Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Encrypted load-balancer IPs broken on certain devices over a wireguard tunnel. #1995

Open
anthr76 opened this issue Jan 9, 2023 · 0 comments

Comments

@anthr76
Copy link
Owner

anthr76 commented Jan 9, 2023

This issue will need to be updated with some further info and is opened to track my evidence in this issue to report it upstream.

With direct routing and kube proxy replacement enabled on Cilium certain devices cannot connect over a wireguard tunnel managed externally from cilium. MTU is set to really low levels to make it work on some devices (1280). Along with adjusting mss

In order to avoid this "oddness" I've temporarily disabled both until I have more time to investigate and deployed kube-proxy.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant