In such deployments gratuitous ARP/ND packets originated by the VR,
e.g., on failover may not have matching eth.src and ARP/ND hardware
address.  It's possible that the Ethernet source used is that of the
physical NIC and the Ethernet address stored in the ARP/ND fields is
the VMAC of the VR.

In these cases FDB learning didn't work properly because it would never
learn the "inner" MAC address.  Also, FDB learning was completely
disabled (programatically) for ports with security configured, even if
they had "unknown" addresses.

This creates an issue because OVN deployments with VRRP running as
workloads will break.  That's because users have no way of configuring
OVN to dynamically learn where the VMAC resides without giving up on
the port security settings.

Dumitru Ceara (2):
  northd: Learn ARP/ND inner MAC addresses in FDB.
  northd: Allow FDB learning on ports with port security.

 NEWS                      |   7 +
 northd/northd.c           | 206 ++++++++++++++++++++++---
 northd/northd.h           |   3 -
 ovn-nb.xml                |  23 ++-
 tests/ovn-ic.at           |  72 +++++++++
 tests/ovn-northd.at       | 192 +++++++++++++++++++++++
 tests/ovn.at              | 314 +++++++++++++++++++++++++++++++++++++-
 utilities/ovn-nbctl.8.xml |   2 +-
 8 files changed, 780 insertions(+), 39 deletions(-)

-- 
2.55.0

_______________________________________________
dev mailing list
[email protected]
https://mail.openvswitch.org/mailman/listinfo/ovs-dev

Reply via email to