Bug 1886746 - SNAT rule does not provide ARP response
Summary: SNAT rule does not provide ARP response
Keywords:
Status: NEW
Alias: None
Product: Red Hat Enterprise Linux Fast Datapath
Classification: Red Hat
Component: ovn2.11
Version: RHEL 7.7
Hardware: Unspecified
OS: Unspecified
medium
medium
Target Milestone: ---
: ---
Assignee: OVN Team
QA Contact: ying xu
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2020-10-09 10:14 UTC by ying xu
Modified: 2023-07-13 07:25 UTC (History)
1 user (show)

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Environment:
Last Closed:
Target Upstream Version:
Embargoed:


Attachments (Terms of Use)

Description ying xu 2020-10-09 10:14:34 UTC
This bug was initially created as a copy of Bug #1861294

I am copying this bug because: 
ovn 2.11 has this bug too.

# rpm -qa|grep ovn
ovn2.11-central-2.11.1-54.el7fdp.x86_64
ovn2.11-2.11.1-54.el7fdp.x86_64
ovn2.11-host-2.11.1-54.el7fdp.x86_64

Description of problem:

This is a bug found on OpenShift running OVN-Kubernetes

When creating a NAT rule of type "snat" there are no ARP responses given to other "nodes" sending ARP requests for the "External IP" as specified in the NAT rule.   

Version-Release number of selected component (if applicable):

rpm -qa | grep ovn
ovn-central-20.06.1-4.fc31.x86_64
ovn-20.06.1-4.fc31.x86_64
ovn-host-20.06.1-4.fc31.x86_64

How reproducible:

Create a snat rule specifying an external and logical IP. Send a packet from the logical IP to an exterior component, the exterior component will perform ARP requests for the external IP (as to be able to provide the answer), the ARP request is never answered to by OVN and thus the response from the exterior component never reaches the logical IP.   

In the example I am providing we have the following:

Component      Logical IP     External IP
netserver-0    10.244.0.3     172.17.0.126

External Component, with IP:
172.17.0.5

tcpdump logs on the node hosting netserver-0, show the following:

$tcpdump -i any arp
08:36:45.831053 ARP, Request who-has 172.17.0.126 tell 172.17.0.5, length 28
08:36:45.831200 ARP, Request who-has 172.17.0.126 tell 172.17.0.5, length 28
08:36:46.861088 ARP, Request who-has 172.17.0.126 tell 172.17.0.5, length 28
08:36:46.861170 ARP, Request who-has 172.17.0.126 tell 172.17.0.5, length 28
08:36:47.885146 ARP, Request who-has 172.17.0.126 tell 172.17.0.5, length 28
08:36:47.885188 ARP, Request who-has 172.17.0.126 tell 172.17.0.5, length 28

Steps to Reproduce:
1.
2.
3.

Actual results:


Expected results:


Additional info:

I have provided the nbdb and sbdb in the attachments, please feel free to ask me for more information if necessary


Note You need to log in before you can comment on or make changes to this bug.