all lists on lists.proxmox.com
 help / color / mirror / Atom feed
From: Lukas Sichert <l.sichert@proxmox.com>
To: pve-devel@lists.proxmox.com
Cc: Lukas Sichert <l.sichert@proxmox.com>
Subject: [PATCH network v4 1/6] sdn: evpn: enable force_forwarding for ipv6 forwarding to subnets
Date: Mon, 27 Jul 2026 15:55:02 +0200	[thread overview]
Message-ID: <20260727135509.14588-2-l.sichert@proxmox.com> (raw)
In-Reply-To: <20260727135509.14588-1-l.sichert@proxmox.com>

EVPN zones can route IPv6 subnet traffic through a VNet, an outgoing
interface, and, for L3VNI setups, a VRF bridge. Until now, this depended
on global IPv6 forwarding state, which also changes Router Advertisement
handling for the whole host.

Use the per-interface 'force_forwarding' setting instead. For IPv6
subnets that need forwarding, generate post-up/post-down commands for
the VNet interface, the outgoing interface, and the EVPN VRF bridge
where applicable.
Update the expected SDN interface output in the zone tests accordingly

Signed-off-by: Lukas Sichert <l.sichert@proxmox.com>
---
 src/PVE/Network/SDN/Zones/EvpnPlugin.pm       | 34 ++++++++++++++++++-
 .../expected_sdn_interfaces                   |  6 ++++
 .../exitnode_snat/expected_sdn_interfaces     |  4 +++
 .../exitnodenullroute/expected_sdn_interfaces |  6 ++++
 .../evpn/ipv4ipv6/expected_sdn_interfaces     |  4 +++
 .../zones/evpn/ipv6/expected_sdn_interfaces   |  4 +++
 .../evpn/ipv6underlay/expected_sdn_interfaces |  4 +++
 7 files changed, 61 insertions(+), 1 deletion(-)

diff --git a/src/PVE/Network/SDN/Zones/EvpnPlugin.pm b/src/PVE/Network/SDN/Zones/EvpnPlugin.pm
index 0e79707..80de5bf 100644
--- a/src/PVE/Network/SDN/Zones/EvpnPlugin.pm
+++ b/src/PVE/Network/SDN/Zones/EvpnPlugin.pm
@@ -302,7 +302,32 @@ sub generate_sdn_config {
     push @iface_config, "mtu $mtu" if $mtu;
     push @iface_config, "alias $alias" if $alias;
     push @iface_config, "ip-forward on" if $enable_forward_v4;
-    push @iface_config, "ip6-forward on" if $enable_forward_v6;
+
+    if ($enable_forward_v6) {
+        push @iface_config, "ip6-forward on";
+
+        push @iface_config, "post-up echo 1 > /proc/sys/net/ipv6/conf/$vnetid/force_forwarding";
+        push @iface_config, "post-down echo 0 > /proc/sys/net/ipv6/conf/$vnetid/force_forwarding";
+
+        if ($is_evpn_gateway) {
+            #find outgoing ipv6 interface
+            my ($outip, $outiface);
+            eval {
+                ($outip, $outiface) =
+                    PVE::Network::SDN::Zones::Plugin::get_local_route_ip('2001:4860:4860::8888');
+            };
+            if ($@) {
+                my $msg = "interface for IPv6 forwarding could not be resolved: $@";
+                log_warn($msg);
+            } elsif ($outiface) {
+                push @iface_config,
+                    "post-up echo 1 > /proc/sys/net/ipv6/conf/$outiface/force_forwarding";
+                push @iface_config,
+                    "post-down echo 0 > /proc/sys/net/ipv6/conf/$outiface/force_forwarding";
+            }
+        }
+    }
+
     push @iface_config, "arp-accept on" if $ipv4 || $ipv6;
     push @iface_config, "vrf $vrf_iface" if $vrf_iface;
     push(@{ $config->{$vnetid} }, @iface_config) if !$config->{$vnetid};
@@ -342,6 +367,13 @@ sub generate_sdn_config {
             push @iface_config, "bridge_fd 0";
             push @iface_config, "mtu $mtu" if $mtu;
             push @iface_config, "vrf $vrf_iface";
+
+            if ($enable_forward_v6) {
+                push @iface_config,
+                    "post-up echo 1 > /proc/sys/net/ipv6/conf/$brvrf/force_forwarding";
+                push @iface_config,
+                    "post-down echo 0 > /proc/sys/net/ipv6/conf/$brvrf/force_forwarding";
+            }
             push(@{ $config->{$brvrf} }, @iface_config) if !$config->{$brvrf};
         }
 
diff --git a/src/test/zones/evpn/exitnode_local_routing_ipv6/expected_sdn_interfaces b/src/test/zones/evpn/exitnode_local_routing_ipv6/expected_sdn_interfaces
index b46d4e7..7b8dc3c 100644
--- a/src/test/zones/evpn/exitnode_local_routing_ipv6/expected_sdn_interfaces
+++ b/src/test/zones/evpn/exitnode_local_routing_ipv6/expected_sdn_interfaces
@@ -8,6 +8,10 @@ iface myvnet
 	bridge_fd 0
 	mtu 1450
 	ip6-forward on
+	post-up echo 1 > /proc/sys/net/ipv6/conf/myvnet/force_forwarding
+	post-down echo 0 > /proc/sys/net/ipv6/conf/myvnet/force_forwarding
+	post-up echo 1 > /proc/sys/net/ipv6/conf/vmbr0/force_forwarding
+	post-down echo 0 > /proc/sys/net/ipv6/conf/vmbr0/force_forwarding
 	arp-accept on
 	vrf vrf_myzone
 
@@ -23,6 +27,8 @@ iface vrfbr_myzone
 	bridge_fd 0
 	mtu 1450
 	vrf vrf_myzone
+	post-up echo 1 > /proc/sys/net/ipv6/conf/vrfbr_myzone/force_forwarding
+	post-down echo 0 > /proc/sys/net/ipv6/conf/vrfbr_myzone/force_forwarding
 
 auto vrfvx_myzone
 iface vrfvx_myzone
diff --git a/src/test/zones/evpn/exitnode_snat/expected_sdn_interfaces b/src/test/zones/evpn/exitnode_snat/expected_sdn_interfaces
index 0d7d174..2addde0 100644
--- a/src/test/zones/evpn/exitnode_snat/expected_sdn_interfaces
+++ b/src/test/zones/evpn/exitnode_snat/expected_sdn_interfaces
@@ -27,6 +27,10 @@ iface myvnet2
 	bridge_fd 0
 	mtu 1450
 	ip6-forward on
+	post-up echo 1 > /proc/sys/net/ipv6/conf/myvnet2/force_forwarding
+	post-down echo 0 > /proc/sys/net/ipv6/conf/myvnet2/force_forwarding
+	post-up echo 1 > /proc/sys/net/ipv6/conf/vmbr0/force_forwarding
+	post-down echo 0 > /proc/sys/net/ipv6/conf/vmbr0/force_forwarding
 	arp-accept on
 	vrf vrf_myzone
 
diff --git a/src/test/zones/evpn/exitnodenullroute/expected_sdn_interfaces b/src/test/zones/evpn/exitnodenullroute/expected_sdn_interfaces
index 4bf5ccf..e406258 100644
--- a/src/test/zones/evpn/exitnodenullroute/expected_sdn_interfaces
+++ b/src/test/zones/evpn/exitnodenullroute/expected_sdn_interfaces
@@ -14,6 +14,10 @@ iface myvnet
 	mtu 1450
 	ip-forward on
 	ip6-forward on
+	post-up echo 1 > /proc/sys/net/ipv6/conf/myvnet/force_forwarding
+	post-down echo 0 > /proc/sys/net/ipv6/conf/myvnet/force_forwarding
+	post-up echo 1 > /proc/sys/net/ipv6/conf/vmbr0/force_forwarding
+	post-down echo 0 > /proc/sys/net/ipv6/conf/vmbr0/force_forwarding
 	arp-accept on
 	vrf vrf_myzone
 
@@ -47,6 +51,8 @@ iface vrfbr_myzone
 	bridge_fd 0
 	mtu 1450
 	vrf vrf_myzone
+	post-up echo 1 > /proc/sys/net/ipv6/conf/vrfbr_myzone/force_forwarding
+	post-down echo 0 > /proc/sys/net/ipv6/conf/vrfbr_myzone/force_forwarding
 
 auto vrfbr_myzone2
 iface vrfbr_myzone2
diff --git a/src/test/zones/evpn/ipv4ipv6/expected_sdn_interfaces b/src/test/zones/evpn/ipv4ipv6/expected_sdn_interfaces
index 7a5d741..a1fdb2b 100644
--- a/src/test/zones/evpn/ipv4ipv6/expected_sdn_interfaces
+++ b/src/test/zones/evpn/ipv4ipv6/expected_sdn_interfaces
@@ -11,6 +11,8 @@ iface myvnet
 	mtu 1450
 	ip-forward on
 	ip6-forward on
+	post-up echo 1 > /proc/sys/net/ipv6/conf/myvnet/force_forwarding
+	post-down echo 0 > /proc/sys/net/ipv6/conf/myvnet/force_forwarding
 	arp-accept on
 	vrf vrf_myzone
 
@@ -26,6 +28,8 @@ iface vrfbr_myzone
 	bridge_fd 0
 	mtu 1450
 	vrf vrf_myzone
+	post-up echo 1 > /proc/sys/net/ipv6/conf/vrfbr_myzone/force_forwarding
+	post-down echo 0 > /proc/sys/net/ipv6/conf/vrfbr_myzone/force_forwarding
 
 auto vrfvx_myzone
 iface vrfvx_myzone
diff --git a/src/test/zones/evpn/ipv6/expected_sdn_interfaces b/src/test/zones/evpn/ipv6/expected_sdn_interfaces
index b2bdbfe..4363842 100644
--- a/src/test/zones/evpn/ipv6/expected_sdn_interfaces
+++ b/src/test/zones/evpn/ipv6/expected_sdn_interfaces
@@ -9,6 +9,8 @@ iface myvnet
 	bridge_fd 0
 	mtu 1450
 	ip6-forward on
+	post-up echo 1 > /proc/sys/net/ipv6/conf/myvnet/force_forwarding
+	post-down echo 0 > /proc/sys/net/ipv6/conf/myvnet/force_forwarding
 	arp-accept on
 	vrf vrf_myzone
 
@@ -24,6 +26,8 @@ iface vrfbr_myzone
 	bridge_fd 0
 	mtu 1450
 	vrf vrf_myzone
+	post-up echo 1 > /proc/sys/net/ipv6/conf/vrfbr_myzone/force_forwarding
+	post-down echo 0 > /proc/sys/net/ipv6/conf/vrfbr_myzone/force_forwarding
 
 auto vrfvx_myzone
 iface vrfvx_myzone
diff --git a/src/test/zones/evpn/ipv6underlay/expected_sdn_interfaces b/src/test/zones/evpn/ipv6underlay/expected_sdn_interfaces
index 3b91f75..7aaf569 100644
--- a/src/test/zones/evpn/ipv6underlay/expected_sdn_interfaces
+++ b/src/test/zones/evpn/ipv6underlay/expected_sdn_interfaces
@@ -9,6 +9,8 @@ iface myvnet
 	bridge_fd 0
 	mtu 1450
 	ip6-forward on
+	post-up echo 1 > /proc/sys/net/ipv6/conf/myvnet/force_forwarding
+	post-down echo 0 > /proc/sys/net/ipv6/conf/myvnet/force_forwarding
 	arp-accept on
 	vrf vrf_myzone
 
@@ -24,6 +26,8 @@ iface vrfbr_myzone
 	bridge_fd 0
 	mtu 1450
 	vrf vrf_myzone
+	post-up echo 1 > /proc/sys/net/ipv6/conf/vrfbr_myzone/force_forwarding
+	post-down echo 0 > /proc/sys/net/ipv6/conf/vrfbr_myzone/force_forwarding
 
 auto vrfvx_myzone
 iface vrfvx_myzone
-- 
2.47.3





  reply	other threads:[~2026-07-27 13:55 UTC|newest]

Thread overview: 7+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-07-27 13:55 [PATCH docs/manager/network/perl-rs v4 0/6] sdn: enable force_forwarding for ipv6 forwarding Lukas Sichert
2026-07-27 13:55 ` Lukas Sichert [this message]
2026-07-27 13:55 ` [PATCH network v4 2/6] sdn: simple: enable force_forwarding for ipv6 forwarding to subnets Lukas Sichert
2026-07-27 13:55 ` [PATCH perl-rs v4 3/6] fabrics: openfabric: enable force_forwarding for ipv6 transit traffic Lukas Sichert
2026-07-27 13:55 ` [PATCH perl-rs v4 4/6] fabrics: bgp: " Lukas Sichert
2026-07-27 13:55 ` [PATCH manager v4 5/6] ui: sdn: remove IPv6 forwarding hint from fabric edit window Lukas Sichert
2026-07-27 13:55 ` [PATCH docs v4 6/6] sdn: drop global ipv6 forwarding workaround from OpenFabric docs Lukas Sichert

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260727135509.14588-2-l.sichert@proxmox.com \
    --to=l.sichert@proxmox.com \
    --cc=pve-devel@lists.proxmox.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.
Service provided by Proxmox Server Solutions GmbH | Privacy | Legal