oops spoke too soon, when I moved the VMs onto different hosts the ACCEPT rules don't seem to apply
ok....Ah, of course - If you're using EVPN you need to allow traffic for the underlay network in the forward chain.. since otherwise packets won't get forwarded to the other node where the VM is hosted.
cat /etc/pve/sdn/firewall/*.fw
cat /etc/pve/firewall/cluster.fw
# from both nodes
cat /etc/network/interfaces.d/sdn
cat /etc/frr/frr.conf
ip a
ip r
cat /etc/pve/sdn/local/host.fw
Sorry for my silence, I was a bit busy the last few days. I took a quick look at the network configuration and nothing stood out immediately. We might have to do some additional debugging via nft monitor. If this is a critical issue then please open a support ticket.Shane, Should I open this as a ticket under my support agreement?
We use essential cookies to make this site work, and optional cookies to enhance your experience.