Hi Yacan, That's interesting, we're actually using it for a kube-proxy replacement too [0], but with CNAT rules being handled in the main VRF. I'd be curious of the networking model you're targeting.
On the cnat evolution, if it's only adding the ability to create FIB-based VIP sessions in a specific FIB, that would be fairly easy. But if you aim at supporting all kube-proxy use-cases, you might require some additional evolutions. Kind regards, -Nathan [0] https://github.com/projectcalico/vpp-dataplane Le mer. 7 avr. 2021 à 04:40, liuyacan <[email protected]> a écrit : > Hi Nathan, > > We hope to use CNAT to play the role of kube-proxy. > Since our applications specifies namespaces, so we want CNAT rules > to take effect in different FIB tables. > > Best Regards, > Yacan > > On 4/6/2021 20:59,Nathan Skrzypczak<[email protected]> > <[email protected]> wrote: > > Hi Yacan, > > There is no particular reason, just that the code for CNAT is quite new, > and > we never implemented vrf support. I don't see any blocker to add it if you > need it. > > What is the use-case you would like to support ? By specifying a table ID, > do you > mean for matching traffic ? Also for the rewrite ? Maybe DNATing to a > different > table ? > > Best regards, > -Nathan > > > > Le mar. 6 avr. 2021 à 11:23, liuyacan <[email protected]> a > écrit : > >> Hi, >> >> We observed that CNAT translation rule now can only be set in the >> default table for v4 and v6. >> Why is there such a restriction ? >> >> Best Regards, >> Yacan >> >> >> >> >> >>
-=-=-=-=-=-=-=-=-=-=-=- Links: You receive all messages sent to this group. View/Reply Online (#19122): https://lists.fd.io/g/vpp-dev/message/19122 Mute This Topic: https://lists.fd.io/mt/81885640/21656 Group Owner: [email protected] Unsubscribe: https://lists.fd.io/g/vpp-dev/unsub [[email protected]] -=-=-=-=-=-=-=-=-=-=-=-
