From: Lukas Sichert <l.sichert@proxmox.com>
To: pve-devel@lists.proxmox.com
Cc: Lukas Sichert <l.sichert@proxmox.com>
Subject: [PATCH network v4 1/6] sdn: evpn: enable force_forwarding for ipv6 forwarding to subnets
Date: Mon, 27 Jul 2026 15:55:02 +0200 [thread overview]
Message-ID: <20260727135509.14588-2-l.sichert@proxmox.com> (raw)
In-Reply-To: <20260727135509.14588-1-l.sichert@proxmox.com>
EVPN zones can route IPv6 subnet traffic through a VNet, an outgoing
interface, and, for L3VNI setups, a VRF bridge. Until now, this depended
on global IPv6 forwarding state, which also changes Router Advertisement
handling for the whole host.
Use the per-interface 'force_forwarding' setting instead. For IPv6
subnets that need forwarding, generate post-up/post-down commands for
the VNet interface, the outgoing interface, and the EVPN VRF bridge
where applicable.
Update the expected SDN interface output in the zone tests accordingly
Signed-off-by: Lukas Sichert <l.sichert@proxmox.com>
---
src/PVE/Network/SDN/Zones/EvpnPlugin.pm | 34 ++++++++++++++++++-
.../expected_sdn_interfaces | 6 ++++
.../exitnode_snat/expected_sdn_interfaces | 4 +++
.../exitnodenullroute/expected_sdn_interfaces | 6 ++++
.../evpn/ipv4ipv6/expected_sdn_interfaces | 4 +++
.../zones/evpn/ipv6/expected_sdn_interfaces | 4 +++
.../evpn/ipv6underlay/expected_sdn_interfaces | 4 +++
7 files changed, 61 insertions(+), 1 deletion(-)
diff --git a/src/PVE/Network/SDN/Zones/EvpnPlugin.pm b/src/PVE/Network/SDN/Zones/EvpnPlugin.pm
index 0e79707..80de5bf 100644
--- a/src/PVE/Network/SDN/Zones/EvpnPlugin.pm
+++ b/src/PVE/Network/SDN/Zones/EvpnPlugin.pm
@@ -302,7 +302,32 @@ sub generate_sdn_config {
push @iface_config, "mtu $mtu" if $mtu;
push @iface_config, "alias $alias" if $alias;
push @iface_config, "ip-forward on" if $enable_forward_v4;
- push @iface_config, "ip6-forward on" if $enable_forward_v6;
+
+ if ($enable_forward_v6) {
+ push @iface_config, "ip6-forward on";
+
+ push @iface_config, "post-up echo 1 > /proc/sys/net/ipv6/conf/$vnetid/force_forwarding";
+ push @iface_config, "post-down echo 0 > /proc/sys/net/ipv6/conf/$vnetid/force_forwarding";
+
+ if ($is_evpn_gateway) {
+ #find outgoing ipv6 interface
+ my ($outip, $outiface);
+ eval {
+ ($outip, $outiface) =
+ PVE::Network::SDN::Zones::Plugin::get_local_route_ip('2001:4860:4860::8888');
+ };
+ if ($@) {
+ my $msg = "interface for IPv6 forwarding could not be resolved: $@";
+ log_warn($msg);
+ } elsif ($outiface) {
+ push @iface_config,
+ "post-up echo 1 > /proc/sys/net/ipv6/conf/$outiface/force_forwarding";
+ push @iface_config,
+ "post-down echo 0 > /proc/sys/net/ipv6/conf/$outiface/force_forwarding";
+ }
+ }
+ }
+
push @iface_config, "arp-accept on" if $ipv4 || $ipv6;
push @iface_config, "vrf $vrf_iface" if $vrf_iface;
push(@{ $config->{$vnetid} }, @iface_config) if !$config->{$vnetid};
@@ -342,6 +367,13 @@ sub generate_sdn_config {
push @iface_config, "bridge_fd 0";
push @iface_config, "mtu $mtu" if $mtu;
push @iface_config, "vrf $vrf_iface";
+
+ if ($enable_forward_v6) {
+ push @iface_config,
+ "post-up echo 1 > /proc/sys/net/ipv6/conf/$brvrf/force_forwarding";
+ push @iface_config,
+ "post-down echo 0 > /proc/sys/net/ipv6/conf/$brvrf/force_forwarding";
+ }
push(@{ $config->{$brvrf} }, @iface_config) if !$config->{$brvrf};
}
diff --git a/src/test/zones/evpn/exitnode_local_routing_ipv6/expected_sdn_interfaces b/src/test/zones/evpn/exitnode_local_routing_ipv6/expected_sdn_interfaces
index b46d4e7..7b8dc3c 100644
--- a/src/test/zones/evpn/exitnode_local_routing_ipv6/expected_sdn_interfaces
+++ b/src/test/zones/evpn/exitnode_local_routing_ipv6/expected_sdn_interfaces
@@ -8,6 +8,10 @@ iface myvnet
bridge_fd 0
mtu 1450
ip6-forward on
+ post-up echo 1 > /proc/sys/net/ipv6/conf/myvnet/force_forwarding
+ post-down echo 0 > /proc/sys/net/ipv6/conf/myvnet/force_forwarding
+ post-up echo 1 > /proc/sys/net/ipv6/conf/vmbr0/force_forwarding
+ post-down echo 0 > /proc/sys/net/ipv6/conf/vmbr0/force_forwarding
arp-accept on
vrf vrf_myzone
@@ -23,6 +27,8 @@ iface vrfbr_myzone
bridge_fd 0
mtu 1450
vrf vrf_myzone
+ post-up echo 1 > /proc/sys/net/ipv6/conf/vrfbr_myzone/force_forwarding
+ post-down echo 0 > /proc/sys/net/ipv6/conf/vrfbr_myzone/force_forwarding
auto vrfvx_myzone
iface vrfvx_myzone
diff --git a/src/test/zones/evpn/exitnode_snat/expected_sdn_interfaces b/src/test/zones/evpn/exitnode_snat/expected_sdn_interfaces
index 0d7d174..2addde0 100644
--- a/src/test/zones/evpn/exitnode_snat/expected_sdn_interfaces
+++ b/src/test/zones/evpn/exitnode_snat/expected_sdn_interfaces
@@ -27,6 +27,10 @@ iface myvnet2
bridge_fd 0
mtu 1450
ip6-forward on
+ post-up echo 1 > /proc/sys/net/ipv6/conf/myvnet2/force_forwarding
+ post-down echo 0 > /proc/sys/net/ipv6/conf/myvnet2/force_forwarding
+ post-up echo 1 > /proc/sys/net/ipv6/conf/vmbr0/force_forwarding
+ post-down echo 0 > /proc/sys/net/ipv6/conf/vmbr0/force_forwarding
arp-accept on
vrf vrf_myzone
diff --git a/src/test/zones/evpn/exitnodenullroute/expected_sdn_interfaces b/src/test/zones/evpn/exitnodenullroute/expected_sdn_interfaces
index 4bf5ccf..e406258 100644
--- a/src/test/zones/evpn/exitnodenullroute/expected_sdn_interfaces
+++ b/src/test/zones/evpn/exitnodenullroute/expected_sdn_interfaces
@@ -14,6 +14,10 @@ iface myvnet
mtu 1450
ip-forward on
ip6-forward on
+ post-up echo 1 > /proc/sys/net/ipv6/conf/myvnet/force_forwarding
+ post-down echo 0 > /proc/sys/net/ipv6/conf/myvnet/force_forwarding
+ post-up echo 1 > /proc/sys/net/ipv6/conf/vmbr0/force_forwarding
+ post-down echo 0 > /proc/sys/net/ipv6/conf/vmbr0/force_forwarding
arp-accept on
vrf vrf_myzone
@@ -47,6 +51,8 @@ iface vrfbr_myzone
bridge_fd 0
mtu 1450
vrf vrf_myzone
+ post-up echo 1 > /proc/sys/net/ipv6/conf/vrfbr_myzone/force_forwarding
+ post-down echo 0 > /proc/sys/net/ipv6/conf/vrfbr_myzone/force_forwarding
auto vrfbr_myzone2
iface vrfbr_myzone2
diff --git a/src/test/zones/evpn/ipv4ipv6/expected_sdn_interfaces b/src/test/zones/evpn/ipv4ipv6/expected_sdn_interfaces
index 7a5d741..a1fdb2b 100644
--- a/src/test/zones/evpn/ipv4ipv6/expected_sdn_interfaces
+++ b/src/test/zones/evpn/ipv4ipv6/expected_sdn_interfaces
@@ -11,6 +11,8 @@ iface myvnet
mtu 1450
ip-forward on
ip6-forward on
+ post-up echo 1 > /proc/sys/net/ipv6/conf/myvnet/force_forwarding
+ post-down echo 0 > /proc/sys/net/ipv6/conf/myvnet/force_forwarding
arp-accept on
vrf vrf_myzone
@@ -26,6 +28,8 @@ iface vrfbr_myzone
bridge_fd 0
mtu 1450
vrf vrf_myzone
+ post-up echo 1 > /proc/sys/net/ipv6/conf/vrfbr_myzone/force_forwarding
+ post-down echo 0 > /proc/sys/net/ipv6/conf/vrfbr_myzone/force_forwarding
auto vrfvx_myzone
iface vrfvx_myzone
diff --git a/src/test/zones/evpn/ipv6/expected_sdn_interfaces b/src/test/zones/evpn/ipv6/expected_sdn_interfaces
index b2bdbfe..4363842 100644
--- a/src/test/zones/evpn/ipv6/expected_sdn_interfaces
+++ b/src/test/zones/evpn/ipv6/expected_sdn_interfaces
@@ -9,6 +9,8 @@ iface myvnet
bridge_fd 0
mtu 1450
ip6-forward on
+ post-up echo 1 > /proc/sys/net/ipv6/conf/myvnet/force_forwarding
+ post-down echo 0 > /proc/sys/net/ipv6/conf/myvnet/force_forwarding
arp-accept on
vrf vrf_myzone
@@ -24,6 +26,8 @@ iface vrfbr_myzone
bridge_fd 0
mtu 1450
vrf vrf_myzone
+ post-up echo 1 > /proc/sys/net/ipv6/conf/vrfbr_myzone/force_forwarding
+ post-down echo 0 > /proc/sys/net/ipv6/conf/vrfbr_myzone/force_forwarding
auto vrfvx_myzone
iface vrfvx_myzone
diff --git a/src/test/zones/evpn/ipv6underlay/expected_sdn_interfaces b/src/test/zones/evpn/ipv6underlay/expected_sdn_interfaces
index 3b91f75..7aaf569 100644
--- a/src/test/zones/evpn/ipv6underlay/expected_sdn_interfaces
+++ b/src/test/zones/evpn/ipv6underlay/expected_sdn_interfaces
@@ -9,6 +9,8 @@ iface myvnet
bridge_fd 0
mtu 1450
ip6-forward on
+ post-up echo 1 > /proc/sys/net/ipv6/conf/myvnet/force_forwarding
+ post-down echo 0 > /proc/sys/net/ipv6/conf/myvnet/force_forwarding
arp-accept on
vrf vrf_myzone
@@ -24,6 +26,8 @@ iface vrfbr_myzone
bridge_fd 0
mtu 1450
vrf vrf_myzone
+ post-up echo 1 > /proc/sys/net/ipv6/conf/vrfbr_myzone/force_forwarding
+ post-down echo 0 > /proc/sys/net/ipv6/conf/vrfbr_myzone/force_forwarding
auto vrfvx_myzone
iface vrfvx_myzone
--
2.47.3
next prev parent reply other threads:[~2026-07-27 13:55 UTC|newest]
Thread overview: 7+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-07-27 13:55 [PATCH docs/manager/network/perl-rs v4 0/6] sdn: enable force_forwarding for ipv6 forwarding Lukas Sichert
2026-07-27 13:55 ` Lukas Sichert [this message]
2026-07-27 13:55 ` [PATCH network v4 2/6] sdn: simple: enable force_forwarding for ipv6 forwarding to subnets Lukas Sichert
2026-07-27 13:55 ` [PATCH perl-rs v4 3/6] fabrics: openfabric: enable force_forwarding for ipv6 transit traffic Lukas Sichert
2026-07-27 13:55 ` [PATCH perl-rs v4 4/6] fabrics: bgp: " Lukas Sichert
2026-07-27 13:55 ` [PATCH manager v4 5/6] ui: sdn: remove IPv6 forwarding hint from fabric edit window Lukas Sichert
2026-07-27 13:55 ` [PATCH docs v4 6/6] sdn: drop global ipv6 forwarding workaround from OpenFabric docs Lukas Sichert
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260727135509.14588-2-l.sichert@proxmox.com \
--to=l.sichert@proxmox.com \
--cc=pve-devel@lists.proxmox.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.