Bug 1383803 - Add note about firewall not being set up by Director in "Director Installation" guide
Summary: Add note about firewall not being set up by Director in "Director Installatio...
Keywords:
Status: CLOSED CURRENTRELEASE
Alias: None
Product: Red Hat OpenStack
Classification: Red Hat
Component: documentation
Version: 10.0 (Newton)
Hardware: Unspecified
OS: Unspecified
high
unspecified
Target Milestone: ---
: 10.0 (Newton)
Assignee: Dan Macpherson
QA Contact: RHOS Documentation Team
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2016-10-11 19:37 UTC by Nathan Kinder
Modified: 2018-08-06 05:09 UTC (History)
4 users (show)

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Environment:
Last Closed: 2018-08-06 05:09:24 UTC
Target Upstream Version:


Attachments (Terms of Use)

Description Nathan Kinder 2016-10-11 19:37:56 UTC
The RH-OSP "Director Installation and Usage" guide has an "Important" section that mentions that ports should be restricted to a minimum in the "Networking Requirements" section.  While this is correct, it is probably worth making it very clear that Director does not configure the firewall in a restrictive manner in this same section.

There are more details available in the following comment of the bug that we plan to use for hardening Director in a future RH-OSP release:

    https://bugzilla.redhat.com/show_bug.cgi?id=1227760#c4

Comment 1 Dan Macpherson 2016-10-12 03:07:27 UTC
Just a consideration here: instead of a documentation fix, would it be worth filing an engineering bug for the Undercloud install config to add that firewall rule automatically?

Comment 2 Dan Macpherson 2017-09-20 04:57:48 UTC
Hi Nathan,

Checking my backlog and found this BZ. I checked the overcloud firewall and it seems more restrictive. In /etc/sysconfig/iptables, all firewall rules for OSP services are listed and at the end is the following rule:

-A INPUT -m state --state NEW -m comment --comment "999 drop all ipv4" -j DROP

This should drop any incoming packets that do not satisfy the previous rules.

Just want to check with you, do we still need a note about the firewall?

Comment 3 Dan Macpherson 2018-08-06 05:09:24 UTC
No response for several month on this BZ. Closing it down.


Note You need to log in before you can comment on or make changes to this bug.