data:image/s3,"s3://crabby-images/e2e0b/e2e0b9a244b8f0d801ed6dc856cbf3fa086ea6e5" alt="Cray Urika-GX Administration Manual Download Page 253"
About Using su
If a root attempts to switch to a restricted users via
su
, the user's shell will respond with the message,
"
interactive logins not permitted
" and then exit. To get around this, root can execute:
#
su -s /bin/bash - restricted-user-name
Public Network Access from Tenant Virtual Machines
If the tenant VM is up and running and all of the network configuration looks like it should be working correctly (the
public interface on
ens4
has an IP address and the interface is up, the gateway and DNS configuration is correct
and so forth) look on the host node (probably one of the login nodes) and make sure that the
br1
network bridge
is up and has the IP address being used for the public IP address of the login node. Also make sure that no other
interface (for example, the Ethernet onto which
br1
is bound) has that same IP address on it. If an interface other
br1
has that same IP address, check the network configuration files in
/etc/sysconfig/network-scripts
.
Look first in
ifcfg-br1
. It should looks something like this:
DEVICE=br1
TYPE=Bridge
BOOTPROTO=static
ONBOOT=yes
NM_CONTROLLED=no
IPADDR=172.30.51.237
NETMASK=255.255.240.0
GATEWAY=172.30.48.1
DNS1=172.30.84.40
DNS2=172.31.84.40
DOMAIN=us.cray.com
Then look at
ifcfg-enp8s0f1
. This is the configuration for the Ethernet device plugged into the public network
and should look something like this:
NAME="enp8s0f1"
DEVICE="enp8s0f1"
ONBOOT=yes
BOOTPROTO=static
TYPE=Ethernet
NM_CONTROLLED=no
BRIDGE=br1
Notice a few different things about this interface config:
●
It has no IP address and is configured with
BOOTPROTO=static
●
It is not controlled by network-manager:
NM_CONTROLLED=no
●
It is bound to the bridge device
br1
:
BRIDGE=br1
●
It is set up to be brought up at boot:
ONBOOT=yes
All of these things need to be true for the tenant VM to work correctly on this host node.
Now, look at the running interface state for both of these interfaces. An IP address on
enp8s0f1
indicates a stale
network state from the time the user switched to bridging. Clear this out using the following command:
# ifdown br1; ifdown enp8s0f1; ifup enp8s0f1; ifup br1
Troubleshooting
S3016
253