On 10/6/26 1:50 PM, Ales Musil wrote:
> On Tue, Oct 6, 2026 at 11:36 AM Dumitru Ceara <[email protected]> wrote:
> 
>> In such deployments gratuitous ARP/ND packets originated by the VR,
>> e.g., on failover may not have matching eth.src and ARP/ND hardware
>> address.  It's possible that the Ethernet source used is that of the
>> physical NIC and the Ethernet address stored in the ARP/ND fields is
>> the VMAC of the VR.
>>
>> In these cases FDB learning didn't work properly because it would never
>> learn the "inner" MAC address.  Also, FDB learning was completely
>> disabled (programatically) for ports with security configured, even if
>> they had "unknown" addresses.
>>
>> This creates an issue because OVN deployments with VRRP running as
>> workloads will break.  That's because users have no way of configuring
>> OVN to dynamically learn where the VMAC resides without giving up on
>> the port security settings.
>>
>> Changes in V2:
>> - Addressed Ales' comments:
>>   - Removed Reported-at in the first patch.
>>   - Improved test in the first patch.
>>   - Added missing documentation changes to both patches.
>>
>> Dumitru Ceara (2):
>>   northd: Learn ARP/ND inner MAC addresses in FDB.
>>   northd: Allow FDB learning on ports with port security.
>>
>>  Documentation/ref/ovn-logical-flows.7.rst |  44 ++-
>>  NEWS                                      |   7 +
>>  northd/northd.c                           | 206 +++++++++++--
>>  northd/northd.h                           |   3 -
>>  ovn-nb.xml                                |  23 +-
>>  tests/ovn-ic.at                           |  72 +++++
>>  tests/ovn-northd.at                       | 192 ++++++++++++
>>  tests/ovn.at                              | 358 +++++++++++++++++++++-
>>  utilities/ovn-nbctl.8.xml                 |   2 +-
>>  9 files changed, 860 insertions(+), 47 deletions(-)
>>
>> --
>> 2.55.0
>>
>>
> Looks good to me, thanks.
> Acked-by: Ales Musil <[email protected]>
> 

Thanks, Ales, for the reviews!

Applied to main, 26.09 and 26.03.

Regards,
Dumitru

_______________________________________________
dev mailing list
[email protected]
https://mail.openvswitch.org/mailman/listinfo/ovs-dev

Reply via email to