nebula icon indicating copy to clipboard operation
nebula copied to clipboard

Nebula will not start on ipv4-only host

Open jprostko opened this issue 4 years ago • 8 comments

Hello,

Is it a hard requirement that ipv6 be available on all hosts running nebula as of v1.4.0? I started upgrading one of my lighthouses to v1.4.0, only to find that nebula would crash out when starting up due to "unable to open socket: address family not supported by protocol".

I had that host set to have ipv6.disable=1 within its GRUB configuration, and after changing the GRUB entry to remove the ipv6 flag, nebula was able to start fine after the reboot, and the UDP listener binded to [::ffff:0.0.0.0] just fine. Afterwards I also explicitly disabled ipv6 on all interfaces but loopback, and nebula also started up fine in that scenario. It seems it's just looking to ensure that the ipv6 kernel module is loaded?

I saw some discussions about ipv6 in other issues, as well as the PR below, but nothing made it sound like ipv6 was now a hard requirement.

https://github.com/slackhq/nebula/pull/369

Thank you.

jprostko avatar May 11 '21 21:05 jprostko

I had the same problem on a host, worked after re-enabling ipv6.

Kemichal avatar May 26 '21 10:05 Kemichal

@jilyaluk thanks for the PR. I hope the Nebula team will merge it. Due to the company security requirements, ipv6 is turned off and we cannot use the latest version.

vladimir-incountry avatar Sep 01 '21 13:09 vladimir-incountry

facing same issue, ipv6 is disabled for security, unable to use nebula

perfecto25 avatar Nov 23 '21 00:11 perfecto25

@nbrownus @wadey @rawdigits @JohnMaguire Hi team! Could you please take a look?

Savemech avatar Apr 01 '22 08:04 Savemech

can this be merged? We want to use this tool but are unable to due to ipv6 requirements

perfecto25 avatar Aug 24 '22 13:08 perfecto25

Same here. Please allow option to disable ipv6 sockets.

rjsocha avatar Sep 20 '22 21:09 rjsocha

Same here. Please allow option to disable ipv6 sockets.

lukytux avatar Sep 27 '22 10:09 lukytux

Hi @Savemech - we're aware of the issue with IPv4-only hosts and have plans to resolve the issue. Unfortunately we don't have an ETA at this time.

The best way to help us prioritize this is to let us know you're affected by voting on the original post with a :+1: reaction.

johnmaguire avatar Sep 27 '22 14:09 johnmaguire