Note: This bug is displayed in read-only format because the product is no longer active in Red Hat Bugzilla.
The FDP team is no longer accepting new bugs in Bugzilla. Please report your issues under FDP project in Jira. Thanks.

Bug 1823003

Summary: options:lb_force_snat_ip does not support dual-stack
Product: Red Hat Enterprise Linux Fast Datapath Reporter: Dan Winship <danw>
Component: ovn2.13Assignee: Mark Michelson <mmichels>
Status: CLOSED ERRATA QA Contact: Jianlin Shi <jishi>
Severity: urgent Docs Contact:
Priority: urgent    
Version: FDP 20.ECC: ctrautma, dcbw, jishi, mmichels, nusiddiq, ralongi
Target Milestone: ---   
Target Release: ---   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2020-09-16 16:01:23 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description Dan Winship 2020-04-10 21:50:00 UTC
ovn-kubernetes uses options:lb_force_snat_ip on its logical routers, but it is only possible to set a single SNAT IP, meaning you can't force both IPv4 and IPv6 connections to be SNATed.

(The dnat_force_snat_ip option seems to have the same problem, though ovn-kubernetes doesn't use that. I'm not sure if there are any other cases, either used by ovn-kubernetes or not.)

Comment 1 Dan Winship 2020-07-09 15:25:11 UTC
poke. any update on this?

Comment 3 Mark Michelson 2020-07-16 18:15:03 UTC
Patch posted to upstream mailing list: https://patchwork.ozlabs.org/project/openvswitch/patch/20200716180606.2820933-1-mmichels@redhat.com/

The patch's approach is to alter both lb_force_snat_ip and dnat_force_snat_ip to accept an IPv4 and IPv6 address.

Example:

ovn-nbctl set logical_router R2 options:lb_force_snat_ip="20.0.0.2 fd20::2"

The logic allows for only one IPv4 and/or one IPv6 address to be specified with the option.

Comment 7 Jianlin Shi 2020-08-24 07:18:56 UTC
test with following script:

#!/bin/bash                                                        
                                                                               
                                                                   
# Logical network:                                                                          
# Three LRs - R1, R2 and R3 that are connected to each other via LS "join"
# in 20.0.0.0/24 network. R1 has switchess foo (192.168.1.0/24) and 
# bar (192.168.2.0/24) connected to it. R2 has alice (172.16.1.0/24) connected
# to it.  R3 has bob (172.16.1.0/24) connected to it. Note how both alice and
# bob have the same subnet behind it.                               
#    foo -- R1 -- join - R2 -- alice                            
#           |          |                                                   
#    bar ----          - R3 --- bob                             
#                                                                   
                                                                
systemctl start openvswitch                                                
systemctl start ovn-northd                                
ovn-nbctl set-connection ptcp:6641                                                          
ovn-sbctl set-connection ptcp:6642                                    
ovs-vsctl set open . external_ids:system-id=hv1 external_ids:ovn-remote=tcp:20.0.31.25:6642 external_ids:ovn-encap-type=geneve external_ids:ovn-encap-ip=20.0.31.25
systemctl restart ovn-controller                                      
                                                                
ovs-vsctl add-br br-nat                                                    
ovs-vsctl set open . external_ids:ovn-bridge-mappings=nattest:br-nat
ip link set br-nat up                                                
                                                                   
ovn-nbctl lr-add R1                                                            
ovn-nbctl lr-add R2                                                  
ovn-nbctl lr-add R3                                                
                                                                                                 
ovn-nbctl set logical_router R2 options:chassis=hv1                  
ovn-nbctl set logical_router R3 options:chassis=hv0                
                                                                               
ovn-nbctl ls-add foo                                               
ovn-nbctl ls-add bar                                                                        
ovn-nbctl ls-add alice                                       
ovn-nbctl ls-add bob                                         
ovn-nbctl ls-add join                                          
                                                               
ovn-nbctl lrp-add R1 foo 00:00:01:01:02:03 192.168.1.1/24 2001::1/64
ovn-nbctl lsp-add foo rp-foo -- set logical_switch_port rp-foo \
        type=router options:router-port=foo addresses=\"00:00:01:01:02:03\"
                                                                                           
ovn-nbctl lrp-add R1 bar 00:00:01:01:02:04 192.168.2.1/24 2002::1/64
ovn-nbctl lsp-add bar rp-bar -- set Logical_Switch_Port rp-bar \           
        type=router options:router-port=bar addresses=\"00:00:01:01:02:04\"
                                                          
ovn-nbctl lrp-add R2 alice 00:00:02:01:02:03 172.16.1.1/24 3001::1/64                       
ovn-nbctl lsp-add alice rp-alice -- set Logical_Switch_Port rp-alice \
        type=router options:router-port=alice addresses=\"00:00:02:01:02:03\"
ovn-nbctl lrp-add R3 bob 00:00:03:01:02:03 172.16.1.2/24 3001::2/64   
ovn-nbctl lsp-add bob rp-bob -- set Logical_Switch_Port rp-bob \
        type=router options:router-port=bob addresses=\"00:00:03:01:02:03\"

ovn-nbctl lrp-add R1 R1_join 00:00:04:01:02:03 20.0.0.1/24 4000::1/64
ovn-nbctl lsp-add join r1-join -- set Logical_Switch_Port r1-join \
        type=router options:router-port=R1_join addresses='"00:00:04:01:02:03"'
ovn-nbctl lrp-add R2 R2_join 00:00:04:01:02:04 20.0.0.2/24 4000::2/64
ovn-nbctl lsp-add join r2-join -- set Logical_Switch_Port r2-join \
        type=router options:router-port=R2_join addresses='"00:00:04:01:02:04"'
ovn-nbctl lrp-add R3 R3_join 00:00:04:01:02:05 20.0.0.3/24 4000::3/64
ovn-nbctl lsp-add join r3-join -- set Logical_Switch_Port r3-join \
        type=router options:router-port=R3_join addresses='"00:00:04:01:02:05"'
ovn-nbctl --policy="src-ip" lr-route-add R1 192.168.1.0/24 20.0.0.2
ovn-nbctl --policy="src-ip" lr-route-add R1 192.168.2.0/24 20.0.0.3
ovn-nbctl --policy="src-ip" lr-route-add R1 2001::/64 4000::2
ovn-nbctl --policy="src-ip" lr-route-add R1 2002::/64 4000::3

ovn-nbctl lr-route-add R2 192.168.0.0/16 20.0.0.1
ovn-nbctl lr-route-add R3 192.168.0.0/16 20.0.0.1
ovn-nbctl lr-route-add R2 2001::/64 4000::1
ovn-nbctl lr-route-add R2 2002::/64 4000::1
ovn-nbctl lr-route-add R3 2001::/64 4000::1
ovn-nbctl lr-route-add R3 2002::/64 4000::1

# add load balancer
ovn-nbctl lb-add lb0 30.0.0.1 192.168.1.2,192.168.2.2
ovn-nbctl lb-add lb0 6010::1 2001::2,2002::2
uuid=`ovn-nbctl lb-list | grep lb0 | awk '{print $1}'`
ovn-nbctl set logical_router R2 load_balancer=$uuid
ovn-nbctl set logical_router R3 load_balancer=$uuid

ovn-nbctl show

ip netns add foo1
ovs-vsctl add-port br-int foo1 -- set interface foo1 type=internal
ip link set foo1 netns foo1
ip netns exec foo1 ip link set foo1 address f0:00:00:01:02:03
ip netns exec foo1 ip link set foo1 up
ip netns exec foo1 ip addr add 192.168.1.2/24 dev foo1
ip netns exec foo1 ip -6 addr add 2001::2/64 dev foo1
ip netns exec foo1 ip route add default via  192.168.1.1 dev foo1
ip netns exec foo1 ip -6 route add default via 2001::1 dev foo1
ovs-vsctl set interface foo1 external_ids:iface-id=foo1
ovn-nbctl lsp-add foo foo1 -- lsp-set-addresses foo1 "f0:00:00:01:02:03 192.168.1.2 2001::2"

ip netns add bar1
ip link add bar1 netns bar1 type veth peer name bar1_br
ip netns exec bar1 ip link set bar1 address f0:00:00:01:02:05
ip netns exec bar1 ip link set bar1 up
ip netns exec bar1 ip addr add 192.168.2.2/24 dev bar1
ip netns exec bar1 ip -6 addr add 2002::2/64 dev bar1
ip netns exec bar1 ip route add default via 192.168.2.1 dev bar1
ip netns exec bar1 ip -6 route add default via 2002::1 dev bar1
ip link set bar1_br up
ovs-vsctl add-port br-int bar1_br
ovs-vsctl set interface bar1_br external_ids:iface-id=bar1
ovn-nbctl lsp-add bar bar1 -- lsp-set-addresses bar1 "f0:00:00:01:02:05 192.168.2.2 2002::2"

ip netns add alice1                                            
ovs-vsctl add-port br-int alice1 -- set interface alice1 type=internal
ip link set alice1 netns alice1                                                             
ip netns exec alice1 ip link set alice1 address f0:00:00:01:02:04
ip netns exec alice1 ip link set alice1 up                                                       
ip netns exec alice1 ip addr add 172.16.1.3/24 dev alice1      
ip netns exec alice1 ip -6 addr add 3001::3/64 dev alice1      
ip netns exec alice1 ip route add default via 172.16.1.1 dev alice1
ip netns exec alice1 ip -6 route add default via 3001::1 dev alice1
ovs-vsctl set interface alice1 external_ids:iface-id=alice1
ovn-nbctl lsp-add alice alice1 -- lsp-set-addresses alice1 "f0:00:00:01:02:04 172.16.1.3 3001::3"
                                                               
ip netns add bob1                                                          
ip link add bob1 netns bob1 type veth peer name bob1_br                    
ip netns exec bob1 ip link set bob1 address f0:00:00:01:02:06
ip netns exec bob1 ip link set bob1 up                                                      
ip netns exec bob1 ip addr add 172.16.1.4/24 dev bob1     
ip netns exec bob1 ip -6 addr add 3001::4/64 dev bob1                                      
ip netns exec bob1 ip route add default via 172.16.1.2 dev bob1       
ip netns exec bob1 ip -6 route add default via 3001::2 dev bob1            
ip link set bob1_br up                                           
ovs-vsctl add-port br-int bob1_br         
ovs-vsctl set interface bob1_br external_ids:iface-id=bob1
ovn-nbctl lsp-add bob bob1 -- lsp-set-addresses bob1 "f0:00:00:01:02:06 172.16.1.4 3001::4"
                                                                   
ovn-nbctl set logical_router R2 options:lb_force_snat_ip="20.0.0.2 4000::2"
ovn-nbctl set logical_router R3 options:lb_force_snat_ip="20.0.0.3 4000::3"
                                                                                                 
ip netns exec alice1 ping 30.0.0.1 -c 1
ip netns exec bob1 ping 30.0.0.1 -c 1
ip netns exec alice1 ping6 6010::1 -c 1                
ip netns exec bob1 ping6 6010::1 -c 1


Verified on ovn2.13-20.06.2-1.el8fdp.x86_64 :

+ ovn-nbctl set logical_router R2 'options:lb_force_snat_ip=20.0.0.2 4000::2'
+ ovn-nbctl set logical_router R3 'options:lb_force_snat_ip=20.0.0.3 4000::3'
+ sleep 5                                                                                             
+ ip netns exec alice1 ping 30.0.0.1 -c 1                                                             
PING 30.0.0.1 (30.0.0.1) 56(84) bytes of data.                                                        
64 bytes from 30.0.0.1: icmp_seq=1 ttl=62 time=3.43 ms
                                                                                                      
--- 30.0.0.1 ping statistics ---                                                                      
1 packets transmitted, 1 received, 0% packet loss, time 0ms
rtt min/avg/max/mdev = 3.430/3.430/3.430/0.000 ms                                                     
+ ip netns exec bob1 ping 30.0.0.1 -c 1                                                               
PING 30.0.0.1 (30.0.0.1) 56(84) bytes of data.                                                        
64 bytes from 30.0.0.1: icmp_seq=1 ttl=62 time=7.45 ms
                                                                                                      
--- 30.0.0.1 ping statistics ---                                                                      
1 packets transmitted, 1 received, 0% packet loss, time 0ms
rtt min/avg/max/mdev = 7.446/7.446/7.446/0.000 ms                                                     
+ ip netns exec alice1 ping6 6010::1 -c 1                                                             
PING 6010::1(6010::1) 56 data bytes                                                                   
64 bytes from 6010::1: icmp_seq=1 ttl=62 time=5.29 ms
                                                                                                      
--- 6010::1 ping statistics ---                                                                       
1 packets transmitted, 1 received, 0% packet loss, time 0ms
rtt min/avg/max/mdev = 5.293/5.293/5.293/0.000 ms                                                     
+ ip netns exec bob1 ping6 6010::1 -c 1                                                               
PING 6010::1(6010::1) 56 data bytes                                                                   
64 bytes from 6010::1: icmp_seq=1 ttl=62 time=7.22 ms
                                                                                                      
--- 6010::1 ping statistics ---                                                                       
1 packets transmitted, 1 received, 0% packet loss, time 0ms
rtt min/avg/max/mdev = 7.218/7.218/7.218/0.000 ms                                                     
[root@dell-per740-12 bz1823003]# rpm -qa | grep -E "openvswitch|ovn"
ovn2.13-host-20.06.2-1.el8fdp.x86_64                                                                  
openvswitch2.13-2.13.0-54.el8fdp.x86_64                                                               
kernel-kernel-networking-openvswitch-ovn-common-1.0-7.noarch
python3-openvswitch2.13-2.13.0-54.el8fdp.x86_64                                                       
ovn2.13-central-20.06.2-1.el8fdp.x86_64                                                               
openvswitch-selinux-extra-policy-1.0-23.el8fdp.noarch
ovn2.13-20.06.2-1.el8fdp.x86_64

packets on foo1:

03:16:29.127838 00:00:01:01:02:03 > f0:00:00:01:02:03, ethertype IPv4 (0x0800), length 98: (tos 0x0, ttl 62, id 52181, offset 0, flags [DF], proto ICMP (1), length 84)
    20.0.0.3 > 192.168.1.2: ICMP echo request, id 22556, seq 1, length 64
03:16:29.128429 f0:00:00:01:02:03 > 00:00:01:01:02:03, ethertype IPv4 (0x0800), length 98: (tos 0x0, ttl 64, id 54732, offset 0, flags [none], proto ICMP (1), length 84)
    192.168.1.2 > 20.0.0.3: ICMP echo reply, id 22556, seq 1, length 64
03:16:29.166737 00:00:01:01:02:03 > f0:00:00:01:02:03, ethertype IPv6 (0x86dd), length 118: (flowlabel 0x09b9b, hlim 62, next-header ICMPv6 (58) payload length: 64) 4000::2 > 2001::2: [icmp6 sum ok] ICMP6, echo request, seq 1
03:16:29.168405 f0:00:00:01:02:03 > 00:00:01:01:02:03, ethertype IPv6 (0x86dd), length 118: (flowlabel 0xc03a1, hlim 64, next-header ICMPv6 (58) payload length: 64) 2001::2 > 4000::2: [icmp6 sum ok] ICMP6, echo reply, seq 1

packets on bar1:

03:16:29.094907 00:00:01:01:02:04 > f0:00:00:01:02:05, ethertype IPv4 (0x0800), length 98: (tos 0x0, ttl 62, id 44139, offset 0, flags [DF], proto ICMP (1), length 84)
    20.0.0.2 > 192.168.2.2: ICMP echo request, id 22555, seq 1, length 64
03:16:29.095515 f0:00:00:01:02:05 > 00:00:01:01:02:04, ethertype IPv4 (0x0800), length 98: (tos 0x0, ttl 64, id 30779, offset 0, flags [none], proto ICMP (1), length 84)
    192.168.2.2 > 20.0.0.2: ICMP echo reply, id 22555, seq 1, length 64
03:16:29.208290 00:00:01:01:02:04 > f0:00:00:01:02:05, ethertype IPv6 (0x86dd), length 118: (flowlabel 0xe95fb, hlim 62, next-header ICMPv6 (58) payload length: 64) 4000::3 > 2002::2: [icmp6 sum ok] ICMP6, echo request, seq 1
03:16:29.209498 f0:00:00:01:02:05 > 00:00:01:01:02:04, ethertype IPv6 (0x86dd), length 118: (flowlabel 0xa84e0, hlim 64, next-header ICMPv6 (58) payload length: 64) 2002::2 > 4000::3: [icmp6 sum ok] ICMP6, echo reply, seq 1

Comment 8 Jianlin Shi 2020-08-24 07:38:27 UTC
(In reply to Jianlin Shi from comment #7)
> test with following script:
> 
> #!/bin/bash                                                        
>                                                                             
> 
>                                                                    
> # Logical network:                                                          
> 
> # Three LRs - R1, R2 and R3 that are connected to each other via LS "join"
> # in 20.0.0.0/24 network. R1 has switchess foo (192.168.1.0/24) and 
> # bar (192.168.2.0/24) connected to it. R2 has alice (172.16.1.0/24)
> connected
> # to it.  R3 has bob (172.16.1.0/24) connected to it. Note how both alice and
> # bob have the same subnet behind it.                               
> #    foo -- R1 -- join - R2 -- alice                            
> #           |          |                                                   
> #    bar ----          - R3 --- bob                             
> #                                                                   
>                                                                 
> systemctl start openvswitch                                                
> systemctl start ovn-northd                                
> ovn-nbctl set-connection ptcp:6641                                          
> 
> ovn-sbctl set-connection ptcp:6642                                    
> ovs-vsctl set open . external_ids:system-id=hv1
> external_ids:ovn-remote=tcp:20.0.31.25:6642
> external_ids:ovn-encap-type=geneve external_ids:ovn-encap-ip=20.0.31.25
> systemctl restart ovn-controller                                      
>                                                                 
> ovs-vsctl add-br br-nat                                                    
> ovs-vsctl set open . external_ids:ovn-bridge-mappings=nattest:br-nat
> ip link set br-nat up                                                
>                                                                    
> ovn-nbctl lr-add R1                                                         
> 
> ovn-nbctl lr-add R2                                                  
> ovn-nbctl lr-add R3                                                
>                                                                             
> 
> ovn-nbctl set logical_router R2 options:chassis=hv1                  
> ovn-nbctl set logical_router R3 options:chassis=hv0     


# this should be hv1
ovn-nbctl set logical_router R3 options:chassis=hv1    
       

also verify on rhel7 version:

+ ovn-nbctl set logical_router R2 'options:lb_force_snat_ip=20.0.0.2 4000::2'                         
+ ovn-nbctl set logical_router R3 'options:lb_force_snat_ip=20.0.0.3 4000::3'
+ ip netns exec foo1 tcpdump -i foo1 -w foo1.pcap                                                     
+ sleep 5
+ ip netns exec bar1 tcpdump -i bar1 -w bar1.pcap                                                     
tcpdump: listening on bar1, link-type EN10MB (Ethernet), capture size 262144 bytes
tcpdump: listening on foo1, link-type EN10MB (Ethernet), capture size 262144 bytes                    
+ ip netns exec alice1 ping 30.0.0.1 -c 1                                                             
PING 30.0.0.1 (30.0.0.1) 56(84) bytes of data.
64 bytes from 30.0.0.1: icmp_seq=1 ttl=62 time=2.85 ms                                                

--- 30.0.0.1 ping statistics ---
1 packets transmitted, 1 received, 0% packet loss, time 0ms
rtt min/avg/max/mdev = 2.853/2.853/2.853/0.000 ms                                                     
+ ip netns exec bob1 ping 30.0.0.1 -c 1                                                               
PING 30.0.0.1 (30.0.0.1) 56(84) bytes of data.
64 bytes from 30.0.0.1: icmp_seq=1 ttl=62 time=12.6 ms                                                

--- 30.0.0.1 ping statistics ---                                                                      
1 packets transmitted, 1 received, 0% packet loss, time 0ms                                           
rtt min/avg/max/mdev = 12.602/12.602/12.602/0.000 ms                                                  
+ ip netns exec alice1 ping6 6010::1 -c 1                                                             
PING 6010::1(6010::1) 56 data bytes                                                                   
64 bytes from 6010::1: icmp_seq=1 ttl=62 time=4.17 ms                                                 

--- 6010::1 ping statistics ---                                                                       
1 packets transmitted, 1 received, 0% packet loss, time 0ms
rtt min/avg/max/mdev = 4.176/4.176/4.176/0.000 ms                                                     
+ ip netns exec bob1 ping6 6010::1 -c 1                                                               
PING 6010::1(6010::1) 56 data bytes                                                                   
64 bytes from 6010::1: icmp_seq=1 ttl=62 time=4.41 ms                                                 

--- 6010::1 ping statistics ---                                                                       
1 packets transmitted, 1 received, 0% packet loss, time 0ms                                           
rtt min/avg/max/mdev = 4.416/4.416/4.416/0.000 ms                                                     
+ pkill tcpdump
5 packets captured12 packets captured                                                                 

16 packets received by filter18 packets received by filter                                            

0 packets dropped by kernel0 packets dropped by kernel                                                

[root@dell-per740-42 bz1823003]# rpm -qa | grep -E "openvswitch|ovn"
openvswitch2.13-2.13.0-45.el7fdp.x86_64
ovn2.13-central-20.06.2-1.el7fdp.x86_64
openvswitch-selinux-extra-policy-1.0-15.el7fdp.noarch
kernel-kernel-networking-openvswitch-ovn-common-1.0-7.noarch
ovn2.13-20.06.2-1.el7fdp.x86_64
ovn2.13-host-20.06.2-1.el7fdp.x86_64

Comment 10 errata-xmlrpc 2020-09-16 16:01:23 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory (ovn2.13 bug fix and enhancement update), and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://access.redhat.com/errata/RHBA-2020:3769