:16:3E:07:C5:CB -m comment --comment "Allow traffic from defined IP/MAC pairs." -j RETURN
-I neutron-openvswi-s355ee-9aee 2 -m comment --comment "Drop traffic without an IP/MAC allow rule." -j DROP
-I neutron-openvswi-sg-chain 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-i355ee-9aee
-I neutron-openvswi-sg-chain 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-o355ee-9aee
COMMIT
# Completed by iptables_manager
# Generated by iptables_manager
*raw
-I neutron-openvswi-PREROUTING 1 -m physdev --physdev-in brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
-I neutron-openvswi-PREROUTING 2 -i brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
-I neutron-openvswi-PREROUTING 3 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
COMMIT
# Completed by iptables_manager
; Stdout: ; Stderr: iptables-restore v1.8.9 (nf_tables): interface name `de8355ee-9aee-4de4-9df9-513d9d62c08c' must be shorter than IFNAMSIZ (15)
Error occurred at line: 6
Try `iptables-restore -h' or 'iptables-restore --help' for more information.
2024-04-18 13:28:56.647 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-FORWARD 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
2024-04-18 13:28:56.647 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-FORWARD 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
2024-04-18 13:28:56.647 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-FORWARD 3 -m physdev --physdev-out 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
2024-04-18 13:28:56.647 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-FORWARD 4 -m physdev --physdev-in 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
2024-04-18 13:28:56.647 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-INPUT 1 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct incoming traffic from VM to the security group chain." -j neutron-openvswi-o355ee-9aee
2024-04-18 13:28:56.647 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-i355ee-9aee 1 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
2024-04-18 13:28:56.647 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-i355ee-9aee 5 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
2024-04-18 13:28:56.647 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-i355ee-9aee 6 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
2024-04-18 13:28:56.647 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 5 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
2024-04-18 13:28:56.647 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 7 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
2024-04-18 13:28:56.647 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 8 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
2024-04-18 13:28:56.647 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-s355ee-9aee 1 -s 172.16.129.142/32 -m mac --mac-source FA:16:3E:07:C5:CB -m comment --comment "Allow traffic from defined IP/MAC pairs." -j RETURN
2024-04-18 13:28:56.647 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-s355ee-9aee 2 -m comment --comment "Drop traffic without an IP/MAC allow rule." -j DROP
2024-04-18 13:28:56.647 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-sg-chain 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-i355ee-9aee
2024-04-18 13:28:56.647 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-sg-chain 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-o355ee-9aee
2024-04-18 13:28:56.647 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent # Completed by iptables_manager
2024-04-18 13:28:56.647 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent ; Stdout: ; Stderr: iptables-restore v1.8.9 (nf_tables): interface name `de8355ee-9aee-4de4-9df9-513d9d62c08c' must be shorter than IFNAMSIZ (15)
2024-04-18 13:28:56.647 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent Error occurred at line: 6
2024-04-18 13:28:56.647 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent Try `iptables-restore -h' or 'iptables-restore --help' for more information.
Apr 18 13:28:58 cloudvirt2001-dev neutron-openvswitch-agent[8372]: 2024-04-18 13:28:58.647 8372 ERROR neutron.agent.linux.iptables_manager [None req-10ea575a-9528-48df-85e1-541677156a43 - - - - - -] IPTablesManager.apply failed to apply the following set of iptables rules:
1. # Generated by iptables_manager
2. *filter
3. :neutron-openvswi-i355ee-9aee - [0:0]
4. :neutron-openvswi-o355ee-9aee - [0:0]
5. :neutron-openvswi-s355ee-9aee - [0:0]
6. -I neutron-openvswi-FORWARD 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
7. -I neutron-openvswi-FORWARD 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
8. -I neutron-openvswi-FORWARD 3 -m physdev --physdev-out 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
9. -I neutron-openvswi-FORWARD 4 -m physdev --physdev-in 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
10. -I neutron-openvswi-INPUT 1 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct incoming traffic from VM to the security group chain." -j neutron-openvswi-o355ee-9aee
11. -I neutron-openvswi-i355ee-9aee 1 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
15. -I neutron-openvswi-i355ee-9aee 5 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
16. -I neutron-openvswi-i355ee-9aee 6 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
21. -I neutron-openvswi-o355ee-9aee 5 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
22. -I neutron-openvswi-o355ee-9aee 6 -j RETURN
23. -I neutron-openvswi-o355ee-9aee 7 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
24. -I neutron-openvswi-o355ee-9aee 8 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
25. -I neutron-openvswi-s355ee-9aee 1 -s 172.16.129.142/32 -m mac --mac-source FA:16:3E:07:C5:CB -m comment --comment "Allow traffic from defined IP/MAC pairs." -j RETURN
26. -I neutron-openvswi-s355ee-9aee 2 -m comment --comment "Drop traffic without an IP/MAC allow rule." -j DROP
27. -I neutron-openvswi-sg-chain 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-i355ee-9aee
28. -I neutron-openvswi-sg-chain 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-o355ee-9aee
29. COMMIT
30. # Completed by iptables_manager
31. # Generated by iptables_manager
32. *raw
33. -I neutron-openvswi-PREROUTING 1 -m physdev --physdev-in brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
34. -I neutron-openvswi-PREROUTING 2 -i brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
35. -I neutron-openvswi-PREROUTING 3 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
-I neutron-openvswi-FORWARD 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
-I neutron-openvswi-FORWARD 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
-I neutron-openvswi-FORWARD 3 -m physdev --physdev-out 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
-I neutron-openvswi-FORWARD 4 -m physdev --physdev-in 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
-I neutron-openvswi-INPUT 1 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct incoming traffic from VM to the security group chain." -j neutron-openvswi-o355ee-9aee
-I neutron-openvswi-i355ee-9aee 1 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
-I neutron-openvswi-i355ee-9aee 4 -m set --match-set NIPv44c29a64f-b883-4622-893c- src -j RETURN
-I neutron-openvswi-i355ee-9aee 5 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
-I neutron-openvswi-i355ee-9aee 6 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
-I neutron-openvswi-o355ee-9aee 5 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
-I neutron-openvswi-o355ee-9aee 6 -j RETURN
-I neutron-openvswi-o355ee-9aee 7 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
-I neutron-openvswi-o355ee-9aee 8 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
-I neutron-openvswi-s355ee-9aee 1 -s 172.16.129.142/32 -m mac --mac-source FA:16:3E:07:C5:CB -m comment --comment "Allow traffic from defined IP/MAC pairs." -j RETURN
-I neutron-openvswi-s355ee-9aee 2 -m comment --comment "Drop traffic without an IP/MAC allow rule." -j DROP
-I neutron-openvswi-sg-chain 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-i355ee-9aee
-I neutron-openvswi-sg-chain 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-o355ee-9aee
COMMIT
# Completed by iptables_manager
# Generated by iptables_manager
*raw
-I neutron-openvswi-PREROUTING 1 -m physdev --physdev-in brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
-I neutron-openvswi-PREROUTING 2 -i brqe40a1c9f-cc -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
-I neutron-openvswi-PREROUTING 3 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c -m comment --comment "Set zone for de8355ee-9aee-4de4-9df9-513d9d62c08c" -j CT --zone 4097
COMMIT
# Completed by iptables_manager
; Stdout: ; Stderr: iptables-restore v1.8.9 (nf_tables): interface name `de8355ee-9aee-4de4-9df9-513d9d62c08c' must be shorter than IFNAMSIZ (15)
Error occurred at line: 6
Try `iptables-restore -h' or 'iptables-restore --help' for more information.
2024-04-18 13:28:58.648 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-FORWARD 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
2024-04-18 13:28:58.648 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-FORWARD 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct traffic from the VM interface to the security group chain." -j neutron-openvswi-sg-chain
2024-04-18 13:28:58.648 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-FORWARD 3 -m physdev --physdev-out 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
2024-04-18 13:28:58.648 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-FORWARD 4 -m physdev --physdev-in 74ab55ca-0cb1-4669-998c-3c86912a3e32 --physdev-is-bridged -m comment --comment "Accept all packets when port is trusted." -j ACCEPT
2024-04-18 13:28:58.648 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-INPUT 1 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Direct incoming traffic from VM to the security group chain." -j neutron-openvswi-o355ee-9aee
2024-04-18 13:28:58.648 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-i355ee-9aee 1 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
2024-04-18 13:28:58.648 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-i355ee-9aee 5 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
2024-04-18 13:28:58.648 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-i355ee-9aee 6 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
2024-04-18 13:28:58.648 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 5 -m state --state RELATED,ESTABLISHED -m comment --comment "Direct packets associated with a known session to the RETURN chain." -j RETURN
2024-04-18 13:28:58.648 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 7 -m state --state INVALID -m comment --comment "Drop packets that appear related to an existing connection (e.g. TCP ACK/FIN) but do not have an entry in conntrack." -j DROP
2024-04-18 13:28:58.648 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-o355ee-9aee 8 -m comment --comment "Send unmatched traffic to the fallback chain." -j neutron-openvswi-sg-fallback
2024-04-18 13:28:58.648 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-s355ee-9aee 1 -s 172.16.129.142/32 -m mac --mac-source FA:16:3E:07:C5:CB -m comment --comment "Allow traffic from defined IP/MAC pairs." -j RETURN
2024-04-18 13:28:58.648 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-s355ee-9aee 2 -m comment --comment "Drop traffic without an IP/MAC allow rule." -j DROP
2024-04-18 13:28:58.648 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-sg-chain 1 -m physdev --physdev-out de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-i355ee-9aee
2024-04-18 13:28:58.648 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent -I neutron-openvswi-sg-chain 2 -m physdev --physdev-in de8355ee-9aee-4de4-9df9-513d9d62c08c --physdev-is-bridged -m comment --comment "Jump to the VM specific chain." -j neutron-openvswi-o355ee-9aee
2024-04-18 13:28:58.648 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent # Completed by iptables_manager
2024-04-18 13:28:58.648 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent ; Stdout: ; Stderr: iptables-restore v1.8.9 (nf_tables): interface name `de8355ee-9aee-4de4-9df9-513d9d62c08c' must be shorter than IFNAMSIZ (15)
2024-04-18 13:28:58.648 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent Error occurred at line: 6
2024-04-18 13:28:58.648 8372 ERROR neutron.plugins.ml2.drivers.openvswitch.agent.ovs_neutron_agent Try `iptables-restore -h' or 'iptables-restore --help' for more information.