Bug 1073965 - iptables rules are not applied at the end of all-in-one installation
Summary: iptables rules are not applied at the end of all-in-one installation
Keywords:
Status: CLOSED INSUFFICIENT_DATA
Alias: None
Product: oVirt
Classification: Retired
Component: ovirt-engine-core
Version: 3.4
Hardware: Unspecified
OS: Unspecified
high
high
Target Milestone: ---
: 3.4.1
Assignee: Sandro Bonazzola
QA Contact: Pavel Stehlik
URL:
Whiteboard: integration
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2014-03-07 15:05 UTC by Dan Kenigsberg
Modified: 2015-10-05 11:35 UTC (History)
7 users (show)

Fixed In Version:
Clone Of: 1073456
Environment:
Last Closed: 2014-04-17 13:38:42 UTC
oVirt Team: ---
Embargoed:


Attachments (Terms of Use)

Description Dan Kenigsberg 2014-03-07 15:05:34 UTC
As reported by Piotr Kliczewski http://lists.ovirt.org/pipermail/users/2014-March/022186.html as well, after installing an all-in-one host, I was unable to connect to VMs over spice until doing

  service iptables restart

ovirt-engine-setup-plugin-allinone-3.4.0-0.12.master.20140228075627.el6.noarch
ovirt-engine-setup-3.4.0-0.12.master.20140228075627.el6.noarch

Comment 1 Sandro Bonazzola 2014-03-13 11:47:06 UTC
Trying to reproduce: http://ur1.ca/gugmq

the only change after service iptables restart is:
-:OUTPUT ACCEPT [8375:4438221]
+:OUTPUT ACCEPT [57:10791]

ovirt-engine-setup-plugin-websocket-proxy-3.4.0-0.13.rc.fc19.noarch
ovirt-engine-setup-plugin-ovirt-engine-common-3.4.0-0.13.rc.fc19.noarch
ovirt-engine-setup-plugin-allinone-3.4.0-0.13.rc.fc19.noarch
ovirt-engine-setup-plugin-ovirt-engine-3.4.0-0.13.rc.fc19.noarch
ovirt-engine-setup-base-3.4.0-0.13.rc.fc19.noarch
ovirt-engine-setup-3.4.0-0.13.rc.fc19.noarch

Dan, can you reproduce this?

Comment 2 Dan Kenigsberg 2014-04-08 09:59:01 UTC
I must admit that I did not try. Piotr, do you have more information?

Sandro, have you started with a fresh EL6 installation, where spice/vnc ports are closed?

Comment 3 Sandro Bonazzola 2014-04-17 13:38:42 UTC
Please reopen if you can reproduce.
In that case, please attach /var/log/ovirt-engine directory content and iptables-save output before and after service iptables restart.
Thanks,


Note You need to log in before you can comment on or make changes to this bug.