Bug 240922

Summary: KVM needs ip_forward enabled
Product: [Fedora] Fedora Reporter: Jeremy West <jwest>
Component: libvirtAssignee: Daniel Veillard <veillard>
Status: CLOSED WONTFIX QA Contact:
Severity: high Docs Contact:
Priority: high    
Version: 9CC: briemers, gjansen, jeevanullas, jhutar, libbe, matt_domsch, redhat-bugzilla, simon, sputhenp, virt-maint, xen-maint
Target Milestone: ---   
Target Release: ---   
Hardware: All   
OS: Linux   
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2009-07-14 09:59:37 EDT Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---

Description Jeremy West 2007-05-22 17:24:26 EDT
Description of problem:
The default networking with KVM will not work properly unless ip_foward is
enabled.  There's currently no instruction or prompt to let you know this.

The advanced user is going to take a look at his routing and figure this out,
but the casual user will be left feeling like kvm sucks.  Can we get something
built into virt-manager to enable this?
Comment 1 Deependra Singh Shekhawat 2007-06-11 23:03:24 EDT
Possible solution:
echo "1" > /proc/sys/net/ipv4/ip_forward on Host.

To make things permanent in /etc/sysctl.conf
net.ipv4.ip_forward = 1

This bug remains in Fedora 7 gold release. Do we see any possible permanent
solution other than the ip_forward trick done manually. 

Comment 2 Daniel Berrange 2007-06-12 07:37:54 EDT
The libvirt daemon does  enable ip_forward whenever a virtual network is
created. There is one network defined automatically upon RPM installation, so
libvirt is normally enabling ip_forward right away.

Now the /etc/sysctl.conf file also has an explicit rule to disable ip_forward,
but this file is loaded by the 'network' init script prior to libvirt running so
its not ordinarily a problem. Except that I just discovered NetworkManager's
init script will load sysctl.conf *again* overiding what libvirt changed :-(
Comment 3 Deependra Singh Shekhawat 2007-06-12 13:06:37 EDT

Today I installed the new libvirt 0.2.3 on Fedora 7. And I booted a live cd from
within virt-manager (using KVM). And it booted well also the ip forwarding thing
seem to have worked though I didn't had ip_forward in the host. I was able to
access internet from within the live cd guest ( network.

That means this bug is solved or it means something else ?

Comment 4 Edmond Hui 2007-06-17 18:58:34 EDT
Hi, just want to report that I am seeing the same problem.

After I enable ip_forward in /etc/sysctl.conf and reboot, networking working.

My guest OS is a Win XP SP2.
Comment 5 Simon Karpen 2008-01-19 17:54:07 EST
This problem is still there in Rawhide on 1/19/08 (6 months later). 

At a minimum, virt-manager should pop up a warning that guest networking will
fail without ip_forward set. 
Comment 6 Geert Jansen 2008-04-27 08:36:55 EDT
This problem is still present in the Fedora 9 preview release (27/04/2008),
almost 12 months after the issue was reported.

As this issue is impacting every user that is running KVM this has a high impact
and really should be fixed asap.
Comment 7 Peter Gordon 2008-05-06 20:36:23 EDT
*** Bug 371571 has been marked as a duplicate of this bug. ***
Comment 8 Bug Zapper 2008-05-13 22:55:55 EDT
Changing version to '9' as part of upcoming Fedora 9 GA.
More information and reason for this action is here:
Comment 9 Bill C. Riemers 2008-09-04 02:21:16 EDT
This is still a problem in Fedora 9.  Although there are also other networking bugs I will report separately.
Comment 10 Bug Zapper 2009-06-09 18:36:59 EDT
This message is a reminder that Fedora 9 is nearing its end of life.
Approximately 30 (thirty) days from now Fedora will stop maintaining
and issuing updates for Fedora 9.  It is Fedora's policy to close all
bug reports from releases that are no longer maintained.  At that time
this bug will be closed as WONTFIX if it remains open with a Fedora 
'version' of '9'.

Package Maintainer: If you wish for this bug to remain open because you
plan to fix it in a currently maintained version, simply change the 'version' 
to a later Fedora version prior to Fedora 9's end of life.

Bug Reporter: Thank you for reporting this issue and we are sorry that 
we may not be able to fix it before Fedora 9 is end of life.  If you 
would still like to see this bug fixed and are able to reproduce it 
against a later version of Fedora please change the 'version' of this 
bug to the applicable version.  If you are unable to change the version, 
please add a comment here and someone will do it for you.

Although we aim to fix as many bugs as possible during every release's 
lifetime, sometimes those efforts are overtaken by events.  Often a 
more recent Fedora release includes newer upstream software that fixes 
bugs or makes them obsolete.

The process we are following is described here: 
Comment 11 Jan Hutaƙ 2009-06-10 03:07:08 EDT
Hi all. Can you still see this issue? I do not see it now in F10, but I'm not sure if I have configured something in the past of it just started to work.
Comment 12 Geert Jansen 2009-06-10 03:41:00 EDT
I have not seen this bug anymore since F10. Virtual networks set up with virt-manager now work out of the box.
Comment 13 Bug Zapper 2009-07-14 09:59:37 EDT
Fedora 9 changed to end-of-life (EOL) status on 2009-07-10. Fedora 9 is 
no longer maintained, which means that it will not receive any further 
security or bug fix updates. As a result we are closing this bug.

If you can reproduce this bug against a currently maintained version of 
Fedora please feel free to reopen this bug against that version.

Thank you for reporting this bug and we are sorry it could not be fixed.