GitHub user mjstark added a comment to the discussion: Cannot view vm instance 
console remotely - site Cannot be reached

I certainly appreciate your response Ewerton,

You probably meant advanced networking, the zone should be core ...I'm using 
Basic networking, since I only have one public IP. Internally I'm NATTED, using 
172.16.0.0/16

Quick look at my setup;
H/W physical;
KVM1 - 172.16.6.1
KVM2 - 172.16.6.2
KVM3 - 172.16.6.3
MGMT - 172.16.6.4

Management traffic - range
172.16.0.1 - 172.16.0.50

Zone GuestNetwork - range (Also configure with Source NAT IP addressing)
172.16.0.51 - 172.16.0.150

Gateway
172.16.1.254

Egress/Ingress Rules
Allow All for CIDR 0.0.0.0/0

That being said. Following the documentation. Egress rules from your security 
groups are supposed to allow for "Console view" to work along with incoming 
traffic, say I want to RDP into a windows instance over port 3389 from the 
internet. I don't believe Cloudstack, was designed to go to that extreme to get 
incoming traffic to work. If so, if surely would have been documented in their 
guides/whitepapers. Seems these are all work-arounds, instead of getting to 
work like the app should, ...the way it's documented.

Even other blogs state that the security group egress rules are all you need, 
as long as you add the virtual router to your physical router and allow all 
incoming. In my case, my virtual router is 172.16.0.95

**Since you are using Advanced networking, this won't work for me.

I'm looking for someone who has incoming traffic working with Basic networking. 
Would like to review their setup**

Thanks again for your help,
Mike

GitHub link: 
https://github.com/apache/cloudstack/discussions/13295#discussioncomment-17346001

----
This is an automatically sent email for [email protected].
To unsubscribe, please send an email to: [email protected]

Reply via email to