[root@primary ~]# ovs-vsctl show
a6b77a09-2647-47d7-8815-ef4d4f689ce8
Bridge br-int
fail_mode: secure
Port "tap5a27427b-22" Interface "tap5a27427b-22"
Port br-int Interface br-int type: internal
Port "patch-br-int-to-provnet-d556080a-799f-4621-bb2d-d4ac9b8bb32e" Interface "patch-br-int-to-provnet-d556080a-799f-4621-bb2d-d4ac9b8bb32e" type: patch options: {peer="patch-provnet-d556080a-799f-4621-bb2d-d4ac9b8bb32e-to-br-int"}
Port "tapa4e1ef4d-40"
tag: 4095 Interface "tapa4e1ef4d-40"
Port "tap4b56611b-99"
tag: 4095 Interface "tap4b56611b-99"
Port "tap473919fe-31"
tag: 4095 Interface "tap473919fe-31"
Bridge br-ex
Port br-ex Interface br-ex type: internal
Port "patch-provnet-d556080a-799f-4621-bb2d-d4ac9b8bb32e-to-br-int" Interface "patch-provnet-d556080a-799f-4621-bb2d-d4ac9b8bb32e-to-br-int" type: patch options: {peer="patch-br-int-to-provnet-d556080a-799f-4621-bb2d-d4ac9b8bb32e"}
[root@primary ~]# ip netns exec ovnmeta-a4e1ef4d-47ce-4b92-8043-70d88237eff1 ssh cirros@10.0.0.4
cirros@10.0.0.4's password:
[root@primary ~]# ip netns exec ovnmeta-a4e1ef4d-47ce-4b92-8043-70d88237eff1 ssh cirros@10.0.0.6
The authenticity of host '10.0.0.6 (10.0.0.6)' can't be established.
RSA key fingerprint is SHA256:cDLkQEB0LfxZfIvpd084MucUa4uohUd0COf3ArPa1A0.
RSA key fingerprint is MD5:cd:4e:f7:f5:e1:bb:61:ea:a7:4d:46:f8:67:43:20:00.
Are you sure you want to continue connecting (yes/no)? yes
Warning: Permanently added '10.0.0.6' (RSA) to the list of known hosts.
cirros@10.0.0.6's password:
[root@primary ~]# ip netns exec ovnmeta-a4e1ef4d-47ce-4b92-8043-70d88237eff1 ssh cirros@10.0.0.8
The authenticity of host '10.0.0.8 (10.0.0.8)' can't be established.
RSA key fingerprint is SHA256:XUX8EfLF2oRJLqDChEEw3smHGeHm7zcQapdpayZcb0Y.
RSA key fingerprint is MD5:33:00:41:fb:96:25:a4:79:b5:2e:63:c8:03:8f:2e:be.
Are you sure you want to continue connecting (yes/no)? ^C
[root@primary ~]#
[root@primary ~]#
Sorry for the delay, I've verified that the solution would be fine for OVN (and I suspect that also for other openflow based solutions which don't use the "NORMAL" rule).
[root@primary ~]# ovs-vsctl show 2647-47d7- 8815-ef4d4f689c e8
Interface "tap5a27427b-22"
Interface br-int
type: internal br-int- to-provnet- d556080a- 799f-4621- bb2d-d4ac9b8bb3 2e"
Interface "patch- br-int- to-provnet- d556080a- 799f-4621- bb2d-d4ac9b8bb3 2e"
type: patch
options: {peer=" patch-provnet- d556080a- 799f-4621- bb2d-d4ac9b8bb3 2e-to-br- int"}
Interface "tapa4e1ef4d-40"
Interface "tap4b56611b-99"
Interface "tap473919fe-31"
Interface br-ex
type: internal provnet- d556080a- 799f-4621- bb2d-d4ac9b8bb3 2e-to-br- int"
Interface "patch- provnet- d556080a- 799f-4621- bb2d-d4ac9b8bb3 2e-to-br- int"
type: patch
options: {peer=" patch-br- int-to- provnet- d556080a- 799f-4621- bb2d-d4ac9b8bb3 2e"} a4e1ef4d- 47ce-4b92- 8043-70d88237ef f1 ssh cirros@10.0.0.4
a6b77a09-
Bridge br-int
fail_mode: secure
Port "tap5a27427b-22"
Port br-int
Port "patch-
Port "tapa4e1ef4d-40"
tag: 4095
Port "tap4b56611b-99"
tag: 4095
Port "tap473919fe-31"
tag: 4095
Bridge br-ex
Port br-ex
Port "patch-
[root@primary ~]# ip netns exec ovnmeta-
cirros@10.0.0.4's password:
[root@primary ~]# ip netns exec ovnmeta- a4e1ef4d- 47ce-4b92- 8043-70d88237ef f1 ssh cirros@10.0.0.6 cDLkQEB0LfxZfIv pd084MucUa4uohU d0COf3ArPa1A0. 4e:f7:f5: e1:bb:61: ea:a7:4d: 46:f8:67: 43:20:00.
The authenticity of host '10.0.0.6 (10.0.0.6)' can't be established.
RSA key fingerprint is SHA256:
RSA key fingerprint is MD5:cd:
Are you sure you want to continue connecting (yes/no)? yes
Warning: Permanently added '10.0.0.6' (RSA) to the list of known hosts.
cirros@10.0.0.6's password:
[root@primary ~]# ip netns exec ovnmeta- a4e1ef4d- 47ce-4b92- 8043-70d88237ef f1 ssh cirros@10.0.0.8 XUX8EfLF2oRJLqD ChEEw3smHGeHm7z cQapdpayZcb0Y. 00:41:fb: 96:25:a4: 79:b5:2e: 63:c8:03: 8f:2e:be.
The authenticity of host '10.0.0.8 (10.0.0.8)' can't be established.
RSA key fingerprint is SHA256:
RSA key fingerprint is MD5:33:
Are you sure you want to continue connecting (yes/no)? ^C
[root@primary ~]#
[root@primary ~]#
Sorry for the delay, I've verified that the solution would be fine for OVN (and I suspect that also for other openflow based solutions which don't use the "NORMAL" rule).