Issue with IP Fragmentation

Jul 2, 2019
23
3
23
Hi,

We have an issue with IP fragmentation not working.

We're not exactly sure where the problem lies but it definitely seems to be related to Proxmox (not affecting VMs on SmartOS at all - connected to the same switches etc).

Basically, our setup is as follows:

1. Running PVE 6.1 with all updates installed and running (except for latest kernel):
pve-manager/6.2-4/9824574a (running kernel: 5.3.13-1-pve)

2. 12-node cluster with firewall/ebtables enabled - cluster > host > VM (icmp traffic allowed)

3. We CAN ping with large (2000byte) packets between VMs on the SAME host (ON THE SAME VLAN), but we are unable to do so between VMs on DIFFERENT hosts but also on the SAME VLAN

4. We also cannot ping those VMs on the Proxmox hosts with large packets from the Internet (standard 56byte packets work fine).

We have a suspicion that this is related to iptables on PVE dropping fragmented datagrams, but we're not sure at which layer (i.e. CLUSTER vs HOST vs VM) nor how to fix it?

Any ideas?

Kind regards,

Angelo.
 
Last edited:
Hi,

here it works. I have made a quick test with block all and ping allowed.
For the Ping rule I have used the Macro.
What nic model do you have? Im my test a i350 is used.

How does your network config looks like.
 

About

The Proxmox community has been around for many years and offers help and support for Proxmox VE, Proxmox Backup Server, and Proxmox Mail Gateway.
We think our community is one of the best thanks to people like you!

Get your subscription!

The Proxmox team works very hard to make sure you are running the best software and getting stable updates and security enhancements, as well as quick enterprise support. Tens of thousands of happy customers have a Proxmox subscription. Get yours easily in our online shop.

Buy now!