Files
puppet-prod/hieradata/roles/infra
unkin-agent b74bced771 Persist rp_filter=0 on every router interface (#539)
Effective rp_filter is max(all, <iface>). Setting `all`/`default` to 0 is not enough after a reboot: `/usr/lib/sysctl.d/50-redhat.conf` sets `net.ipv4.conf.*.rp_filter = 1`, which udev applies to every interface as it is created, so routed asymmetric traffic gets dropped once shorewall goes.

- add `net.ipv4.conf.*.rp_filter: 0` to the router role, overriding the vendor glob
- disable `enforce` for it, since `sysctl -n` cannot read glob keys

Reviewed-on: #539
Co-authored-by: unkin-agent <unkin-agent@unkin.net>
Co-committed-by: unkin-agent <unkin-agent@unkin.net>
2026-10-04 16:02:00 +11:00
..
2025-05-21 19:58:12 +10:00
2025-07-05 15:51:28 +10:00
2026-04-06 22:46:40 +10:00
2024-08-31 23:00:58 +10:00
2024-06-02 19:23:39 +10:00
2024-10-27 13:26:07 +11:00
2023-11-17 23:12:37 +11:00
2024-08-25 02:14:35 +10:00
2024-06-19 22:36:04 +10:00