I have the impression, and it is confirmed by a colleague in another company, that there are propagation problems when you change rules or routing on subnets…
The changes made in My Zerotier are not taken into account or very long after.
This makes it very difficult to evaluate the new rules.
Is there a way to know if a rule has been propagated, or to force this propagation?
I am in France, can it come from a ZT rooot server? How to know which root server we depend on?
Hello,
for subnets you can check zerotier-cli listnetworks -j
Unfortunately there’s no way to list the rules from the client.
Are you using tags or capabilties? I’ve seen those get kind of “stuck”.
Please put a accept ethertype arp; at the top of your rule set. At least during testing.
Leaving and re-joining the network can also help speed things up.
I’m writing an article on the use of dna rules in mixed context with ZT clients and site-to-site, my conclusion is that the documentation and rules should evolve, for the moment I’m struggling to find examples to rely on.
I will put this article here, I count on you to validate that I did not write too much nonsense!