Keepalived direct routing (DSR) with nftables fails to pass client's FIN to real backend
Issue
- Connections are left in
FIN_WAIT1
orESTABLISHED
on real backend whennftables
is used inkeepalived
with direct routing configuration
Environment
- Red Hat Enterprise Linux 8 (RHEL8)
nftables
keepalived
using direct routing (a.k.a direct server response, DSR)
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.