undercloud : firewall rules not persisted accross reboot
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
tripleo |
Fix Released
|
High
|
Kevin Carter |
Bug Description
[stack@leafs ~]$ rpm -q openstack-
openstack-
/**
* Install undercloud
*/
[stack@leafs ~]$ sudo iptables -L INPUT -v
Chain INPUT (policy ACCEPT 0 packets, 0 bytes)
pkts bytes target prot opt in out source destination
203K 50M neutron-
468K 104M ACCEPT all -- any any anywhere anywhere /* 000 accept related established rules ipv4 */ ctstate RELATED,ESTABLISHED
0 0 ACCEPT icmp -- any any anywhere anywhere /* 001 accept all icmp ipv4 */ ctstate NEW
16267 976K ACCEPT all -- lo any anywhere anywhere /* 002 accept all to lo interface ipv4 */ ctstate NEW
0 0 ACCEPT tcp -- any any 172.20.0.0/26 anywhere tcp dpt:ssh /* 003 accept ssh from ctlplane subnet 172.20.0.1/26 ipv4 */ ctstate NEW
0 0 ACCEPT udp -- any any anywhere anywhere udp dpt:ntp /* 105 ntp ipv4 */ ctstate NEW
0 0 ACCEPT vrrp -- any any anywhere anywhere /* 106 keepalived vrrp ipv4 */ ctstate NEW
0 0 ACCEPT vrrp -- any any anywhere anywhere /* 106 neutron_l3 vrrp ipv4 */ ctstate NEW
0 0 ACCEPT tcp -- any any anywhere anywhere tcp dpt:snmp-tcp-port /* 107 haproxy stats ipv4 */ ctstate NEW
0 0 ACCEPT tcp -- any any anywhere anywhere tcp dpt:25672 /* 109 rabbitmq ipv4 */ ctstate NEW
0 0 ACCEPT tcp -- any any anywhere anywhere tcp dpt:amqp /* 109 rabbitmq ipv4 */ ctstate NEW
0 0 ACCEPT tcp -- any any anywhere anywhere tcp dpt:epmd /* 109 rabbitmq ipv4 */ ctstate NEW
0 0 ACCEPT tcp -- any any anywhere anywhere tcp dpt:openstack-id /* 111 keystone ipv4 */ ctstate NEW
0 0 ACCEPT tcp -- any any anywhere anywhere tcp dpt:13000 /* 111 keystone ipv4 */ ctstate NEW
14 840 ACCEPT tcp -- any any anywhere anywhere tcp dpt:commplex-main /* 111 keystone ipv4 */ ctstate NEW
0 0 ACCEPT tcp -- any any anywhere anywhere tcp dpt:13292 /* 112 glance_api ipv4 */ ctstate NEW
8 480 ACCEPT tcp -- any any anywhere anywhere tcp dpt:armtechdaemon /* 112 glance_api ipv4 */ ctstate NEW
0 0 ACCEPT tcp -- any any anywhere anywhere tcp dpt:13774 /* 113 nova_api ipv4 */ ctstate NEW
9 540 ACCEPT tcp -- any any anywhere anywhere tcp dpt:8774 /* 113 nova_api ipv4 */ ctstate NEW
0 0 ACCEPT tcp -- any any anywhere anywhere tcp dpt:13888 /* 113 zaqar_api ipv4 */ ctstate NEW
0 0 ACCEPT tcp -- any any anywhere anywhere tcp dpt:hbci /* 113 zaqar_api ipv4 */ ctstate NEW
11 660 ACCEPT tcp -- any any anywhere anywhere tcp dpt:ddi-tcp-1 /* 113 zaqar_api ipv4 */ ctstate NEW
10 600 ACCEPT tcp -- any any anywhere anywhere tcp dpt:cslistener /* 113 zaqar_api ipv4 */ ctstate NEW
0 0 ACCEPT tcp -- any any anywhere anywhere tcp dpt:13696 /* 114 neutron api ipv4 */ ctstate NEW
11 660 ACCEPT tcp -- any any anywhere anywhere tcp dpt:9696 /* 114 neutron api ipv4 */ ctstate NEW
0 0 ACCEPT udp -- any any anywhere anywhere udp dpt:bootps /* 115 neutron dhcp input ipv4 */ ctstate NEW
0 0 ACCEPT udp -- any any anywhere anywhere udp dpt:4789 /* 118 neutron vxlan networks ipv4 */ ctstate NEW
0 0 ACCEPT tcp -- any any anywhere anywhere tcp dpt:websm /* 119 novajoin ipv4 */ ctstate NEW
1 60 ACCEPT tcp -- any any 172.20.0.0/26 anywhere tcp dpt:memcache /* 121 memcached 172.20.0.1/26 ipv4 */ ctstate NEW
0 0 ACCEPT tcp -- any any anywhere anywhere tcp dpt:13808 /* 122 swift proxy ipv4 */ ctstate NEW
19 1140 ACCEPT tcp -- any any anywhere anywhere tcp dpt:webcache /* 122 swift proxy ipv4 */ ctstate NEW
0 0 ACCEPT tcp -- any any anywhere anywhere tcp dpt:6002 /* 123 swift storage ipv4 */ ctstate NEW
0 0 ACCEPT tcp -- any any anywhere anywhere tcp dpt:6001 /* 123 swift storage ipv4 */ ctstate NEW
0 0 ACCEPT tcp -- any any anywhere anywhere tcp dpt:x11 /* 123 swift storage ipv4 */ ctstate NEW
0 0 ACCEPT tcp -- any any anywhere anywhere tcp dpt:rsync /* 123 swift storage ipv4 */ ctstate NEW
0 0 ACCEPT udp -- any any 172.20.0.0/26 anywhere udp dpt:snmp /* 124 snmp 172.20.0.1/26 ipv4 */ ctstate NEW
0 0 ACCEPT tcp -- any any anywhere anywhere tcp dpt:13004 /* 125 heat_api ipv4 */ ctstate NEW
22 1320 ACCEPT tcp -- any any anywhere anywhere tcp dpt:8004 /* 125 heat_api ipv4 */ ctstate NEW
1 60 ACCEPT tcp -- any any anywhere anywhere tcp dpt:13385 /* 133 ironic api ipv4 */ ctstate NEW
29 1740 ACCEPT tcp -- any any anywhere anywhere tcp dpt:6385 /* 133 ironic api ipv4 */ ctstate NEW
0 0 ACCEPT tcp -- any any anywhere anywhere tcp dpt:13989 /* 133 mistral ipv4 */ ctstate NEW
22 1320 ACCEPT tcp -- any any anywhere anywhere tcp dpt:sunwebadmins /* 133 mistral ipv4 */ ctstate NEW
0 0 ACCEPT udp -- any any anywhere anywhere udp dpt:tftp /* 134 ironic conductor TFTP ipv4 */ ctstate NEW
1 60 ACCEPT tcp -- any any anywhere anywhere tcp dpt:radan-http /* 135 ironic conductor HTTP ipv4 */ ctstate NEW
0 0 ACCEPT gre -- any any anywhere anywhere /* 136 neutron gre networks ipv4 */
26 1560 ACCEPT tcp -- any any anywhere anywhere tcp dpt:mmcc /* 137 ironic-inspector ipv4 */ ctstate NEW
0 0 ACCEPT udp -- any any anywhere anywhere udp dpt:bootps /* 137 ironic-inspector dhcp input ipv4 */ ctstate NEW
0 0 ACCEPT tcp -- any any anywhere anywhere tcp dpt:13778 /* 138 placement ipv4 */ ctstate NEW
34 2040 ACCEPT tcp -- any any anywhere anywhere tcp dpt:8778 /* 138 placement ipv4 */ ctstate NEW
0 0 ACCEPT tcp -- any any anywhere anywhere tcp dpt:13787 /* 155 docker-registry ipv4 */ ctstate NEW
0 0 ACCEPT tcp -- any any anywhere anywhere tcp dpt:msgsrvr /* 155 docker-registry ipv4 */ ctstate NEW
360 23304 LOG all -- any any anywhere anywhere /* 998 log all ipv4 */ ctstate NEW limit: avg 20/min burst 15 LOG level warning
412 26424 ACCEPT all -- any any anywhere anywhere /* 999 drop all ipv4 */ ctstate NEW
3179K 598M ACCEPT all -- any any anywhere anywhere ctstate RELATED,ESTABLISHED
122K 7291K ACCEPT all -- lo any anywhere anywhere
865 93594 INPUT_direct all -- any any anywhere anywhere
865 93594 INPUT_ZONES_SOURCE all -- any any anywhere anywhere
865 93594 INPUT_ZONES all -- any any anywhere anywhere
0 0 DROP all -- any any anywhere anywhere ctstate INVALID
864 93534 REJECT all -- any any anywhere anywhere reject-with icmp-host-
/**
* Do a reboot
*/
[stack@leafs ~]$ sudo reboot
Connection to leafs.lab.
Connection to leafs.lab.
[hjensas@hjensas ~]$ ssh <email address hidden>
<email address hidden>'s password:
Last login: Tue Dec 3 17:28:29 2019 from 192.168.122.1
/**
* Firewall rules are gone
*/
[stack@leafs ~]$ sudo iptables -L INPUT -v
Chain INPUT (policy ACCEPT 0 packets, 0 bytes)
pkts bytes target prot opt in out source destination
1854 434K ACCEPT all -- any any anywhere anywhere ctstate RELATED,ESTABLISHED
211 12677 ACCEPT all -- lo any anywhere anywhere
3 204 INPUT_direct all -- any any anywhere anywhere
3 204 INPUT_ZONES_SOURCE all -- any any anywhere anywhere
3 204 INPUT_ZONES all -- any any anywhere anywhere
0 0 DROP all -- any any anywhere anywhere ctstate INVALID
2 144 REJECT all -- any any anywhere anywhere reject-with icmp-host-
Changed in tripleo: | |
assignee: | nobody → Kevin Carter (kevin-carter) |
status: | Triaged → In Progress |
Changed in tripleo: | |
milestone: | ussuri-1 → ussuri-2 |
Reverting commit 50367fbe3563d34 976deb377ed32b6 f26aeca44f fixes the issue.