Hi,
the topic of "conntrack state migration not supported or disabled, active connections might get dropped" has been discussed multiple times and there are a few posts regarding fixes in the qemu-server, last fix is in 9.1.3 if i understood correctly - i read alot of those. This issue/question is NOT related to those bugs.
I understood that i have to use "nftables" in Proxmox 9 to properly support conntrack, which is enabled on each host in Firewall -> Option -> nftables = yes.
What else do i need to do
- Restart all VMs ? Or does the conntract work for each VM that was restarted ?
- Do i need to enable the firewall on each virtual machine in Firewall -> Options ?
- Do i need to enable firewalling on the respective interface of a VM in the interface settings ?
What i confirmed already is
- nftables enabled
- the proxmox-firewall systemd unit is active and running
What i tested is
- enable firewall on one VM
- set INPUT and OUTPUT to default ACCEPT
- enabled the firewall on the interface
- tried a live migration with the "conntrack" ticketmark on
and i still get the conntrack error notification.
---
I am not sure how to proceed - maybe someone can point me to the right direction
Thanks already
Soeren
the topic of "conntrack state migration not supported or disabled, active connections might get dropped" has been discussed multiple times and there are a few posts regarding fixes in the qemu-server, last fix is in 9.1.3 if i understood correctly - i read alot of those. This issue/question is NOT related to those bugs.
I understood that i have to use "nftables" in Proxmox 9 to properly support conntrack, which is enabled on each host in Firewall -> Option -> nftables = yes.
What else do i need to do
- Restart all VMs ? Or does the conntract work for each VM that was restarted ?
- Do i need to enable the firewall on each virtual machine in Firewall -> Options ?
- Do i need to enable firewalling on the respective interface of a VM in the interface settings ?
What i confirmed already is
- nftables enabled
- the proxmox-firewall systemd unit is active and running
What i tested is
- enable firewall on one VM
- set INPUT and OUTPUT to default ACCEPT
- enabled the firewall on the interface
- tried a live migration with the "conntrack" ticketmark on
and i still get the conntrack error notification.
---
I am not sure how to proceed - maybe someone can point me to the right direction
Thanks already
Soeren