openstack-manuals/doc/install-guide/source/neutron-compute-install-opt...

1.3 KiB

Networking Option 1: Provider networks

Install and configure the Networking components on a compute node.

Configure the Linux bridge agent

The Linux bridge agent builds layer-2 (bridging and switching) virtual networking infrastructure for instances including VXLAN tunnels for private networks and handles security groups.

Edit the /etc/neutron/plugins/ml2/linuxbridge_agent.conf file.

  1. In the [linux_bridge] section, map the public virtual network to the public physical network interface:

    [linux_bridge]
    physical_interface_mappings = public:PUBLIC_INTERFACE_NAME

    Replace PUBLIC_INTERFACE_NAME with the name of the underlying physical public network interface.

  2. In the [vxlan] section, disable VXLAN overlay networks:

    [vxlan]
    enable_vxlan = False
  3. In the [securitygroup] section, enable security groups, enable ipset, and configure the Linux bridge iptables firewall driver:

    [securitygroup]
    ...
    enable_security_group = True
    enable_ipset = True
    firewall_driver = neutron.agent.linux.iptables_firewall.IptablesFirewallDriver

Return to Networking compute node configuration <neutron-compute-compute>.