Red Hat Bugzilla – Bug 1061668
Inconsistent values for remote console ports
Last modified: 2016-01-26 20:59:54 EST
Title: Virtualization Host Firewall Requirements Describe the issue: Table 2.2. "Virtualization Host Firewall Requirements" states that ports 5900-6411 must be open for remote console access, but Example 2.3. "Option Name: IPTablesConfig" on the same page opens ports 5634-6166. Suggestions for improvement: The values should be the same, or the difference between RHEV-H and RHEL hosts should be explicit if there is one. Additional information: Example 2.3 description also states: "Recommended (default) values: Automatically generated by vdsm bootstrap script", this is the only mention of vdsm bootstrap in the install docs (except for hosts uninstalling) and it adds to the confusion when configuring a RHEL host.
Checked port requirements listed in "Virtualization Host Firewall Requirements" (topic 7851). These have been recently updated (in April 2014), and the values mentioned above have been corrected. Both now mention opening ports 5900-6923. The mention of the 'vdsm bootstrap script' has existed in this topic since mid-2012; the potential for confusion had not been previously recognised. I have now removed mention of the script, and the relevant section now simply states, "Recommended (default) values: Automatically generated".
Documentation Link ------------------------------ https://documentation-devel.engineering.redhat.com/site/documentation/en-US/Red_Hat_Enterprise_Virtualization/3.5-Beta/html-single/Administration_Guide/index.html#Virtualization_Host_Firewall_Requirements1 What Changed ------------------------------ The following topic was revised to remove reference to the 'vdsm bootstrap script' from Example A.1. Option Name: IPTablesConfig Virtualization Host Firewall Requirements [7851-681853] Updated revision history: [34613-687019] NVR ------------------------------ Red_Hat_Enterprise_Virtualization-Administration_Guide-3.5-Beta-web-en-US-3.5-5.el6eng Moving to ON_QA.