Firewall Rules for Red Hat OpenStack Platform
List of required ports and protocols.
Abstract
1. Firewall Rules for Red Hat OpenStack Platform
This article describes the firewall configuration created by the director on Red Hat OpenStack Platform 10. These ports are required for services running on the overcloud.
1.1. Nova API
Service | Protocol | Ports | Notes |
---|---|---|---|
nova | TCP | 6080 | Nova novnc Proxy |
nova | TCP | 13080 | Nova novnc Proxy (SSL) |
nova | TCP | 8773 | Nova EC2 API |
nova | TCP | 3773 | Nova EC2 API (SSL) |
nova | TCP | 8774 | Nova API |
nova | TCP | 13774 | Nova API (SSL) |
nova | TCP | 8775 | Nova Metadata |
1.2. HAProxy
Service | Protocol | Ports | Notes |
---|---|---|---|
haproxy_stats | TCP | 1993 |
1.3. Glance Registry API
Service | Protocol | Ports | Notes |
---|---|---|---|
glance | TCP | 9191 | Glance Registry API |
1.4. Ceilometer API
Service | Protocol | Ports | Notes |
---|---|---|---|
ceilometer | TCP | 8777 | Ceilometer API |
ceilometer | TCP | 13777 | Ceilometer API (SSL) |
1.5. Keystone
Service | Protocol | Ports | Notes |
---|---|---|---|
keystone | TCP | 5000 | Keystone Public API |
keystone | TCP | 13000 | Keystone Public API (SSL) |
keystone | TCP | 35357 | Keystone Admin API |
keystone | TCP | 13357 | Keystone Admin API (SSL) |
1.6. Ironic Conductor
Service | Protocol | Ports | Notes |
---|---|---|---|
TFTP | UDP | 69 | |
HTTP | TCP | 8088 |
1.7. Nova Libvirt
Service | Protocol | Ports | Notes |
---|---|---|---|
nova_libvirt | TCP | 16514 |
1.8. RabbitMQ
Service | Protocol | Ports | Notes |
---|---|---|---|
rabbitmq | TCP | 4369 | Rabbitmq |
rabbitmq | TCP | 5672 | Rabbitmq |
rabbitmq | TCP | 25672 | Rabbitmq |
1.9. Glance API
Service | Protocol | Ports | Notes |
---|---|---|---|
glance | TCP | 9292 | Glance API |
glance | TCP | 13292 | Glance API (SSL) |
1.10. keepalived
Service | Protocol | Ports | Notes |
---|---|---|---|
VRRP | VRRP | VRRP |
1.11. Redis
Service | Protocol | Ports | Notes |
---|---|---|---|
redis | TCP | 6379 | Internal service coordination |
redis | TCP | 26379 |
1.12. MySQL Galera
Service | Protocol | Ports | Notes |
---|---|---|---|
mysql_galera | TCP | 873 | MySQL |
mysql_galera | TCP | 3306 | |
mysql_galera | TCP | 4444 | |
mysql_galera | TCP | 4567 | |
mysql_galera | TCP | 4568 | |
mysql_galera | TCP | 9200 | Galera-monitor |
1.13. MongoDB
Service | Protocol | Ports | Notes |
---|---|---|---|
mongodb_config | TCP | 27019 | mongodb_config |
mongodb_sharding | TCP | 27018 | mongodb_sharding |
mongodb | TCP | 27017 | MongoDB |
1.14. NTP
Service | Protocol | Ports | Notes |
---|---|---|---|
ntp | UDP | 123 | NTP |
1.15. Swift Storage
Service | Protocol | Ports | Notes |
---|---|---|---|
swift | TCP | 873 | Rsync |
swift | TCP | 6000 | Object Server |
swift | TCP | 6001 | Container Server |
swift | TCP | 6002 | Account Server |
1.16. Ceph OSD
Service | Protocol | Ports | Notes |
---|---|---|---|
ceph | TCP | 6800-7300 |
1.17. Neutron L3
Service | Protocol | Ports | Notes |
---|---|---|---|
VRRP | VRRP | VRRP |
1.18. Heat CloudFormation API service
Service | Protocol | Ports | Notes |
---|---|---|---|
heat | TCP | 8000 | Heat AWS CloudFormation-compatible API |
heat | TCP | 13800 | Heat AWS CloudFormation-compatible API (SSL) |
1.19. Gnocchi API
Service | Protocol | Ports | Notes |
---|---|---|---|
gnocchi | TCP | 8041 | Gnocchi API |
gnocchi | TCP | 13041 | Gnocchi API (SSL) |
1.20. Gnocchi Statsd
Service | Protocol | Ports | Notes |
---|---|---|---|
gnocchi_statsd | UDP | 8125 | Network daemon for statistics |
1.21. Neutron DHCP
Service | Protocol | Ports | Notes |
---|---|---|---|
neutron_DHCP | UDP | 67 | Provisioning the Overcloud |
neutron_DHCP | UDP | 68 |
1.22. Ceilometer SNMP
Service | Protocol | Ports | Notes |
---|---|---|---|
SNMP | UDP | 161 | Ceilometer |
1.23. Heat API
Service | Protocol | Ports | Notes |
---|---|---|---|
heat | TCP | 8004 | Heat API Endpoint |
heat | TCP | 13004 | Heat API Endpoint (SSL) |
1.24. Neutron OVS Agent
Service | Protocol | Ports | Notes |
---|---|---|---|
neutron_vxlan | UDP | 4789 | VXLAN |
neutron_vxlan | GRE | GRE |
1.25. Swift Proxy
Service | Protocol | Ports | Notes |
---|---|---|---|
swift | TCP | 8080 | Swift Proxy |
swift | TCP | 13808 | Swift Proxy (SSL) |
1.26. Heat AWS CloudWatch-compatible API
Service | Protocol | Ports | Notes |
---|---|---|---|
heat | TCP | 8003 | Heat AWS CloudWatch-compatible API |
heat | TCP | 13003 | Heat AWS CloudWatch-compatible API (SSL) |
1.27. Memcached service
Service | Protocol | Ports | Notes |
---|---|---|---|
memcached | TCP | 11211 |
1.28. Ceph Monitor service
Service | Protocol | Ports | Notes |
---|---|---|---|
ceph | TCP | 6789 |
1.29. Ceph RadosGW service
Service | Protocol | Ports | Notes |
---|---|---|---|
ceph_rgw | TCP | 8080 | Ceph RGW |
ceph_rgw | TCP | 13080 | Ceph RGW (SSL) |
1.30. Cinder API
Service | Protocol | Ports | Notes |
---|---|---|---|
cinder | TCP | 8776 | Cinder API |
cinder | TCP | 13776 | Cinder API (SSL) |
1.31. Cinder Volume iSCSI Initiator
Service | Protocol | Ports | Notes |
---|---|---|---|
iSCSI | TCP | 3260 |
1.32. Ironic API
Service | Protocol | Ports | Notes |
---|---|---|---|
ironic | TCP | 6385 | Ironic API |
ironic | TCP | 13385 | Ironic API (SSL) |
1.33. pacemaker
Service | Protocol | Ports | Notes |
---|---|---|---|
pacemaker | TCP | 2224 | |
pacemaker | TCP | 3121 | |
pacemaker | TCP | 21064 | |
pacemaker | UDP | 5405 |
1.34. Sahara API
Service | Protocol | Ports | Notes |
---|---|---|---|
sahara | TCP | 8386 | Sahara API |
sahara | TCP | 13386 | Sahara API (SSL) |
1.35. Neutron API
Service | Protocol | Ports | Notes |
---|---|---|---|
neutron | TCP | 9696 | Neutron API |
neutron | TCP | 13696 | Neutron API (SSL) |
1.36. Horizon
Service | Protocol | Ports | Notes |
---|---|---|---|
horizon | TCP | 80 | Dashboard |
horizon | TCP | 443 | Dashboard (SSL) |
1.37. AODH API
Service | Protocol | Ports | Notes |
---|---|---|---|
aodh_api | TCP | 8042 | |
aodh_api | TCP | 13042 |
1.38. Manila API
Service | Protocol | Ports | Notes |
---|---|---|---|
manila | TCP | 8786 | Manila API |
manila | TCP | 13786 | Manila API |