Skip to content

Conversation

@bazuchan
Copy link
Contributor

No description provided.

@murali-reddy
Copy link
Member

@bazuchan Sorry I am not sure what the problem is. Could you please open an issue and link to this PR or add some description?

Why do we need that rule in OUTPUT chain, the one in PREROUTING should apply to both the cases?

@bazuchan
Copy link
Contributor Author

When a local process on a node (or host-networked pod) originates connection to tunneled service, it's packets doesn't go through PREROUTING chain. You can see it on this chart https://en.wikipedia.org/wiki/Netfilter#/media/File:Netfilter-packet-flow.svg. So it doesn't get fwmark-ed and doesn't get routed to IPVS.

@murali-reddy
Copy link
Member

got it. LGTM. thanks.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants