Something like: restart node; start the OVS/Linuxbridge agent with iptables firewall enabled; check that no traceback is in the logs; check that br_netfilter kernel module is loaded.
OK, one more step to trigger the error is to actually land an instance on the compute node in question. Without it, the OVS agent will not attempt to configure any iptables rules for ports because there are no ports to configure in the first place.
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.
For information on the advisory, and where to find the updated
files, follow the link below.
If the solution does not work for you, open a new bug report.
https://rhn.redhat.com/errata/RHBA-2016-2988.html