Red Hat Bugzilla – Bug 1141739
[Doc] firewalld needs to be disabled on network and compute nodes when using ovs
Last modified: 2015-02-16 20:01:31 EST
This section should also ask for firewalld being disabled, as we do for networkmanager for now. https://access.redhat.com/documentation/en-US/Red_Hat_Enterprise_Linux_OpenStack_Platform/5/html/Installation_and_Configuration_Guide/sect-Common_Networking_Configuration.html#Configuring_the_Firewall4 It should be disabled for either compute or network nodes. It will create behavior like the one you're seeing in the compute nodes (ovs agent reloads iptables manually via iptables-save iptables-restore), and the same for network node. For the API servers it should be safe to use firewalld as long as all the API ports, and RPC ports are allowed as necessary.
Ready for QA once package is completed.
Peer review comments: In 7.4.2. Disable firewalld: Suggest replacing "Disable the firewalld service for Compute and Networking (neutron) nodes running..." with "Disable the firewalld service for Compute and OpenStack Networking nodes running..." Checked doc for firewall-cmd commands that might not have been removed, none found. OK.
Fixed. Ready for QA once package has been created.
Setting to verified.