Best Practice CentOs 7 Firewalld on Controller

Hi there, I am currently setting up a new OpenStack cluster (Newton) and was wondering, what are the best practices concerning Firewalld on CentOs 7 for the Controller Node?

In most guides that I have read people tend to turn off firewalld - is this because of laziness/simplicity or is this the general best practice when working with OpenStack?

Cheers Jatha