Page MenuHomeVyOS Platform

Make net.*.ip_nonlocal_bind being default
Open, LowPublic

Description

When using VRRP (keepalived) but also broken containers (who dont properly interact with listenadress when VRFs are being used even if allow-host-networks is set for the container) something common that shows up when troubleshooting is the missing net.ipv4.ip_nonlocal_bind=1 (and net.ipv6.ip_nonlocal_bind=1) since kernel defaults are "0" for both sysctl parameters.

Its an easy workaround to add this yourself like:

set system sysctl parameter net.ipv4.ip_nonlocal_bind value '1'
set system sysctl parameter net.ipv6.ip_nonlocal_bind value '1'

But shouldnt VyOS have both being set to "1" as default?

Ref:

https://docs.kernel.org/networking/ip-sysctl.html

Details

Version
2026.03
Is it a breaking change?
Unspecified (possibly destroys the router)
Issue type
Unspecified (please specify)

Event Timeline

Apachez created this object in space S1 VyOS Public.

I don't know if the default value of 1 is a good idea, but per feature, it could be.
For example, we use it in the OpenVPN https://github.com/vyos/vyos-1x/blob/3edf114bed538733388252da0d23b49002273558/src/conf_mode/interfaces_openvpn.py#L844

I second that it should be at least well documented that setting this sysctl is required to allow non local binds. I had to introduce a check for it being active in my PR solving a regression with HAProxy (and other services relying on the same code path) here: https://github.com/vyos/vyos-1x/pull/5266

I raised the question over there if it should either always be set implicitly by features that require it or never set automatically but mentioned accordingly in the documentation.

IMHO having the docs mention it where required and maybe even the CLI hinting about it on config failures caused by the lack of it being set would be a "cleaner" way than blindly activate it by default.