Skip to content
DnsLister Forum

Where domain hunters compare notes

VYOS asymmetric routing issue with 3 interface setup

I am currently deploying a VyOS instance in a PoC environment and looking for the most logical and robust approach to resolve an asymmetric routing issue regarding management traffic.

The Scenario & Architecture:

I have a 3-interface setup designed for strict traffic isolation:

  • eth0: Dedicated for Management (SSH) and DNS traffic. It also maintains active BGP sessions with local DNS servers.
  • eth1 : Used for establishing GRE tunnels to get the traffic.
  • eth2 : Internet breakout. The system’s default route (0.0.0.0/0) points to the gateway on this interface.

The Issue:

The customer requires SSH access strictly via eth0. When an SSH connection is initiated from an external management subnet to eth0, the inbound packets arrive correctly. However, because the main routing table dictates the default route via eth2, VyOS sends the return traffic (SYN-ACK) out through eth2. This asymmetric routing breaks the connection. Currently, SSH is only successful when initiated from the exact same local subnet as eth0.

My Question:

What is the officially recommended VyOS “best practice” to resolve this asymmetric routing for locally generated return traffic?

Thank you in advance for your insights.

Source: r/vyos · by /u/Lal-1010

Leave a Reply

Your email address will not be published. Required fields are marked *