From: Hannes Laimer <h.laimer@proxmox.com>
To: Lukas Sichert <l.sichert@proxmox.com>
Cc: pve-devel@lists.proxmox.com
Subject: Re: [PATCH docs/manager/network/perl-rs v4 0/6] sdn: enable force_forwarding for ipv6 forwarding
Date: Mon, 24 Aug 2026 09:33:17 +0200 [thread overview]
Message-ID: <aovyl-alOe35QR7X@nana.intra.proxmox.com> (raw)
In-Reply-To: <20260727135509.14588-1-l.sichert@proxmox.com>
Generally this works well, and is a very solid improvment over what we
currently have. Aside from the comments on the patches, it looks like
some tests need updating :P
```
modified: src/test/zones/evpn/bgp_fabric/expected_sdn_interfaces
modified: src/test/zones/evpn/openfabric_fabric_ipv6/expected_sdn_interfaces
modified: src/test/zones/evpn/openfabric_fabric_ipv6_only/expected_sdn_interfaces
```
On 2026-07-27 15:55, Lukas Sichert wrote:
> Gabriel's upstream kernel patch [1] added
> net.ipv6.conf.<iface>.force_forwarding. This allows enabling IPv6
> forwarding on selected interfaces without requiring
> net.ipv6.conf.all.forwarding.
>
> This is useful for SDN setups because all.forwarding has host-wide side
> effects. In particular, it disables Router Advertisement processing by
> default, which can break SLAAC on unrelated interfaces. SDN only needs
> forwarding on the VNet, exit-node, or fabric interfaces that participate
> in routed IPv6 traffic.
>
> This series generates ifupdown post-up/post-down commands for those
> interfaces so force_forwarding is enabled when the interface is brought
> up and reset when it is brought down. /network/interfaces.d/sdn gets
> regenerated on SDN Apply. This means that removing a VNet also removes
> the corresponding 'post-down' commands configured to the interface of
> the VNet. Therefore it cannot happen, that deleting one VNet in the GUI
> removes force_forwarding on the outgoing interfaces, which might be used
> by other VNets as well. The tests are adjusted for the generated
> /etc/network/interfaces.d/sdn output. Also the series rewrites the
> documentation to reflect the updated behaviour and removes the UI warning
> to enable 'all.forwarding'.
>
>
> [1] lkml.org/lkml/2025/7/7/577
>
> changes from v3 to v4 (thanks @Stefan):
> -wrap resolving outgoing interface in eval block
> -remove unnecessary 'ip6-forward' for vrfbr interface
> -Drop the fabric edit GUI hint that told users to enable
> net.ipv6.conf.all.forwarding
> -remove whitespace formatting changes
>
> changes from v2 to v3 (thanks @Gabriel):
> -Move the IPv6 force_forwarding post-up/post-down commands out of the
> subnet loop, so they are generated only once for the VNet instead of
> once per subnet.
> -Enable ip6-forward and force_forwarding on EVPN L3VNI VRF bridge
> interfaces, fixing IPv6 forwarding when traffic exits through another
> node.
>
> changes from v1 to v2 (thanks @Gabriel, @Hannes):
> -add force_forwarding also to bgp fabrics
> -explicitly mention the force_forwarding flag in the documentation
> -add a reference link to the sysctl documentation
> -mention bgp as a fabric with ipv6 support
>
>
> network:
>
> Lukas Sichert (2):
> sdn: evpn: enable force_forwarding for ipv6 forwarding to subnets
> sdn: simple: enable force_forwarding for ipv6 forwarding to subnets
>
> src/PVE/Network/SDN/Zones/EvpnPlugin.pm | 34 ++++++++++++++++++-
> src/PVE/Network/SDN/Zones/SimplePlugin.pm | 25 +++++++++++++-
> .../expected_sdn_interfaces | 6 ++++
> .../exitnode_snat/expected_sdn_interfaces | 4 +++
> .../exitnodenullroute/expected_sdn_interfaces | 6 ++++
> .../evpn/ipv4ipv6/expected_sdn_interfaces | 4 +++
> .../zones/evpn/ipv6/expected_sdn_interfaces | 4 +++
> .../evpn/ipv6underlay/expected_sdn_interfaces | 4 +++
> .../simple/ipv4v6/expected_sdn_interfaces | 4 +++
> .../simple/ipv6snat/expected_sdn_interfaces | 4 +++
> 10 files changed, 93 insertions(+), 2 deletions(-)
>
>
> perl-rs:
>
> Lukas Sichert (2):
> fabrics: openfabric: enable force_forwarding for ipv6 transit traffic
> fabrics: bgp: enable force_forwarding for ipv6 transit traffic
>
> pve-rs/src/bindings/sdn/fabrics.rs | 18 ++++++++++++++++++
> 1 file changed, 18 insertions(+)
>
>
> manager:
>
> Lukas Sichert (1):
> ui: sdn: remove IPv6 forwarding hint from fabric edit window
>
> www/manager6/sdn/fabrics/FabricEdit.js | 59 +++++++++-----------------
> 1 file changed, 20 insertions(+), 39 deletions(-)
>
>
> docs:
>
> Lukas Sichert (1):
> sdn: drop global ipv6 forwarding workaround from OpenFabric docs
>
> pvesdn.adoc | 21 +++++----------------
> 1 file changed, 5 insertions(+), 16 deletions(-)
>
>
> Summary over all repositories:
> 13 files changed, 136 insertions(+), 57 deletions(-)
>
> --
> Generated by murpp 0.12.0
>
>
>
>
prev parent reply other threads:[~2026-08-24 7:33 UTC|newest]
Thread overview: 10+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-07-27 13:55 [PATCH docs/manager/network/perl-rs v4 0/6] sdn: enable force_forwarding for ipv6 forwarding Lukas Sichert
2026-07-27 13:55 ` [PATCH network v4 1/6] sdn: evpn: enable force_forwarding for ipv6 forwarding to subnets Lukas Sichert
2026-08-24 7:23 ` Hannes Laimer
2026-07-27 13:55 ` [PATCH network v4 2/6] sdn: simple: " Lukas Sichert
2026-07-27 13:55 ` [PATCH perl-rs v4 3/6] fabrics: openfabric: enable force_forwarding for ipv6 transit traffic Lukas Sichert
2026-08-24 7:27 ` Hannes Laimer
2026-07-27 13:55 ` [PATCH perl-rs v4 4/6] fabrics: bgp: " Lukas Sichert
2026-07-27 13:55 ` [PATCH manager v4 5/6] ui: sdn: remove IPv6 forwarding hint from fabric edit window Lukas Sichert
2026-07-27 13:55 ` [PATCH docs v4 6/6] sdn: drop global ipv6 forwarding workaround from OpenFabric docs Lukas Sichert
2026-08-24 7:33 ` Hannes Laimer [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=aovyl-alOe35QR7X@nana.intra.proxmox.com \
--to=h.laimer@proxmox.com \
--cc=l.sichert@proxmox.com \
--cc=pve-devel@lists.proxmox.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.