Upgrade PVE5.4 to PVE6 - suddenly, gre conntrack module is needed


Active Member
Dec 16, 2018
Hello there,

this post is more for information puropses, should someone else stumble over the same problem.

We just upgraded our 5.4 environment to 6.0. To provide internal connectivity for some of our VMs, we have another ovs (vmbrX, with no physical device connected) on each node, all of them being linked in a mesh via GRE. It worked nicely all the time, until we upgraded to PVE6. Suddenly, the GRE traffic was blocked, assumingly by this rule:

-A PVEFW-Drop -m conntrack --ctstate INVALID -j DROP

Solution: load module nf_conntrack_proto_gre.

I don't know, if this is meant to be like this, it got me off guard and had me search a while.

Kind regards,
Thanks for sharing the find!

Did you see anything in the journal/dmesg which indicated that this might be the reason?


no, I tcpdump-ed myself through it and then searched online. I found an old thread here, which guided me into the right direction.

Kind regards,


The Proxmox community has been around for many years and offers help and support for Proxmox VE, Proxmox Backup Server, and Proxmox Mail Gateway.
We think our community is one of the best thanks to people like you!

Get your subscription!

The Proxmox team works very hard to make sure you are running the best software and getting stable updates and security enhancements, as well as quick enterprise support. Tens of thousands of happy customers have a Proxmox subscription. Get yours easily in our online shop.

Buy now!