Yes, from the ingress node I can reach every other node and the externally connected client. But from the external client I only reach the ingress node. So the connection is established successfully. When I look at the kernel log on the ingress node, only traffic to the ingress node itself is visible, traffic to other nodes is not... The only workaround is to enable the ingress on the first node (the netmaker Server) . Then all traffic will be forwarded successfully. It looks like a forwarding rule is not applied correctly to the nodes