跨 VPC 访问 NodePort 经常超时

• 两个VPC之间使用对等连接打通的，CVM 之间通信应该就跟在一个内网一样可以互通。
• 为什么同一 VPC 下访问没问题，跨 VPC 有问题? 两者访问的区别是什么?

• client 在 VPC a 的 TKE 集群的节点
• server 在 VPC b 的 TKE 集群的节点

An additional mechanism could be added to the TCP, a per-host cache of the last timestamp received from any connection. This value could then be used in the PAWS mechanism to reject old duplicate segments from earlier incarnations of the connection, if the timestamp clock can be guaranteed to have ticked at least once since the old connection was open. This would require that the TIME-WAIT delay plus the RTT together must be at least one tick of the sender’s timestamp clock. Such an extension is not part of the proposal of this RFC.

Linux 是否启用这种行为取决于 tcp_timestampstcp_tw_recycle，因为 tcp_timestamps 缺省开启，所以当 tcp_tw_recycle 被开启后，实际上这种行为就被激活了，当客户端或服务端以 NAT 方式构建的时候就可能出现问题。