Bug 193449 - DomU and iptables nat issue
DomU and iptables nat issue
Product: Fedora
Classification: Fedora
Component: kernel-xen (Show other bugs)
i686 Linux
medium Severity medium
: ---
: ---
Assigned To: Xen Maintainance List
Virtualization Bugs
Depends On:
  Show dependency treegraph
Reported: 2006-05-28 18:40 EDT by Steve Schwartz
Modified: 2009-12-14 15:39 EST (History)
1 user (show)

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Last Closed: 2008-02-26 18:08:40 EST
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---

Attachments (Terms of Use)

  None (edit)
Description Steve Schwartz 2006-05-28 18:40:27 EDT
Description of problem:
DomU cannot be reached from wkstn on a nat IP from eth1 which is not bridged.
DomU can be pinged from Dom0 or wkstn.
System setup is simple:
dom0: eth0 has real IP address to internet
dom0: eth1 has nat IP address to internal network
dom0: *nat rule for postrouting
domU: eth0 has real IP address to internet
Domu can be pinged from wkstn and dom0, DomU can ping Dom0 and wkstn
ssh and httpd (only major services setup on domU) see a connection on DomU but
data does not reach the nat IP address the request came from.
running: iptables -t nat -L -nv on domU corrects this.
Once list command above is run, everything works properly.
If iptables service is restarted, it stops working again.

Version-Release number of selected component (if applicable):
Dom0: 2.6.16-1.2122_FC5xen0
DomU: 2.6.16-1.2122_FC5xenU
iptables: iptables-1.3.5-1.2

How reproducible:

Steps to Reproduce:
1. setup server and workstation as listed above.
2. run: service iptables restart
3. try to browse or ssh from wkstn to domU, it doesn't fail to connect, it just
sits waiting for a response.
4. on domU run: iptables -t nat -L -nv
5. repeat step 3 response from domU is received properly.
Actual results:
when iptables is restarted on domU, services cannot be connected to from a wkstn
with a nat ip address on a non bridged eth1.
Once iptables -t nat -L -nv is run on domU, all services can be connected to

Expected results:
no communication restricted except based on firewall rules and available services.

Additional info:
Comment 1 Red Hat Bugzilla 2007-07-24 21:31:35 EDT
change QA contact
Comment 2 Chris Lalancette 2008-02-26 18:08:40 EST
This report targets FC5, which is now end-of-life.

Please re-test against Fedora 7 or later, and if the issue persists, open a new bug.


Note You need to log in before you can comment on or make changes to this bug.