[pve-devel] [PATCH firewall 1/1] firewall: set default value of NDP to 1 for nodes and guests

Michael Köppl m.koeppl at proxmox.com
Tue Nov 11 11:25:46 CET 2025


The default value of 0 is incorrect, as by default, NDP is enabled for
both iptables and nftables. Change the default value to 1 to reflect
that.

Signed-off-by: Michael Köppl <m.koeppl at proxmox.com>
---
 src/PVE/Firewall.pm | 4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)

diff --git a/src/PVE/Firewall.pm b/src/PVE/Firewall.pm
index ec9c9ae..93f8c34 100644
--- a/src/PVE/Firewall.pm
+++ b/src/PVE/Firewall.pm
@@ -1404,7 +1404,7 @@ our $host_option_properties = {
     ndp => {
         description => "Enable NDP (Neighbor Discovery Protocol).",
         type => 'boolean',
-        default => 0,
+        default => 1,
         optional => 1,
     },
     nf_conntrack_allow_invalid => {
@@ -1475,7 +1475,7 @@ our $vm_option_properties = {
     ndp => {
         description => "Enable NDP (Neighbor Discovery Protocol).",
         type => 'boolean',
-        default => 0,
+        default => 1,
         optional => 1,
     },
     radv => {
-- 
2.47.3





More information about the pve-devel mailing list