Hello, Yes, this call is supposed to route locally generated packets after daddr is translated by Netfilter. But IPVS uses LOCAL_OUT hook to post packets to real servers. If you use DR method, daddr
Hi, This priority number does not look correct, this should be -100 which is NF_IP_PRI_NAT_DST (in recent nftables versions you can use: ... priority dstnat; Why do you need DNAT in this case? In the
I had some time to set up some test VMs for this, which I can post if you'd like (several GB), or I can tarball up the configs. Our setup still doesn't work in 5.15, and we have some LVS servers held
$ext_ip is something reachable from the "outside"; it just has to be something which can get to the nft box that isn't the real server or the same host. We have a public IP in this case. $vip is some
Hello! We have been successfully using nft dnat and IPVS in DR mode on 4.9, 4.14 kernels, but since upgrading to 4.19, such rules now appear to miss the IPVS input hook and instead appear to hit loca