In such deployments gratuitous ARP/ND packets originated by the VR, e.g., on failover may not have matching eth.src and ARP/ND hardware address. It's possible that the Ethernet source used is that of the physical NIC and the Ethernet address stored in the ARP/ND fields is the VMAC of the VR.
In these cases FDB learning didn't work properly because it would never learn the "inner" MAC address. Also, FDB learning was completely disabled (programatically) for ports with security configured, even if they had "unknown" addresses. This creates an issue because OVN deployments with VRRP running as workloads will break. That's because users have no way of configuring OVN to dynamically learn where the VMAC resides without giving up on the port security settings. Changes in V2: - Addressed Ales' comments: - Removed Reported-at in the first patch. - Improved test in the first patch. - Added missing documentation changes to both patches. Dumitru Ceara (2): northd: Learn ARP/ND inner MAC addresses in FDB. northd: Allow FDB learning on ports with port security. Documentation/ref/ovn-logical-flows.7.rst | 44 ++- NEWS | 7 + northd/northd.c | 206 +++++++++++-- northd/northd.h | 3 - ovn-nb.xml | 23 +- tests/ovn-ic.at | 72 +++++ tests/ovn-northd.at | 192 ++++++++++++ tests/ovn.at | 358 +++++++++++++++++++++- utilities/ovn-nbctl.8.xml | 2 +- 9 files changed, 860 insertions(+), 47 deletions(-) -- 2.55.0 _______________________________________________ dev mailing list [email protected] https://mail.openvswitch.org/mailman/listinfo/ovs-dev
