--- /dev/null
+::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
+: Copyright (c) 2017 Mirantis Inc., Enea AB and others.
+:
+: All rights reserved. This program and the accompanying materials
+: are made available under the terms of the Apache License, Version 2.0
+: which accompanies this distribution, and is available at
+: http://www.apache.org/licenses/LICENSE-2.0
+::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
+From: Alexandru Avadanii <Alexandru.Avadanii@enea.com>
+Date: Mon, 1 Jan 2018 17:06:59 +0100
+Subject: [PATCH] Add proxy node management network VIP
+
+Signed-off-by: Alexandru Avadanii <Alexandru.Avadanii@enea.com>
+---
+ config/installers/fuel/pod_config.yml.j2 | 1 +
+ 1 file changed, 1 insertion(+)
+
+diff --git a/config/installers/fuel/pod_config.yml.j2 b/config/installers/fuel/pod_config.yml.j2
+index f380535..2d0cdee 100644
+--- a/config/installers/fuel/pod_config.yml.j2
++++ b/config/installers/fuel/pod_config.yml.j2
+@@ -61,6 +61,7 @@ parameters:
+     opnfv_openstack_proxy_address: {{ net_public | ipaddr_index('103') }}
+     opnfv_openstack_proxy_node01_address: {{ net_public | ipaddr_index('104') }}
+     opnfv_openstack_proxy_node02_address: {{ net_public | ipaddr_index('105') }}
++    opnfv_openstack_proxy_control_address: {{ net_mgmt | ipaddr_index('103') }}
+     opnfv_openstack_proxy_node01_control_address: {{ net_mgmt | ipaddr_index('104') }}
+     opnfv_openstack_proxy_node02_control_address: {{ net_mgmt | ipaddr_index('105') }}
+     opnfv_openstack_control_address: {{ net_mgmt | ipaddr_index('10') }}
 
 The v3 API should be used instead.
 
 Change-Id: I7e9a1b180f4e0ddb24ec72ed9f08c9e2580c7897
+---
+ keystone/client/single.yml | 2 +-
+ 1 file changed, 1 insertion(+), 1 deletion(-)
 
 diff --git a/keystone/client/single.yml b/keystone/client/single.yml
-index ebf5b5ff..80077105 100644
+index ebf5b5f..8007710 100644
 --- a/keystone/client/single.yml
 +++ b/keystone/client/single.yml
 @@ -4,7 +4,7 @@ classes:
 
     opnfv_openstack_proxy_address: 172.30.10.103
     opnfv_openstack_proxy_node01_address: 172.30.10.104
     opnfv_openstack_proxy_node02_address: 172.30.10.105
+    opnfv_openstack_proxy_control_address: 10.167.4.103
     opnfv_openstack_proxy_node01_control_address: 10.167.4.104
     opnfv_openstack_proxy_node02_control_address: 10.167.4.105
     opnfv_openstack_control_address: 10.167.4.10
 
     openstack_version: pike
 
     # openstack service addresses
+    openstack_proxy_control_address: ${_param:opnfv_openstack_proxy_control_address}
     openstack_proxy_node01_control_address: ${_param:opnfv_openstack_proxy_node01_control_address}
     openstack_proxy_node02_control_address: ${_param:opnfv_openstack_proxy_node02_control_address}
     openstack_proxy_address: ${_param:opnfv_openstack_proxy_address}
     network:
       host:
         prx:
-          address: ${_param:openstack_proxy_address}
+          address: ${_param:openstack_proxy_control_address}
           names:
             - ${_param:openstack_proxy_hostname}
             - ${_param:openstack_proxy_hostname}.${_param:cluster_domain}
 
   - system.salt.minion.cert.proxy
   - system.sphinx.server.doc.reclass
   - service.keepalived.cluster.single
+  - system.keepalived.cluster.instance.openstack_web_public_vip
 parameters:
   _param:
-    keepalived_vip_interface: ${_param:single_nic}
+    cluster_vip_address: ${_param:openstack_proxy_address}
+    keepalived_openstack_web_public_vip_address: ${_param:cluster_vip_address}
+    keepalived_openstack_web_public_vip_interface: ${_param:single_nic}
+    keepalived_vip_address: ${_param:openstack_proxy_control_address}
+    keepalived_vip_interface: ${_param:control_nic}
     keepalived_vip_virtual_router_id: 240
     nginx_proxy_ssl:
       enabled: true
       authority: ${_param:salt_minion_ca_authority}
       engine: salt
       mode: secure
-    cluster_vip_address: ${_param:openstack_proxy_address}
     salt_minion_ca_host: cfg01.${_param:cluster_domain}
   linux:
     system: