此内容没有您所选择的语言版本。
7.2. Configure OpenStack Networking
Important
vif_plugging_is_fatal option is commented out in the [DEFAULT] section of the /etc/nova/nova.conf file, and defaults to True. This option controls whether instances should fail to boot if VIF plugging fails. Similarly, the notify_nova_on_port_status_changes and notify_nova_on_port_data_changes options are commented out in the [DEFAULT] section of the /etc/neutron/neutron.conf file, and default to False. These options control whether notifications should be sent to nova on port status or data changes. However, this combination of values can prevent instances from booting. To allow instances to boot correctly, set all of these options to either True or False. To set True, run the following commands:
			False, run the following commands instead:
			7.2.1. Set the OpenStack Networking Plug-in
Note
neutron.conf by their nominated short names, instead of their lengthy class names. For example: 
core_plugin = neutron.plugins.ml2.plugin:Ml2Plugin
core_plugin = neutron.plugins.ml2.plugin:Ml2Plugincore_plugin = ml2
core_plugin = ml2| Short name | Class name | 
|---|---|
| bigswitch | neutron.plugins.bigswitch.plugin:NeutronRestProxyV2 | 
| brocade | neutron.plugins.brocade.NeutronPlugin:BrocadePluginV2 | 
| cisco | neutron.plugins.cisco.network_plugin:PluginV2 | 
| embrane | neutron.plugins.embrane.plugins.embrane_ovs_plugin:EmbraneOvsPlugin | 
| hyperv | neutron.plugins.hyperv.hyperv_neutron_plugin:HyperVNeutronPlugin | 
| linuxbridge | neutron.plugins.linuxbridge.lb_neutron_plugin:LinuxBridgePluginV2 | 
| midonet | neutron.plugins.midonet.plugin:MidonetPluginV2 | 
| ml2 | neutron.plugins.ml2.plugin:Ml2Plugin | 
| mlnx | neutron.plugins.mlnx.mlnx_plugin:MellanoxEswitchPlugin | 
| nec | neutron.plugins.nec.nec_plugin:NECPluginV2 | 
| openvswitch | neutron.plugins.openvswitch.ovs_neutron_plugin:OVSNeutronPluginV2 | 
| plumgrid | neutron.plugins.plumgrid.plumgrid_plugin.plumgrid_plugin:NeutronPluginPLUMgridV2 | 
| ryu | neutron.plugins.ryu.ryu_neutron_plugin:RyuNeutronPluginV2 | 
| vmware | neutron.plugins.vmware.plugin:NsxPlugin | 
service_plugins option accepts a comma-delimited list of multiple service plugins.
			| Short name | Class name | 
|---|---|
| dummy | neutron.tests.unit.dummy_plugin:DummyServicePlugin | 
| router | neutron.services.l3_router.l3_router_plugin:L3RouterPlugin | 
| firewall | neutron.services.firewall.fwaas_plugin:FirewallPlugin | 
| lbaas | neutron.services.loadbalancer.plugin:LoadBalancerPlugin | 
| metering | neutron.services.metering.metering_plugin:MeteringPlugin | 
7.2.1.1. Enable the ML2 Plug-in
neutron-server service.
				Procedure 7.1. Enabling the ML2 Plug-in
- Create a symbolic link to direct OpenStack Networking to theml2_conf.inifile:ln -s /etc/neutron/plugins/ml2/ml2_conf.ini /etc/neutron/plugin.ini # ln -s /etc/neutron/plugins/ml2/ml2_conf.ini /etc/neutron/plugin.iniCopy to Clipboard Copied! Toggle word wrap Toggle overflow 
- Set the tenant network type. Supported values aregre,local,vlan, andvxlan. The default value islocal, but this is not recommended for enterprise deployments:openstack-config --set /etc/neutron/plugin.ini \ ml2 tenant_network_types TYPE # openstack-config --set /etc/neutron/plugin.ini \ ml2 tenant_network_types TYPECopy to Clipboard Copied! Toggle word wrap Toggle overflow Replace TYPE with the tenant network type.
- If you choseflatorvlannetworking, you must also map physical networks to VLAN ranges:openstack-config --set /etc/neutron/plugin.ini \ ml2 network_vlan_ranges NAME:START:END # openstack-config --set /etc/neutron/plugin.ini \ ml2 network_vlan_ranges NAME:START:ENDCopy to Clipboard Copied! Toggle word wrap Toggle overflow Replace the following values:- Replace NAME with the name of the physical network.
- Replace START with the VLAN identifier that starts the range.
- Replace END with the VLAN identifier that ends the range.
 Multiple ranges can be specified using a comma-delimited list, for example:physnet1:1000:2999,physnet2:3000:3999 physnet1:1000:2999,physnet2:3000:3999Copy to Clipboard Copied! Toggle word wrap Toggle overflow 
- Set the driver types. Supported values arelocal,flat,vlan,gre, andvxlan:openstack-config --set /etc/neutron/plugin.ini \ ml2 type_drivers TYPE # openstack-config --set /etc/neutron/plugin.ini \ ml2 type_drivers TYPECopy to Clipboard Copied! Toggle word wrap Toggle overflow Replace TYPE with the driver type. Specify multiple drivers using a comma-delimited list.
- Set the mechanism drivers. Available values areopenvswitch,linuxbridge, andl2population:openstack-config --set /etc/neutron/plugin.ini \ ml2 mechanism_drivers TYPE # openstack-config --set /etc/neutron/plugin.ini \ ml2 mechanism_drivers TYPECopy to Clipboard Copied! Toggle word wrap Toggle overflow Replace TYPE with the mechanism driver type. Specify multiple mechanism drivers using a comma-delimited list.
- Enable L2 population:openstack-config --set /etc/neutron/plugin.ini \ agent l2_population True # openstack-config --set /etc/neutron/plugin.ini \ agent l2_population TrueCopy to Clipboard Copied! Toggle word wrap Toggle overflow 
- Set the firewall driver in the/etc/neutron/plugins/ml2/openvswitch_agent.inifile or the/etc/neutron/plugins/ml2/linuxbridge_agent.inifile, depending on which plug-in agent you are using:- Open vSwitch Firewall Driver - openstack-config --set /etc/neutron/plugins/ml2/openvswitch_agent.ini - # openstack-config --set /etc/neutron/plugins/ml2/openvswitch_agent.ini securitygroup firewall_driver neutron.agent.linux.iptables_firewall.OVSHybridIptablesFirewallDriver- Copy to Clipboard Copied! - Toggle word wrap Toggle overflow 
- Linux Bridge Firewall Driver - openstack-config --set /etc/neutron/plugins/ml2/linuxbridge_agent.ini - # openstack-config --set /etc/neutron/plugins/ml2/linuxbridge_agent.ini securitygroup firewall_driver neutron.agent.linux.iptables_firewall.IptablesFirewallDriver- Copy to Clipboard Copied! - Toggle word wrap Toggle overflow 
 
- Enable the ML2 plug-in and the L3 router:openstack-config --set /etc/neutron/neutron.conf \ DEFAULT core_plugin ml2 openstack-config --set /etc/neutron/neutron.conf \ DEFAULT service_plugins router # openstack-config --set /etc/neutron/neutron.conf \ DEFAULT core_plugin ml2 # openstack-config --set /etc/neutron/neutron.conf \ DEFAULT service_plugins routerCopy to Clipboard Copied! Toggle word wrap Toggle overflow 
7.2.1.2. Enable the Open vSwitch Plug-in
neutron-server service.
				Note
Procedure 7.2. Enabling the Open vSwitch Plug-in
- Create a symbolic link to direct OpenStack Networking to theopenvswitch_agent.inifile:ln -s /etc/neutron/plugins/ml2/openvswitch_agent.ini \ /etc/neutron/plugin.ini # ln -s /etc/neutron/plugins/ml2/openvswitch_agent.ini \ /etc/neutron/plugin.iniCopy to Clipboard Copied! Toggle word wrap Toggle overflow 
- Set the tenant network type. Supported values aregre,local,vlan, andvxlan. The default value islocal, but this is not recommended for enterprise deployments:openstack-config --set /etc/neutron/plugin.ini \ OVS tenant_network_type TYPE # openstack-config --set /etc/neutron/plugin.ini \ OVS tenant_network_type TYPECopy to Clipboard Copied! Toggle word wrap Toggle overflow Replace TYPE with the tenant network type.
- If you choseflatorvlannetworking, you must also map physical networks to VLAN ranges:openstack-config --set /etc/neutron/plugin.ini \ OVS network_vlan_ranges NAME:START:END # openstack-config --set /etc/neutron/plugin.ini \ OVS network_vlan_ranges NAME:START:ENDCopy to Clipboard Copied! Toggle word wrap Toggle overflow Replace the following values:- Replace NAME with the name of the physical network.
- Replace START with the VLAN identifier that starts the range.
- Replace END with the VLAN identifier that ends the range.
 Multiple ranges can be specified using a comma-delimited list, for example:physnet1:1000:2999,physnet2:3000:3999 physnet1:1000:2999,physnet2:3000:3999Copy to Clipboard Copied! Toggle word wrap Toggle overflow 
- Set the firewall driver:openstack-config --set /etc/neutron/plugin.ini \ securitygroup firewall_driver neutron.agent.linux.iptables_firewall.OVSHybridIptablesFirewallDriver # openstack-config --set /etc/neutron/plugin.ini \ securitygroup firewall_driver neutron.agent.linux.iptables_firewall.OVSHybridIptablesFirewallDriverCopy to Clipboard Copied! Toggle word wrap Toggle overflow 
- Enable the Open vSwitch plug-in:openstack-config --set /etc/neutron/neutron.conf \ DEFAULT core_plugin openvswitch # openstack-config --set /etc/neutron/neutron.conf \ DEFAULT core_plugin openvswitchCopy to Clipboard Copied! Toggle word wrap Toggle overflow 
7.2.1.3. Enable the Linux Bridge Plug-in
neutron-server service.
				Note
Procedure 7.3. Enabling the Linux Bridge Plug-in
- Create a symbolic link to direct OpenStack Networking to thelinuxbridge_agent.inifile:ln -s /etc/neutron/plugins/ml2/linuxbridge_agent.ini \ /etc/neutron/plugin.ini# ln -s /etc/neutron/plugins/ml2/linuxbridge_agent.ini \ /etc/neutron/plugin.iniCopy to Clipboard Copied! Toggle word wrap Toggle overflow 
- Set the tenant network type. Supported values areflat,vlan, andlocal. The default islocal, but this is not recommended for enterprise deployments:openstack-config --set /etc/neutron/plugin.ini \ VLAN tenant_network_type TYPE # openstack-config --set /etc/neutron/plugin.ini \ VLAN tenant_network_type TYPECopy to Clipboard Copied! Toggle word wrap Toggle overflow Replace TYPE with the chosen tenant network type.
- If you choseflatorvlannetworking, you must also map physical networks to VLAN ranges:openstack-config --set /etc/neutron/plugin.ini \ LINUX_BRIDGE network_vlan_ranges NAME:START:END # openstack-config --set /etc/neutron/plugin.ini \ LINUX_BRIDGE network_vlan_ranges NAME:START:ENDCopy to Clipboard Copied! Toggle word wrap Toggle overflow - Replace NAME with the name of the physical network.
- Replace START with the VLAN identifier that starts the range.
- Replace END with the VLAN identifier that ends the range.
 Multiple ranges can be specified using a comma-delimited list, for example:physnet1:1000:2999,physnet2:3000:3999 physnet1:1000:2999,physnet2:3000:3999Copy to Clipboard Copied! Toggle word wrap Toggle overflow 
- Set the firewall driver:openstack-config --set /etc/neutron/plugin.ini \ securitygroup firewall_driver neutron.agent.linux.iptables_firewall.IptablesFirewallDriver # openstack-config --set /etc/neutron/plugin.ini \ securitygroup firewall_driver neutron.agent.linux.iptables_firewall.IptablesFirewallDriverCopy to Clipboard Copied! Toggle word wrap Toggle overflow 
- Enable the Linux Bridge plug-in:openstack-config --set /etc/neutron/neutron.conf \ DEFAULT core_plugin linuxbridge # openstack-config --set /etc/neutron/neutron.conf \ DEFAULT core_plugin linuxbridgeCopy to Clipboard Copied! Toggle word wrap Toggle overflow 
7.2.2. Create the OpenStack Networking Database
root user, and prior to starting the neutron-server service.
	Procedure 7.4. Creating the OpenStack Networking Database
- Connect to the database service:mysql -u root -p # mysql -u root -pCopy to Clipboard Copied! Toggle word wrap Toggle overflow 
- Create the database with one of the following names:This example creates the ML2- If you are using the ML2 plug-in, the recommended database name isneutron_ml2
- If you are using the Open vSwitch plug-in, the recommended database name isovs_neutron.
- If you are using the Linux Bridge plug-in, the recommended database name isneutron_linux_bridge.
 neutron_ml2database:mysql> CREATE DATABASE neutron_ml2 character set utf8; mysql> CREATE DATABASE neutron_ml2 character set utf8;Copy to Clipboard Copied! Toggle word wrap Toggle overflow 
- Create aneutrondatabase user and grant the user access to theneutron_ml2database:mysql> GRANT ALL ON neutron_ml2.* TO 'neutron'@'%' IDENTIFIED BY 'PASSWORD'; mysql> GRANT ALL ON neutron_ml2.* TO 'neutron'@'localhost' IDENTIFIED BY 'PASSWORD'; mysql> GRANT ALL ON neutron_ml2.* TO 'neutron'@'%' IDENTIFIED BY 'PASSWORD'; mysql> GRANT ALL ON neutron_ml2.* TO 'neutron'@'localhost' IDENTIFIED BY 'PASSWORD';Copy to Clipboard Copied! Toggle word wrap Toggle overflow Replace PASSWORD with a secure password that will be used to authenticate with the database server as this user.
- Flush the database privileges to ensure that they take effect immediately:mysql> FLUSH PRIVILEGES; mysql> FLUSH PRIVILEGES;Copy to Clipboard Copied! Toggle word wrap Toggle overflow 
- Exit themysqlclient:mysql> quit mysql> quitCopy to Clipboard Copied! Toggle word wrap Toggle overflow 
/etc/neutron/plugin.ini file. It must be updated to point to a valid database server before starting the service. All steps in this procedure must be performed on the server hosting OpenStack Networking, while logged in as the root user.
	Procedure 7.5. Configuring the OpenStack Networking SQL Database Connection
- Set the value of theconnectionconfiguration key.openstack-config --set /etc/neutron/plugin.ini \ DATABASE sql_connection mysql://USER:PASS@IP/DB # openstack-config --set /etc/neutron/plugin.ini \ DATABASE sql_connection mysql://USER:PASS@IP/DBCopy to Clipboard Copied! Toggle word wrap Toggle overflow Replace the following values:- Replace USER with the OpenStack Networking database user name, usuallyneutron.
- Replace PASS with the password of the database user.
- Replace IP with the IP address or host name of the database server.
- Replace DB with the name of the OpenStack Networking database.
 Important The IP address or host name specified in the connection configuration key must match the IP address or host name to which the OpenStack Networking database user was granted access when creating the OpenStack Networking database. Moreover, if the database is hosted locally and you granted permissions to 'localhost' when creating the database, you must enter 'localhost'.
- Upgrade the OpenStack Networking database schema:neutron-db-manage --config-file /usr/share/neutron/neutron-dist.conf \ --config-file /etc/neutron/neutron.conf --config-file /etc/neutron/plugin.ini upgrade head # neutron-db-manage --config-file /usr/share/neutron/neutron-dist.conf \ --config-file /etc/neutron/neutron.conf --config-file /etc/neutron/plugin.ini upgrade headCopy to Clipboard Copied! Toggle word wrap Toggle overflow 
7.2.4. Create the OpenStack Networking Identity Records
services tenant. For more information, see:
	keystonerc_admin file and on which the keystone command-line utility is installed.
	Procedure 7.6. Creating Identity Records for OpenStack Networking
- Set up the shell to access Keystone as the administrative user:source ~/keystonerc_admin # source ~/keystonerc_adminCopy to Clipboard Copied! Toggle word wrap Toggle overflow 
- Create theneutronuser:Copy to Clipboard Copied! Toggle word wrap Toggle overflow Replace PASSWORD with a secure password that will be used by OpenStack Networking when authenticating with the Identity service.
- Link theneutronuser and theadminrole together within the context of theservicestenant:[(keystone_admin)]# keystone user-role-add --user neutron --role admin --tenant services [(keystone_admin)]# keystone user-role-add --user neutron --role admin --tenant servicesCopy to Clipboard Copied! Toggle word wrap Toggle overflow 
- Create theneutronOpenStack Networking service entry:Copy to Clipboard Copied! Toggle word wrap Toggle overflow 
- Create theneutronendpoint entry:Copy to Clipboard Copied! Toggle word wrap Toggle overflow Replace IP with the IP address or host name of the server that will act as the OpenStack Networking node.
7.2.5. Configure OpenStack Networking Authentication
root user.
	Procedure 7.7. Configuring the OpenStack Networking Service to Authenticate through the Identity Service
- Set the authentication strategy tokeystone:openstack-config --set /etc/neutron/neutron.conf \ DEFAULT auth_strategy keystone # openstack-config --set /etc/neutron/neutron.conf \ DEFAULT auth_strategy keystoneCopy to Clipboard Copied! Toggle word wrap Toggle overflow 
- Set the Identity service host that OpenStack Networking must use:openstack-config --set /etc/neutron/neutron.conf \ keystone_authtoken auth_host IP # openstack-config --set /etc/neutron/neutron.conf \ keystone_authtoken auth_host IPCopy to Clipboard Copied! Toggle word wrap Toggle overflow Replace IP with the IP address or host name of the server hosting the Identity service.
- Set OpenStack Networking to authenticate as the correct tenant:openstack-config --set /etc/neutron/neutron.conf \ keystone_authtoken admin_tenant_name services # openstack-config --set /etc/neutron/neutron.conf \ keystone_authtoken admin_tenant_name servicesCopy to Clipboard Copied! Toggle word wrap Toggle overflow Replace services with the name of the tenant created for the use of OpenStack Networking. Examples in this guide useservices.
- Set OpenStack Networking to authenticate using theneutronadministrative user account:openstack-config --set /etc/neutron/neutron.conf \ keystone_authtoken admin_user neutron # openstack-config --set /etc/neutron/neutron.conf \ keystone_authtoken admin_user neutronCopy to Clipboard Copied! Toggle word wrap Toggle overflow 
- Set OpenStack Networking to use the correctneutronadministrative user account password:openstack-config --set /etc/neutron/neutron.conf \ keystone_authtoken admin_password PASSWORD # openstack-config --set /etc/neutron/neutron.conf \ keystone_authtoken admin_password PASSWORDCopy to Clipboard Copied! Toggle word wrap Toggle overflow Replace PASSWORD with the password set when theneutronuser was created.
9696. The firewall on the OpenStack Networking node must be configured to allow network traffic on this port. All steps in this procedure must be performed on the server hosting OpenStack Networking, while logged in as the root user.
	Procedure 7.8. Configuring the Firewall to Allow OpenStack Networking Traffic
- Open the/etc/sysconfig/iptablesfile in a text editor.
- Add an INPUT rule allowing TCP traffic on port9696. The new rule must appear before any INPUT rules that REJECT traffic:-A INPUT -p tcp -m multiport --dports 9696 -j ACCEPT -A INPUT -p tcp -m multiport --dports 9696 -j ACCEPTCopy to Clipboard Copied! Toggle word wrap Toggle overflow 
- Save the changes to the/etc/sysconfig/iptablesfile.
- Restart theiptablesservice to ensure that the change takes effect:systemctl restart iptables.service # systemctl restart iptables.serviceCopy to Clipboard Copied! Toggle word wrap Toggle overflow 
root user.
			Procedure 7.9. Configuring the OpenStack Networking Service to use the RabbitMQ Message Broker
- Set RabbitMQ as the RPC back end:openstack-config --set /etc/neutron/neutron.conf \ DEFAULT rpc_backend neutron.openstack.common.rpc.impl_kombu # openstack-config --set /etc/neutron/neutron.conf \ DEFAULT rpc_backend neutron.openstack.common.rpc.impl_kombuCopy to Clipboard Copied! Toggle word wrap Toggle overflow 
- Set OpenStack Networking to connect to the RabbitMQ host:openstack-config --set /etc/neutron/neutron.conf \ DEFAULT rabbit_host RABBITMQ_HOST # openstack-config --set /etc/neutron/neutron.conf \ DEFAULT rabbit_host RABBITMQ_HOSTCopy to Clipboard Copied! Toggle word wrap Toggle overflow Replace RABBITMQ_HOST with the IP address or host name of the message broker.
- Set the message broker port to5672:openstack-config --set /etc/neutron/neutron.conf \ DEFAULT rabbit_port 5672 # openstack-config --set /etc/neutron/neutron.conf \ DEFAULT rabbit_port 5672Copy to Clipboard Copied! Toggle word wrap Toggle overflow 
- Set the RabbitMQ user name and password created for OpenStack Networking when RabbitMQ was configured:openstack-config --set /etc/neutron/neutron.conf \ DEFAULT rabbit_userid neutron openstack-config --set /etc/neutron/neutron.conf \ DEFAULT rabbit_password NEUTRON_PASS # openstack-config --set /etc/neutron/neutron.conf \ DEFAULT rabbit_userid neutron # openstack-config --set /etc/neutron/neutron.conf \ DEFAULT rabbit_password NEUTRON_PASSCopy to Clipboard Copied! Toggle word wrap Toggle overflow Replaceneutronand NEUTRON_PASS with the RabbitMQ user name and password created for OpenStack Networking.
- When RabbitMQ was launched, theneutronuser was granted read and write permissions to all resources: specifically, through the virtual host/. Configure the Networking service to connect to this virtual host:openstack-config --set /etc/neutron/neutron.conf \ DEFAULT rabbit_virtual_host / # openstack-config --set /etc/neutron/neutron.conf \ DEFAULT rabbit_virtual_host /Copy to Clipboard Copied! Toggle word wrap Toggle overflow 
Procedure 7.10. Enabling SSL Communication Between OpenStack Networking and the RabbitMQ Message Broker
- Enable SSL communication with the message broker:Copy to Clipboard Copied! Toggle word wrap Toggle overflow Replace the following values:- Replace /path/to/client.crt with the absolute path to the exported client certificate.
- Replace /path/to/clientkeyfile.key with the absolute path to the exported client key file.
 
- If your certificates were signed by a third-party Certificate Authority (CA), you must also run the following command:openstack-config --set /etc/neutron/neutron.conf \ DEFAULT kombu_ssl_ca_certs /path/to/ca.crt # openstack-config --set /etc/neutron/neutron.conf \ DEFAULT kombu_ssl_ca_certs /path/to/ca.crtCopy to Clipboard Copied! Toggle word wrap Toggle overflow Replace /path/to/ca.crt with the absolute path to the CA file provided by the third-party CA (see Section 2.3.4, “Enable SSL on the RabbitMQ Message Broker” for more information).
Procedure 7.11. Configuring OpenStack Networking to Communicate with the Compute Service
- Set OpenStack Networking to connect to the Compute controller node:openstack-config --set /etc/neutron/neutron.conf \ DEFAULT nova_url http://CONTROLLER_IP:8774/v2 # openstack-config --set /etc/neutron/neutron.conf \ DEFAULT nova_url http://CONTROLLER_IP:8774/v2Copy to Clipboard Copied! Toggle word wrap Toggle overflow Replace CONTROLLER_IP with the IP address or host name of the Compute controller node.
- Set the user name, password, and tenant for thenovauser:Copy to Clipboard Copied! Toggle word wrap Toggle overflow Replace TENANT_ID with the unique identifier of the tenant created for the use of the Compute service. Replace PASSWORD with the password set when thenovauser was created.
- Set OpenStack Networking to connect to the Compute controller node in an administrative context:openstack-config --set /etc/neutron/neutron.conf \ DEFAULT nova_admin_auth_url http://CONTROLLER_IP:35357/v2.0 # openstack-config --set /etc/neutron/neutron.conf \ DEFAULT nova_admin_auth_url http://CONTROLLER_IP:35357/v2.0Copy to Clipboard Copied! Toggle word wrap Toggle overflow Replace CONTROLLER_IP with the IP address or host name of the Compute controller node.
- Set OpenStack Networking to use the correct region for the Compute controller node:openstack-config --set /etc/neutron/neutron.conf \ DEFAULT nova_region_name RegionOne # openstack-config --set /etc/neutron/neutron.conf \ DEFAULT nova_region_name RegionOneCopy to Clipboard Copied! Toggle word wrap Toggle overflow 
7.2.10. Launch OpenStack Networking
neutron-server service and configure it to start at boot time:
	systemctl start neutron-server.service systemctl enable neutron-server.service
# systemctl start neutron-server.service
# systemctl enable neutron-server.serviceImportant
force_gateway_on_subnet configuration key to True in the /etc/neutron/neutron.conf file.