hi, we need to monitor openstack-heat compute so on -with snmp.the requirement is to have port 161 162 open on compute ceph heat.We have redhat 7 with snmpd installed on each of the mentioned servers.

is there any possibility to write a template in heat that will open port 161 162 on every openstack server? tnx

Heat deals with resources that are managed by OpenStack, for example Nova servers or Neutron networks, not with the configuration of the cloud hosts. To configure your hosts automatically, use a tool like Ansible.

If the hosts are managed by OpenStack (e.g. undercloud), perhaps a security group or even Neutron FWaaS is the right solution?

Security groups are sets of IP filter rules that are applied to all project instances, which define networking access to the instance.

The Firewall-as-a-Service (FWaaS) plug-in applies firewalls to OpenStack objects such as projects

routers, and router ports. i am new in openstack-i need a sort of template to let port 161 of snmp to work on all coputes,controllers so on.Or any other solution to let thraffin on port 161.

Again: Heat controls OpenStack resources. You can’t use it to control the infrastructure on which your cloud runs.

Why don’t you use iptables to open the ports?

