|
CORRECTION (GA-R1/C2): D-125 rack-bridge follow-up was CONFOUNDED, not evidence
The rack has no default route (transit-only netplan; WAN bridge IP-less), so 172.30.2.51-sourced traffic to 1.1.1.1 fails in the rack's own routing table before the NAT is consulted. Its ICMP/TCP failures say nothing about virbr4; the only clean signal is the guest's ICMP failure, and a guest TCP datapoint is still missing. Measurement request widened accordingly: FULL nft AND iptables-save dumps (backend unmeasured), diffing virbr4 vs virbr11 across BOTH rule families -- POSTROUTING masquerade (subnet-keyed) and FORWARD accept (interface-keyed, which a subnet grep would miss). Fix-forward pre-staged: net-destroy/net-start reinstalls libvirt's rules. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01KiUu1oqt76tWvV4vEC3NAr |
|---|
|
|
| docs/CURRENT-STATE.md |
|---|
| docs/changelog-20260719-dc0-deploy-stepB.md |
|---|