Skip to content

How can I avoid VRRP packet sending failure when hot loading firewall? #2322

Answered by pqarmitage
qqliuxiaoran asked this question in Q&A
Discussion options

You must be logged in to vote

@qqliuxiaoran Is it possible to make the backup machine reload the firewall configuration immediately after the rsync, rather than waiting for the backup machine switching to MASTER state? The problem seems to be reloading the firewall configuration at the same time as transitioning to master.

We have in the past seen problems with systems not being able to receive VRRP adverts until they become master and send an advert; once they have sent an advert, they can start receiving them and if they are lower priority than the true master, they then revert to backup state. This appears to be due to their initially being no conntrack entry for the VRRP adverts, and only once an entry has been cr…

Replies: 2 comments 2 replies

Comment options

You must be logged in to vote
1 reply
@qqliuxiaoran
Comment options

Comment options

You must be logged in to vote
1 reply
@qqliuxiaoran
Comment options

Answer selected by qqliuxiaoran
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants