Skip to content

Encrypted load-balancer IPs broken on certain devices over a wireguard tunnel. #1995

@anthr76

Description

@anthr76

This issue will need to be updated with some further info and is opened to track my evidence in this issue to report it upstream.

With direct routing and kube proxy replacement enabled on Cilium certain devices cannot connect over a wireguard tunnel managed externally from cilium. MTU is set to really low levels to make it work on some devices (1280). Along with adjusting mss

In order to avoid this "oddness" I've temporarily disabled both until I have more time to investigate and deployed kube-proxy.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions