Back to bug 2039844

Who When What Removed Added
Red Hat Bugzilla 2022-01-12 14:29:17 UTC Pool ID sst_networking_rhel_9
RHEL Program Management 2022-01-12 14:29:24 UTC CC bstinson, jwboyer
Red Hat One Jira (issues.redhat.com) 2022-01-12 14:31:31 UTC Link ID Red Hat Issue Tracker RHELPLAN-107590
Red Hat Bugzilla 2022-02-22 05:41:42 UTC CC atragler
Till Maas 2022-04-07 10:27:37 UTC Flags needinfo?(irlapati)
Doc Type --- If docs needed, set a value
Thomas Haller 2022-04-07 10:43:11 UTC CC thaller
Sam Irlapati 2022-05-20 02:06:58 UTC Flags needinfo?(irlapati)
Sam Irlapati 2022-11-15 14:39:22 UTC CC sfaye
Keywords Triaged
Flags needinfo?(irlapati)
Flags needinfo?(irlapati)
Red Hat Bugzilla 2022-12-12 12:28:24 UTC Priority unspecified low
Doc Type If docs needed, set a value No Doc Update
Doc Type No Doc Update No Doc Update
Red Hat One Jira (issues.redhat.com) 2023-01-20 11:51:20 UTC Link ID Red Hat Issue Tracker NMT-16
Seth Goldin 2023-02-11 01:55:07 UTC CC seth
Vladimir Benes 2023-07-13 13:27:07 UTC Pool ID sst_networking_core_rhel_9 sst_network_management_rhel_9
Assignee nm-team fge
CC vbenes
Gris Ge 2023-07-24 09:10:20 UTC Flags needinfo?(irlapati)
Sam Irlapati 2023-07-26 04:20:04 UTC Flags needinfo?(irlapati)
Gris Ge 2023-07-27 11:05:47 UTC Flags needinfo?(irlapati)
Gris Ge 2023-07-27 11:18:10 UTC Doc Type No Doc Update Known Issue
Doc Text Cause: The default setting of IPv4 `rp_filter` 2(strict) will block wireguard connection when using fwmark based source routing rule.

Consequence: The wireguard connection with `wireguard.fwmark` and external IPv4 peer in NetworkManager will not work.

Workaround (if any):

By changing the `rp_filter` from 2 to 1 or 0 could resolve the problem.

Assuming the `eth1` is the interface for wireguard outgoing network flow, you may change the `rp_filter` via command:

sysctl -w net.ipv4.conf.eth1.rp_filter=1

To persistent this change, you may create `/etc/sysctl.d/99-wireguard.conf` with content of

net.ipv4.conf.eth1.rp_filter=1


Result: The wireguard connection activated as expected.
Sam Irlapati 2023-07-27 14:04:28 UTC Flags needinfo?(irlapati)
Fernando F. Mancera 2023-07-28 15:57:13 UTC CC ferferna
Assignee fge ferferna
Fernando F. Mancera 2023-07-31 09:42:53 UTC Status NEW CLOSED
Resolution --- WONTFIX
Last Closed 2023-07-31 09:42:53 UTC
Neal Gompa 2023-08-01 05:04:45 UTC CC ngompa13

Back to bug 2039844