2020-12-07 02:48

Change outbound nodeport rule to accept RELATED and ESTABLISHED traffic

This pull request fixes issue #692


  • 点赞
  • 写回答
  • 关注问题
  • 收藏
  • 复制链接分享
  • 邀请回答


  • weixin_39764603 weixin_39764603 5月前

    thanks for the PR and detailed bug report #692

    I don't recall why (but very likely due docker changing default FORWRD policy as described in https://github.com/kubernetes/kubernetes/issues/39823) that rule was added as part of #120. Current rule is a bad solution. So it must be changed.

    I need to test it to understand better. But here are the questions that are going through my mind

    • Is ACCEPT for RELATED and ESTABLISHED is enough? Does IPVS<-->real-server traffic is considered RELATED to the client<-->IPVS
    • Does the packet hit FORWARD chain, from http://www.austintek.com/LVS/LVS-HOWTO/HOWTO/LVS-HOWTO.filter_rules.html it indicates packet may go through the POSTROUTING chain

    Let me try the fix and revert back

    点赞 评论 复制链接分享
  • weixin_39620118 weixin_39620118 5月前

    Hello! Is there any news on this issue?

    点赞 评论 复制链接分享
  • weixin_39530288 weixin_39530288 5月前

    , thanks for the fix!

    -reddy I wonder if there are any updates from your side? It looks like we are hitting the same problem at the end.

    点赞 评论 复制链接分享
  • weixin_39620118 weixin_39620118 5月前

    -reddy any news on this?

    点赞 评论 复制链接分享