neutron rules are saved in /etc/sysconfig/iptables and /etc/sysconfig/ip6tables in Red Hat OpenStack Director
Issue
Iptables neutron runtime rules are saved into iptables startup config. This causes old stale neutron rules to be loaded at boot time.
This issue can be triggered by:
- An administrator ran
servce iptables save
and saved temporary neutron rules into/etc/sysconfig/iptables
and/etc/sysconfig/ip6tables
. - OpenStack Director made neutron iptables rules persistent: https://bugzilla.redhat.com/show_bug.cgi?id=1541528
Environment
Red Hat OpenStack Platform 7 - 11
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.