Description of problem: If automatic firewall configuration is chosen, NFS server ports are closed off. This causes problems for NFS storage domains. Version-Release number of selected component (if applicable): 3.4 How reproducible: Every time Steps to Reproduce: 1. On a 3.3 RHEV-M system acting as a NFS server for storage domain 2. Upgrade RHEV-M to 3.4, taking defaults 3. Try to access NFS storage domain from hypervisor Actual results: Timeout Expected results: Access to storage domain Additional info: This could be viewed as a bug or as an RFE. In my case, I encountered it on an ISO domain.
Diagnosing the error may be difficult. Once you do, an easy workaround is to add the appropriate iptables rules after the fact.
sandro - please verify for: 1. clean install 3.3 with ISO domain and firewall, check rules, upgrade to 3.4 (with reconfigure firewall), check rules. 2. same from 3.4 to 3.5...
Simone is taking care of trying to reproduce the issue. Moving the needinfo on him.
Reproduced. Upgrading from 3.3.4 to 3.4.2 it loses this rules: ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 state NEW tcp dpt:6100 ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 state NEW tcp dpt:111 ACCEPT udp -- 0.0.0.0/0 0.0.0.0/0 state NEW udp dpt:111 ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 state NEW tcp dpt:662 ACCEPT udp -- 0.0.0.0/0 0.0.0.0/0 state NEW udp dpt:662 ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 state NEW tcp dpt:875 ACCEPT udp -- 0.0.0.0/0 0.0.0.0/0 state NEW udp dpt:875 ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 state NEW tcp dpt:892 ACCEPT udp -- 0.0.0.0/0 0.0.0.0/0 state NEW udp dpt:892 ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 state NEW tcp dpt:2049 ACCEPT udp -- 0.0.0.0/0 0.0.0.0/0 state NEW udp dpt:32769 ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 state NEW tcp dpt:32803
Hey, Simone. I am using recent master rpms, and I have some problems with running engine-setup, it fails with the following message (pretty much default on all options): [ ERROR ] Failed to execute stage 'Setup validation': 'str' object has no attribute 'review_config' And this is the trace from the log: 2014-09-28 14:15:36 DEBUG otopi.context context._executeMethod:138 Stage validation METHOD otopi.plugins.ovirt_engine_setup.base.network.firewall_manager.Plugin._review_config 2014-09-28 14:15:36 DEBUG otopi.context context._executeMethod:152 method exception Traceback (most recent call last): File "/usr/lib/python2.6/site-packages/otopi/context.py", line 142, in _executeMethod method['method']() File "/usr/share/ovirt-engine/setup/bin/../plugins/ovirt-engine-setup/base/network/firewall_manager.py", line 247, in _review_config manager.review_config() AttributeError: 'str' object has no attribute 'review_config' 2014-09-28 14:15:36 ERROR otopi.context context._executeMethod:161 Failed to execute stage 'Setup validation': 'str' object has no attribute 'review_config' Could it be somehow related to http://gerrit.ovirt.org/#/c/33085/ ? Thanks
Yes, it's a fault of mine. I added a patch to address that case. Thanks.
*** Bug 1071306 has been marked as a duplicate of this bug. ***
Moving this to Scott.
Added to 3.4.4 tracker
in vt8
Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory, and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. https://rhn.redhat.com/errata/RHSA-2015-0158.html