Bugzilla will be upgraded to version 5.0. The upgrade date is tentatively scheduled for 2 December 2018, pending final testing and feedback.
Bug 1191114 - VXLAN traffic port (4789) and GRE should allowed between all nodes when tunnelling is enabled
VXLAN traffic port (4789) and GRE should allowed between all nodes when tunne...
Status: CLOSED ERRATA
Product: Red Hat OpenStack
Classification: Red Hat
Component: openstack-puppet-modules (Show other bugs)
6.0 (Juno)
Unspecified Unspecified
unspecified Severity medium
: ga
: 7.0 (Kilo)
Assigned To: Ivan Chavero
Itzik Brown
:
Depends On:
Blocks:
  Show dependency treegraph
 
Reported: 2015-02-10 08:32 EST by Itzik Brown
Modified: 2015-08-05 09:21 EDT (History)
4 users (show)

See Also:
Fixed In Version: openstack-packstack-2015.1-0.3.dev1565.gd1211af.el7ost
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2015-08-05 09:21:09 EDT
Type: Bug
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)


External Trackers
Tracker ID Priority Status Summary Last Updated
Red Hat Product Errata RHEA-2015:1548 normal SHIPPED_LIVE Red Hat Enterprise Linux OpenStack Platform Enhancement Advisory 2015-08-05 13:07:06 EDT

  None (edit)
Description Itzik Brown 2015-02-10 08:32:48 EST
Description of problem:
When using Packstack to install Openstack it runs iptables to allow traffic between Network nodes and compute nodes but not between compute nodes.

Staypuft, on the other hand opens port 4789 without restrictions.

Version-Release number of selected component (if applicable):
RHEL7.0

How reproducible:


Steps to Reproduce:
1.After installation run iptables -S |grep 4789 (For VXLAN) Or iptables -S|grep -i gre (For GRE)
2. Verify that there are rules just between the Network nodes and the compute nodes
3.

Actual results:
As described above.

Expected results:
When tunnelling is enabled there should be rules to allow tunnelled traffic between all the nodes in the cloud.

Additional info:
Comment 4 Ivan Chavero 2015-06-19 03:17:57 EDT
this bug is fixed in the latest version
Comment 8 Itzik Brown 2015-07-07 09:39:57 EDT
Verified VXLAN
packstack Kilo 2015.1.dev1589.g1d6372f
Comment 10 errata-xmlrpc 2015-08-05 09:21:09 EDT
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://access.redhat.com/errata/RHEA-2015:1548

Note You need to log in before you can comment on or make changes to this bug.