Hi Yacan,

That's interesting, we're actually using it for a kube-proxy replacement
too [0],
but with CNAT rules being handled in the main VRF. I'd be curious of the
networking model you're targeting.

On the cnat evolution, if it's only adding the ability to create FIB-based
VIP
sessions in a specific FIB, that would be fairly easy. But if you aim at
supporting all kube-proxy use-cases, you might require some additional
evolutions.

Kind regards,
-Nathan

[0] https://github.com/projectcalico/vpp-dataplane

Le mer. 7 avr. 2021 à 04:40, liuyacan <[email protected]> a écrit :

> Hi  Nathan,
>
>    We hope to use CNAT to play the role of kube-proxy.
>    Since our applications specifies namespaces,  so we want CNAT rules
>    to take effect in different FIB tables.
>
> Best Regards,
> Yacan
>
> On 4/6/2021 20:59,Nathan Skrzypczak<[email protected]>
> <[email protected]> wrote:
>
> Hi Yacan,
>
> There is no particular reason, just that the code for CNAT is quite new,
> and
> we never implemented vrf support. I don't see any blocker to add it if you
> need it.
>
> What is the use-case you would like to support ? By specifying a table ID,
> do you
> mean for matching traffic ? Also for the rewrite ? Maybe DNATing to a
> different
> table ?
>
> Best regards,
> -Nathan
>
>
>
> Le mar. 6 avr. 2021 à 11:23, liuyacan <[email protected]> a
> écrit :
>
>> Hi,
>>
>>     We observed that CNAT translation rule now can only be set in the
>> default table for v4 and v6.
>>     Why is there such a restriction ?
>>
>> Best Regards,
>> Yacan
>>
>>
>>
>> 
>>
>>
-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.
View/Reply Online (#19122): https://lists.fd.io/g/vpp-dev/message/19122
Mute This Topic: https://lists.fd.io/mt/81885640/21656
Group Owner: [email protected]
Unsubscribe: https://lists.fd.io/g/vpp-dev/unsub [[email protected]]
-=-=-=-=-=-=-=-=-=-=-=-

Reply via email to