Article ID: 121588, created on May 15, 2014, last review on Jun 17, 2016

  • Applies to:
  • Virtuozzo 6.0


  1. Containers are configured in bridged networking mode.
  2. TCP/UDP Packets, larger than the MTU size (1500 bytes), are getting dropped on leaving the containers.
  3. The issue may affect some complex applications, which highly depend on network activity.


The issue is recognized as a kernel bug with internal ID PSBM-26316: fragmented packets are getting dropped by the bridge.


There are two possible workarounds:

  1. Disable bridge-netfilter on the node:

    # echo 0 > /proc/sys/net/bridge/bridge-nf-call-iptables
    # echo 0 > /proc/sys/net/bridge/bridge-nf-call-ip6tables

    This solution breaks private network functionality.

  2. Enable conntracks on the node. The procedure is described in details in the following article:

    Issues with firewall on HW Node - Impossible to use ip_nat and ipt_state modules

The permanent fix is included in 2.6.32-042stab092.1 kernel. Update the PCS node to the latest available version.

Search Words


c62e8726973f80975db0531f1ed5c6a2 2897d76d56d2010f4e3a28f864d69223 0dd5b9380c7d4884d77587f3eb0fa8ef

Email subscription for changes to this article
Save as PDF