Bug 1916373

Summary: failure doing UPI installation with IPSec enabled
Product: OpenShift Container Platform Reporter: Matthew Staebler <mstaeble>
Component: InstallerAssignee: Mark Gray <mark.d.gray>
Installer sub component: openshift-installer QA Contact: Anurag saxena <anusaxen>
Status: CLOSED CURRENTRELEASE Docs Contact:
Severity: high    
Priority: high CC: gpei, jialiu, mark.d.gray, yunjiang, zzhao
Version: 4.7   
Target Milestone: ---   
Target Release: 4.7.0   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: Doc Type: No Doc Update
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2021-02-08 17:28:03 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description Matthew Staebler 2021-01-14 16:31:26 UTC
https://bugzilla.redhat.com/show_bug.cgi?id=1908782 made changes to allow IKE, ESP and Nat-t traffic required for IPSec-enabled cluster. However, the changes were only made for IPI installations. Similar changes need to also be made for UPI installations.

Comment 2 zhaozhanqi 2021-02-07 11:22:31 UTC
Verified this bug on UPI on aws/openstack/gcp