There are some older discussions about KRBD and needing "rxbounce" for Windows Guests over there in redhat....
https://bugzilla.redhat.com/show_bug.cgi?id=2109455
And something in CEPH-Docs
https://docs.ceph.com/en/reef/man/8/rbd/ (rxbounce)
Maybe it has something to do with this....
Answering my own question... yes migrate between nodes is enough.
Oh and you loose any Mac-Adress-Spoofing possibility. Like using opnsense in HA-Mode with VIPs.... cause only the known Mac-Adresses in are allowed....
Ergänzend noch. Wie geht man mit dieser Meldung im SYSLOG um?
Sep 26 16:54:56 RZA-GENOA3 proxmox-firewall[2334]: proxmox_firewall: error updating firewall rules: cannot execute nftables commands
Sorry für den "delay"... wir haben da jetzt einige Wochen und Updates weiter mit getestet.... soweit scheint wohl alles nun zu laufen....
Was jedoch auffällt... angenommen wir aktivieren die Firewall nur für einen einzelnen Guest auf einem Node, scheint die ConnTrack-Tabelle trotzdem von allen...
I am not talking about some traffic.... it is "ALL" Traffic in a VLAN where we have about 15 opnsense Firewalls... all see "every" Traffic from every other node, even directed to foreign Addresses.... thats why I asked...
Ich grab das mal wieder aus.
Wir haben hier einen ganz frischen TK-Cluster mit AMD-Genoa und aktuellstem PVE 8.2.6. Der hat die gleiche "krätze"... KRBD aktiviert und schon hagelt es immer wieder:
Sep 24 08:34:20 RZA-GENOA1 kernel: libceph: read_partial_message 0000000066dae705 data crc...
Did you ever solved this? We have a comparable issue here.... GuestVMs in same VLAN see traffic from each other and even saturate 10GBit Network when Backups are running between 2 specific hosts....
I believe this is more or less a showstopper then for many cusomters of ProxmoxVE. Many of them want an overview of health in the webgui, to know "when" to call the experts before its to late....
This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
By continuing to use this site, you are consenting to our use of cookies.