Hacker Newsnew | past | comments | ask | show | jobs | submitlogin
Learning about Linux fwmark masks (utcc.utoronto.ca)
38 points by zdw on Feb 14, 2023 | hide | past | favorite | 1 comment


Had to learn about these the hard way when trying to set up a Wireguard tunnel on machines that are also Kubernetes nodes.

Turns out that kubernetes (specifically flannel? I forget exactly) aggressively colonizes half of the fwmark namespace, and Wireguard was trying to use a value in that range. For a non networking guy that was hard to figure out.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: