Firewall Rules for Red Hat OpenStack Platform
List of required ports and protocols. Copy linkLink copied to clipboard!
Abstract
1. Firewall Rules for Red Hat OpenStack Platform Copy linkLink copied to clipboard!
This article describes the firewall configuration created by the director on Red Hat OpenStack Platform 10. These ports are required for services running on the overcloud.
1.1. Nova API Copy linkLink copied to clipboard!
| Service | Protocol | Ports | Notes |
|---|---|---|---|
| nova | TCP | 6080 | Nova novnc Proxy |
| nova | TCP | 13080 | Nova novnc Proxy (SSL) |
| nova | TCP | 8773 | Nova EC2 API |
| nova | TCP | 3773 | Nova EC2 API (SSL) |
| nova | TCP | 8774 | Nova API |
| nova | TCP | 13774 | Nova API (SSL) |
| nova | TCP | 8775 | Nova Metadata |
1.2. HAProxy Copy linkLink copied to clipboard!
| Service | Protocol | Ports | Notes |
|---|---|---|---|
| haproxy_stats | TCP | 1993 |
1.3. Glance Registry API Copy linkLink copied to clipboard!
| Service | Protocol | Ports | Notes |
|---|---|---|---|
| glance | TCP | 9191 | Glance Registry API |
1.4. Ceilometer API Copy linkLink copied to clipboard!
| Service | Protocol | Ports | Notes |
|---|---|---|---|
| ceilometer | TCP | 8777 | Ceilometer API |
| ceilometer | TCP | 13777 | Ceilometer API (SSL) |
1.5. Keystone Copy linkLink copied to clipboard!
| Service | Protocol | Ports | Notes |
|---|---|---|---|
| keystone | TCP | 5000 | Keystone Public API |
| keystone | TCP | 13000 | Keystone Public API (SSL) |
| keystone | TCP | 35357 | Keystone Admin API |
| keystone | TCP | 13357 | Keystone Admin API (SSL) |
1.6. Ironic Conductor Copy linkLink copied to clipboard!
| Service | Protocol | Ports | Notes |
|---|---|---|---|
| TFTP | UDP | 69 | |
| HTTP | TCP | 8088 |
1.7. Nova Libvirt Copy linkLink copied to clipboard!
| Service | Protocol | Ports | Notes |
|---|---|---|---|
| nova_libvirt | TCP | 16514 |
1.8. RabbitMQ Copy linkLink copied to clipboard!
| Service | Protocol | Ports | Notes |
|---|---|---|---|
| rabbitmq | TCP | 4369 | Rabbitmq |
| rabbitmq | TCP | 5672 | Rabbitmq |
| rabbitmq | TCP | 25672 | Rabbitmq |
1.9. Glance API Copy linkLink copied to clipboard!
| Service | Protocol | Ports | Notes |
|---|---|---|---|
| glance | TCP | 9292 | Glance API |
| glance | TCP | 13292 | Glance API (SSL) |
1.10. keepalived Copy linkLink copied to clipboard!
| Service | Protocol | Ports | Notes |
|---|---|---|---|
| VRRP | VRRP | VRRP |
1.11. Redis Copy linkLink copied to clipboard!
| Service | Protocol | Ports | Notes |
|---|---|---|---|
| redis | TCP | 6379 | Internal service coordination |
| redis | TCP | 26379 |
1.12. MySQL Galera Copy linkLink copied to clipboard!
| Service | Protocol | Ports | Notes |
|---|---|---|---|
| mysql_galera | TCP | 873 | MySQL |
| mysql_galera | TCP | 3306 | |
| mysql_galera | TCP | 4444 | |
| mysql_galera | TCP | 4567 | |
| mysql_galera | TCP | 4568 | |
| mysql_galera | TCP | 9200 | Galera-monitor |
1.13. MongoDB Copy linkLink copied to clipboard!
| Service | Protocol | Ports | Notes |
|---|---|---|---|
| mongodb_config | TCP | 27019 | mongodb_config |
| mongodb_sharding | TCP | 27018 | mongodb_sharding |
| mongodb | TCP | 27017 | MongoDB |
1.14. NTP Copy linkLink copied to clipboard!
| Service | Protocol | Ports | Notes |
|---|---|---|---|
| ntp | UDP | 123 | NTP |
1.15. Swift Storage Copy linkLink copied to clipboard!
| Service | Protocol | Ports | Notes |
|---|---|---|---|
| swift | TCP | 873 | Rsync |
| swift | TCP | 6000 | Object Server |
| swift | TCP | 6001 | Container Server |
| swift | TCP | 6002 | Account Server |
1.16. Ceph OSD Copy linkLink copied to clipboard!
| Service | Protocol | Ports | Notes |
|---|---|---|---|
| ceph | TCP | 6800-7300 |
1.17. Neutron L3 Copy linkLink copied to clipboard!
| Service | Protocol | Ports | Notes |
|---|---|---|---|
| VRRP | VRRP | VRRP |
1.18. Heat CloudFormation API service Copy linkLink copied to clipboard!
| Service | Protocol | Ports | Notes |
|---|---|---|---|
| heat | TCP | 8000 | Heat AWS CloudFormation-compatible API |
| heat | TCP | 13800 | Heat AWS CloudFormation-compatible API (SSL) |
1.19. Gnocchi API Copy linkLink copied to clipboard!
| Service | Protocol | Ports | Notes |
|---|---|---|---|
| gnocchi | TCP | 8041 | Gnocchi API |
| gnocchi | TCP | 13041 | Gnocchi API (SSL) |
1.20. Gnocchi Statsd Copy linkLink copied to clipboard!
| Service | Protocol | Ports | Notes |
|---|---|---|---|
| gnocchi_statsd | UDP | 8125 | Network daemon for statistics |
1.21. Neutron DHCP Copy linkLink copied to clipboard!
| Service | Protocol | Ports | Notes |
|---|---|---|---|
| neutron_DHCP | UDP | 67 | Provisioning the Overcloud |
| neutron_DHCP | UDP | 68 |
1.22. Ceilometer SNMP Copy linkLink copied to clipboard!
| Service | Protocol | Ports | Notes |
|---|---|---|---|
| SNMP | UDP | 161 | Ceilometer |
1.23. Heat API Copy linkLink copied to clipboard!
| Service | Protocol | Ports | Notes |
|---|---|---|---|
| heat | TCP | 8004 | Heat API Endpoint |
| heat | TCP | 13004 | Heat API Endpoint (SSL) |
1.24. Neutron OVS Agent Copy linkLink copied to clipboard!
| Service | Protocol | Ports | Notes |
|---|---|---|---|
| neutron_vxlan | UDP | 4789 | VXLAN |
| neutron_vxlan | GRE | GRE |
1.25. Swift Proxy Copy linkLink copied to clipboard!
| Service | Protocol | Ports | Notes |
|---|---|---|---|
| swift | TCP | 8080 | Swift Proxy |
| swift | TCP | 13808 | Swift Proxy (SSL) |
1.26. Heat AWS CloudWatch-compatible API Copy linkLink copied to clipboard!
| Service | Protocol | Ports | Notes |
|---|---|---|---|
| heat | TCP | 8003 | Heat AWS CloudWatch-compatible API |
| heat | TCP | 13003 | Heat AWS CloudWatch-compatible API (SSL) |
1.27. Memcached service Copy linkLink copied to clipboard!
| Service | Protocol | Ports | Notes |
|---|---|---|---|
| memcached | TCP | 11211 |
1.28. Ceph Monitor service Copy linkLink copied to clipboard!
| Service | Protocol | Ports | Notes |
|---|---|---|---|
| ceph | TCP | 6789 |
1.29. Ceph RadosGW service Copy linkLink copied to clipboard!
| Service | Protocol | Ports | Notes |
|---|---|---|---|
| ceph_rgw | TCP | 8080 | Ceph RGW |
| ceph_rgw | TCP | 13080 | Ceph RGW (SSL) |
1.30. Cinder API Copy linkLink copied to clipboard!
| Service | Protocol | Ports | Notes |
|---|---|---|---|
| cinder | TCP | 8776 | Cinder API |
| cinder | TCP | 13776 | Cinder API (SSL) |
1.31. Cinder Volume iSCSI Initiator Copy linkLink copied to clipboard!
| Service | Protocol | Ports | Notes |
|---|---|---|---|
| iSCSI | TCP | 3260 |
1.32. Ironic API Copy linkLink copied to clipboard!
| Service | Protocol | Ports | Notes |
|---|---|---|---|
| ironic | TCP | 6385 | Ironic API |
| ironic | TCP | 13385 | Ironic API (SSL) |
1.33. pacemaker Copy linkLink copied to clipboard!
| Service | Protocol | Ports | Notes |
|---|---|---|---|
| pacemaker | TCP | 2224 | |
| pacemaker | TCP | 3121 | |
| pacemaker | TCP | 21064 | |
| pacemaker | UDP | 5405 |
1.34. Sahara API Copy linkLink copied to clipboard!
| Service | Protocol | Ports | Notes |
|---|---|---|---|
| sahara | TCP | 8386 | Sahara API |
| sahara | TCP | 13386 | Sahara API (SSL) |
1.35. Neutron API Copy linkLink copied to clipboard!
| Service | Protocol | Ports | Notes |
|---|---|---|---|
| neutron | TCP | 9696 | Neutron API |
| neutron | TCP | 13696 | Neutron API (SSL) |
1.36. Horizon Copy linkLink copied to clipboard!
| Service | Protocol | Ports | Notes |
|---|---|---|---|
| horizon | TCP | 80 | Dashboard |
| horizon | TCP | 443 | Dashboard (SSL) |
1.37. AODH API Copy linkLink copied to clipboard!
| Service | Protocol | Ports | Notes |
|---|---|---|---|
| aodh_api | TCP | 8042 | |
| aodh_api | TCP | 13042 |
1.38. Manila API Copy linkLink copied to clipboard!
| Service | Protocol | Ports | Notes |
|---|---|---|---|
| manila | TCP | 8786 | Manila API |
| manila | TCP | 13786 | Manila API |