Dual Home with bosh issues (asymmetric routing)

Shaozhen Ding

Micro Bosh allows users to make the micrbosh dual home by injecting a
deployment_network section in manifest file.

Then micro bosh has two network cards sitting on two different network.

E.g. network 1 with ip (vCenter)
network 2 with ip (deployment IP)

However when I deploy the my deployment in the network 3. I found some
timeout issue.

I found that in network 3 I can not ping the deployment IP (

Dig into this:

this issue comes from
https://my.stonesoft.com/support/document.do?docid=1377 called as
asymmetric routing.

do a route -n in microbosh:

Destination Gateway Genmask Flags Metric Ref Use
Iface UG 0 0 0
eth0 U 0 0 0
eth0 U 0 0 0

The problem comes as

The network packet (ICMP) comes from the third network (E.g.
to ping When micro bosh echo back it will use ip, since eth0 is the default gateway.....

when router seeing src and comes back from ->
mismatch!!!!, then it drops the packet.

Many routers would disallow asymmetric routing. Linux router could disallow
this by enable net.ipv4.conf.all.rp_filter=1

By adding a static route to microbosh. E.g. route add dev
eth1, which force the traffic to use the second NIC. Then ping from works