节点的时候,总是连接失败"/>
新加计算节点的时候,总是连接失败
使用packstack安装完成后的openstack,再新加计算节点的时候,总是提示连接失败。
检查了半天是因为iptable的原因,因为自己安装的脚本在给rabbitmq加的rule如下,只有通过192.168.12.22这个节点才可以访问它,所有新加的计算节点总是连接不大rabbitmq。
ACCEPT tcp -- 192.168.12.22 0.0.0.0/0 multiport dports 5671,5672
why controller drop my compute node packet, check below iptable rule:
[root@controller log(keystone_admin)]# iptables -nL
Chain INPUT (policy ACCEPT)
target prot opt source destination
ACCEPT udp -- 0.0.0.0/0 0.0.0.0/0 udp dpt:53
ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 tcp dpt:53
ACCEPT udp -- 0.0.0.0/0 0.0.0.0/0 udp dpt:67
ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 tcp dpt:67
# only allow 192.168.12.22 packet to connect to rabbitmq
ACCEPT tcp -- 192.168.12.22 0.0.0.0/0 multiport dports 5671,5672 /* 001 amqp incoming amqp_192.168.12.22 */
ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 multiport dports 8042 /* 001 aodh-api incoming aodh_api */
ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 multiport dports 8777 /* 001 ceilometer-api incoming ceilometer_api */
ACCEPT tcp -- 192.168.12.22 0.0.0.0/0 multiport dports 3260 /* 001 cinder incoming cinder_192.168.12.22 */
ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 multiport dports 8776 /* 001 cinder-api incoming cinder_api */
ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 multiport dports 9292 /* 001 glance incoming glance_api */
ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 multiport dports 8041 /* 001 gnocchi-api incoming gnocchi_api */
ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 multiport dports 80 /* 001 horizon 80 incoming */
ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 multiport dports 5000 /* 001 keystone incoming keystone */
ACCEPT tcp -- 192.168.12.22 0.0.0.0/0 multiport dports 3306 /* 001 mariadb incoming mariadb_192.168.12.22 */
ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 multiport dports 9696 /* 001 neutron server incoming neutron_server_192.168.12.22 */
ACCEPT udp -- 192.168.12.22 0.0.0.0/0 multiport dports 6081 /* 001 neutron tunnel port incoming neutron_tunnel_192.168.12.22_192.168.12.22 */
ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 multiport dports 8773,8774,8775,8778 /* 001 nova api incoming nova_api */
ACCEPT tcp -- 192.168.12.22 0.0.0.0/0 multiport dports 5900:5999 /* 001 nova compute incoming nova_compute */
ACCEPT tcp -- 192.168.12.22 0.0.0.0/0 multiport dports 16509,49152:49215 /* 001 nova qemu migration incoming nova_qemu_migration_192.168.12.22_192.168.12.22 */
ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 multiport dports 6080 /* 001 novncproxy incoming */
ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 multiport dports 6641 /* 001 ovn northd incoming ovn_northd_192.168.12.22 */
ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 multiport dports 6642 /* 001 ovn southd incoming ovn_southd_192.168.12.22 */
ACCEPT tcp -- 192.168.12.22 0.0.0.0/0 multiport dports 6379 /* 001 redis service incoming redis service from 192.168.12.22 */
ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 multiport dports 8080 /* 001 swift proxy incoming swift_proxy */
ACCEPT tcp -- 192.168.12.22 0.0.0.0/0 multiport dports 6000,6001,6002,873 /* 001 swift storage and rsync incoming swift_storage_and_rsync_192.168.12.22 */
ACCEPT all -- 0.0.0.0/0 0.0.0.0/0 state RELATED,ESTABLISHED
ACCEPT icmp -- 0.0.0.0/0 0.0.0.0/0
ACCEPT all -- 0.0.0.0/0 0.0.0.0/0
ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 state NEW tcp dpt:22
REJECT all -- 0.0.0.0/0 0.0.0.0/0 reject-with icmp-host-prohibited
更多推荐
新加计算节点的时候,总是连接失败
发布评论