On Tue, Oct 6, 2026 at 11:36 AM Dumitru Ceara <[email protected]> wrote:
> In such deployments gratuitous ARP/ND packets originated by the VR, > e.g., on failover may not have matching eth.src and ARP/ND hardware > address. It's possible that the Ethernet source used is that of the > physical NIC and the Ethernet address stored in the ARP/ND fields is > the VMAC of the VR. > > In these cases FDB learning didn't work properly because it would never > learn the "inner" MAC address. Also, FDB learning was completely > disabled (programatically) for ports with security configured, even if > they had "unknown" addresses. > > This creates an issue because OVN deployments with VRRP running as > workloads will break. That's because users have no way of configuring > OVN to dynamically learn where the VMAC resides without giving up on > the port security settings. > > Changes in V2: > - Addressed Ales' comments: > - Removed Reported-at in the first patch. > - Improved test in the first patch. > - Added missing documentation changes to both patches. > > Dumitru Ceara (2): > northd: Learn ARP/ND inner MAC addresses in FDB. > northd: Allow FDB learning on ports with port security. > > Documentation/ref/ovn-logical-flows.7.rst | 44 ++- > NEWS | 7 + > northd/northd.c | 206 +++++++++++-- > northd/northd.h | 3 - > ovn-nb.xml | 23 +- > tests/ovn-ic.at | 72 +++++ > tests/ovn-northd.at | 192 ++++++++++++ > tests/ovn.at | 358 +++++++++++++++++++++- > utilities/ovn-nbctl.8.xml | 2 +- > 9 files changed, 860 insertions(+), 47 deletions(-) > > -- > 2.55.0 > > Looks good to me, thanks. Acked-by: Ales Musil <[email protected]> _______________________________________________ dev mailing list [email protected] https://mail.openvswitch.org/mailman/listinfo/ovs-dev
