Stop the Reverse Path Filter from Silently Dropping Your Multi-Homed Traffic

Networking & Firewalls (Nftables/Iptables/WireGuard)

Stop the Reverse Path Filter from Silently Dropping Your Multi-Homed Traffic

Technical Briefing | 10/8/2026

You add a second network interface to a box, wire it up, and suddenly half your traffic just disappears into the ether. You check the routing table, the routes look fine, and the firewall rules appear wide open. But the packets just don’t come back. This bit me in prod during a migration, and it took an hour of tcpdumping to realize the kernel was throwing away perfectly valid packets because it didn’t like where they were arriving from.

Why the kernel thinks your traffic is spoofed

The culprit is rp_filter. It’s a security feature designed to stop IP spoofing by checking if the source address of an incoming packet is actually reachable via the interface it arrived on. If the kernel thinks the best way to get to that source is via eth0, but the packet shows up on eth1, it drops the packet immediately. It’s helpful if you’re a single-homed gateway, but it’s a nightmare for anything using policy-based routing or multiple uplinks.

sysctl -w net.ipv4.conf.all.rp_filter=2

  • Setting rp_filter to 1 enables strict mode which causes these silent drops
  • Setting it to 2 allows loose mode where the kernel just verifies if the source is reachable on any interface
  • Don’t turn it off entirely unless you really understand the risk of spoofed source addresses

When to disable it entirely

If you are running complex VRF setups or WireGuard tunnels that bridge across different physical interfaces, even loose mode can be too restrictive. If you’ve exhausted your options, toggle it to 0 for specific interfaces only rather than globally. Just remember that if you disable this globally, you are now responsible for filtering spoofed traffic at your perimeter firewall, because the kernel has stopped doing it for you.

Keep an eye on your sysctl configuration files in /etc/sysctl.d/ so these changes survive a reboot. It is the kind of thing you set once and forget, but your future self will thank you for documenting why you had to relax the security posture on those specific interfaces.

Linux Admin Automation  |  © www.ngelinux.com  |  10/8/2026

0 0 votes
Article Rating
Subscribe
Notify of
guest

0 Comments
Newest
Oldest Most Voted