You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
With TCPDump, I see the ICMP, but the http packet doesn't arrive on the node.
Hm, this is pretty strange because VXLAN doesn't handle ICMP vs TCP / HTTP traffic differently. I wonder if there is something else (like a policy rule or similar?) that might be blocking the TCP/HTTP traffic on the ingress node?
Do you see the TCP traffic egress the Ingress node using tcpdump?
Hello,
I got an issue with Calico
v3.29
and VXLanCrossSubnet :I have a cluster (
v1.31.2
) with nodes in "admin" LAN et two nodes in "dmz" LAN (the ingresses nodes).In the firewall between the LANs, due of the issue, we opened all network traffic (tcp/udp/icmp).
The issue is :
From the Ingress node, I can ping a pod on an admin node, but when I try to curl the TCP Port (of the pod), the packet doesn't reach the node.
With TCPDump, I see the ICMP, but the http packet doesn't arrive on the node.
My config :
On my ingress node :
The really strange thing, is that I have the same setup on a v1.30 cluster with Calico v3.28.1 and it work as expected.
It seem to be related to
VXLan
cause it happend only over Cross Subnets.Any idea to help me out ?
Thanks 🙏
The text was updated successfully, but these errors were encountered: