Cannot connect even closed firewalld service on hosts.
-----Original Message-----
From: users-bounces(a)ovirt.org <users-bounces(a)ovirt.org> On Behalf Of
Matthew.Stier(a)fujitsu.com
Sent: Thursday, January 14, 2021 11:20 PM
To: Strahil Nikolov <hunter86_bg(a)yahoo.com>; tommy <sz_cuitao(a)163.com>;
eevans(a)digitaldatatechs.com
Cc: users(a)ovirt.org
Subject: [ovirt-users] Re: VM console does not work with new cluster.
Listed in firewalld service 'vdsm'
-----Original Message-----
From: Strahil Nikolov <hunter86_bg(a)yahoo.com>
Sent: Wednesday, January 13, 2021 10:52 PM
To: tommy <sz_cuitao(a)163.com>; Stier, Matthew <Matthew.Stier(a)fujitsu.com>;
eevans(a)digitaldatatechs.com
Cc: users(a)ovirt.org
Subject: Re: [ovirt-users] Re: VM console does not work with new cluster.
I don't see the VNC ports at all (5900 and above).
Here is my firewall
on oVirt 4.3.10:
public (active)
target: default
icmp-block-inversion: no
interfaces: enp4s0 enp5s0f0 enp5s0f1 enp7s5f0 enp7s5f1 enp7s6f0
enp7s6f1 ovirtmgmt team0
sources:
services: cockpit ctdb dhcpv6-client glusterfs libvirt-tls nfs nfs3 nrpe ovirt-imageio
ovirt-storageconsole ovirt-vmconsole rpc-bind samba snmp ssh vdsm
ports: 111/tcp 2049/tcp 54321/tcp 5900/tcp 5900-6923/tcp 5666/tcp 16514/tcp 54322/tcp
22/tcp 6081/udp 8080/tcp 963/udp 965/tcp
protocols:
masquerade: no
forward-ports:
source-ports:
icmp-blocks:
rich rules:
Best Regards,
Strahil Nikolov
В 05:25 +0800 на 13.01.2021 (ср), tommy написа:
I encountered the question too.
The follow file is the connect file for vm that can connect using
remote viewer:
[virt-viewer]
type=vnc
host=192.168.10.41
port=5900
password=rdXQA4zr/UAY
# Password is valid for 120 seconds.
delete-this-file=1
fullscreen=0
title=HostedEngine:%d
toggle-fullscreen=shift+f11
release-cursor=shift+f12
secure-attention=ctrl+alt+end
versions=rhev-win64:2.0-160;rhev-win32:2.0-160;rhel8:7.0-3;rhel7:2.0-
6;rhel6:99.0-1
newer-version-url=
http://www.ovirt.org/documentation/admin-guide/virt/console-client-res
ources
[ovirt]
host=ooeng.tltd.com:443
vm-guid=76f99df2-ef79-45d9-8eea-a32b168f9ef3
sso-token=4Up7TfLLBjSuQgPkQvRz3D-
fUGZWZg4ynApe2Y7ylkARCFwQWsfEr3dU8FjlK8esctm3Im4tz80mE1DjrNT3XQ
admin=1
ca=-----BEGIN CERTIFICATE-----
\nMIIDqDCCApCgAwIBAgICEAAwDQYJKoZIhvcNAQELBQAwPzELMAkGA1UEBhMCVVMxETA
PBgNVBAoM\nCHRsdGQuY29tMR0wGwYDVQQDDBRvb2VuZy50bHRkLmNvbS4xNzczMDAeFw
0yMTAxMTAxNjE1NDda\nFw0zMTAxMDkxNjE1NDdaMD8xCzAJBgNVBAYTAlVTMREwDwYDV
QQKDAh0bHRkLmNvbTEdMBsGA1UE\nAwwUb29lbmcudGx0ZC5jb20uMTc3MzAwggEiMA0G
CSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCg\nYT9S7hWiXQUzAqFQKbg2nMjwyHDmb/J
mKeJAUVZqNKRg1q80IpWyoM12Zw0nX1eTwMnVY/JtJON4\n13PoEC3So8nniGt+wtHr44
ysvCWfU0SBk/ZPnKmQ58o5MlSkidHwySChXfVPYLPWeUJ1JUrujna/\nCbi5bmmjx2pqw
LrZXX8Q5NO2MRKOTs0Dtg16Q6z+a3cXLIffVJfhPGS3AkIh6nznNaDeH5gFZZbd\nr3DK
E4xrpdw/7y6CgjmHe4vwGxOIyE+gElZ/lVtqznLMwohz7wgtgsDA36277mujNyMjMbrSF
heu\n5WfbIa9VVSZWEkISVq6eswLOQ1IRaFyJsFN9AgMBAAGjga0wgaowHQYDVR0OBBYE
FDYEqJOMqN8+\nQhCP7DAkqF3RZMFdMGgGA1UdIwRhMF+AFDYEqJOMqN8+QhCP7DAkqF3
RZMFdoUOkQTA/MQswCQYD\nVQQGEwJVUzERMA8GA1UECgwIdGx0ZC5jb20xHTAbBgNVBA
MMFG9vZW5nLnRsdGQuY29tLjE3NzMw\nggIQADAPBgNVHRMBAf8EBTADAQH/MA4GA1UdD
wEB/wQEAwIBBjANBgkqhkiG9w0BAQsFAAOCAQEA\nAKs0/yQWkoOkGcL0PjF9ijekdMmj
rLZGyh5uLot7h9s/Y2+5l9n9IzEjjx9chi8xwt6MBsR6/nBT\n/skcciv2veM22HwNGjd
rHvhfbZFnZsGe2TU60kGzKjlv1En/8Pgd2aWBcwTlr+SErBXkehNEJRj9\n1saycPgwS4
pHS04c2+4JMhpe+hxgsO2+N/SYkP95Lf7ZQynVsN/SKx7X3cWybErCqoB7G7McqaHN\nV
Ww+QNXo5islWUXqeDc3RcnW3kq0XUEzEtp6hoeRcLKO99QrAW31zqU/QY+EeZ6Fax1O/j
rDafZn\npTs0KJFNgeVnUhKanB29ONy+tmnUmTAgPMaKKw==\n-----END
CERTIFICATE-----\n
the firewall list of the host 192.168.10.41 is:
[root@ooengh1 ~]# firewall-cmd --list-all public (active)
target: default
icmp-block-inversion: no
interfaces: bond0 ovirtmgmt
sources:
services: cockpit dhcpv6-client libvirt-tls ovirt-imageio ovirt-
vmconsole snmp ssh vdsm
ports: 6900/tcp 22/tcp 6081/udp
protocols:
masquerade: no
forward-ports:
source-ports:
icmp-blocks:
rich rules:
the follow file is the connect file that vm that cannot connect using
remote viewer:
[virt-viewer]
type=vnc
host=ohost1.tltd.com
port=5900
password=4/jWA+RLaSZe
# Password is valid for 120 seconds.
delete-this-file=1
fullscreen=0
title=testol:%d
toggle-fullscreen=shift+f11
release-cursor=shift+f12
secure-attention=ctrl+alt+end
versions=rhev-win64:2.0-160;rhev-win32:2.0-160;rhel8:7.0-3;rhel7:2.0-
6;rhel6:99.0-1
newer-version-url=
http://www.ovirt.org/documentation/admin-guide/virt/console-client-res
ources
[ovirt]
host=ooeng.tltd.com:443
vm-guid=2b0eeecf-e561-4f60-b16d-dccddfcc852a
sso-token=4Up7TfLLBjSuQgPkQvRz3D-
fUGZWZg4ynApe2Y7ylkARCFwQWsfEr3dU8FjlK8esctm3Im4tz80mE1DjrNT3XQ
admin=1
ca=-----BEGIN CERTIFICATE-----
\nMIIDqDCCApCgAwIBAgICEAAwDQYJKoZIhvcNAQELBQAwPzELMAkGA1UEBhMCVVMxETA
PBgNVBAoM\nCHRsdGQuY29tMR0wGwYDVQQDDBRvb2VuZy50bHRkLmNvbS4xNzczMDAeFw
0yMTAxMTAxNjE1NDda\nFw0zMTAxMDkxNjE1NDdaMD8xCzAJBgNVBAYTAlVTMREwDwYDV
QQKDAh0bHRkLmNvbTEdMBsGA1UE\nAwwUb29lbmcudGx0ZC5jb20uMTc3MzAwggEiMA0G
CSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCg\nYT9S7hWiXQUzAqFQKbg2nMjwyHDmb/J
mKeJAUVZqNKRg1q80IpWyoM12Zw0nX1eTwMnVY/JtJON4\n13PoEC3So8nniGt+wtHr44
ysvCWfU0SBk/ZPnKmQ58o5MlSkidHwySChXfVPYLPWeUJ1JUrujna/\nCbi5bmmjx2pqw
LrZXX8Q5NO2MRKOTs0Dtg16Q6z+a3cXLIffVJfhPGS3AkIh6nznNaDeH5gFZZbd\nr3DK
E4xrpdw/7y6CgjmHe4vwGxOIyE+gElZ/lVtqznLMwohz7wgtgsDA36277mujNyMjMbrSF
heu\n5WfbIa9VVSZWEkISVq6eswLOQ1IRaFyJsFN9AgMBAAGjga0wgaowHQYDVR0OBBYE
FDYEqJOMqN8+\nQhCP7DAkqF3RZMFdMGgGA1UdIwRhMF+AFDYEqJOMqN8+QhCP7DAkqF3
RZMFdoUOkQTA/MQswCQYD\nVQQGEwJVUzERMA8GA1UECgwIdGx0ZC5jb20xHTAbBgNVBA
MMFG9vZW5nLnRsdGQuY29tLjE3NzMw\nggIQADAPBgNVHRMBAf8EBTADAQH/MA4GA1UdD
wEB/wQEAwIBBjANBgkqhkiG9w0BAQsFAAOCAQEA\nAKs0/yQWkoOkGcL0PjF9ijekdMmj
rLZGyh5uLot7h9s/Y2+5l9n9IzEjjx9chi8xwt6MBsR6/nBT\n/skcciv2veM22HwNGjd
rHvhfbZFnZsGe2TU60kGzKjlv1En/8Pgd2aWBcwTlr+SErBXkehNEJRj9\n1saycPgwS4
pHS04c2+4JMhpe+hxgsO2+N/SYkP95Lf7ZQynVsN/SKx7X3cWybErCqoB7G7McqaHN\nV
Ww+QNXo5islWUXqeDc3RcnW3kq0XUEzEtp6hoeRcLKO99QrAW31zqU/QY+EeZ6Fax1O/j
rDafZn\npTs0KJFNgeVnUhKanB29ONy+tmnUmTAgPMaKKw==\n-----END
CERTIFICATE-----\n
the firewall list of the host ohost1.tltd.com(192.168.10.160) is:
[root@ohost1 ~]# firewall-cmd --list-all public (active)
target: default
icmp-block-inversion: no
interfaces: bond0 ovirtmgmt
sources:
services: cockpit dhcpv6-client libvirt-tls ovirt-imageio ovirt-
vmconsole snmp ssh vdsm
ports: 22/tcp 6081/udp
protocols:
masquerade: no
forward-ports:
source-ports:
icmp-blocks:
rich rules:
Please give me some advice,thanks.
-----Original Message-----
From: users-bounces(a)ovirt.org <users-bounces(a)ovirt.org> On Behalf Of
Strahil Nikolov via Users
Sent: Wednesday, January 13, 2021 3:15 AM
To: Matthew.Stier(a)fujitsu.com; eevans(a)digitaldatatechs.com;
users(a)ovirt.org
Subject: [ovirt-users] Re: VM console does not work with new cluster.
> It’s just that once the VM has been moved to the new cluster,
> selecting console results in the same behavior, but that virt-
> viewer starts and stops within a second.
In order to debug, you will need to compare the files provided when
you press the "console" button from both clusters and identify the
problem.
Have you compared the firewalld ports on 2 nodes (old and new
cluster) ?
Best Regards,
Strahil Nikolov
_______________________________________________
Users mailing list -- users(a)ovirt.org
To unsubscribe send an email to users-leave(a)ovirt.org Privacy
Statement:
https://www.ovirt.org/privacy-policy.html
oVirt Code of Conduct:
https://www.ovirt.org/community/about/community-guidelines/
List Archives:
https://lists.ovirt.org/archives/list/users@ovirt.org/message/3U5ZIELT
USPKT6KZ7UZWWFCDRNCF5YLN/
_______________________________________________
Users mailing list -- users(a)ovirt.org
To unsubscribe send an email to users-leave(a)ovirt.org Privacy Statement:
https://www.ovirt.org/privacy-policy.html
oVirt Code of Conduct:
https://www.ovirt.org/community/about/community-guidelines/
List Archives:
https://lists.ovirt.org/archives/list/users@ovirt.org/message/N7JRNNAJDZH...