Description of problem: When using Packstack to install Openstack it runs iptables to allow traffic between Network nodes and compute nodes but not between compute nodes. Staypuft, on the other hand opens port 4789 without restrictions. Version-Release number of selected component (if applicable): RHEL7.0 How reproducible: Steps to Reproduce: 1.After installation run iptables -S |grep 4789 (For VXLAN) Or iptables -S|grep -i gre (For GRE) 2. Verify that there are rules just between the Network nodes and the compute nodes 3. Actual results: As described above. Expected results: When tunnelling is enabled there should be rules to allow tunnelled traffic between all the nodes in the cloud. Additional info:
this bug is fixed in the latest version
Verified VXLAN packstack Kilo 2015.1.dev1589.g1d6372f
Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory, and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. https://access.redhat.com/errata/RHEA-2015:1548