Ubuntu 20.04
Sponsored Link

OpenStack Yoga : Neutron ネットワークを構成 (VXLAN)
2022/04/04
 
OpenStack Network Service(Neutron)による仮想ネットワークの構成です。
例として、VXLAN タイプのネットワークを構成します。
事前に以下のように Control ノードNetwork ノードCompute ノードの 各 Neutron サービスノードを構築済みであることが前提です。
また、当例では Network ノードが 2 つのネットワークインターフェースを持っているものとします。
また、下例で eth1 の方は IP なしでインターフェースを UP しています。
IP なしでのインターフェース UP の設定はこちらの [1] を参照ください
------------+---------------------------+---------------------------+------------
            |                           |                           |
        eth0|10.0.0.30              eth0|10.0.0.50              eth0|10.0.0.51
+-----------+-----------+   +-----------+-----------+   +-----------+-----------+
|    [ Control Node ]   |   |    [ Network Node ]   |   |    [ Compute Node ]   |
|                       |   |                       |   |                       |
|  MariaDB    RabbitMQ  |   |        L2 Agent       |   |        Libvirt        |
|  Memcached  httpd     |   |        L3 Agent       |   |     Nova Compute      |
|  Keystone   Glance    |   |     Metadata Agent    |   |        L2 Agent       |
|  Nova API             |   |                       |   |                       |
|  Neutron Server       |   |                       |   |                       |
|  Metadata Agent       |   |                       |   |                       |
+-----------------------+   +-----------+-----------+   +-----------------------+
                                    eth1|(UP with no IP)

[1] Control ノードで以下のように設定変更します。
root@dlp ~(keystone)#
vi /etc/neutron/plugins/ml2/ml2_conf.ini
# 155行目 : [tenant_network_types] に値を追記

tenant_network_types =
vxlan
# 206行目 : 追記

[ml2_type_flat]
flat_networks = physnet1
# 262行目 : 追記

[ml2_type_vxlan]
vni_ranges = 1:1000
root@dlp ~(keystone)#
systemctl restart neutron-server

[2] Network ノードで以下のように設定変更します。
root@network:~#
vi /etc/neutron/plugins/ml2/ml2_conf.ini
# 155行目 : [tenant_network_types] に値を追記

tenant_network_types =
vxlan
# 206行目 : 追記

[ml2_type_flat]
flat_networks = physnet1
# 262行目 : 追記

[ml2_type_vxlan]
vni_ranges = 1:1000
root@network:~#
vi /etc/neutron/plugins/ml2/linuxbridge_agent.ini
# 161行目 : 追記

[agent]
prevent_arp_spoofing = True
# 190行目 : 追記

[linux_bridge]
physical_interface_mappings = physnet1:eth1
# 257行目 : コメント解除

enable_vxlan = true
root@network:~#
vi /etc/neutron/dhcp_agent.ini
# 85行目 : 追記

dnsmasq_config_file = /etc/neutron/dnsmasq-neutron.conf
root@network:~#
vi /etc/neutron/dnsmasq-neutron.conf
# 新規作成

dhcp-option-force=26,1450
root@network:~#
for service in l3-agent dhcp-agent metadata-agent linuxbridge-agent; do
systemctl restart neutron-$service
done

[3] Compute ノードで以下のように設定変更します。
root@node01:~#
vi /etc/neutron/plugins/ml2/ml2_conf.ini
# 155行目 : [tenant_network_types] に値を追記

tenant_network_types =
vxlan
# 206行目 : 追記

[ml2_type_flat]
flat_networks = physnet1
# 262行目 : 追記

[ml2_type_vxlan]
vni_ranges = 1:1000
root@node01:~#
vi /etc/neutron/plugins/ml2/linuxbridge_agent.ini
# 161行目 : 追記

[agent]
prevent_arp_spoofing = True
# 257行目 : コメント解除

enable_vxlan = true
root@node01:~#
systemctl restart neutron-linuxbridge-agent

[4] 仮想ルーターを作成します。作業場所はどこでもよいですが、当例では Control ノード上で作業します。
# 仮想ルーター作成

root@dlp ~(keystone)#
openstack router create router01

+-------------------------+------------------------------------------------------------------------+
| Field                   | Value                                                                  |
+-------------------------+------------------------------------------------------------------------+
| admin_state_up          | UP                                                                     |
| availability_zone_hints |                                                                        |
| availability_zones      |                                                                        |
| created_at              | 2022-04-04T04:49:21Z                                                   |
| description             |                                                                        |
| distributed             | False                                                                  |
| external_gateway_info   | null                                                                   |
| flavor_id               | None                                                                   |
| ha                      | False                                                                  |
| id                      | 101b5009-68ee-4918-944b-2c2cd7ddf2e7                                   |
| location                | Munch({'cloud': '', 'region_name': '', 'zone': None, 'project': M..... |
| name                    | router01                                                               |
| project_id              | ddb7c08ba73a48eea040270d13a7b0cf                                       |
| revision_number         | 1                                                                      |
| routes                  |                                                                        |
| status                  | ACTIVE                                                                 |
| tags                    |                                                                        |
| updated_at              | 2022-04-04T04:49:21Z                                                   |
+-------------------------+------------------------------------------------------------------------+
[5] 内部用のネットワークを作成し、仮想ルーターに関連付けます。
# 内部用ネットワーク作成

root@dlp ~(keystone)#
openstack network create private --provider-network-type vxlan

+---------------------------+---------------------------------------------------------------------+
| Field                     | Value                                                               |
+---------------------------+---------------------------------------------------------------------+
| admin_state_up            | UP                                                                  |
| availability_zone_hints   |                                                                     |
| availability_zones        |                                                                     |
| created_at                | 2022-04-04T04:49:53Z                                                |
| description               |                                                                     |
| dns_domain                | None                                                                |
| id                        | 7a07a4ee-a4b8-4d33-ace4-e5475183251b                                |
| ipv4_address_scope        | None                                                                |
| ipv6_address_scope        | None                                                                |
| is_default                | False                                                               |
| is_vlan_transparent       | None                                                                |
| location                  | Munch({'cloud': '', 'region_name': '', 'zone': None, 'project'..... |
| mtu                       | 1450                                                                |
| name                      | private                                                             |
| port_security_enabled     | True                                                                |
| project_id                | ddb7c08ba73a48eea040270d13a7b0cf                                    |
| provider:network_type     | vxlan                                                               |
| provider:physical_network | None                                                                |
| provider:segmentation_id  | 26                                                                  |
| qos_policy_id             | None                                                                |
| revision_number           | 1                                                                   |
| router:external           | Internal                                                            |
| segments                  | None                                                                |
| shared                    | False                                                               |
| status                    | ACTIVE                                                              |
| subnets                   |                                                                     |
| tags                      |                                                                     |
| updated_at                | 2022-04-04T04:49:53Z                                                |
+---------------------------+---------------------------------------------------------------------+

# 内部用ネットワークにサブネット作成

root@dlp ~(keystone)#
openstack subnet create private-subnet --network private \
--subnet-range 192.168.100.0/24 --gateway 192.168.100.1 \
--dns-nameserver 10.0.0.10

+----------------------+--------------------------------------------------------------------------+
| Field                | Value                                                                    |
+----------------------+--------------------------------------------------------------------------+
| allocation_pools     | 192.168.100.2-192.168.100.254                                            |
| cidr                 | 192.168.100.0/24                                                         |
| created_at           | 2022-04-04T04:51:04Z                                                     |
| description          |                                                                          |
| dns_nameservers      | 10.0.0.10                                                                |
| dns_publish_fixed_ip | None                                                                     |
| enable_dhcp          | True                                                                     |
| gateway_ip           | 192.168.100.1                                                            |
| host_routes          |                                                                          |
| id                   | 965631bf-31f7-496c-a9ce-b399f183c707                                     |
| ip_version           | 4                                                                        |
| ipv6_address_mode    | None                                                                     |
| ipv6_ra_mode         | None                                                                     |
| location             | Munch({'cloud': '', 'region_name': '', 'zone': None, 'project': Mun..... |
| name                 | private-subnet                                                           |
| network_id           | 7a07a4ee-a4b8-4d33-ace4-e5475183251b                                     |
| project_id           | ddb7c08ba73a48eea040270d13a7b0cf                                         |
| revision_number      | 0                                                                        |
| segment_id           | None                                                                     |
| service_types        |                                                                          |
| subnetpool_id        | None                                                                     |
| tags                 |                                                                          |
| updated_at           | 2022-04-04T04:51:04Z                                                     |
+----------------------+--------------------------------------------------------------------------+

# 仮想ルーターに内部ネットワークを設定

root@dlp ~(keystone)#
openstack router add subnet router01 private-subnet
[6] 外部接続用のネットワークを作成し、仮想ルーターに関連付けます。
# 外部用ネットワーク作成

root@dlp ~(keystone)#
openstack network create \
--provider-physical-network physnet1 \
--provider-network-type flat --external public

+---------------------------+---------------------------------------------------------------------+
| Field                     | Value                                                               |
+---------------------------+---------------------------------------------------------------------+
| admin_state_up            | UP                                                                  |
| availability_zone_hints   |                                                                     |
| availability_zones        |                                                                     |
| created_at                | 2022-04-04T04:51:54Z                                                |
| description               |                                                                     |
| dns_domain                | None                                                                |
| id                        | b5601461-7253-482a-b5e8-26c2760c657c                                |
| ipv4_address_scope        | None                                                                |
| ipv6_address_scope        | None                                                                |
| is_default                | False                                                               |
| is_vlan_transparent       | None                                                                |
| location                  | Munch({'cloud': '', 'region_name': '', 'zone': None, 'project'..... |
| mtu                       | 1500                                                                |
| name                      | public                                                              |
| port_security_enabled     | True                                                                |
| project_id                | ddb7c08ba73a48eea040270d13a7b0cf                                    |
| provider:network_type     | flat                                                                |
| provider:physical_network | physnet1                                                            |
| provider:segmentation_id  | None                                                                |
| qos_policy_id             | None                                                                |
| revision_number           | 1                                                                   |
| router:external           | External                                                            |
| segments                  | None                                                                |
| shared                    | False                                                               |
| status                    | ACTIVE                                                              |
| subnets                   |                                                                     |
| tags                      |                                                                     |
| updated_at                | 2022-04-04T04:51:54Z                                                |
+---------------------------+---------------------------------------------------------------------+

# 外部用ネットワークにサブネット作成

root@dlp ~(keystone)#
openstack subnet create public-subnet \
--network public --subnet-range 10.0.0.0/24 \
--allocation-pool start=10.0.0.200,end=10.0.0.254 \
--gateway 10.0.0.1 --dns-nameserver 10.0.0.10 --no-dhcp

+----------------------+---------------------------------------------------------------------------+
| Field                | Value                                                                     |
+----------------------+---------------------------------------------------------------------------+
| allocation_pools     | 10.0.0.200-10.0.0.254                                                     |
| cidr                 | 10.0.0.0/24                                                               |
| created_at           | 2022-04-04T04:52:28Z                                                      |
| description          |                                                                           |
| dns_nameservers      | 10.0.0.10                                                                 |
| dns_publish_fixed_ip | None                                                                      |
| enable_dhcp          | False                                                                     |
| gateway_ip           | 10.0.0.1                                                                  |
| host_routes          |                                                                           |
| id                   | 57293b3d-24a5-443a-9699-54858bfc9d2b                                      |
| ip_version           | 4                                                                         |
| ipv6_address_mode    | None                                                                      |
| ipv6_ra_mode         | None                                                                      |
| location             | Munch({'cloud': '', 'region_name': '', 'zone': None, 'project': Munc..... |
| name                 | public-subnet                                                             |
| network_id           | b5601461-7253-482a-b5e8-26c2760c657c                                      |
| project_id           | ddb7c08ba73a48eea040270d13a7b0cf                                          |
| revision_number      | 0                                                                         |
| segment_id           | None                                                                      |
| service_types        |                                                                           |
| subnetpool_id        | None                                                                      |
| tags                 |                                                                           |
| updated_at           | 2022-04-04T04:52:28Z                                                      |
+----------------------+---------------------------------------------------------------------------+

# 仮想ルーターにゲートウェイを設定

root@dlp ~(keystone)#
openstack router set router01 --external-gateway public

[7] 作成したネットワークは、外部用はデフォルトで全プロジェクトがアクセス可能ですが、内部用はデフォルトでは [admin] プロジェクトのみがアクセス可能なため、内部ネットワークを利用させたいプロジェクトにアクセス権限を付与しておきます。
# ネットワーク RBAC リスト表示

root@dlp ~(keystone)#
openstack network rbac list

+--------------------------------------+-------------+--------------------------------------+
| ID                                   | Object Type | Object ID                            |
+--------------------------------------+-------------+--------------------------------------+
| ae3ba4c6-7c72-4c78-8b24-709afe4261dd | network     | b5601461-7253-482a-b5e8-26c2760c657c |
+--------------------------------------+-------------+--------------------------------------+

# RBAC の詳細
# [access_as_external] のみ全プロジェクトがアクセス可能な状態

root@dlp ~(keystone)#
openstack network rbac show ae3ba4c6-7c72-4c78-8b24-709afe4261dd

+-------------------+-------------------------------------------------------------------------+
| Field             | Value                                                                   |
+-------------------+-------------------------------------------------------------------------+
| action            | access_as_external                                                      |
| id                | ae3ba4c6-7c72-4c78-8b24-709afe4261dd                                    |
| location          | Munch({'cloud': '', 'region_name': '', 'zone': None, 'project': Mu..... |
| name              | None                                                                    |
| object_id         | b5601461-7253-482a-b5e8-26c2760c657c                                    |
| object_type       | network                                                                 |
| project_id        | ddb7c08ba73a48eea040270d13a7b0cf                                        |
| target_project_id | *                                                                       |
+-------------------+-------------------------------------------------------------------------+

# 作成済みネットワーク一覧

root@dlp ~(keystone)#
openstack network list

+--------------------------------------+---------+--------------------------------------+
| ID                                   | Name    | Subnets                              |
+--------------------------------------+---------+--------------------------------------+
| 7a07a4ee-a4b8-4d33-ace4-e5475183251b | private | 965631bf-31f7-496c-a9ce-b399f183c707 |
| b5601461-7253-482a-b5e8-26c2760c657c | public  | 57293b3d-24a5-443a-9699-54858bfc9d2b |
+--------------------------------------+---------+--------------------------------------+

# 作成済みプロジェクト一覧

root@dlp ~(keystone)#
openstack project list

+----------------------------------+-----------+
| ID                               | Name      |
+----------------------------------+-----------+
| c043fb355eff47e69642adfcd7a55620 | service   |
| d3434f55aa5541cfab5f13916da0697d | hiroshima |
| ddb7c08ba73a48eea040270d13a7b0cf | admin     |
+----------------------------------+-----------+

# [private] への [access_as_shared] アクセス権を [hiroshima] プロジェクトに付与

root@dlp ~(keystone)#
netID=$(openstack network list | grep private | awk '{ print $2 }')

root@dlp ~(keystone)#
prjID=$(openstack project list | grep hiroshima | awk '{ print $2 }')

root@dlp ~(keystone)#
openstack network rbac create --target-project $prjID --type network --action access_as_shared $netID

+-------------------+-----------------------------------------------------------------------------+
| Field             | Value                                                                       |
+-------------------+-----------------------------------------------------------------------------+
| action            | access_as_shared                                                            |
| id                | 7dd210da-efb0-4aa1-8d7c-34c69d71b5af                                        |
| location          | Munch({'cloud': '', 'region_name': '', 'zone': None, 'project': Munch(..... |
| name              | None                                                                        |
| object_id         | 7a07a4ee-a4b8-4d33-ace4-e5475183251b                                        |
| object_type       | network                                                                     |
| project_id        | ddb7c08ba73a48eea040270d13a7b0cf                                            |
| target_project_id | d3434f55aa5541cfab5f13916da0697d                                            |
+-------------------+-----------------------------------------------------------------------------+
[8] 内部ネットワークへのアクセス権を付与したプロジェクトに所属する任意のユーザーでログインし、 作成した内部ネットワークをインスタンスに紐付けてインスタンスを作成・起動します。
# 利用可能な [flavor] 確認

ubuntu@dlp ~(keystone)$
openstack flavor list

+----+----------+------+------+-----------+-------+-----------+
| ID | Name     |  RAM | Disk | Ephemeral | VCPUs | Is Public |
+----+----------+------+------+-----------+-------+-----------+
| 0  | m1.small | 2048 |   10 |         0 |     1 | True      |
+----+----------+------+------+-----------+-------+-----------+

# 利用可能なイメージ確認

ubuntu@dlp ~(keystone)$
openstack image list

+--------------------------------------+------------+--------+
| ID                                   | Name       | Status |
+--------------------------------------+------------+--------+
| 53f6415a-1f98-485f-be0b-3f80edf523df | Ubuntu2004 | active |
+--------------------------------------+------------+--------+

# 利用可能なネットワーク確認

ubuntu@dlp ~(keystone)$
openstack network list

+--------------------------------------+---------+--------------------------------------+
| ID                                   | Name    | Subnets                              |
+--------------------------------------+---------+--------------------------------------+
| 7a07a4ee-a4b8-4d33-ace4-e5475183251b | private | 965631bf-31f7-496c-a9ce-b399f183c707 |
| b5601461-7253-482a-b5e8-26c2760c657c | public  | 57293b3d-24a5-443a-9699-54858bfc9d2b |
+--------------------------------------+---------+--------------------------------------+

# インスタンス用のセキュリティグループを作成

ubuntu@dlp ~(keystone)$
openstack security group create secgroup01

+-----------------+-------------------------------------------------------------------------------+
| Field           | Value                                                                         |
+-----------------+-------------------------------------------------------------------------------+
| created_at      | 2022-04-04T04:56:12Z                                                          |
| description     | secgroup01                                                                    |
| id              | a303a30e-c6f5-4180-b43e-aa959ee4abc5                                          |
| location        | Munch({'cloud': '', 'region_name': '', 'zone': None, 'project': Munch({'id':  |
| name            | secgroup01                                                                    |
| project_id      | d3434f55aa5541cfab5f13916da0697d                                              |
| revision_number | 1                                                                             |
| rules           | created_at='2022-04-04T04:56:12Z', direction='egress', ethertype='IPv6',..... |
|                 | created_at='2022-04-04T04:56:12Z', direction='egress', ethertype='IPv4',..... |
| stateful        | True                                                                          |
| tags            | []                                                                            |
| updated_at      | 2022-04-04T04:56:12Z                                                          |
+-----------------+-------------------------------------------------------------------------------+

# インスタンス接続用の SSH キーペア作成

ubuntu@dlp ~(keystone)$
ssh-keygen -q -N ""

Enter file in which to save the key (/home/ubuntu/.ssh/id_rsa):
# 公開鍵登録

ubuntu@dlp ~(keystone)$
openstack keypair create --public-key ~/.ssh/id_rsa.pub mykey

+-------------+-------------------------------------------------+
| Field       | Value                                           |
+-------------+-------------------------------------------------+
| created_at  | None                                            |
| fingerprint | c1:4e:1a:12:3a:d1:b5:dd:64:c8:52:4d:2f:3c:6e:82 |
| id          | mykey                                           |
| is_deleted  | None                                            |
| name        | mykey                                           |
| type        | ssh                                             |
| user_id     | 95f196a1851c4b93b016871f7d5ded82                |
+-------------+-------------------------------------------------+

ubuntu@dlp ~(keystone)$
netID=$(openstack network list | grep private | awk '{ print $2 }')

ubuntu@dlp ~(keystone)$
openstack server create --flavor m1.small --image Ubuntu2004 --security-group secgroup01 --nic net-id=$netID --key-name mykey Ubuntu-2004
ubuntu@dlp ~(keystone)$
openstack server list

+--------------------------------------+-------------+--------+------------------------+------------+----------+
| ID                                   | Name        | Status | Networks               | Image      | Flavor   |
+--------------------------------------+-------------+--------+------------------------+------------+----------+
| 59d1c5ba-a214-4c5b-94ff-789f837ecc32 | Ubuntu-2004 | ACTIVE | private=192.168.100.11 | Ubuntu2004 | m1.small |
+--------------------------------------+-------------+--------+------------------------+------------+----------+
[9] 作成した仮想マシンインスタンスにフローティング IP を割り当てます。
ubuntu@dlp ~(keystone)$
openstack floating ip create public

+---------------------+---------------------------------------------------------------------------+
| Field               | Value                                                                     |
+---------------------+---------------------------------------------------------------------------+
| created_at          | 2022-04-04T04:58:23Z                                                      |
| description         |                                                                           |
| dns_domain          | None                                                                      |
| dns_name            | None                                                                      |
| fixed_ip_address    | None                                                                      |
| floating_ip_address | 10.0.0.201                                                                |
| floating_network_id | b5601461-7253-482a-b5e8-26c2760c657c                                      |
| id                  | 9c099bba-90d3-417f-b3be-4a387995a8f5                                      |
| location            | Munch({'cloud': '', 'region_name': '', 'zone': None, 'project': Munc..... |
| name                | 10.0.0.201                                                                |
| port_details        | None                                                                      |
| port_id             | None                                                                      |
| project_id          | d3434f55aa5541cfab5f13916da0697d                                          |
| qos_policy_id       | None                                                                      |
| revision_number     | 0                                                                         |
| router_id           | None                                                                      |
| status              | DOWN                                                                      |
| subnet_id           | None                                                                      |
| tags                | []                                                                        |
| updated_at          | 2022-04-04T04:58:23Z                                                      |
+---------------------+---------------------------------------------------------------------------+

ubuntu@dlp ~(keystone)$
openstack server add floating ip Ubuntu-2004 10.0.0.201
# 設定確認

ubuntu@dlp ~(keystone)$
openstack floating ip show 10.0.0.201

+---------------------+----------------------------------------------------------------------------+
| Field               | Value                                                                      |
+---------------------+----------------------------------------------------------------------------+
| created_at          | 2022-04-04T04:58:23Z                                                       |
| description         |                                                                            |
| dns_domain          | None                                                                       |
| dns_name            | None                                                                       |
| fixed_ip_address    | 192.168.100.11                                                             |
| floating_ip_address | 10.0.0.201                                                                 |
| floating_network_id | b5601461-7253-482a-b5e8-26c2760c657c                                       |
| id                  | 9c099bba-90d3-417f-b3be-4a387995a8f5                                       |
| location            | Munch({'cloud': '', 'region_name': '', 'zone': None, 'project': Munch..... |
| name                | 10.0.0.201                                                                 |
| port_details        | admin_state_up='True', device_id='59d1c5ba-a214-4c5b-94ff-789f837ecc3..... |
| port_id             | 2b1e910e-1324-4ca3-9e8f-f408a1e3e663                                       |
| project_id          | d3434f55aa5541cfab5f13916da0697d                                           |
| qos_policy_id       | None                                                                       |
| revision_number     | 2                                                                          |
| router_id           | 101b5009-68ee-4918-944b-2c2cd7ddf2e7                                       |
| status              | ACTIVE                                                                     |
| subnet_id           | None                                                                       |
| tags                | []                                                                         |
| updated_at          | 2022-04-04T04:59:02Z                                                       |
+---------------------+----------------------------------------------------------------------------+

ubuntu@dlp ~(keystone)$
openstack server list

+--------------------------------------+-------------+--------+------------------------------------+------------+----------+
| ID                                   | Name        | Status | Networks                           | Image      | Flavor   |
+--------------------------------------+-------------+--------+------------------------------------+------------+----------+
| 59d1c5ba-a214-4c5b-94ff-789f837ecc32 | Ubuntu-2004 | ACTIVE | private=10.0.0.201, 192.168.100.11 | Ubuntu2004 | m1.small |
+--------------------------------------+-------------+--------+------------------------------------+------------+----------+
[10] 起動した仮想マシンインスタンスに SSH 接続できるように、先に作成したセキュリティグループにポート許可の設定を追加します。
# ICMP 許可

ubuntu@dlp ~(keystone)$
openstack security group rule create --protocol icmp --ingress secgroup01

+-------------------------+-----------------------------------------------------------------------+
| Field                   | Value                                                                 |
+-------------------------+-----------------------------------------------------------------------+
| created_at              | 2022-04-04T04:40:20Z                                                  |
| description             |                                                                       |
| direction               | ingress                                                               |
| ether_type              | IPv4                                                                  |
| id                      | 8d2a4bc7-1a0c-4ec0-b77d-b5522de3b603                                  |
| location                | Munch({'cloud': '', 'region_name': '', 'zone': None, 'project': ..... |
| name                    | None                                                                  |
| port_range_max          | None                                                                  |
| port_range_min          | None                                                                  |
| project_id              | d3434f55aa5541cfab5f13916da0697d                                      |
| protocol                | icmp                                                                  |
| remote_address_group_id | None                                                                  |
| remote_group_id         | None                                                                  |
| remote_ip_prefix        | 0.0.0.0/0                                                             |
| revision_number         | 0                                                                     |
| security_group_id       | 442b3351-ecff-49be-a48b-c5f36bc906b9                                  |
| tags                    | []                                                                    |
| updated_at              | 2022-04-04T04:40:20Z                                                  |
+-------------------------+-----------------------------------------------------------------------+

# SSH 許可

ubuntu@dlp ~(keystone)$
openstack security group rule create --protocol tcp --dst-port 22:22 secgroup01

+-------------------------+------------------------------------------------------------------------+
| Field                   | Value                                                                  |
+-------------------------+------------------------------------------------------------------------+
| created_at              | 2022-04-04T04:40:49Z                                                   |
| description             |                                                                        |
| direction               | ingress                                                                |
| ether_type              | IPv4                                                                   |
| id                      | 886f4f4f-74e1-4246-82b6-d97bedc214bb                                   |
| location                | Munch({'cloud': '', 'region_name': '', 'zone': None, 'project': M..... |
| name                    | None                                                                   |
| port_range_max          | 22                                                                     |
| port_range_min          | 22                                                                     |
| project_id              | d3434f55aa5541cfab5f13916da0697d                                       |
| protocol                | tcp                                                                    |
| remote_address_group_id | None                                                                   |
| remote_group_id         | None                                                                   |
| remote_ip_prefix        | 0.0.0.0/0                                                              |
| revision_number         | 0                                                                      |
| security_group_id       | 442b3351-ecff-49be-a48b-c5f36bc906b9                                   |
| tags                    | []                                                                     |
| updated_at              | 2022-04-04T04:40:49Z                                                   |
+-------------------------+------------------------------------------------------------------------+

ubuntu@dlp ~(keystone)$
openstack security group rule list secgroup01

+--------------------------------------+-------------+-----------+-----------+------------+-----------+-----------------------+----------------------+
| ID                                   | IP Protocol | Ethertype | IP Range  | Port Range | Direction | Remote Security Group | Remote Address Group |
+--------------------------------------+-------------+-----------+-----------+------------+-----------+-----------------------+----------------------+
| 43ddb4a5-caa8-4418-b1ce-9d3ac47b2164 | None        | IPv6      | ::/0      |            | egress    | None                  | None                 |
| 4be8aab2-ed86-4f87-b032-4c43695823a4 | None        | IPv4      | 0.0.0.0/0 |            | egress    | None                  | None                 |
| 886f4f4f-74e1-4246-82b6-d97bedc214bb | tcp         | IPv4      | 0.0.0.0/0 | 22:22      | ingress   | None                  | None                 |
| 8d2a4bc7-1a0c-4ec0-b77d-b5522de3b603 | icmp        | IPv4      | 0.0.0.0/0 |            | ingress   | None                  | None                 |
+--------------------------------------+-------------+-----------+-----------+------------+-----------+-----------------------+----------------------+
[11] 仮想マシンインスタンスに割りあてられたフローティング IP 宛てに SSH 接続することで、インスタンスに SSH ログインできます。
ubuntu@dlp ~(keystone)$
openstack server list

+--------------------------------------+-------------+--------+------------------------------------+------------+----------+
| ID                                   | Name        | Status | Networks                           | Image      | Flavor   |
+--------------------------------------+-------------+--------+------------------------------------+------------+----------+
| 59d1c5ba-a214-4c5b-94ff-789f837ecc32 | Ubuntu-2004 | ACTIVE | private=10.0.0.201, 192.168.100.11 | Ubuntu2004 | m1.small |
+--------------------------------------+-------------+--------+------------------------------------+------------+----------+

ubuntu@dlp ~(keystone)$
ssh ubuntu@10.0.0.201

The authenticity of host '10.0.0.201 (10.0.0.201)' can't be established.
ECDSA key fingerprint is SHA256:My7yBMW4ho2Yn7PVwmvKOMyW4tIEMnxGua4drGZX6KI.
Are you sure you want to continue connecting (yes/no/[fingerprint])? yes
Warning: Permanently added '10.0.0.201' (ECDSA) to the list of known hosts.
Welcome to Ubuntu 20.04.4 LTS (GNU/Linux 5.4.0-105-generic x86_64)

.....
.....

To run a command as administrator (user "root"), use "sudo <command>".
See "man sudo_root" for details.

ubuntu@ubuntu-2004:~$     # ログインできた
関連コンテンツ