ayounsi (Arzhel Younsi)
Network Engineer

Projects

Today

  • Clear sailing ahead.

Tomorrow

  • Clear sailing ahead.

Saturday

  • Clear sailing ahead.

User Details

User Since
Apr 3 2017, 6:23 PM (88 w, 2 d)
Availability
Available
IRC Nick
xionox
LDAP User
Ayounsi
MediaWiki User
AYounsi (WMF) [ Global Accounts ]

Recent Activity

Yesterday

ayounsi added a comment to T207663: Renumber cloud-instance-transport1-b-eqiad to public IPs.

@aborrero Everything is ready to be merged/commited.

Wed, Dec 12, 11:07 PM · cloud-services-team (Kanban), Patch-For-Review, netops, Operations
ayounsi added a comment to T207663: Renumber cloud-instance-transport1-b-eqiad to public IPs.

To be pushed:

cr1-eqiad
[edit interfaces ae2 unit 1120 family inet]
        address 10.64.22.2/24 { ... }
+       address 208.80.155.90/29 {
+           vrrp-group 121 {
+               virtual-address 208.80.155.89;
+               track {
+                   interface ae2.1120 {
+                       bandwidth-threshold 20g priority-cost 50;
+                       bandwidth-threshold 30g priority-cost 30;
+                   }
+               }
+           }
+       }
Wed, Dec 12, 10:38 PM · cloud-services-team (Kanban), Patch-For-Review, netops, Operations
ayounsi updated the task description for T210456: codfw row B recable and add QFX.
Wed, Dec 12, 9:13 PM · Patch-For-Review, ops-codfw, netops, Operations
ayounsi updated the task description for T210456: codfw row B recable and add QFX.
Wed, Dec 12, 6:56 PM · Patch-For-Review, ops-codfw, netops, Operations
ayounsi updated the task description for T210456: codfw row B recable and add QFX.
Wed, Dec 12, 5:57 PM · Patch-For-Review, ops-codfw, netops, Operations
ayounsi updated the task description for T210456: codfw row B recable and add QFX.
Wed, Dec 12, 5:08 PM · Patch-For-Review, ops-codfw, netops, Operations
ayounsi closed T211079: IPv6 ~20ms higher ping than IPv4 to gerrit as Resolved.

Actually, this can be closed.

Wed, Dec 12, 4:40 PM · Operations, Traffic, netops
ayounsi updated the task description for T210456: codfw row B recable and add QFX.
Wed, Dec 12, 4:38 PM · Patch-For-Review, ops-codfw, netops, Operations
ayounsi updated the task description for T210456: codfw row B recable and add QFX.
Wed, Dec 12, 4:20 PM · Patch-For-Review, ops-codfw, netops, Operations
ayounsi updated the task description for T210456: codfw row B recable and add QFX.
Wed, Dec 12, 4:16 PM · Patch-For-Review, ops-codfw, netops, Operations

Tue, Dec 11

ayounsi triaged T211730: Replace accepted-prefix-limit with prefix-limit as Low priority.
Tue, Dec 11, 10:00 PM · netops, Operations
ayounsi triaged T211728: Outbound BGP graceful shutdown as Normal priority.
Tue, Dec 11, 9:49 PM · Operations, netops
ayounsi added a subtask for T211079: IPv6 ~20ms higher ping than IPv4 to gerrit: T204281: Stop prioritizing peering over transit.
Tue, Dec 11, 8:32 PM · Operations, Traffic, netops
ayounsi added a parent task for T204281: Stop prioritizing peering over transit: T211079: IPv6 ~20ms higher ping than IPv4 to gerrit.
Tue, Dec 11, 8:31 PM · Performance-Team (Radar), Operations, netops
ayounsi changed the status of T211079: IPv6 ~20ms higher ping than IPv4 to gerrit from Open to Stalled.

All done, marking the task as stalled until T204281

Tue, Dec 11, 8:31 PM · Operations, Traffic, netops
ayounsi added a comment to T211254: Free up 185.15.59.0/24.

Talked a bit over IRC, tldr, the rationale has been added to the beginning of the task's description.
Triggering conversation was about removing WMCS 185.15.56.0/23 from prod ACLs.

Tue, Dec 11, 8:26 PM · Traffic, Operations, netops
ayounsi added a comment to T211079: IPv6 ~20ms higher ping than IPv4 to gerrit.

The issue is not present in eqdfw, eqiad, esams, as HE is not sending those routes through the RS.
Pushing the "avoid HE prefixes from the RS" change to those sites to ensure the issue doesn't show up if for some reasons we start getting HE routes via the those RS.

Tue, Dec 11, 8:21 PM · Operations, Traffic, netops
ayounsi triaged T211715: Interface errors on cr1-codfw:xe-5/3/1 as High priority.
Tue, Dec 11, 7:30 PM · Operations, ops-codfw
ayounsi added a comment to T211254: Free up 185.15.59.0/24.

If we need to free up 208.80.152.0/24, it is currently only used for:

  • 208.80.152.224/28 - frack-codfw
  • 208.80.152.240/28 - sandbox1-a-codfw
Tue, Dec 11, 7:19 PM · Traffic, Operations, netops
ayounsi added a comment to T211079: IPv6 ~20ms higher ping than IPv4 to gerrit.

Confirmed working, return path now takes NTT back and is ~17ms faster (to the last hop of previously shared traceroutes).

bast1002:~$ mtr a.gormless.thn.aa.net.uk --report-wide -6
Start: Tue Dec 11 18:29:07 2018
HOST: bast1002                                   Loss%   Snt   Last   Avg  Best  Wrst StDev
  1.|-- ae3-1003.cr2-eqiad.wikimedia.org            0.0%    10    0.2   1.0   0.2   7.8   2.3
  2.|-- ae0.cr1-eqiad.wikimedia.org                 0.0%    10    1.3   0.5   0.3   1.3   0.0
  3.|-- xe-0-0-28-0.a03.asbnva02.us.bb.gin.ntt.net  0.0%    10    0.6   4.2   0.2  33.1  10.3
  4.|-- ae-70.r06.asbnva02.us.bb.gin.ntt.net        0.0%    10    0.6   0.6   0.6   0.7   0.0
  5.|-- ae-2.r22.asbnva02.us.bb.gin.ntt.net         0.0%    10    0.4   0.4   0.4   0.5   0.0
  6.|-- ae-5.r25.nycmny01.us.bb.gin.ntt.net         0.0%    10    6.5   6.5   6.4   6.5   0.0
  7.|-- ae-1.r24.nycmny01.us.bb.gin.ntt.net         0.0%    10    9.5   6.6   6.2   9.5   1.0
  8.|-- ae-9.r24.londen12.uk.bb.gin.ntt.net         0.0%    10   74.8  75.0  74.7  76.7   0.5
  9.|-- ae-1.r04.londen05.uk.bb.gin.ntt.net         0.0%    10   73.5  73.3  73.2  73.5   0.0
 10.|-- e.aimless.tch.aa.net.uk                    30.0%    10   74.2  74.2  74.1  74.2   0.0
 11.|-- a.gormless.thn.aa.net.uk                    0.0%    10   73.2  73.1  73.0  73.4   0.0
Tue, Dec 11, 6:40 PM · Operations, Traffic, netops
ayounsi added a comment to T211079: IPv6 ~20ms higher ping than IPv4 to gerrit.

Left to push:

cr2-eqdfw
[edit protocols bgp group IX6 neighbor 2001:504:0:4:ffff:ffff:ffff:1]
+     import [ BGP_sanitize_in BGP_IXP_RS_in BGP_community_actions ];
[edit protocols bgp group IX6 neighbor 2001:504:0:4:ffff:ffff:ffff:2]
+     import [ BGP_sanitize_in BGP_IXP_RS_in BGP_community_actions ];
[edit policy-options]
+   policy-statement BGP_IXP_RS_in {
+       term avoid-paths-ixp-rs {
+           from as-path-group AVOID-PATHS-IXP-RS;
+           then {
+               community add AVOIDED_PATH;
+           }
+       }
+       then next policy;
+   }
[edit policy-options]
    as-path-group SELECTED-PATHS { ... }
+   as-path-group AVOID-PATHS-IX-RS {
+       as-path NONE 0;
+       as-path HE "6939 .*";
+   }

To be adapted for other sites: AVOID-PATHS-IX-RS group, different IX neighbors RS IPs

Tue, Dec 11, 6:06 PM · Operations, Traffic, netops
ayounsi closed T211699: Remove static routes for NS v6 IPs as Resolved.

Cleaned up.

Tue, Dec 11, 4:36 PM · Operations, netops
ayounsi triaged T211699: Remove static routes for NS v6 IPs as Normal priority.
Tue, Dec 11, 4:15 PM · Operations, netops
ayounsi added a comment to T210456: codfw row B recable and add QFX.

Part's ETA is today, rescheduling this work to tomorrow (Dec. 12th) same time.

Tue, Dec 11, 4:06 PM · Patch-For-Review, ops-codfw, netops, Operations
ayounsi updated the task description for T210456: codfw row B recable and add QFX.
Tue, Dec 11, 4:05 PM · Patch-For-Review, ops-codfw, netops, Operations
ayounsi updated the task description for T210447: codfw row A recable and add QFX.
Tue, Dec 11, 4:04 PM · ops-codfw, netops, Operations
ayounsi added a comment to T210447: codfw row A recable and add QFX.

Part's ETA is today, for DCops convenience, rescheduling this one to next Wednesday, and row B to Dec. 12th, same time.

Tue, Dec 11, 4:04 PM · ops-codfw, netops, Operations
Reedy awarded T211079: IPv6 ~20ms higher ping than IPv4 to gerrit a The World Burns token.
Tue, Dec 11, 3:40 PM · Operations, Traffic, netops
ayounsi added a comment to T211079: IPv6 ~20ms higher ping than IPv4 to gerrit.
  • It's been a while, but I believe an import statement in the neighbor block overrides the parent one in its entirety, and does not supplement it, so we'd have to repeat the whole import chain there.

Noted, that is not an issue as it doesn't make the configuration much more complex.

Tue, Dec 11, 2:34 AM · Operations, Traffic, netops

Mon, Dec 10

ayounsi added a comment to T211254: Free up 185.15.59.0/24.

Added some context in the task description.

Mon, Dec 10, 11:05 PM · Traffic, Operations, netops
ayounsi updated the task description for T211254: Free up 185.15.59.0/24.
Mon, Dec 10, 10:56 PM · Traffic, Operations, netops
ayounsi claimed T211079: IPv6 ~20ms higher ping than IPv4 to gerrit.
Mon, Dec 10, 10:37 PM · Operations, Traffic, netops
ayounsi added a comment to T211079: IPv6 ~20ms higher ping than IPv4 to gerrit.

Talked to Faidon last week, we agreed that a mechanism to ignore AS paths learned from the route servers would be a useful thing to have and not only a hotfix for this issue.
Not tested but I *think* this would work, reviews welcome. The main thing I'm not 100% sure about is the order of import.
If they are on the same level, such as import [ BGP_sanitize_in BGP_IXP_in BGP_community_actions ]; they are processed in order (left to right).
Applying import BGP_IX_RS_in at a higher level *should* import it fist, and then the less specific.
If it doesn't, then we could apply import [ BGP_sanitize_in BGP_IXP_RS_in BGP_community_actions ]; and add an explicit permit at the end of BGP_community_actions

Mon, Dec 10, 10:37 PM · Operations, Traffic, netops
ayounsi updated the task description for T210456: codfw row B recable and add QFX.
Mon, Dec 10, 7:36 PM · Patch-For-Review, ops-codfw, netops, Operations

Fri, Dec 7

ayounsi triaged T211459: rancid causes puppet to flap on netmon1002 as Low priority.
Fri, Dec 7, 10:17 PM · monitoring

Thu, Dec 6

ayounsi added a subtask for T209460: CloudVPS: our ideal future model: Unknown Object (Task).
Thu, Dec 6, 9:15 PM · Operations, cloud-services-team (Kanban), Epic

Wed, Dec 5

ayounsi triaged T211254: Free up 185.15.59.0/24 as Low priority.
Wed, Dec 5, 10:45 PM · Traffic, Operations, netops
ayounsi added a comment to T211079: IPv6 ~20ms higher ping than IPv4 to gerrit.

I'm all for testing T204281, but it's probably wise to wait for January for that.

Wed, Dec 5, 4:49 PM · Operations, Traffic, netops

Tue, Dec 4

ayounsi updated the task description for T210447: codfw row A recable and add QFX.
Tue, Dec 4, 9:11 PM · ops-codfw, netops, Operations
ayounsi added a comment to T210447: codfw row A recable and add QFX.

Parts keeps getting delayed, new shipping is expected for this Friday, rescheduling the work for next Wednesday.

Tue, Dec 4, 9:11 PM · ops-codfw, netops, Operations
ayounsi updated the task description for T211131: DNS recursors TCP retransmits.
Tue, Dec 4, 6:28 PM · Pybal, Operations, Traffic
ayounsi lowered the priority of T211131: DNS recursors TCP retransmits from Normal to Low.

Doing a DNS query over TCP from bast2001 to dns2001 (directly) or dns2002 (via the LVS VIP dig @dns-rec-lb.codfw.wikimedia.org en.wikipedia.org +tcp) doesn't show any retransmits. So the issue seems to be limited to pybal healthchecks.

Tue, Dec 4, 6:22 PM · Pybal, Operations, Traffic
ayounsi updated the task description for T211131: DNS recursors TCP retransmits.
Tue, Dec 4, 5:44 PM · Pybal, Operations, Traffic
ayounsi triaged T211131: DNS recursors TCP retransmits as Normal priority.
Tue, Dec 4, 5:43 PM · Pybal, Operations, Traffic

Mon, Dec 3

ayounsi updated the task description for T210447: codfw row A recable and add QFX.
Mon, Dec 3, 7:12 PM · ops-codfw, netops, Operations
ayounsi closed T201097: Add virtual chassis port status alerting as Resolved.

Done.
Runnbook at https://wikitech.wikimedia.org/wiki/Network_monitoring#VCP_status

Mon, Dec 3, 4:31 PM · Patch-For-Review, monitoring, Operations, netops

Thu, Nov 29

ayounsi closed T210788: faulty VC link on asw2-c-eqiad as Resolved.

That was actually an unused port.

Thu, Nov 29, 9:36 PM · netops, ops-eqiad, Operations
ayounsi triaged T210788: faulty VC link on asw2-c-eqiad as High priority.
Thu, Nov 29, 9:21 PM · netops, ops-eqiad, Operations
ayounsi closed T210612: Remove neodymium/sarin from router ACLs as Resolved.

Removed!

Thu, Nov 29, 7:49 PM · Operations, netops
ayounsi added a comment to T205898: Netbox: explore NAPALM integration.

All test configuration for Netbox/Napalm has been removed.

Thu, Nov 29, 7:06 PM · Patch-For-Review, Operations
ayounsi assigned T210683: lvs1006 down to Cmjohnson.

Port looks down (but not disabled) on the switch side, I'd say next step is for Chris to try re-seating then different cable/ports/etc.

Thu, Nov 29, 2:54 AM · netops, ops-eqiad, Traffic, Operations

Mon, Nov 26

ayounsi updated the task description for T196489: upgrade all codfw switch stacks to include additional 10G switch per row.
Mon, Nov 26, 11:35 PM · ops-codfw, netops, Operations
ayounsi added a subtask for T196489: upgrade all codfw switch stacks to include additional 10G switch per row: T210467: codfw row D recable and add QFX.
Mon, Nov 26, 11:35 PM · ops-codfw, netops, Operations
ayounsi added a parent task for T210467: codfw row D recable and add QFX: T196489: upgrade all codfw switch stacks to include additional 10G switch per row.
Mon, Nov 26, 11:35 PM · User-jijiki, Patch-For-Review, ops-codfw, netops, Operations
ayounsi triaged T210467: codfw row D recable and add QFX as Normal priority.
Mon, Nov 26, 11:34 PM · User-jijiki, Patch-For-Review, ops-codfw, netops, Operations
ayounsi updated the task description for T196489: upgrade all codfw switch stacks to include additional 10G switch per row.
Mon, Nov 26, 9:51 PM · ops-codfw, netops, Operations
ayounsi added a subtask for T196489: upgrade all codfw switch stacks to include additional 10G switch per row: T210456: codfw row B recable and add QFX.
Mon, Nov 26, 9:51 PM · ops-codfw, netops, Operations
ayounsi added a parent task for T210456: codfw row B recable and add QFX: T196489: upgrade all codfw switch stacks to include additional 10G switch per row.
Mon, Nov 26, 9:51 PM · Patch-For-Review, ops-codfw, netops, Operations
ayounsi reassigned T210447: codfw row A recable and add QFX from ayounsi to Papaul.
Mon, Nov 26, 9:51 PM · ops-codfw, netops, Operations
ayounsi reassigned T210456: codfw row B recable and add QFX from ayounsi to Papaul.
Mon, Nov 26, 9:51 PM · Patch-For-Review, ops-codfw, netops, Operations
ayounsi triaged T210456: codfw row B recable and add QFX as Normal priority.
Mon, Nov 26, 9:50 PM · Patch-For-Review, ops-codfw, netops, Operations
ayounsi updated the task description for T205897: Netbox: fill network topology.
Mon, Nov 26, 9:06 PM · Operations
ayounsi updated the task description for T205897: Netbox: fill network topology.
Mon, Nov 26, 9:03 PM · Operations
ayounsi updated the task description for T196489: upgrade all codfw switch stacks to include additional 10G switch per row.
Mon, Nov 26, 8:43 PM · ops-codfw, netops, Operations
ayounsi added a parent task for T208272: codfw row C recable and add QFX: T196489: upgrade all codfw switch stacks to include additional 10G switch per row.
Mon, Nov 26, 8:43 PM · Patch-For-Review, ops-codfw, Operations, netops
ayounsi added a subtask for T196489: upgrade all codfw switch stacks to include additional 10G switch per row: T208272: codfw row C recable and add QFX.
Mon, Nov 26, 8:43 PM · ops-codfw, netops, Operations
ayounsi triaged T210447: codfw row A recable and add QFX as Normal priority.
Mon, Nov 26, 8:42 PM · ops-codfw, netops, Operations
ayounsi updated the task description for T196489: upgrade all codfw switch stacks to include additional 10G switch per row.
Mon, Nov 26, 8:03 PM · ops-codfw, netops, Operations
ayounsi merged T197147: Rack/Setup new codfw QFX5100 10G switch into T196489: upgrade all codfw switch stacks to include additional 10G switch per row.
Mon, Nov 26, 8:03 PM · ops-codfw, netops, Operations
ayounsi merged task T197147: Rack/Setup new codfw QFX5100 10G switch into T196489: upgrade all codfw switch stacks to include additional 10G switch per row.
Mon, Nov 26, 8:03 PM · netops, Operations
ayounsi updated the task description for T207668: Increase network capacity (2018-19 Q2 Goal).
Mon, Nov 26, 8:02 PM · Goal, Traffic, netops, Operations
ayounsi added a comment to T201411: Fatal error on Special:Log caused by date input (TimestampException error).

IP removed from Amsterdam router's blacklist.

Mon, Nov 26, 7:42 PM · MW-1.32-notes (WMF-deploy-2018-09-18 (1.32.0-wmf.22)), Core-Platform-Team-Old (CPT-Q1-Jul-Sep-2018), MediaWiki-Logging, Wikimedia-production-error

Tue, Nov 20

ayounsi closed T208726: Access to network devices for Riccardo (volans) as Resolved.

Pushed everywhere except Frack infra as I don't want to make any change there during the fundraising campaigns without approval.

Tue, Nov 20, 11:14 PM · netops, Operations
ayounsi added a comment to T201411: Fatal error on Special:Log caused by date input (TimestampException error).

The IP 91.247.38.47 is still in the blacklist filters of the esams network devices, is it safe to remove it? If not, when should I ping you again about it?
Thanks

Tue, Nov 20, 10:43 PM · MW-1.32-notes (WMF-deploy-2018-09-18 (1.32.0-wmf.22)), Core-Platform-Team-Old (CPT-Q1-Jul-Sep-2018), MediaWiki-Logging, Wikimedia-production-error
ayounsi added a comment to T208576: Netbox: Usage guidelines for WMCS .

I think the main risk with Netbox and its ton of great features is to have outdated/incorrect data down the road.
For example it's easy to mass import facts from our current infrastructure, but how are we making sure that info will still be correct in 2 year?
For that I see several ways:

  • Don't enter data you don't need
  • Use Netbox reports to ensure data consistency (cf. the work started in T205899)
  • Use external scripts to look for discrepancies between Netbox and the infrastructure
  • Manual reviews
  • Have runbooks mention updating Netbox when needed
Tue, Nov 20, 9:36 PM · Operations, cloud-services-team (Kanban)
ayounsi updated the task description for T205897: Netbox: fill network topology.
Tue, Nov 20, 7:40 PM · Operations
ayounsi closed T209588: asw2-a-eqiad FPC2 reboot as Resolved.

Not much we can do here, if it happen again though, we should RMA the device.

Tue, Nov 20, 5:41 PM · Operations, netops
ayounsi triaged T209989: Bird multihop BFD as Normal priority.
Tue, Nov 20, 5:36 PM · Operations, netops
ayounsi closed T209841: LibreNMS IRC bot registration as Resolved.

Thanks, that works!

Tue, Nov 20, 2:29 AM · Patch-For-Review, monitoring
ayounsi closed T209841: LibreNMS IRC bot registration, a subtask of T48252: IRC bots account pending nickserv registration (tracking), as Resolved.
Tue, Nov 20, 2:29 AM · Tracking

Mon, Nov 19

ayounsi updated the task description for T205897: Netbox: fill network topology.
Mon, Nov 19, 8:50 PM · Operations
ayounsi updated the task description for T205897: Netbox: fill network topology.
Mon, Nov 19, 6:32 PM · Operations
ayounsi closed T208091: Fix missing PDU's for row C eqiad in netbox as Resolved.

Serial exported from LibreNMS.

Mon, Nov 19, 6:32 PM · Operations, netops, ops-eqiad
ayounsi closed T208091: Fix missing PDU's for row C eqiad in netbox , a subtask of T205897: Netbox: fill network topology, as Resolved.
Mon, Nov 19, 6:32 PM · Operations
ayounsi added a comment to T205829: IPv6 ping to eqiad on ripe-atlas-eqiad IPv6 noisy alert.

Reply from the RIPE:

Mon, Nov 19, 5:20 PM · Patch-For-Review, Operations, netops
ayounsi added a subtask for T205897: Netbox: fill network topology: T208091: Fix missing PDU's for row C eqiad in netbox .
Mon, Nov 19, 5:18 PM · Operations
ayounsi added a parent task for T208091: Fix missing PDU's for row C eqiad in netbox : T205897: Netbox: fill network topology.
Mon, Nov 19, 5:18 PM · Operations, netops, ops-eqiad
ayounsi added a comment to T205898: Netbox: explore NAPALM integration.

[...] but I'm wondering what "some devices facts" means exactly

Uptime, OS version, serial#, etc...
And it only displays it as far as I know.

Mon, Nov 19, 5:00 PM · Patch-For-Review, Operations
ayounsi triaged T209841: LibreNMS IRC bot registration as Normal priority.
Mon, Nov 19, 2:02 PM · Patch-For-Review, monitoring

Sat, Nov 17

ayounsi closed T207278: Move dumpsdata1001 as Resolved.

Correct, thanks!

Sat, Nov 17, 4:38 PM · Dumps-Generation, ops-eqiad, Operations

Fri, Nov 16

ayounsi claimed T209145: Investigate network issues in codfw that caused 503 errors.

Not answering the question but adding data points.

Fri, Nov 16, 1:12 AM · Operations, netops
ayounsi updated the task description for T209145: Investigate network issues in codfw that caused 503 errors.
Fri, Nov 16, 12:35 AM · Operations, netops

Thu, Nov 15

ayounsi added a comment to T205899: Develop and deploy at least three Netbox reports to assist with data correctness and consistency.

More report suggestions I have in mind:

  • Display all active network devices not connected to a console server, and this only in sites that have at least 1 active console server (to ignore eqord, knams, eqdfw)
  • Display all active devices with at least "wmf" or "spare" in the name (as they should be "planned" or "inventory") - cf. T209074
Thu, Nov 15, 6:53 PM · Patch-For-Review, Operations, Operations-Software-Development
ayounsi triaged T209588: asw2-a-eqiad FPC2 reboot as Normal priority.
Thu, Nov 15, 2:24 PM · netops, Operations

Tue, Nov 13

ayounsi closed T209424: Permit routing from eqiad1-r instances to labnet1001 as Resolved.
Tue, Nov 13, 10:33 PM · netops, Operations, cloud-services-team (Kanban)
ayounsi added a comment to T209424: Permit routing from eqiad1-r instances to labnet1001.

Pushed to cr1/2-eqiad

[edit firewall family inet filter cloud-in4]
[...]
+      term labnet-nova-api {
+          from {
+              destination-address {
+                  /* labnet1001 */
+                  10.64.20.13/32;
+              }
+              protocol tcp;
+              destination-port 8774;
+          }
+          then accept;
+      }
[...]
Tue, Nov 13, 10:30 PM · netops, Operations, cloud-services-team (Kanban)

Nov 13 2018

ayounsi added a comment to T209011: Change routing to ensure that traffic originating from Cloud VPS is seen as non-private IPs by Wikimedia wikis.

If needed note that I can add a (temporary) logging statement on the firewall to see all flows going from 172.16/12 to our public ranges, if it's of any help. I guess the same is possible on the OpenStack gateway.

Nov 13 2018, 1:54 PM · cloud-services-team (Kanban), Cloud-VPS
ayounsi removed a parent task for T174596: dmz_cidr only includes some wikimedia public IP ranges, leading to some very strange behaviour: Unknown Object (Task).
Nov 13 2018, 12:53 PM · cloud-services-team (Kanban), netops, Operations, Cloud-VPS
ayounsi added a parent task for T209011: Change routing to ensure that traffic originating from Cloud VPS is seen as non-private IPs by Wikimedia wikis: Unknown Object (Task).
Nov 13 2018, 12:53 PM · cloud-services-team (Kanban), Cloud-VPS

Nov 12 2018

ayounsi added a comment to T208726: Access to network devices for Riccardo (volans).

I'll take care of it, I already gave him access to one device we use for tests, and need to find time to push his access everywhere. This is low urgency anyway.

Nov 12 2018, 10:21 AM · netops, Operations