Note: This bug is displayed in read-only format because the product is no longer active in Red Hat Bugzilla.
This project is now read‑only. Starting Monday, February 2, please use https://ibm-ceph.atlassian.net/ for all bug tracking management.

Bug 1496812

Summary: Need to "firewall-cmd --zone=public --add-port=6800-7300/tcp" for ceph-mgr ports
Product: [Red Hat Storage] Red Hat Ceph Storage Reporter: John Wilkins <jowilkin>
Component: DocumentationAssignee: Bara Ancincova <bancinco>
Status: CLOSED CURRENTRELEASE QA Contact: Parikshith <pbyregow>
Severity: urgent Docs Contact:
Priority: urgent    
Version: 3.0CC: asriram, hnallurv, kdreyer
Target Milestone: rc   
Target Release: 3.0   
Hardware: Unspecified   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2017-12-26 03:39:01 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On:    
Bug Blocks: 1496210    

Description John Wilkins 2017-09-28 13:05:12 UTC
Description of problem:

The documentation does not indicate that opening ports 6800-7300 is required on ceph-mgr nodes, which are usually monitor nodes.


How reproducible:

100%

Steps to Reproduce:
1. Follow installation docs
2. See if cluster maintains HEALTH_OK 


Actual results:

[root@rhel-mon ~]# ceph health
HEALTH_WARN Reduced data availability: 160 pgs inactive; Degraded data redundancy: 160 pgs unclean


Expected results:

[root@rhel-mon ~]# ceph health
HEALTH_OK


Additional info:

Also need some info for troubleshooting.

Comment 2 Ken Dreyer (Red Hat) 2017-09-28 15:47:51 UTC
FYI, firewalld in RHEL 7.3 and newer ships "ceph" and "ceph-mon" service definitions, so users don't have to remember the exact port numbers.

  $ rpm -ql firewalld | grep ceph
  /usr/lib/firewalld/services/ceph-mon.xml
  /usr/lib/firewalld/services/ceph.xml

  $ cat /usr/lib/firewalld/services/ceph.xml
  <?xml version="1.0" encoding="utf-8"?>
  <service>
    <short>ceph</short>
    <description>Ceph is a distributed object store and file system. Enable this  option to support Ceph's Object Storage Daemons (OSD) or Metadata Server Daemons (MDS).</description>
    <port protocol="tcp" port="6800-7300"/>
  </service>

You can enable the 6800-7300 ports like this:

  firewall-cmd --zone=public --add-service=ceph

Or the Mon port like this:

  firewall-cmd --zone=public --add-service=ceph-mon