In such deployments gratuitous ARP/ND packets originated by the VR, e.g., on failover may not have matching eth.src and ARP/ND hardware address. It's possible that the Ethernet source used is that of the physical NIC and the Ethernet address stored in the ARP/ND fields is the VMAC of the VR.
In these cases FDB learning didn't work properly because it would never learn the "inner" MAC address. Also, FDB learning was completely disabled (programatically) for ports with security configured, even if they had "unknown" addresses. This creates an issue because OVN deployments with VRRP running as workloads will break. That's because users have no way of configuring OVN to dynamically learn where the VMAC resides without giving up on the port security settings. Dumitru Ceara (2): northd: Learn ARP/ND inner MAC addresses in FDB. northd: Allow FDB learning on ports with port security. NEWS | 7 + northd/northd.c | 206 ++++++++++++++++++++++--- northd/northd.h | 3 - ovn-nb.xml | 23 ++- tests/ovn-ic.at | 72 +++++++++ tests/ovn-northd.at | 192 +++++++++++++++++++++++ tests/ovn.at | 314 +++++++++++++++++++++++++++++++++++++- utilities/ovn-nbctl.8.xml | 2 +- 8 files changed, 780 insertions(+), 39 deletions(-) -- 2.55.0 _______________________________________________ dev mailing list [email protected] https://mail.openvswitch.org/mailman/listinfo/ovs-dev
