[ovn] Geneve traffic should not create conntrack entries
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
tripleo |
Fix Released
|
High
|
Michele Baldessari |
Bug Description
Geneve UDP traffic right now creates conntrack entries whenever there's traffic between different hypervisors:
udp 17 26 src=172.17.2.55 dst=172.17.2.75 sport=8543 dport=6081 [UNREPLIED] src=172.17.2.75 dst=172.17.2.55 sport=6081 dport=8543 mark=0 secctx=
udp 17 26 src=172.17.2.75 dst=172.17.2.55 sport=6901 dport=6081 [UNREPLIED] src=172.17.2.55 dst=172.17.2.75 sport=6081 dport=6901 mark=0 secctx=
These are not needed and can impact performance. From TripleO we can prevent this from happening by adding the following iptables rules wherever ovn-controller runs (ie. tunnel endpoints).
iptables -t raw -A PREROUTING -p udp --dport 6081 -j NOTRACK
iptables -t raw -A OUTPUT -p udp --dport 6081 -j NOTRACK
Changed in tripleo: | |
importance: | Undecided → High |
milestone: | none → victoria-1 |
Changed in tripleo: | |
assignee: | Daniel Alvarez (dalvarezs) → Michele Baldessari (michele) |
Changed in tripleo: | |
assignee: | Michele Baldessari (michele) → Daniel Alvarez (dalvarezs) |
Changed in tripleo: | |
assignee: | Daniel Alvarez (dalvarezs) → Michele Baldessari (michele) |
Changed in tripleo: | |
milestone: | victoria-1 → victoria-3 |
Fix proposed to branch: master /review. opendev. org/738419
Review: https:/