Bugzilla will be upgraded to version 5.0. The upgrade date is tentatively scheduled for 2 December 2018, pending final testing and feedback.
Bug 1489155 - Port 8185 needs to be opened in iptables to allow comunication between networking-odl and ODL via websocket
Port 8185 needs to be opened in iptables to allow comunication between networ...
Status: CLOSED ERRATA
Product: Red Hat OpenStack
Classification: Red Hat
Component: openstack-tripleo-heat-templates (Show other bugs)
12.0 (Pike)
Unspecified Unspecified
urgent Severity high
: beta
: 12.0 (Pike)
Assigned To: Tim Rozet
Itzik Brown
: Triaged
Depends On:
Blocks:
  Show dependency treegraph
 
Reported: 2017-09-06 16:15 EDT by Sai Sindhur Malleni
Modified: 2018-10-18 03:21 EDT (History)
3 users (show)

See Also:
Fixed In Version: openstack-tripleo-heat-templates-7.0.2-0.20171007062244.el7ost.noarch.rpm
Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of:
Environment:
N/A
Last Closed: 2017-12-13 17:05:43 EST
Type: Bug
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)


External Trackers
Tracker ID Priority Status Summary Last Updated
Launchpad 1715484 None None None 2017-09-06 16:26 EDT
OpenStack gerrit 501416 None None None 2017-09-06 16:34 EDT
Red Hat Product Errata RHEA-2017:3462 normal SHIPPED_LIVE Red Hat OpenStack Platform 12.0 Enhancement Advisory 2018-02-15 20:43:25 EST

  None (edit)
Description Sai Sindhur Malleni 2017-09-06 16:15:42 EDT
Description of problem:
In a clustered setup (3 OSP Controllers+3 ODLs ) we are seeing instaces failing to boot and this has been identified to be due to lack of communication between ODL and networking-odl once the neutron port transitions to ACTIVE. More info can be found at https://bugzilla.redhat.com/show_bug.cgi?id=1486917

One of the issues identified was a missing iptables rule for port 8185 over which the websocket communication happens. So, we need Director to setup iptables rules for this port at deploy time.

We are able to manually workaround using:
sudo iptables -I INPUT 15 -p tcp -m multiport --dports 8081,8185 -m state --state NEW -j ACCEPT 

Version-Release number of selected component (if applicable):
OSP 12

How reproducible:
100%

Steps to Reproduce:
1. Deploy clustered OSP +ODL
2. Boot instance
3.

Actual results:
Instance doesn't boot and the neutron port is never set to ACTIVE

Expected results:
Instance boots

Additional info:
Comment 1 Sai Sindhur Malleni 2017-09-06 16:16:14 EDT
The fix needs to go into tripleo-heat-templates/blob/master/puppet/services/opendaylight-api.yaml according to Tim Rozet.
Comment 3 Itzik Brown 2017-11-05 06:55:11 EST
Checked with openstack-tripleo-heat-templates-7.0.3-0.20171023134948.el7ost.noarch

Port 8185 is Open
-A INPUT -p tcp -m multiport --dports 8081,6640,6653,2550,8185 -m state --state NEW -m comment --comment "137 opendaylight api ipv4" -j ACCEPT
Comment 6 errata-xmlrpc 2017-12-13 17:05:43 EST
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://access.redhat.com/errata/RHEA-2017:3462

Note You need to log in before you can comment on or make changes to this bug.