host-route via allow-address-pair doesn't work without disabling RPF
Affects | Status | Importance | Assigned to | Milestone | ||
---|---|---|---|---|---|---|
Juniper Openstack | Status tracked in Trunk | |||||
Trunk |
Fix Committed
|
Medium
|
Unassigned | |||
OpenContrail |
New
|
Medium
|
Unassigned |
Bug Description
In a scenario where there is a VRRP VIP between 2 VMs and a host-route via the VIP the ingress flow gets dropped.
The problem is that the interface-
VM_1 .......
| .......
VMI_1 ...... <---- VIP ---> ... VMI_2
(aap on vip) .................. (aap on vip)
One workaround is to disable RPF P2 side but this can't be done using openstack APIs.
The other solution is to create interface-
to announce the P1 prefix since they have AAP on the VIP that has a host-route to P1
Observed on 2.21.x
description: | updated |
description: | updated |
description: | updated |
Changed in opencontrail: | |
importance: | Undecided → Medium |
description: | updated |
Review in progress for https:/ /review. opencontrail. org/21271
Submitter: Jean-Philippe Braun (<email address hidden>)