Bugzilla will be upgraded to version 5.0. The upgrade date is tentatively scheduled for 2 December 2018, pending final testing and feedback.
Bug 1141739 - [Doc] firewalld needs to be disabled on network and compute nodes when using ovs
[Doc] firewalld needs to be disabled on network and compute nodes when using ovs
Status: CLOSED CURRENTRELEASE
Product: Red Hat OpenStack
Classification: Red Hat
Component: doc-Installation_and_Configuration_Guide (Show other bugs)
5.0 (RHEL 7)
x86_64 All
high Severity high
: ---
: 5.0 (RHEL 7)
Assigned To: Martin Lopes
Ruediger Landmann
: Documentation, Triaged
Depends On:
Blocks:
  Show dependency treegraph
 
Reported: 2014-09-15 07:03 EDT by Jeff Dexter
Modified: 2015-02-16 20:01 EST (History)
7 users (show)

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2015-02-15 18:49:54 EST
Type: Bug
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)

  None (edit)
Description Jeff Dexter 2014-09-15 07:03:56 EDT
This section should also ask for firewalld being disabled, as we do for networkmanager
for now.

https://access.redhat.com/documentation/en-US/Red_Hat_Enterprise_Linux_OpenStack_Platform/5/html/Installation_and_Configuration_Guide/sect-Common_Networking_Configuration.html#Configuring_the_Firewall4

It should be disabled for either compute or network nodes. It will create
behavior like the one you're seeing in the compute nodes (ovs agent reloads
iptables manually via iptables-save iptables-restore), and the same
for network node.

   For the API servers it should be safe to use firewalld as long as all
the API ports, and RPC ports are allowed as necessary.
Comment 12 Martin Lopes 2014-10-02 00:46:22 EDT
Ready for QA once package is completed.
Comment 14 Bruce Reeler 2014-10-06 23:04:05 EDT
Peer review comments:

In 7.4.2. Disable firewalld:
Suggest replacing
"Disable the firewalld service for Compute and Networking (neutron) nodes running..."
with
"Disable the firewalld service for Compute and OpenStack Networking nodes running..."


Checked doc for firewall-cmd commands that might not have been removed, none found. OK.
Comment 15 Martin Lopes 2014-10-07 00:27:05 EDT
Fixed. Ready for QA once package has been created.
Comment 18 Martin Lopes 2014-10-19 19:11:55 EDT
Setting to verified.

Note You need to log in before you can comment on or make changes to this bug.