Bug 1129498
Summary: | [doc] Capsule Pre-req section: group iptables commands together for faster copy-paste | ||
---|---|---|---|
Product: | Red Hat Satellite | Reporter: | Xixi <xdmoon> |
Component: | Docs Install Guide | Assignee: | Peter Ondrejka <pondrejk> |
Status: | CLOSED CURRENTRELEASE | QA Contact: | Tahlia Richardson <trichard> |
Severity: | medium | Docs Contact: | |
Priority: | medium | ||
Version: | 6.0.3 | CC: | daobrien, hhudgeon, mosvald, pmoravec |
Target Milestone: | Unspecified | ||
Target Release: | Unused | ||
Hardware: | Unspecified | ||
OS: | Unspecified | ||
Whiteboard: | |||
Fixed In Version: | Doc Type: | Bug Fix | |
Doc Text: | Story Points: | --- | |
Clone Of: | Environment: | ||
Last Closed: | 2015-07-27 08:51:11 UTC | Type: | Bug |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: | |||
Bug Depends On: | |||
Bug Blocks: | 1115190 |
Description
Xixi
2014-08-13 00:14:40 UTC
Since this issue was entered in Red Hat Bugzilla, the release flag has been set to ? to ensure that it is properly evaluated for this release. There is a typo in first iptables command, in Satellite6 installation: # iptables -I INPUT -m state --state NEW -p tcp --dport 443 -j ACCEPT \ && -I INPUT -m state --state NEW -p tcp --dport 5671 -j ACCEPT \ .. (see missing "iptables" command on 2nd line). Capsule server installation seems fine. Could be one another change done? (please disregard it if you see it as ridiculous) Now the commands end with: .. && iptables -I INPUT -m state --state NEW -p tcp --dport 8080 -j ACCEPT \ # iptables-save > /etc/sysconfig/iptables The whole text and also '\' at the end of the last-but-one line suggest to grab whole text - including the latest line(!) - to clipboard and execute. That would mean "iptables-save" command wont be performed, as it is commented out by "# " (that was meant as root prompt). So I suggest replacing "#" by "&&" as well here. The same applies both to Satellite and also Capsule prerequisites. Thanks for consideration. (I already saw one customer with the default too-restrictive firewall after Sat6 "installed" and I suspect it could be due to this) (In reply to Pavel Moravec from comment #13) > Could be one another change done? (please disregard it if you see it as > ridiculous) > > Now the commands end with: > .. > && iptables -I INPUT -m state --state NEW -p tcp --dport 8080 -j ACCEPT \ > # iptables-save > /etc/sysconfig/iptables > > The whole text and also '\' at the end of the last-but-one line suggest to > grab whole text - including the latest line(!) - to clipboard and execute. > > That would mean "iptables-save" command wont be performed, as it is > commented out by "# " (that was meant as root prompt). > Yes, that's a mistake, sorry :-( > So I suggest replacing "#" by "&&" as well here. > > The same applies both to Satellite and also Capsule prerequisites. > > Thanks for consideration. > > (I already saw one customer with the default too-restrictive firewall after > Sat6 "installed" and I suspect it could be due to this) There's two ways we can fix this. Either: - remove the \ from last iptables line before "iptables-save" and run the last command separately (I think that's how it was intended), or - remove the # from the last line and replace it with && as you suggest. If ppl are copy/pasting the whole lot then the latter is probably the better solution. I'd like to assign this to Athene because she's working on this book atm. Just need to do a quick find/replace; I think there are three instances of this type throughout the book. Thanks for picking this up. Since this issue was entered in Red Hat Bugzilla, the release flag has been set to ? to ensure that it is properly evaluated for this release. Changed as per request: http://file.bne.redhat.com/~achan/Satellite_61/html-single/#form-Red_Hat_Satellite-Installation_Guide-Prerequisites-Required_Network_Ports http://file.bne.redhat.com/~achan/Satellite_61/html-single/#sect-Red_Hat_Satellite-Installation_Guide-Red_Hat_Satellite_Capsule_Server_Prerequisites-Required_Network_Ports All # tags on the Capsule Required Network Ports Section and Server Required Network Ports section have been removed. |