Bug 2162592 - OVN Load Balancers should allow all "related" ICMP error messages to pass through
Summary: OVN Load Balancers should allow all "related" ICMP error messages to pass thr...
Keywords:
Status: VERIFIED
Alias: None
Product: Red Hat Enterprise Linux Fast Datapath
Classification: Red Hat
Component: ovn22.12
Version: FDP 22.L
Hardware: Unspecified
OS: Unspecified
high
unspecified
Target Milestone: ---
: ---
Assignee: Ales Musil
QA Contact: ying xu
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2023-01-20 05:01 UTC by OVN Bot
Modified: 2023-03-14 03:15 UTC (History)
11 users (show)

Fixed In Version: ovn22.12-22.12.0-15.el9fdp
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Environment:
Last Closed:
Target Upstream Version:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Issue Tracker FD-2636 0 None None None 2023-01-20 05:01:51 UTC

Description OVN Bot 2023-01-20 05:01:00 UTC
This is an automatically-generated clone of issue https://bugzilla.redhat.com/show_bug.cgi?id=2126083

Comment 3 ying xu 2023-03-07 07:40:15 UTC
reproduced on version:
ovn22.09-22.09.0-46.el9fdp.x86_64
ovn22.09-central-22.09.0-46.el9fdp.x86_64
ovn22.09-host-22.09.0-46.el9fdp.x86_64


and verified on version:
ovn22.12-22.12.0-20.el9fdp.x86_64
ovn22.12-central-22.12.0-20.el9fdp.x86_64
ovn22.12-host-22.12.0-20.el9fdp.x86_64



topo as below:
                          system1                                                                                  system2
server0-------ls1----------lr1-----public------------br-ext------------br-ext--------pulic-----------lr2---------ls2--------client
and set LB on lr1(enabled reject=true), dnat and snat on lr2. and set mtu=500 on lr2.


I start connection between server and client,
send big packet to client.
then I can see lr2 send icmp unreachable packets to lb vip.

on old version:
big packets not pass

on fixed version:
big packets pass


Note You need to log in before you can comment on or make changes to this bug.