Iptables on Virtual router

2018-03-06 Thread Kumar, Varun
Hello, Is it possible to write custom iptables on the Virtual router that's created by cloudstack and make it persistent across restarts ? It looks like /etc/iptables/router_rules.v4 on the VR is the file that's being created but I am looking for the script that creates this file. Any insi

Re: Iptables on Virtual router

2018-03-06 Thread Dag Sonstebo
Hi Varun, No there’s no method for this, all firewall rules for the VR are contained in the CloudStack database and written on demand when the VR is created or firewall changes made. Regards, Dag Sonstebo Cloud Architect ShapeBlue On 06/03/2018, 11:56, "Kumar, Varun" wrote: Hello,

CS fail after upgrade to 4.11

2018-03-06 Thread Piotr Pisz
All, After upgrade from 4.10 to 4.11 We have these errors in managemen log. Is this a problem with our db or an incorrect upgrade? We repeated the upgrade but with the same result. What can we do? Please help J Regards, Piotr 2018-03-06 19:52:43,719 INFO [c.c.s.ConfigurationServerI

RE: CS fail after upgrade to 4.11

2018-03-06 Thread Paul Angus
Hi Piotr, Did you see this section in the upgrade notes for 4.10 to 4.11 ? Apache CloudStack 4.10.0.0 users who are upgrading to 4.11.0.0 should read the following discussion and workaround for a db-upgrade issue: http://markmail.org/message/f42kqr3mx4r4hgih [email protected]  www.sh

RE: VHD import

2018-03-06 Thread Grégoire Lamodière
Hi Dag, All, I spent some time working on this matter, and here are the results of my tests. It might be usefull in case anyone has to restore instances from nfs store. I think I were facing 2 issues. 1/ You are right, in case vm crashed (ie was running at the time of network crash), you may a

RE: Iptables on Virtual router

2018-03-06 Thread Kumar, Varun
Thanks Dag. I am running into a scenario where a VR is required for dhcp service on the public Internet facing vlan and want to restrict connections to known trusted sources only. Has anyone in the community run into such a situation before and found a workaround ? Thanks, Varun -Orig

Re: Iptables on Virtual router

2018-03-06 Thread Makrand
Varun, If you're talking about allowing access to VMs behind VR from specific Internet sources, that is as simple as adding source in firewall (by clicking on public IP of network or VM) at cloud-stack level where you define TCP/UDP protocol and port number etc. I know this is very simple, but ju

RE: CS fail after upgrade to 4.11

2018-03-06 Thread Piotr Pisz
Hi Paul, You were right and the script helped, the upgrade was a success. Unfortunately, we have a strange symptom, in UI all hosts are not visible (see picture). There are no major errors in the log. On DB all hosts have status Up but all operation like VM power on ending with info "No host are