cloudstack-users mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From Muhammad Adeel Zahid <>
Subject Re: Iptables of Host machine blocks http traffic to Guest VM's
Date Thu, 19 Oct 2017 19:32:15 GMT
I am using KVM as hypervisor and for network configuration I followed the following link

Except that my ip addresses are from 10.0.0.x series. And I do not know about ingress/egress
rules and how to configure them.

Quick Installation Guide for CentOS 6 — Apache CloudStack ...<>
High level overview of the process¶ This runbook will focus on building a CloudStack cloud
using KVM on CentOS 6.5 with NFS storage on a flat layer-2 network ...

From: Rafael Weingärtner <>
Sent: Friday, October 20, 2017 12:19:49 AM
Subject: Re: Iptables of Host machine blocks http traffic to Guest VM's

What type of deployment are you using?
Did you try configuring the ingress/egress rules for the network of the VM
you are creating?

On Thu, Oct 19, 2017 at 5:17 PM, Muhammad Adeel Zahid <>

> One more finding. Even restarting the iptables service does the trick. Why
> is that? What can I do to avoid having to restart the iptables service?
> Regards
> Adeel
> ________________________________
> From: Muhammad Adeel Zahid <>
> Sent: Friday, October 20, 2017 12:08:43 AM
> To:
> Subject: Iptables of Host machine blocks http traffic to Guest VM's
> Hello,
> Finally, I have created a template from centos 6.8 ISO with jdk 1.8
> installed and a web application hosted. I can now create VM's from this
> templates and they work fine except one problem. The web applications in
> guest VMs created from template are only accessible from the host running
> the VMs. If I access them (web applications) from some other system on the
> same LAN they are not accessible until I turn off the iptables service on
> host machine. Is there an ip table rule that I can add to work around this
> problem not only for the existing VMs but for the VMs I will be creating on
> this host in the future?
> Regards
> Adeel

Rafael Weingärtner

  • Unnamed multipart/alternative (inline, None, 0 bytes)
View raw message