Bug 1741477 - [3.11] EgressIP doesn't work with NetworkPolicy unless traffic from default project is allowed
Summary: [3.11] EgressIP doesn't work with NetworkPolicy unless traffic from default p...
Alias: None
Product: OpenShift Container Platform
Classification: Red Hat
Component: Networking
Version: 3.11.0
Hardware: Unspecified
OS: Unspecified
Target Milestone: ---
: 3.11.z
Assignee: Casey Callendrello
QA Contact: zhaozhanqi
: 1742249 (view as bug list)
Depends On: 1700431 1741499
Blocks: 1766583
TreeView+ depends on / blocked
Reported: 2019-08-15 09:18 UTC by K Chandra Sekar
Modified: 2023-12-15 16:41 UTC (History)
10 users (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Cause: Egress IPs did not work correctly in namespaces with restrictive NetworkPolicies. Consequence: Pods that accepted traffic only from specific sources would not be able to send egress traffic via egress IPs, because the response from the external server would be mistakenly rejected by their NetworkPolicies. Fix: Replies from egress traffic are now correctly recognized as replies rather than as new connections. Result: Egress IPs and NetworkPolicy work together.
Clone Of: 1700431
: 1766583 (view as bug list)
Last Closed: 2019-09-24 08:08:08 UTC
Target Upstream Version:

Attachments (Terms of Use)

System ID Private Priority Status Summary Last Updated
Github openshift origin pull 23610 0 'None' closed Bug 1741477: [3.11] Pass egress IP packets to conntrack 2021-02-05 15:10:27 UTC
Red Hat Product Errata RHBA-2019:2816 0 None None None 2019-09-24 08:08:18 UTC

Comment 1 Casey Callendrello 2019-08-26 11:26:21 UTC
*** Bug 1742249 has been marked as a duplicate of this bug. ***

Comment 3 huirwang 2019-09-19 10:21:36 UTC
Verified in version: v3.11.146


1. Create a project p1 using egressIP
2. Add egressIP to node A
3. Create a pod in project p1 which is *not* running on node A.
4. Create a networkPolicy which only allows traffic from itself. Used the file in "Steps to Reproduce :step4"

Go to the pod in project p1 and try to reach a resource outside OpenShift. 
/ # ping www.google.com
PING www.google.com ( 56(84) bytes of data.
64 bytes from iad23s61-in-f4.1e100.net ( icmp_seq=1 ttl=48 time=287 ms
64 bytes from iad23s61-in-f4.1e100.net ( icmp_seq=2 ttl=48 time=286 ms
64 bytes from iad23s61-in-f4.1e100.net ( icmp_seq=3 ttl=48 time=285 ms
64 bytes from iad23s61-in-f4.1e100.net ( icmp_seq=4 ttl=48 time=286 ms

Result: it works.

5. Create a rule that allows traffic from the default project. Used the file in "Steps to Reproduce :step6"
Result: it works, traffic goes through.

6. Completely remove every networkPolicy. Traffic also works

Comment 5 errata-xmlrpc 2019-09-24 08:08:08 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.


Note You need to log in before you can comment on or make changes to this bug.