I performed a iprules check on an OSP14 deployment. The compute node has the updated rule needed to resolve this issue.
(undercloud) [stack@undercloud-0 ~]$ cat /etc/yum.repos.d/latest-installed
14 -p 2019-06-26.1
(undercloud) [stack@undercloud-0 ~]$ rpm -qa | grep templates
openstack-tripleo-heat-templates-9.3.1-0.20190513171738.el7ost.noarch
(undercloud) [stack@undercloud-0 ~]$ ssh heat-admin.24.9
Warning: Permanently added '192.168.24.9' (ECDSA) to the list of known hosts.
[heat-admin@overcloud-ceph3-0 ~]$ sudo iptables -L
Chain INPUT (policy ACCEPT)
[...]
ACCEPT tcp -- anywhere anywhere multiport dports ssh state NEW /* 003 accept ssh from any ipv4 */
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.
For information on the advisory, and where to find the updated
files, follow the link below.
If the solution does not work for you, open a new bug report.
https://access.redhat.com/errata/RHBA-2019:1672