Bug 1073965

Summary: iptables rules are not applied at the end of all-in-one installation
Product: [Retired] oVirt Reporter: Dan Kenigsberg <danken>
Component: ovirt-engine-coreAssignee: Sandro Bonazzola <sbonazzo>
Status: CLOSED INSUFFICIENT_DATA QA Contact: Pavel Stehlik <pstehlik>
Severity: high Docs Contact:
Priority: high    
Version: 3.4CC: acathrow, danken, gklein, iheim, pkliczew, sbonazzo, yeylon
Target Milestone: ---   
Target Release: 3.4.1   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard: integration
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: 1073456 Environment:
Last Closed: 2014-04-17 13:38:42 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description Dan Kenigsberg 2014-03-07 15:05:34 UTC
As reported by Piotr Kliczewski http://lists.ovirt.org/pipermail/users/2014-March/022186.html as well, after installing an all-in-one host, I was unable to connect to VMs over spice until doing

  service iptables restart

ovirt-engine-setup-plugin-allinone-3.4.0-0.12.master.20140228075627.el6.noarch
ovirt-engine-setup-3.4.0-0.12.master.20140228075627.el6.noarch

Comment 1 Sandro Bonazzola 2014-03-13 11:47:06 UTC
Trying to reproduce: http://ur1.ca/gugmq

the only change after service iptables restart is:
-:OUTPUT ACCEPT [8375:4438221]
+:OUTPUT ACCEPT [57:10791]

ovirt-engine-setup-plugin-websocket-proxy-3.4.0-0.13.rc.fc19.noarch
ovirt-engine-setup-plugin-ovirt-engine-common-3.4.0-0.13.rc.fc19.noarch
ovirt-engine-setup-plugin-allinone-3.4.0-0.13.rc.fc19.noarch
ovirt-engine-setup-plugin-ovirt-engine-3.4.0-0.13.rc.fc19.noarch
ovirt-engine-setup-base-3.4.0-0.13.rc.fc19.noarch
ovirt-engine-setup-3.4.0-0.13.rc.fc19.noarch

Dan, can you reproduce this?

Comment 2 Dan Kenigsberg 2014-04-08 09:59:01 UTC
I must admit that I did not try. Piotr, do you have more information?

Sandro, have you started with a fresh EL6 installation, where spice/vnc ports are closed?

Comment 3 Sandro Bonazzola 2014-04-17 13:38:42 UTC
Please reopen if you can reproduce.
In that case, please attach /var/log/ovirt-engine directory content and iptables-save output before and after service iptables restart.
Thanks,