b74bced771da83b194baaca8f40a9486dff4e503
Effective rp_filter is max(all, <iface>). Setting `all`/`default` to 0 is not enough after a reboot: `/usr/lib/sysctl.d/50-redhat.conf` sets `net.ipv4.conf.*.rp_filter = 1`, which udev applies to every interface as it is created, so routed asymmetric traffic gets dropped once shorewall goes. - add `net.ipv4.conf.*.rp_filter: 0` to the router role, overriding the vendor glob - disable `enforce` for it, since `sysctl -n` cannot read glob keys Reviewed-on: #539 Co-authored-by: unkin-agent <unkin-agent@unkin.net> Co-committed-by: unkin-agent <unkin-agent@unkin.net>
Description
production puppet-control repository
Languages
Puppet
66.5%
HTML
27.6%
Ruby
5.9%