Bug 1027134

Summary: Firewall prevents networking in VMs
Product: [Fedora] Fedora Reporter: Kai Engert (:kaie) (inactive account) <kengert>
Component: firewalldAssignee: Thomas Woerner <twoerner>
Status: CLOSED INSUFFICIENT_DATA QA Contact: Fedora Extras Quality Assurance <extras-qa>
Severity: unspecified Docs Contact:
Priority: unspecified    
Version: 19CC: jpopelka, kengert, twoerner
Target Milestone: ---   
Target Release: ---   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2014-06-10 17:15:15 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description Kai Engert (:kaie) (inactive account) 2013-11-06 08:53:46 UTC
Installed a fresh F19.

Attempted to make use of VMs that I had used on a different system.

Actual behaviour:
VMs couldn't start networking, they were stuck in "connecting"

I didn't think of the defaul firewall as a potential cause.
Once I did, the only obvious remedy was: disable firewall

Questions:
(a) Could firewalld allow communication with local VMs by default?
(b) If (a) => no, then:
    Could there be an easily discoverable fix to allow the user
    to allow such communication, without having to disable the firewall?

Comment 1 Thomas Woerner 2013-11-29 16:54:54 UTC
What kind of VMs have you been using? Created and set up by libvirt?

Comment 2 Kai Engert (:kaie) (inactive account) 2013-11-29 19:27:56 UTC
Yes, all of them had been created using virt-manager. Linux VMs, RHEL/Fedora.

Comment 3 Thomas Woerner 2013-12-02 11:18:58 UTC
Are there errors in the logs related to libvirt or firewalld?
Is the libvirt configuration modified?

Please attach the output of the iptables-save command.

Comment 4 Kai Engert (:kaie) (inactive account) 2014-06-10 17:15:15 UTC
Looks I didn't have the time to follow up with the requested details :(