Files

30 lines
36 KiB
HTML
Raw Permalink Blame History

This file contains invisible Unicode characters
This file contains invisible Unicode characters that are indistinguishable to humans but may be processed differently by a computer. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
<!doctype html>
<html lang="en" dir="ltr" class="docs-wrapper docs-doc-page docs-version-current plugin-docs plugin-id-default docs-doc-id-troubleshooting/other-troubleshooting-tips/networking" data-has-hydrated="false">
<head>
<meta charset="UTF-8">
<meta name="generator" content="Docusaurus v2.4.3">
<title data-rh="true">Networking | Rancher</title><meta data-rh="true" name="viewport" content="width=device-width,initial-scale=1"><meta data-rh="true" name="twitter:card" content="summary_large_image"><meta data-rh="true" property="og:url" content="https://ranchermanager.docs.rancher.com/troubleshooting/other-troubleshooting-tips/networking"><meta data-rh="true" name="docusaurus_locale" content="en"><meta data-rh="true" name="docsearch:language" content="en"><meta data-rh="true" name="docusaurus_version" content="current"><meta data-rh="true" name="docusaurus_tag" content="docs-default-current"><meta data-rh="true" name="docsearch:version" content="current"><meta data-rh="true" name="docsearch:docusaurus_tag" content="docs-default-current"><meta data-rh="true" property="og:title" content="Networking | Rancher"><meta data-rh="true" name="description" content="The commands/steps listed on this page can be used to check networking related issues in your cluster."><meta data-rh="true" property="og:description" content="The commands/steps listed on this page can be used to check networking related issues in your cluster."><link data-rh="true" rel="icon" href="/img/favicon.png"><link data-rh="true" rel="alternate" href="https://ranchermanager.docs.rancher.com/troubleshooting/other-troubleshooting-tips/networking" hreflang="en"><link data-rh="true" rel="alternate" href="https://ranchermanager.docs.rancher.com/zh/troubleshooting/other-troubleshooting-tips/networking" hreflang="zh"><link data-rh="true" rel="alternate" href="https://ranchermanager.docs.rancher.com/troubleshooting/other-troubleshooting-tips/networking" hreflang="x-default"><link data-rh="true" rel="preconnect" href="https://30NEY6C9UY-dsn.algolia.net" crossorigin="anonymous"><link data-rh="true" rel="canonical" href="https://ranchermanager.docs.rancher.com/troubleshooting/other-troubleshooting-tips/networking"><link rel="preconnect" href="https://www.googletagmanager.com">
<script>window.dataLayer=window.dataLayer||[]</script>
<script>!function(e,t,a,n,g){e[n]=e[n]||[],e[n].push({"gtm.start":(new Date).getTime(),event:"gtm.js"});var m=t.getElementsByTagName(a)[0],r=t.createElement(a);r.async=!0,r.src="https://www.googletagmanager.com/gtm.js?id=GTM-57KS2MW",m.parentNode.insertBefore(r,m)}(window,document,"script","dataLayer")</script>
<link rel="search" type="application/opensearchdescription+xml" title="Rancher" href="/opensearch.xml">
<script src="https://cdn.cookielaw.org/scripttemplates/otSDKStub.js" charset="UTF-8" data-domain-script="0f98beb0-fc4c-417d-a42e-564e2cae42d2" async></script>
<script src="/scripts/optanonwrapper.js" async></script><link rel="stylesheet" href="/assets/css/styles.dea80607.css">
<link rel="preload" href="/assets/js/runtime~main.d98f8a34.js" as="script">
<link rel="preload" href="/assets/js/main.e9ebdfba.js" as="script">
</head>
<body class="navigation-with-keyboard">
<noscript><iframe src="https://www.googletagmanager.com/ns.html?id=GTM-57KS2MW" height="0" width="0" style="display:none;visibility:hidden"></iframe></noscript>
<script>!function(){function t(t){document.documentElement.setAttribute("data-theme",t)}var e=function(){var t=null;try{t=new URLSearchParams(window.location.search).get("docusaurus-theme")}catch(t){}return t}()||function(){var t=null;try{t=localStorage.getItem("theme")}catch(t){}return t}();t(null!==e?e:"light")}()</script><div id="__docusaurus">
<div role="region" aria-label="Skip to main content"><a class="skipToContent_fXgn" href="#__docusaurus_skipToContent_fallback">Skip to main content</a></div><nav aria-label="Main" class="navbar navbar--fixed-top"><div class="navbar__inner"><div class="navbar__items"><button aria-label="Toggle navigation bar" aria-expanded="false" class="navbar__toggle clean-btn" type="button"><svg width="30" height="30" viewBox="0 0 30 30" aria-hidden="true"><path stroke="currentColor" stroke-linecap="round" stroke-miterlimit="10" stroke-width="2" d="M4 7h22M4 15h22M4 23h22"></path></svg></button><a class="navbar__brand" href="/"><div class="navbar__logo"><img src="/img/rancher-logo-horiz-color.svg" alt="logo" class="themedImage_ToTc themedImage--light_HNdA"><img src="/img/rancher-logo-horiz-color.svg" alt="logo" class="themedImage_ToTc themedImage--dark_i4oU"></div><b class="navbar__title text--truncate"></b></a><div class="navbar__item dropdown dropdown--hoverable"><a aria-current="page" class="navbar__link active" aria-haspopup="true" aria-expanded="false" role="button" href="/">Latest</a><ul class="dropdown__menu"><li><a aria-current="page" class="dropdown__link dropdown__link--active" href="/troubleshooting/other-troubleshooting-tips/networking">Latest</a></li><li><a class="dropdown__link" href="/v2.9/troubleshooting/other-troubleshooting-tips/networking">v2.9 (Preview)</a></li><li><a class="dropdown__link" href="/v2.8/troubleshooting/other-troubleshooting-tips/networking">v2.8</a></li><li><a class="dropdown__link" href="/v2.7/troubleshooting/other-troubleshooting-tips/networking">v2.7</a></li><li><a class="dropdown__link" href="/v2.6/troubleshooting/other-troubleshooting-tips/networking">v2.6</a></li><li><a class="dropdown__link" href="/v2.5/troubleshooting/other-troubleshooting-tips/networking">v2.5</a></li><li><a class="dropdown__link" href="/v2.0-v2.4/troubleshooting/other-troubleshooting-tips/networking">v2.0-v2.4</a></li><li><a class="dropdown__link" href="/versions">All versions</a></li></ul></div><div class="navbar__item dropdown dropdown--hoverable"><a href="#" aria-haspopup="true" aria-expanded="false" role="button" class="navbar__link"><svg viewBox="0 0 24 24" width="20" height="20" aria-hidden="true" class="iconLanguage_nlXk"><path fill="currentColor" d="M12.87 15.07l-2.54-2.51.03-.03c1.74-1.94 2.98-4.17 3.71-6.53H17V4h-7V2H8v2H1v1.99h11.17C11.5 7.92 10.44 9.75 9 11.35 8.07 10.32 7.3 9.19 6.69 8h-2c.73 1.63 1.73 3.17 2.98 4.56l-5.09 5.02L4 19l5-5 3.11 3.11.76-2.04zM18.5 10h-2L12 22h2l1.12-3h4.75L21 22h2l-4.5-12zm-2.62 7l1.62-4.33L19.12 17h-3.24z"></path></svg>English</a><ul class="dropdown__menu"><li><a href="/troubleshooting/other-troubleshooting-tips/networking" target="_self" rel="noopener noreferrer" class="dropdown__link dropdown__link--active" lang="en">English</a></li><li><a href="/zh/troubleshooting/other-troubleshooting-tips/networking" target="_self" rel="noopener noreferrer" class="dropdown__link" lang="zh">简体中文</a></li></ul></div><div class="searchBox_ZlJk"><button type="button" class="DocSearch DocSearch-Button" aria-label="Search"><span class="DocSearch-Button-Container"><svg width="20" height="20" class="DocSearch-Search-Icon" viewBox="0 0 20 20"><path d="M14.386 14.386l4.0877 4.0877-4.0877-4.0877c-2.9418 2.9419-7.7115 2.9419-10.6533 0-2.9419-2.9418-2.9419-7.7115 0-10.6533 2.9418-2.9419 7.7115-2.9419 10.6533 0 2.9419 2.9418 2.9419 7.7115 0 10.6533z" stroke="currentColor" fill="none" fill-rule="evenodd" stroke-linecap="round" stroke-linejoin="round"></path></svg><span class="DocSearch-Button-Placeholder">Search</span></span><span class="DocSearch-Button-Keys"></span></button></div></div><div class="navbar__items navbar__items--right"><div class="navbar__item dropdown dropdown--hoverable dropdown--right"><a href="#" aria-haspopup="true" aria-expanded="false" role="button" class="navbar__link">Quick Links</a><ul class="dropdown__menu"><li><a href="https://github.com/rancher/rancher" target="_blank" rel="noopener noreferrer" class="dropdown__link">GitHub<svg width="12" height="12" aria-hidden="true" viewBox="0 0 24 24" class="iconExternalLink_nPIU"><path fill="currentColor" d="M21 13v10h-21v-19h12v2h-10v15h17v-8h2zm3-12h-10.988l4.035 4-6.977 7.07 2.828 2.828 6.977-7.07 4.125 4.172v-11z"></path></svg></a></li><li><a href="https://github.com/rancher/rancher-docs" target="_blank" rel="noopener noreferrer" class="dropdown__link">Docs GitHub<svg width="12" height="12" aria-hidden="true" viewBox="0 0 24 24" class="iconExternalLink_nPIU"><path fill="currentColor" d="M21 13v10h-21v-19h12v2h-10v15h17v-8h2zm3-12h-10.988l4.035 4-6.977 7.07 2.828 2.828 6.977-7.07 4.125 4.172v-11z"></path></svg></a></li></ul></div><div class="navbar__item dropdown dropdown--hoverable dropdown--right"><a href="#" aria-haspopup="true" aria-expanded="false" role="button" class="navbar__link">More from SUSE</a><ul class="dropdown__menu"><li><a href="https://www.rancher.com" target="_blank" rel="noopener noreferrer" class="dropdown__link navbar__icon navbar__rancher">Rancher<svg width="12" height="12" aria-hidden="true" viewBox="0 0 24 24" class="iconExternalLink_nPIU"><path fill="currentColor" d="M21 13v10h-21v-19h12v2h-10v15h17v-8h2zm3-12h-10.988l4.035 4-6.977 7.07 2.828 2.828 6.977-7.07 4.125 4.172v-11z"></path></svg></a></li><li><hr style="margin: 0.3rem 0;"></li><li><a href="https://elemental.docs.rancher.com/" target="_blank" rel="noopener noreferrer" class="dropdown__link navbar__icon navbar__elemental">Elemental<svg width="12" height="12" aria-hidden="true" viewBox="0 0 24 24" class="iconExternalLink_nPIU"><path fill="currentColor" d="M21 13v10h-21v-19h12v2h-10v15h17v-8h2zm3-12h-10.988l4.035 4-6.977 7.07 2.828 2.828 6.977-7.07 4.125 4.172v-11z"></path></svg></a></li><li><a href="https://fleet.rancher.io/" target="_blank" rel="noopener noreferrer" class="dropdown__link navbar__icon navbar__fleet">Fleet<svg width="12" height="12" aria-hidden="true" viewBox="0 0 24 24" class="iconExternalLink_nPIU"><path fill="currentColor" d="M21 13v10h-21v-19h12v2h-10v15h17v-8h2zm3-12h-10.988l4.035 4-6.977 7.07 2.828 2.828 6.977-7.07 4.125 4.172v-11z"></path></svg></a></li><li><a href="https://harvesterhci.io" target="_blank" rel="noopener noreferrer" class="dropdown__link navbar__icon navbar__harvester">Harvester<svg width="12" height="12" aria-hidden="true" viewBox="0 0 24 24" class="iconExternalLink_nPIU"><path fill="currentColor" d="M21 13v10h-21v-19h12v2h-10v15h17v-8h2zm3-12h-10.988l4.035 4-6.977 7.07 2.828 2.828 6.977-7.07 4.125 4.172v-11z"></path></svg></a></li><li><a href="https://rancherdesktop.io/" target="_blank" rel="noopener noreferrer" class="dropdown__link navbar__icon navbar__rancher__desktop">Rancher Desktop<svg width="12" height="12" aria-hidden="true" viewBox="0 0 24 24" class="iconExternalLink_nPIU"><path fill="currentColor" d="M21 13v10h-21v-19h12v2h-10v15h17v-8h2zm3-12h-10.988l4.035 4-6.977 7.07 2.828 2.828 6.977-7.07 4.125 4.172v-11z"></path></svg></a></li><li><hr style="margin: 0.3rem 0;"></li><li><a href="https://opensource.suse.com" target="_blank" rel="noopener noreferrer" class="dropdown__link navbar__icon navbar__suse">More Projects...<svg width="12" height="12" aria-hidden="true" viewBox="0 0 24 24" class="iconExternalLink_nPIU"><path fill="currentColor" d="M21 13v10h-21v-19h12v2h-10v15h17v-8h2zm3-12h-10.988l4.035 4-6.977 7.07 2.828 2.828 6.977-7.07 4.125 4.172v-11z"></path></svg></a></li></ul></div></div></div><div role="presentation" class="navbar-sidebar__backdrop"></div></nav><div id="__docusaurus_skipToContent_fallback" class="main-wrapper mainWrapper_z2l0 docsWrapper_BCFX"><button aria-label="Scroll back to top" class="clean-btn theme-back-to-top-button backToTopButton_sjWU" type="button"></button><div class="docPage__5DB"><aside class="theme-doc-sidebar-container docSidebarContainer_b6E3"><div class="sidebarViewport_Xe31"><div class="sidebar_njMd"><nav aria-label="Docs sidebar" class="menu thin-scrollbar menu_SIkG"><ul class="theme-doc-sidebar-menu menu__list"><li class="theme-doc-sidebar-item-link theme-doc-sidebar-item-link-level-1 menu__list-item"><a class="menu__link" href="/">What is Rancher?</a></li><li class="theme-doc-sidebar-item-category theme-doc-sidebar-item-category-level-1 menu__list-item menu__list-item--collapsed"><div class="menu__list-item-collapsible"><a class="menu__link menu__link--sublist menu__link--sublist-caret" aria-expanded="false" href="/getting-started/overview">Getting Started</a></div></li><li class="theme-doc-sidebar-item-category theme-doc-sidebar-item-category-level-1 menu__list-item menu__list-item--collapsed"><div class="menu__list-item-collapsible"><a class="menu__link menu__link--sublist menu__link--sublist-caret" aria-expanded="false" href="/how-to-guides/new-user-guides">How-to Guides</a></div></li><li class="theme-doc-sidebar-item-category theme-doc-sidebar-item-category-level-1 menu__list-item menu__list-item--collapsed"><div class="menu__list-item-collapsible"><a class="menu__link menu__link--sublist menu__link--sublist-caret" aria-expanded="false" href="/reference-guides/best-practices">Reference Guides</a></div></li><li class="theme-doc-sidebar-item-category theme-doc-sidebar-item-category-level-1 menu__list-item menu__list-item--collapsed"><div class="menu__list-item-collapsible"><a class="menu__link menu__link--sublist" aria-expanded="false" href="/integrations-in-rancher">Integrations in Rancher</a><button aria-label="Toggle the collapsible sidebar category &#x27;Integrations in Rancher&#x27;" type="button" class="clean-btn menu__caret"></button></div></li><li class="theme-doc-sidebar-item-category theme-doc-sidebar-item-category-level-1 menu__list-item menu__list-item--collapsed"><div class="menu__list-item-collapsible"><a class="menu__link menu__link--sublist menu__link--sublist-caret" aria-expanded="false" href="/faq/general-faq">FAQ</a></div></li><li class="theme-doc-sidebar-item-category theme-doc-sidebar-item-category-level-1 menu__list-item"><div class="menu__list-item-collapsible"><a class="menu__link menu__link--sublist menu__link--sublist-caret menu__link--active" aria-expanded="true" href="/troubleshooting/general-troubleshooting">Troubleshooting</a></div><ul style="display:block;overflow:visible;height:auto" class="menu__list"><li class="theme-doc-sidebar-item-link theme-doc-sidebar-item-link-level-2 menu__list-item"><a class="menu__link" tabindex="0" href="/troubleshooting/general-troubleshooting">General Troubleshooting</a></li><li class="theme-doc-sidebar-item-category theme-doc-sidebar-item-category-level-2 menu__list-item menu__list-item--collapsed"><div class="menu__list-item-collapsible"><a class="menu__link menu__link--sublist" aria-expanded="false" tabindex="0" href="/troubleshooting/kubernetes-components">Kubernetes Components</a><button aria-label="Toggle the collapsible sidebar category &#x27;Kubernetes Components&#x27;" type="button" class="clean-btn menu__caret"></button></div></li><li class="theme-doc-sidebar-item-category theme-doc-sidebar-item-category-level-2 menu__list-item"><div class="menu__list-item-collapsible"><a class="menu__link menu__link--sublist menu__link--sublist-caret menu__link--active" aria-expanded="true" tabindex="0" href="/troubleshooting/other-troubleshooting-tips/kubernetes-resources">Other Troubleshooting Tips</a></div><ul style="display:block;overflow:visible;height:auto" class="menu__list"><li class="theme-doc-sidebar-item-link theme-doc-sidebar-item-link-level-3 menu__list-item"><a class="menu__link" tabindex="0" href="/troubleshooting/other-troubleshooting-tips/kubernetes-resources">Kubernetes Resources</a></li><li class="theme-doc-sidebar-item-link theme-doc-sidebar-item-link-level-3 menu__list-item"><a class="menu__link menu__link--active" aria-current="page" tabindex="0" href="/troubleshooting/other-troubleshooting-tips/networking">Networking</a></li><li class="theme-doc-sidebar-item-link theme-doc-sidebar-item-link-level-3 menu__list-item"><a class="menu__link" tabindex="0" href="/troubleshooting/other-troubleshooting-tips/dns">DNS</a></li><li class="theme-doc-sidebar-item-link theme-doc-sidebar-item-link-level-3 menu__list-item"><a class="menu__link" tabindex="0" href="/troubleshooting/other-troubleshooting-tips/rancher-ha">Rancher HA</a></li><li class="theme-doc-sidebar-item-link theme-doc-sidebar-item-link-level-3 menu__list-item"><a class="menu__link" tabindex="0" href="/troubleshooting/other-troubleshooting-tips/registered-clusters">Registered Clusters</a></li><li class="theme-doc-sidebar-item-link theme-doc-sidebar-item-link-level-3 menu__list-item"><a class="menu__link" tabindex="0" href="/troubleshooting/other-troubleshooting-tips/logging">Logging</a></li><li class="theme-doc-sidebar-item-link theme-doc-sidebar-item-link-level-3 menu__list-item"><a class="menu__link" tabindex="0" href="/troubleshooting/other-troubleshooting-tips/user-id-tracking-in-audit-logs">User ID Tracking in Audit Logs</a></li><li class="theme-doc-sidebar-item-link theme-doc-sidebar-item-link-level-3 menu__list-item"><a class="menu__link" tabindex="0" href="/troubleshooting/other-troubleshooting-tips/expired-webhook-certificate-rotation">Rotation of Expired Webhook Certificates</a></li></ul></li></ul></li><li class="theme-doc-sidebar-item-category theme-doc-sidebar-item-category-level-1 menu__list-item menu__list-item--collapsed"><div class="menu__list-item-collapsible"><a class="menu__link menu__link--sublist menu__link--sublist-caret" aria-expanded="false" href="/api/quickstart">Rancher Kubernetes API</a></div></li><li class="theme-doc-sidebar-item-link theme-doc-sidebar-item-link-level-1 menu__list-item"><a class="menu__link" href="/contribute-to-rancher">Contributing to Rancher</a></li><li class="theme-doc-sidebar-item-link theme-doc-sidebar-item-link-level-1 menu__list-item"><a class="menu__link" href="/glossary">Glossary</a></li></ul></nav></div></div></aside><main class="docMainContainer_gTbr"><div class="container padding-top--md padding-bottom--lg"><div class="row"><div class="col docItemCol_VOVn"><div class="docItemContainer_Djhp"><article><nav class="theme-doc-breadcrumbs breadcrumbsContainer_Z_bl" aria-label="Breadcrumbs"><ul class="breadcrumbs" itemscope="" itemtype="https://schema.org/BreadcrumbList"><li class="breadcrumbs__item"><a aria-label="Home page" class="breadcrumbs__link" href="/"><svg viewBox="0 0 24 24" class="breadcrumbHomeIcon_YNFT"><path d="M10 19v-5h4v5c0 .55.45 1 1 1h3c.55 0 1-.45 1-1v-7h1.7c.46 0 .68-.57.33-.87L12.67 3.6c-.38-.34-.96-.34-1.34 0l-8.36 7.53c-.34.3-.13.87.33.87H5v7c0 .55.45 1 1 1h3c.55 0 1-.45 1-1z" fill="currentColor"></path></svg></a></li><li class="breadcrumbs__item"><span class="breadcrumbs__link">Troubleshooting</span><meta itemprop="position" content="1"></li><li class="breadcrumbs__item"><span class="breadcrumbs__link">Other Troubleshooting Tips</span><meta itemprop="position" content="2"></li><li itemscope="" itemprop="itemListElement" itemtype="https://schema.org/ListItem" class="breadcrumbs__item breadcrumbs__item--active"><span class="breadcrumbs__link" itemprop="name">Networking</span><meta itemprop="position" content="3"></li></ul></nav><span class="theme-doc-version-badge badge badge--secondary">Version: Latest</span><div class="tocCollapsible_ETCw theme-doc-toc-mobile tocMobile_ITEo"><button type="button" class="clean-btn tocCollapsibleButton_TO0P">On this page</button></div><div class="theme-doc-markdown markdown"><header><h1>Networking</h1></header><p>The commands/steps listed on this page can be used to check networking related issues in your cluster.</p><p>Make sure you configured the correct kubeconfig (for example, <code>export KUBECONFIG=$PWD/kube_config_cluster.yml</code> for Rancher HA) or are using the embedded kubectl via the UI.</p><h3 class="anchor anchorWithStickyNavbar_LWe7" id="double-check-if-all-the-required-ports-are-opened-in-your-host-firewall">Double check if all the required ports are opened in your (host) firewall<a href="#double-check-if-all-the-required-ports-are-opened-in-your-host-firewall" class="hash-link" aria-label="Direct link to Double check if all the required ports are opened in your (host) firewall" title="Direct link to Double check if all the required ports are opened in your (host) firewall">​</a></h3><p>Double check if all the <a href="/how-to-guides/new-user-guides/kubernetes-clusters-in-rancher-setup/node-requirements-for-rancher-managed-clusters#networking-requirements">required ports</a> are opened in your (host) firewall. The overlay network uses UDP in comparison to all other required ports which are TCP.</p><h3 class="anchor anchorWithStickyNavbar_LWe7" id="check-if-overlay-network-is-functioning-correctly">Check if overlay network is functioning correctly<a href="#check-if-overlay-network-is-functioning-correctly" class="hash-link" aria-label="Direct link to Check if overlay network is functioning correctly" title="Direct link to Check if overlay network is functioning correctly">​</a></h3><p>The pod can be scheduled to any of the hosts you used for your cluster, but that means that the NGINX ingress controller needs to be able to route the request from <code>NODE_1</code> to <code>NODE_2</code>. This happens over the overlay network. If the overlay network is not functioning, you will experience intermittent TCP/HTTP connection failures due to the NGINX ingress controller not being able to route to the pod.</p><p>To test the overlay network, you can launch the following <code>DaemonSet</code> definition. This will run a <code>swiss-army-knife</code> container on every host (image was developed by Rancher engineers and can be found here: <a href="https://github.com/rancherlabs/swiss-army-knife" target="_blank" rel="noopener noreferrer">https://github.com/rancherlabs/swiss-army-knife</a>), which we will use to run a <code>ping</code> test between containers on all hosts.</p><div class="theme-admonition theme-admonition-caution alert alert--warning admonition_LlT9"><div class="admonitionHeading_tbUL"><span class="admonitionIcon_kALy"><svg viewBox="0 0 16 16"><path fill-rule="evenodd" d="M8.893 1.5c-.183-.31-.52-.5-.887-.5s-.703.19-.886.5L.138 13.499a.98.98 0 0 0 0 1.001c.193.31.53.501.886.501h13.964c.367 0 .704-.19.877-.5a1.03 1.03 0 0 0 .01-1.002L8.893 1.5zm.133 11.497H6.987v-2.003h2.039v2.003zm0-3.004H6.987V5.987h2.039v4.006z"></path></svg></span>caution</div><div class="admonitionContent_S0QG"><p>The <code>swiss-army-knife</code> container does not support Windows nodes. It also <a href="https://github.com/leodotcloud/swiss-army-knife/issues/18" target="_blank" rel="noopener noreferrer">does not support ARM nodes</a>, such as a Raspberry Pi. When the test encounters incompatible nodes, this is recorded in the pod logs as an error message, such as <code>exec user process caused: exec format error</code> for ARM nodes, or <code>ImagePullBackOff (Back-off pulling image &quot;rancherlabs/swiss-army-knife)</code> for Windows nodes.</p></div></div><ol><li><p>Save the following file as <code>overlaytest.yml</code></p><div class="codeBlockContainer_Ckt0 theme-code-block" style="--prism-color:#bfc7d5;--prism-background-color:#292d3e"><div class="codeBlockContent_biex"><pre tabindex="0" class="prism-code language-text codeBlock_bY9V thin-scrollbar"><code class="codeBlockLines_e6Vv"><span class="token-line" style="color:#bfc7d5"><span class="token plain">apiVersion: apps/v1</span><br></span><span class="token-line" style="color:#bfc7d5"><span class="token plain">kind: DaemonSet</span><br></span><span class="token-line" style="color:#bfc7d5"><span class="token plain">metadata:</span><br></span><span class="token-line" style="color:#bfc7d5"><span class="token plain"> name: overlaytest</span><br></span><span class="token-line" style="color:#bfc7d5"><span class="token plain">spec:</span><br></span><span class="token-line" style="color:#bfc7d5"><span class="token plain"> selector:</span><br></span><span class="token-line" style="color:#bfc7d5"><span class="token plain"> matchLabels:</span><br></span><span class="token-line" style="color:#bfc7d5"><span class="token plain"> name: overlaytest</span><br></span><span class="token-line" style="color:#bfc7d5"><span class="token plain"> template:</span><br></span><span class="token-line" style="color:#bfc7d5"><span class="token plain"> metadata:</span><br></span><span class="token-line" style="color:#bfc7d5"><span class="token plain"> labels:</span><br></span><span class="token-line" style="color:#bfc7d5"><span class="token plain"> name: overlaytest</span><br></span><span class="token-line" style="color:#bfc7d5"><span class="token plain"> spec:</span><br></span><span class="token-line" style="color:#bfc7d5"><span class="token plain"> tolerations:</span><br></span><span class="token-line" style="color:#bfc7d5"><span class="token plain"> - operator: Exists</span><br></span><span class="token-line" style="color:#bfc7d5"><span class="token plain"> containers:</span><br></span><span class="token-line" style="color:#bfc7d5"><span class="token plain"> - image: rancherlabs/swiss-army-knife</span><br></span><span class="token-line" style="color:#bfc7d5"><span class="token plain"> imagePullPolicy: Always</span><br></span><span class="token-line" style="color:#bfc7d5"><span class="token plain"> name: overlaytest</span><br></span><span class="token-line" style="color:#bfc7d5"><span class="token plain"> command: [&quot;sh&quot;, &quot;-c&quot;, &quot;tail -f /dev/null&quot;]</span><br></span><span class="token-line" style="color:#bfc7d5"><span class="token plain"> terminationMessagePath: /dev/termination-log</span><br></span><span class="token-line" style="color:#bfc7d5"><span class="token plain" style="display:inline-block"></span><br></span></code></pre><div class="buttonGroup__atx"><button type="button" aria-label="Copy code to clipboard" title="Copy" class="clean-btn"><span class="copyButtonIcons_eSgA" aria-hidden="true"><svg viewBox="0 0 24 24" class="copyButtonIcon_y97N"><path fill="currentColor" d="M19,21H8V7H19M19,5H8A2,2 0 0,0 6,7V21A2,2 0 0,0 8,23H19A2,2 0 0,0 21,21V7A2,2 0 0,0 19,5M16,1H4A2,2 0 0,0 2,3V17H4V3H16V1Z"></path></svg><svg viewBox="0 0 24 24" class="copyButtonSuccessIcon_LjdS"><path fill="currentColor" d="M21,7L9,19L3.5,13.5L4.91,12.09L9,16.17L19.59,5.59L21,7Z"></path></svg></span></button></div></div></div></li><li><p>Launch it using <code>kubectl create -f overlaytest.yml</code></p></li><li><p>Wait until <code>kubectl rollout status ds/overlaytest -w</code> returns: <code>daemon set &quot;overlaytest&quot; successfully rolled out</code>.</p></li><li><p>Run the following script, from the same location. It will have each <code>overlaytest</code> container on every host ping each other:</p><div class="codeBlockContainer_Ckt0 theme-code-block" style="--prism-color:#bfc7d5;--prism-background-color:#292d3e"><div class="codeBlockContent_biex"><pre tabindex="0" class="prism-code language-text codeBlock_bY9V thin-scrollbar"><code class="codeBlockLines_e6Vv"><span class="token-line" style="color:#bfc7d5"><span class="token plain">#!/bin/bash</span><br></span><span class="token-line" style="color:#bfc7d5"><span class="token plain">echo &quot;=&gt; Start network overlay test&quot;</span><br></span><span class="token-line" style="color:#bfc7d5"><span class="token plain"> kubectl get pods -l name=overlaytest -o jsonpath=&#x27;{range .items[*]}{@.metadata.name}{&quot; &quot;}{@.spec.nodeName}{&quot;\n&quot;}{end}&#x27; |</span><br></span><span class="token-line" style="color:#bfc7d5"><span class="token plain"> while read spod shost</span><br></span><span class="token-line" style="color:#bfc7d5"><span class="token plain"> do kubectl get pods -l name=overlaytest -o jsonpath=&#x27;{range .items[*]}{@.status.podIP}{&quot; &quot;}{@.spec.nodeName}{&quot;\n&quot;}{end}&#x27; |</span><br></span><span class="token-line" style="color:#bfc7d5"><span class="token plain"> while read tip thost</span><br></span><span class="token-line" style="color:#bfc7d5"><span class="token plain"> do kubectl --request-timeout=&#x27;10s&#x27; exec $spod -c overlaytest -- /bin/sh -c &quot;ping -c2 $tip &gt; /dev/null 2&gt;&amp;1&quot;</span><br></span><span class="token-line" style="color:#bfc7d5"><span class="token plain"> RC=$?</span><br></span><span class="token-line" style="color:#bfc7d5"><span class="token plain"> if [ $RC -ne 0 ]</span><br></span><span class="token-line" style="color:#bfc7d5"><span class="token plain"> then echo FAIL: $spod on $shost cannot reach pod IP $tip on $thost</span><br></span><span class="token-line" style="color:#bfc7d5"><span class="token plain"> else echo $shost can reach $thost</span><br></span><span class="token-line" style="color:#bfc7d5"><span class="token plain"> fi</span><br></span><span class="token-line" style="color:#bfc7d5"><span class="token plain"> done</span><br></span><span class="token-line" style="color:#bfc7d5"><span class="token plain"> done</span><br></span><span class="token-line" style="color:#bfc7d5"><span class="token plain">echo &quot;=&gt; End network overlay test&quot;</span><br></span></code></pre><div class="buttonGroup__atx"><button type="button" aria-label="Copy code to clipboard" title="Copy" class="clean-btn"><span class="copyButtonIcons_eSgA" aria-hidden="true"><svg viewBox="0 0 24 24" class="copyButtonIcon_y97N"><path fill="currentColor" d="M19,21H8V7H19M19,5H8A2,2 0 0,0 6,7V21A2,2 0 0,0 8,23H19A2,2 0 0,0 21,21V7A2,2 0 0,0 19,5M16,1H4A2,2 0 0,0 2,3V17H4V3H16V1Z"></path></svg><svg viewBox="0 0 24 24" class="copyButtonSuccessIcon_LjdS"><path fill="currentColor" d="M21,7L9,19L3.5,13.5L4.91,12.09L9,16.17L19.59,5.59L21,7Z"></path></svg></span></button></div></div></div></li><li><p>When this command has finished running, it will output the state of each route:</p><div class="codeBlockContainer_Ckt0 theme-code-block" style="--prism-color:#bfc7d5;--prism-background-color:#292d3e"><div class="codeBlockContent_biex"><pre tabindex="0" class="prism-code language-text codeBlock_bY9V thin-scrollbar"><code class="codeBlockLines_e6Vv"><span class="token-line" style="color:#bfc7d5"><span class="token plain">=&gt; Start network overlay test</span><br></span><span class="token-line" style="color:#bfc7d5"><span class="token plain">Error from server (NotFound): pods &quot;wk2&quot; not found</span><br></span><span class="token-line" style="color:#bfc7d5"><span class="token plain">FAIL: overlaytest-5bglp on wk2 cannot reach pod IP 10.42.7.3 on wk2</span><br></span><span class="token-line" style="color:#bfc7d5"><span class="token plain">Error from server (NotFound): pods &quot;wk2&quot; not found</span><br></span><span class="token-line" style="color:#bfc7d5"><span class="token plain">FAIL: overlaytest-5bglp on wk2 cannot reach pod IP 10.42.0.5 on cp1</span><br></span><span class="token-line" style="color:#bfc7d5"><span class="token plain">Error from server (NotFound): pods &quot;wk2&quot; not found</span><br></span><span class="token-line" style="color:#bfc7d5"><span class="token plain">FAIL: overlaytest-5bglp on wk2 cannot reach pod IP 10.42.2.12 on wk1</span><br></span><span class="token-line" style="color:#bfc7d5"><span class="token plain">command terminated with exit code 1</span><br></span><span class="token-line" style="color:#bfc7d5"><span class="token plain">FAIL: overlaytest-v4qkl on cp1 cannot reach pod IP 10.42.7.3 on wk2</span><br></span><span class="token-line" style="color:#bfc7d5"><span class="token plain">cp1 can reach cp1</span><br></span><span class="token-line" style="color:#bfc7d5"><span class="token plain">cp1 can reach wk1</span><br></span><span class="token-line" style="color:#bfc7d5"><span class="token plain">command terminated with exit code 1</span><br></span><span class="token-line" style="color:#bfc7d5"><span class="token plain">FAIL: overlaytest-xpxwp on wk1 cannot reach pod IP 10.42.7.3 on wk2</span><br></span><span class="token-line" style="color:#bfc7d5"><span class="token plain">wk1 can reach cp1</span><br></span><span class="token-line" style="color:#bfc7d5"><span class="token plain">wk1 can reach wk1</span><br></span><span class="token-line" style="color:#bfc7d5"><span class="token plain">=&gt; End network overlay test</span><br></span></code></pre><div class="buttonGroup__atx"><button type="button" aria-label="Copy code to clipboard" title="Copy" class="clean-btn"><span class="copyButtonIcons_eSgA" aria-hidden="true"><svg viewBox="0 0 24 24" class="copyButtonIcon_y97N"><path fill="currentColor" d="M19,21H8V7H19M19,5H8A2,2 0 0,0 6,7V21A2,2 0 0,0 8,23H19A2,2 0 0,0 21,21V7A2,2 0 0,0 19,5M16,1H4A2,2 0 0,0 2,3V17H4V3H16V1Z"></path></svg><svg viewBox="0 0 24 24" class="copyButtonSuccessIcon_LjdS"><path fill="currentColor" d="M21,7L9,19L3.5,13.5L4.91,12.09L9,16.17L19.59,5.59L21,7Z"></path></svg></span></button></div></div></div><p>If you see error in the output, there is some issue with the route between the pods on the two hosts. In the above output the node <code>wk2</code> has no connectivity over the overlay network. This could be because the <a href="/how-to-guides/new-user-guides/kubernetes-clusters-in-rancher-setup/node-requirements-for-rancher-managed-clusters#networking-requirements">required ports</a> for overlay networking are not opened for <code>wk2</code>.</p></li><li><p>You can now clean up the DaemonSet by running <code>kubectl delete ds/overlaytest</code>.</p></li></ol><h3 class="anchor anchorWithStickyNavbar_LWe7" id="check-if-mtu-is-correctly-configured-on-hosts-and-on-peeringtunnel-appliancesdevices">Check if MTU is correctly configured on hosts and on peering/tunnel appliances/devices<a href="#check-if-mtu-is-correctly-configured-on-hosts-and-on-peeringtunnel-appliancesdevices" class="hash-link" aria-label="Direct link to Check if MTU is correctly configured on hosts and on peering/tunnel appliances/devices" title="Direct link to Check if MTU is correctly configured on hosts and on peering/tunnel appliances/devices">​</a></h3><p>When the MTU is incorrectly configured (either on hosts running Rancher, nodes in created/imported clusters or on appliances/devices in between), error messages will be logged in Rancher and in the agents, similar to:</p><ul><li><code>websocket: bad handshake</code></li><li><code>Failed to connect to proxy</code></li><li><code>read tcp: i/o timeout</code></li></ul><p>See <a href="https://cloud.google.com/vpn/docs/concepts/mtu-considerations#gateway_mtu_vs_system_mtu" target="_blank" rel="noopener noreferrer">Google Cloud VPN: MTU Considerations</a> for an example how to configure MTU correctly when using Google Cloud VPN between Rancher and cluster nodes.</p></div><footer class="theme-doc-footer docusaurus-mt-lg"><div class="theme-doc-footer-edit-meta-row row"><div class="col"><a href="https://github.com/rancher/rancher-docs/edit/main/docs/troubleshooting/other-troubleshooting-tips/networking.md" target="_blank" rel="noreferrer noopener" class="theme-edit-this-page"><svg fill="currentColor" height="20" width="20" viewBox="0 0 40 40" class="iconEdit_Z9Sw" aria-hidden="true"><g><path d="m34.5 11.7l-3 3.1-6.3-6.3 3.1-3q0.5-0.5 1.2-0.5t1.1 0.5l3.9 3.9q0.5 0.4 0.5 1.1t-0.5 1.2z m-29.5 17.1l18.4-18.5 6.3 6.3-18.4 18.4h-6.3v-6.2z"></path></g></svg>Edit this page</a></div><div class="col lastUpdated_vwxv"><span class="theme-last-updated">Last updated<!-- --> on <b><time datetime="2024-05-29T23:31:21.000Z">May 29, 2024</time></b></span></div></div></footer></article><nav class="pagination-nav docusaurus-mt-lg" aria-label="Docs pages"><a class="pagination-nav__link pagination-nav__link--prev" href="/troubleshooting/other-troubleshooting-tips/kubernetes-resources"><div class="pagination-nav__sublabel">Previous</div><div class="pagination-nav__label">Kubernetes Resources</div></a><a class="pagination-nav__link pagination-nav__link--next" href="/troubleshooting/other-troubleshooting-tips/dns"><div class="pagination-nav__sublabel">Next</div><div class="pagination-nav__label">DNS</div></a></nav></div></div><div class="col col--3"><div class="tableOfContents_bqdL thin-scrollbar theme-doc-toc-desktop"><ul class="table-of-contents table-of-contents__left-border"><li><a href="#double-check-if-all-the-required-ports-are-opened-in-your-host-firewall" class="table-of-contents__link toc-highlight">Double check if all the required ports are opened in your (host) firewall</a></li><li><a href="#check-if-overlay-network-is-functioning-correctly" class="table-of-contents__link toc-highlight">Check if overlay network is functioning correctly</a></li><li><a href="#check-if-mtu-is-correctly-configured-on-hosts-and-on-peeringtunnel-appliancesdevices" class="table-of-contents__link toc-highlight">Check if MTU is correctly configured on hosts and on peering/tunnel appliances/devices</a></li></ul></div></div></div></div></main></div></div><footer class="footer footer--dark"><div class="container container-fluid"><div class="footer__bottom text--center"><div class="footer__copyright">Copyright © 2024 SUSE Rancher. All Rights Reserved.</div></div></div></footer></div>
<script src="/assets/js/runtime~main.d98f8a34.js"></script>
<script src="/assets/js/main.e9ebdfba.js"></script>
</body>
</html>