DM: Incorrect RT export policy for private VN
Affects | Status | Importance | Assigned to | Milestone | ||
---|---|---|---|---|---|---|
Juniper Openstack | Status tracked in Trunk | |||||
R2.20 |
Fix Committed
|
High
|
Suresh Balineni | |||
Trunk |
Fix Committed
|
High
|
Suresh Balineni |
Bug Description
When DM pushes the VRF config corresponding to a contrail VN, it sets the route import/export policy. This VRF should export only the configured RT and should import all RTs that are permitted based on policy configurations. Currently, the export policy is set to export all RT.
VN1 with RT 10000 and VN2 with RT 20000 are created. The resulting policy-options:
policy-options {
policy-
term t1 {
then {
}
}
}
information type: | Proprietary → Public |
tags: | added: device-manager |
summary: |
- [R2.20] DM: Incorrect RT export policy for private VN + DM: Incorrect RT export policy for private VN |
no longer affects: | juniperopenstack/r2.30 |
@Amit
Discussed the other question you asked Suresh i.e. why add the
auto-generated targets to MX config. We should continue doing
that because it's not mandatory for the user to configure route
target on the VN. It's needed only if the routes need to go to
a WAN network that uses it's own RT to represent the VPN. If
the 2 VN is needed on the MX only to do inter-VN L3 forwarding
user shouldn't need to configure the RT on the VN.
IOW, once Suresh has fixed this bug, you should test the inter-
subnet routing functionality without configuring RTs on the VNs.