From: Hannes Laimer <h.laimer@proxmox.com>
To: Lukas Sichert <l.sichert@proxmox.com>
Cc: pve-devel@lists.proxmox.com
Subject: Re: [PATCH docs/manager/network/perl-rs v4 0/6] sdn: enable force_forwarding for ipv6 forwarding
Date: Mon, 24 Aug 2026 09:33:17 +0200 [thread overview]
Message-ID: <aovyl-alOe35QR7X@nana.intra.proxmox.com> (raw)
In-Reply-To: <20260727135509.14588-1-l.sichert@proxmox.com>
Generally this works well, and is a very solid improvment over what we
currently have. Aside from the comments on the patches, it looks like
some tests need updating :P
```
modified: src/test/zones/evpn/bgp_fabric/expected_sdn_interfaces
modified: src/test/zones/evpn/openfabric_fabric_ipv6/expected_sdn_interfaces
modified: src/test/zones/evpn/openfabric_fabric_ipv6_only/expected_sdn_interfaces
```
On 2026-07-27 15:55, Lukas Sichert wrote:
> Gabriel's upstream kernel patch [1] added
> net.ipv6.conf.<iface>.force_forwarding. This allows enabling IPv6
> forwarding on selected interfaces without requiring
> net.ipv6.conf.all.forwarding.
>
> This is useful for SDN setups because all.forwarding has host-wide side
> effects. In particular, it disables Router Advertisement processing by
> default, which can break SLAAC on unrelated interfaces. SDN only needs
> forwarding on the VNet, exit-node, or fabric interfaces that participate
> in routed IPv6 traffic.
>
> This series generates ifupdown post-up/post-down commands for those
> interfaces so force_forwarding is enabled when the interface is brought
> up and reset when it is brought down. /network/interfaces.d/sdn gets
> regenerated on SDN Apply. This means that removing a VNet also removes
> the corresponding 'post-down' commands configured to the interface of
> the VNet. Therefore it cannot happen, that deleting one VNet in the GUI
> removes force_forwarding on the outgoing interfaces, which might be used
> by other VNets as well. The tests are adjusted for the generated
> /etc/network/interfaces.d/sdn output. Also the series rewrites the
> documentation to reflect the updated behaviour and removes the UI warning
> to enable 'all.forwarding'.
>
>
> [1] lkml.org/lkml/2025/7/7/577
>
> changes from v3 to v4 (thanks @Stefan):
> -wrap resolving outgoing interface in eval block
> -remove unnecessary 'ip6-forward' for vrfbr interface
> -Drop the fabric edit GUI hint that told users to enable
> net.ipv6.conf.all.forwarding
> -remove whitespace formatting changes
>
> changes from v2 to v3 (thanks @Gabriel):
> -Move the IPv6 force_forwarding post-up/post-down commands out of the
> subnet loop, so they are generated only once for the VNet instead of
> once per subnet.
> -Enable ip6-forward and force_forwarding on EVPN L3VNI VRF bridge
> interfaces, fixing IPv6 forwarding when traffic exits through another
> node.
>
> changes from v1 to v2 (thanks @Gabriel, @Hannes):
> -add force_forwarding also to bgp fabrics
> -explicitly mention the force_forwarding flag in the documentation
> -add a reference link to the sysctl documentation
> -mention bgp as a fabric with ipv6 support
>
>
> network:
>
> Lukas Sichert (2):
> sdn: evpn: enable force_forwarding for ipv6 forwarding to subnets
> sdn: simple: enable force_forwarding for ipv6 forwarding to subnets
>
> src/PVE/Network/SDN/Zones/EvpnPlugin.pm | 34 ++++++++++++++++++-
> src/PVE/Network/SDN/Zones/SimplePlugin.pm | 25 +++++++++++++-
> .../expected_sdn_interfaces | 6 ++++
> .../exitnode_snat/expected_sdn_interfaces | 4 +++
> .../exitnodenullroute/expected_sdn_interfaces | 6 ++++
> .../evpn/ipv4ipv6/expected_sdn_interfaces | 4 +++
> .../zones/evpn/ipv6/expected_sdn_interfaces | 4 +++
> .../evpn/ipv6underlay/expected_sdn_interfaces | 4 +++
> .../simple/ipv4v6/expected_sdn_interfaces | 4 +++
> .../simple/ipv6snat/expected_sdn_interfaces | 4 +++
> 10 files changed, 93 insertions(+), 2 deletions(-)
>
>
> perl-rs:
>
> Lukas Sichert (2):
> fabrics: openfabric: enable force_forwarding for ipv6 transit traffic
> fabrics: bgp: enable force_forwarding for ipv6 transit traffic
>
> pve-rs/src/bindings/sdn/fabrics.rs | 18 ++++++++++++++++++
> 1 file changed, 18 insertions(+)
>
>
> manager:
>
> Lukas Sichert (1):
> ui: sdn: remove IPv6 forwarding hint from fabric edit window
>
> www/manager6/sdn/fabrics/FabricEdit.js | 59 +++++++++-----------------
> 1 file changed, 20 insertions(+), 39 deletions(-)
>
>
> docs:
>
> Lukas Sichert (1):
> sdn: drop global ipv6 forwarding workaround from OpenFabric docs
>
> pvesdn.adoc | 21 +++++----------------
> 1 file changed, 5 insertions(+), 16 deletions(-)
>
>
> Summary over all repositories:
> 13 files changed, 136 insertions(+), 57 deletions(-)
>
> --
> Generated by murpp 0.12.0
>
>
>
>
prev parent reply other threads:[~2026-08-24 7:33 UTC|newest]
Thread overview: 10+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-07-27 13:55 [PATCH docs/manager/network/perl-rs v4 0/6] sdn: enable force_forwarding for ipv6 forwarding Lukas Sichert
2026-07-27 13:55 ` [PATCH network v4 1/6] sdn: evpn: enable force_forwarding for ipv6 forwarding to subnets Lukas Sichert
2026-08-24 7:23 ` Hannes Laimer
2026-07-27 13:55 ` [PATCH network v4 2/6] sdn: simple: " Lukas Sichert
2026-07-27 13:55 ` [PATCH perl-rs v4 3/6] fabrics: openfabric: enable force_forwarding for ipv6 transit traffic Lukas Sichert
2026-08-24 7:27 ` Hannes Laimer
2026-07-27 13:55 ` [PATCH perl-rs v4 4/6] fabrics: bgp: " Lukas Sichert
2026-07-27 13:55 ` [PATCH manager v4 5/6] ui: sdn: remove IPv6 forwarding hint from fabric edit window Lukas Sichert
2026-07-27 13:55 ` [PATCH docs v4 6/6] sdn: drop global ipv6 forwarding workaround from OpenFabric docs Lukas Sichert
2026-08-24 7:33 ` Hannes Laimer [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=aovyl-alOe35QR7X@nana.intra.proxmox.com \
--to=h.laimer@proxmox.com \
--cc=l.sichert@proxmox.com \
--cc=pve-devel@lists.proxmox.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox