Disabling conntrack for GENEVE increases throughput by 5-10% per our OVN datapath testing. $ iptables -t raw -A PREROUTING -p udp --dport 6081 -j NOTRACK $ iptables -t raw -A OUTPUT -p udp --dport 6081 -j NOTRACK
Verified on 4.6.0-0.nightly-2020-07-25-091217 iptables-raw-compute.internal 5:-A PREROUTING -p udp -m udp --dport 6081 -j NOTRACK 6:-A OUTPUT -p udp -m udp --dport 6081 -j NOTRACK
Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory (OpenShift Container Platform 4.6 GA Images), and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. https://access.redhat.com/errata/RHBA-2020:4196