Bug 1302370 - [Documentation] Firewall error when appliance is connected to multiple networks
[Documentation] Firewall error when appliance is connected to multiple networks
Status: NEW
Product: Red Hat CloudForms Management Engine
Classification: Red Hat
Component: Documentation (Show other bugs)
5.5.0
Unspecified Unspecified
high Severity high
: GA
: cfme-future
Assigned To: Red Hat CloudForms Documentation
Red Hat CloudForms Documentation
doc
:
: 1302369 (view as bug list)
Depends On:
Blocks:
  Show dependency treegraph
 
Reported: 2016-01-27 10:59 EST by Sergio Ocon
Modified: 2017-10-19 01:16 EDT (History)
7 users (show)

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Cause: When you install CF 5 in RHEV and you are using more than one network, the default firewall is configured for eth0 and does not take into account those multiple networks Consequence: Firewall error when appliance is connected to multiple networks Fix: Steps to add the new nic to the manageiq firewall zone: 1- Add new networki (management network), assuming eth1 2- Log into the appliance and add the new interface to the manageiq zone using command: firewall-cmd --zone=manageiq --add-interface eth1 3- Now the new nic, eth1, has been added to the manageiq firewall zone: firewall-cmd --list-all Result:
Story Points: ---
Clone Of:
Environment:
Last Closed:
Type: Bug
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)

  None (edit)
Description Sergio Ocon 2016-01-27 10:59:47 EST
Description of problem:
When you install CF 5 in RHEV and you are using more than one network, the default firewall is configured for eth0 and does not take into account those multiple networks

Version-Release number of selected component (if applicable):
5.5.0.13.20151201120956_653c0d4 

How reproducible:
Tested in a customer

Steps to Reproduce:
1. Import the appliance with eth0
2. Add new network (management network)
3. Connection to RHEV does not refresh, it is stuck when you refresh states

Actual results:
Data is not received unless you disable firewall

Expected results:
Firewall is configured in the appliance when executing IP configuration to allow connection

Additional info:
Customer is using a production environment where appliance is connecting using eth0 (production network), but the manager is connected through a different environment (RHEV-M is in another VLAN that the production network)
When you add eth1 you need to disable firewall to make it work.
Comment 3 Shveta 2016-02-01 16:32:20 EST
Assigning to add test case
Comment 4 Joe Vlcek 2016-02-03 16:20:13 EST
*** Bug 1302369 has been marked as a duplicate of this bug. ***
Comment 5 Joe Vlcek 2016-02-03 16:45:46 EST
Can you please try to add the new interface to the manageiq firewall zone?

Steps to add the new nic to the manageiq firewall zone:
1- Add new networki (management network), assuming eth1

2- Log into the appliance and add the new interface to the manageiq zone using command:
      firewall-cmd --zone=manageiq --add-interface eth1

3- Now the new nic, eth1, has been added to the manageiq firewall zone:  
      firewall-cmd --list-all

Please let us know if this solves the issue.
Comment 7 Sergio Ocon 2016-02-11 02:28:35 EST
Customer has tested the solution and and the problem has been solved.
This case can be closed

Thanks,
Sergio
Comment 8 Lucy Bopf 2016-05-25 22:26:28 EDT
Moving to NEW to be reviewed as the schedule allows.

Note You need to log in before you can comment on or make changes to this bug.