Bug 2162592

Summary: OVN Load Balancers should allow all "related" ICMP error messages to pass through
Product: Red Hat Enterprise Linux Fast Datapath Reporter: OVN Bot <ovn-bot>
Component: ovn22.12Assignee: Ales Musil <amusil>
Status: CLOSED UPSTREAM QA Contact: ying xu <yinxu>
Severity: unspecified Docs Contact:
Priority: high    
Version: FDP 22.LCC: amusil, ctrautma, dceara, fbaudin, fwestpha, jiji, jishi, kkarampo, mmichels
Target Milestone: ---   
Target Release: ---   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: ovn22.12-22.12.0-15.el9fdp Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2025-02-10 04:01:43 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description OVN Bot 2023-01-20 05:01:00 UTC
This is an automatically-generated clone of issue https://bugzilla.redhat.com/show_bug.cgi?id=2126083

Comment 3 ying xu 2023-03-07 07:40:15 UTC
reproduced on version:
ovn22.09-22.09.0-46.el9fdp.x86_64
ovn22.09-central-22.09.0-46.el9fdp.x86_64
ovn22.09-host-22.09.0-46.el9fdp.x86_64


and verified on version:
ovn22.12-22.12.0-20.el9fdp.x86_64
ovn22.12-central-22.12.0-20.el9fdp.x86_64
ovn22.12-host-22.12.0-20.el9fdp.x86_64



topo as below:
                          system1                                                                                  system2
server0-------ls1----------lr1-----public------------br-ext------------br-ext--------pulic-----------lr2---------ls2--------client
and set LB on lr1(enabled reject=true), dnat and snat on lr2. and set mtu=500 on lr2.


I start connection between server and client,
send big packet to client.
then I can see lr2 send icmp unreachable packets to lb vip.

on old version:
big packets not pass

on fixed version:
big packets pass

Comment 7 Red Hat Bugzilla 2025-02-10 04:01:43 UTC
This product has been discontinued or is no longer tracked in Red Hat Bugzilla.