MilanHofmann commented on issue #7185:
URL: https://github.com/apache/cloudstack/issues/7185#issuecomment-1433005487

   @weizhouapache 
   Sure:
   Currently the SSVM does not have any access to the network of the host OR 
other servers from outside.
   It HAS a default route now, but no traffic goes out.
   I can SSH from the host into the VM, but not from the managament server.
   The VM is also of course not able to connect to the secondary storage.
   The firewall is turned off.
   
   Good to know, that the routes are not a problem.
   
   Maybe this will help us, the iptables of the host:
   -P INPUT ACCEPT
   -P FORWARD ACCEPT
   -P OUTPUT ACCEPT
   -N BF-brenp125s0-300
   -N BF-brenp125s0-300-IN
   -N BF-brenp125s0-300-OUT
   -N BF-cloudbr0
   -N BF-cloudbr0-IN
   -N BF-cloudbr0-OUT
   -N s-23-VM
   -N s-25-VM
   -N v-24-VM
   -N v-26-VM
   -A FORWARD -i cloudbr0 -o cloudbr0 -j ACCEPT
   -A FORWARD -o brenp125s0-300 -m physdev --physdev-is-bridged -j 
BF-brenp125s0-300
   -A FORWARD -i brenp125s0-300 -m physdev --physdev-is-bridged -j 
BF-brenp125s0-300
   -A FORWARD -o brenp125s0-300 -j DROP
   -A FORWARD -i brenp125s0-300 -j DROP
   -A FORWARD -o cloudbr0 -m physdev --physdev-is-bridged -j BF-cloudbr0
   -A FORWARD -i cloudbr0 -m physdev --physdev-is-bridged -j BF-cloudbr0
   -A FORWARD -o cloudbr0 -j DROP
   -A FORWARD -i cloudbr0 -j DROP
   -A BF-brenp125s0-300 -m state --state RELATED,ESTABLISHED -j ACCEPT
   -A BF-brenp125s0-300 -m physdev --physdev-is-in --physdev-is-bridged -j 
BF-brenp125s0-300-IN
   -A BF-brenp125s0-300 -m physdev --physdev-is-out --physdev-is-bridged -j 
BF-brenp125s0-300-OUT
   -A BF-brenp125s0-300 -m physdev --physdev-out enp125s0.300 
--physdev-is-bridged -j ACCEPT
   -A BF-brenp125s0-300-IN -m physdev --physdev-in vnet8 --physdev-is-bridged 
-j s-25-VM
   -A BF-brenp125s0-300-IN -m physdev --physdev-in vnet11 --physdev-is-bridged 
-j v-26-VM
   -A BF-brenp125s0-300-OUT -m physdev --physdev-out vnet8 --physdev-is-bridged 
-j s-25-VM
   -A BF-brenp125s0-300-OUT -m physdev --physdev-out vnet11 
--physdev-is-bridged -j v-26-VM
   -A BF-cloudbr0 -m state --state RELATED,ESTABLISHED -j ACCEPT
   -A BF-cloudbr0 -m physdev --physdev-is-in --physdev-is-bridged -j 
BF-cloudbr0-IN
   -A BF-cloudbr0 -m physdev --physdev-is-out --physdev-is-bridged -j 
BF-cloudbr0-OUT
   -A BF-cloudbr0 -m physdev --physdev-out enp125s0 --physdev-is-bridged -j 
ACCEPT
   -A BF-cloudbr0-IN -m physdev --physdev-in vnet7 --physdev-is-bridged -j 
s-25-VM
   -A BF-cloudbr0-IN -m physdev --physdev-in vnet10 --physdev-is-bridged -j 
v-26-VM
   -A BF-cloudbr0-OUT -m physdev --physdev-out vnet7 --physdev-is-bridged -j 
s-25-VM
   -A BF-cloudbr0-OUT -m physdev --physdev-out vnet10 --physdev-is-bridged -j 
v-26-VM
   -A s-23-VM -m physdev --physdev-in vnet4 --physdev-is-bridged -j RETURN
   -A s-23-VM -m physdev --physdev-in vnet5 --physdev-is-bridged -j RETURN
   -A s-23-VM -j ACCEPT
   -A s-25-VM -m physdev --physdev-in vnet7 --physdev-is-bridged -j RETURN
   -A s-25-VM -m physdev --physdev-in vnet8 --physdev-is-bridged -j RETURN
   -A s-25-VM -j ACCEPT
   -A v-24-VM -m physdev --physdev-in vnet1 --physdev-is-bridged -j RETURN
   -A v-24-VM -m physdev --physdev-in vnet2 --physdev-is-bridged -j RETURN
   -A v-24-VM -j ACCEPT
   -A v-26-VM -m physdev --physdev-in vnet11 --physdev-is-bridged -j RETURN
   -A v-26-VM -m physdev --physdev-in vnet10 --physdev-is-bridged -j RETURN
   -A v-26-VM -j ACCEPT
   
   
   
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to