Hello,
We have a three node cluster running 9.1.2 with all three nodes as exit nodes.
VMs inside the cluster can reach outside and back normally, but it is only if we have a primary exit node defined that nodes on the outside can ping and reach nodes inside the cluster.
Seems similar to this https://forum.proxmox.com/threads/evpn-vpls-with-multi-exit-nodes-firewall-drop-packet-with-asymetric-routing.158225/
but i have manually set net.ipv4.conf.all.rp_filter to 0 but it does not solve the issue.
I do not notice any changes in the routing when i designate a primary exit router or remove it.
I do not have a firewall activated (had but deactivated them on two nodes), not the hosts or cluster firewall or the VNET firewall.
Conntrack is still active, is that what is causing me these issues or Is this working as intended?
I would like to avoid using a primary exit node since it could put us in a bad spot if the designated node should fail for some reason.
Thanks
Mathias
We have a three node cluster running 9.1.2 with all three nodes as exit nodes.
VMs inside the cluster can reach outside and back normally, but it is only if we have a primary exit node defined that nodes on the outside can ping and reach nodes inside the cluster.
Seems similar to this https://forum.proxmox.com/threads/evpn-vpls-with-multi-exit-nodes-firewall-drop-packet-with-asymetric-routing.158225/
but i have manually set net.ipv4.conf.all.rp_filter to 0 but it does not solve the issue.
I do not notice any changes in the routing when i designate a primary exit router or remove it.
I do not have a firewall activated (had but deactivated them on two nodes), not the hosts or cluster firewall or the VNET firewall.
Conntrack is still active, is that what is causing me these issues or Is this working as intended?
I would like to avoid using a primary exit node since it could put us in a bad spot if the designated node should fail for some reason.
Thanks
Mathias