Page MenuHomePhabricator

cloudgw: review security policy for edge network
Closed, ResolvedPublic


Since there were a bunch of hosts migrated to a new switch, previously working connections no longer work.

Example to

aborrero@cloudcontrol2004-dev:~ $ ping
PING ( 56(84) bytes of data.
--- ping statistics ---
94 packets transmitted, 0 received, 100% packet loss, time 95217ms

Among other things, this makes basically all tests on WMCS cookbooks fail for codfw1dev.

Event Timeline

@aborrero my apologies I messed up the vlan list for cloudgw2002. cloud-instance-transport1-b-codfw (2120) was missing. Should be ok now.

cmooney@cloudsw1-b1-codfw> show arp interface irb.2120               
MAC Address       Address         Name                      Interface               Flags
d0:8e:79:f5:86:44  cloudgw2003-dev.codfw1dev irb.2120 [ge-0/0/17.0]  none
2c:ea:7f:7b:e1:04  cloudgw2002-dev.codfw1dev irb.2120 [ge-0/0/6.0]   none
d0:8e:79:f5:86:44  wan.cloudgw.codfw1dev.wik irb.2120 [ge-0/0/17.0]  none
Total entries: 3
cmooney@wikilap:~$ ping
PING ( 56(84) bytes of data.
64 bytes from icmp_seq=1 ttl=46 time=159 ms
64 bytes from icmp_seq=2 ttl=46 time=157 ms

@aborrero re-reading the description it sounds like there may be some other issues? Let me know if there is anything specific, the particular problem/fix above only deals with cloudgw2002.