Ask Your Question

Revision history [back]

This might the first reason :-

root@ice-neutron ~]# nova secgroup-list-rules default 
+-------------+-----------+---------+----------+--------------+
| IP Protocol | From Port | To Port | IP Range | Source Group | 
+-------------+-----------+---------+----------+--------------+
|             |           |         |          | default      |
|             |           |         |          | default      |
+-------------+-----------+---------+----------+--------------+

Should look like this
+-------------+-----------+---------+-----------+--------------+
| IP Protocol | From Port | To Port | IP Range  | Source Group |
+-------------+-----------+---------+-----------+--------------+
|             |           |         |           | default      |
|             |           |         |           | default      |
| tcp         | 22        | 22      | 0.0.0.0/0 |              |
| icmp        | -1        | -1      | 0.0.0.0/0 |              |
+-------------+-----------+---------+-----------+--------------+

# nova secgroup-add-rule default icmp -1 -1 0.0.0.0/0
# nova secgroup-add-rule default tcp 22 22 0.0.0.0/0

This might the first reason :-

root@ice-neutron ~]# nova secgroup-list-rules default 
+-------------+-----------+---------+----------+--------------+
| IP Protocol | From Port | To Port | IP Range | Source Group | 
+-------------+-----------+---------+----------+--------------+
|             |           |         |          | default      |
|             |           |         |          | default      |
+-------------+-----------+---------+----------+--------------+

Should look like this
+-------------+-----------+---------+-----------+--------------+
| IP Protocol | From Port | To Port | IP Range  | Source Group |
+-------------+-----------+---------+-----------+--------------+
|             |           |         |           | default      |
|             |           |         |           | default      |
| tcp         | 22        | 22      | 0.0.0.0/0 |              |
| icmp        | -1        | -1      | 0.0.0.0/0 |              |
+-------------+-----------+---------+-----------+--------------+

# nova secgroup-add-rule default icmp -1 -1 0.0.0.0/0
# nova secgroup-add-rule default tcp 22 22 0.0.0.0/0

This might the first reason :-

root@ice-neutron ~]# nova secgroup-list-rules default 
+-------------+-----------+---------+----------+--------------+
| IP Protocol | From Port | To Port | IP Range | Source Group | 
+-------------+-----------+---------+----------+--------------+
|             |           |         |          | default      |
|             |           |         |          | default      |
+-------------+-----------+---------+----------+--------------+

# .   keystonerc_admin
# nova secgroup-add-rule default icmp -1 -1 0.0.0.0/0
# nova secgroup-add-rule default tcp 22 22 0.0.0.0/0

OR as particular tenant

 $ neutron security-group-rule-create --protocol icmp \
  --direction ingress --remote-ip-prefix 0.0.0.0/0 default
 $ neutron security-group-rule-create --protocol tcp \
  --port-range-min 22 --port-range-max 22 \
  --direction ingress --remote-ip-prefix 0.0.0.0/0 default

This might the first reason :-

:-

    root@ice-neutron ~]# nova secgroup-list-rules default 
 +-------------+-----------+---------+----------+--------------+
 | IP Protocol | From Port | To Port | IP Range | Source Group | 
 +-------------+-----------+---------+----------+--------------+
 |             |           |         |          | default      |
 |             |           |         |          | default      |
 +-------------+-----------+---------+----------+--------------+

To fix it run :-
    # .   keystonerc_admin
 # nova secgroup-add-rule default icmp -1 -1 0.0.0.0/0
 # nova secgroup-add-rule default tcp 22 22 0.0.0.0/0

OR as particular tenant

tenant

     $ neutron security-group-rule-create --protocol icmp \
   --direction ingress --remote-ip-prefix 0.0.0.0/0 default
  $ neutron security-group-rule-create --protocol tcp \
   --port-range-min 22 --port-range-max 22 \
   --direction ingress --remote-ip-prefix 0.0.0.0/0 default