fix(phpipam): fix London SSH via WG MTU reduction (1420→1200)
Root cause: PMTU black hole on WireGuard tunnel. The tunnel runs over the HE IPv6 6in4 tunnel (gif0 MTU 1280). With WG overhead (~80 bytes), effective inner MTU is 1200 — but both sides were configured at 1420. SSH kex packets >1200 bytes were silently dropped. Fix: Set tun_wg0 MTU to 1200 on pfSense + peer_855 MTU to 1200 on London GL-iNet. Re-enabled London DHCP/ARP import in remote CronJob. All 3 sites now fully automated: - Sofia: Kea leases + ARP every 5min - London: DHCP + ARP via pfSense→London SSH hop, hourly - Valchedrym: DHCP + ARP via pfSense→OpenWRT SSH hop, hourly [ci skip] Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
This commit is contained in:
parent
d7de5de07c
commit
75255d22a2
1 changed files with 2 additions and 3 deletions
|
|
@ -601,9 +601,8 @@ resource "kubernetes_cron_job_v1" "phpipam_remote_import" {
|
|||
echo "=== Valchedrym (192.168.0.1 via pfSense) ==="
|
||||
VALCHEDRYM=$$(ssh -o ConnectTimeout=10 admin@10.0.20.1 'timeout 15 ssh -o StrictHostKeyChecking=no -o ConnectTimeout=5 root@192.168.0.1 "cat /tmp/dhcp.leases 2>/dev/null; echo ---ARP---; cat /proc/net/arp 2>/dev/null" 2>/dev/null' 2>/dev/null || echo "")
|
||||
|
||||
# London: dropbear SSH kex too slow for automated use; skip for now
|
||||
# TODO: install lightweight agent on London GL-iNet to push data
|
||||
LONDON=""
|
||||
echo "=== London (192.168.8.1 via pfSense) ==="
|
||||
LONDON=$$(ssh -o ConnectTimeout=10 admin@10.0.20.1 'timeout 15 ssh -o StrictHostKeyChecking=no -o ConnectTimeout=5 root@192.168.8.1 "cat /tmp/dhcp.leases 2>/dev/null; echo ---ARP---; cat /proc/net/arp 2>/dev/null" 2>/dev/null' 2>/dev/null || echo "")
|
||||
|
||||
echo "=== Importing ==="
|
||||
export LONDON_DATA="$$LONDON"
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue