On Tue, Oct 6, 2026 at 11:36 AM Dumitru Ceara <[email protected]> wrote:

> In such deployments gratuitous ARP/ND packets originated by the VR,
> e.g., on failover may not have matching eth.src and ARP/ND hardware
> address.  It's possible that the Ethernet source used is that of the
> physical NIC and the Ethernet address stored in the ARP/ND fields is
> the VMAC of the VR.
>
> In these cases FDB learning didn't work properly because it would never
> learn the "inner" MAC address.  Also, FDB learning was completely
> disabled (programatically) for ports with security configured, even if
> they had "unknown" addresses.
>
> This creates an issue because OVN deployments with VRRP running as
> workloads will break.  That's because users have no way of configuring
> OVN to dynamically learn where the VMAC resides without giving up on
> the port security settings.
>
> Changes in V2:
> - Addressed Ales' comments:
>   - Removed Reported-at in the first patch.
>   - Improved test in the first patch.
>   - Added missing documentation changes to both patches.
>
> Dumitru Ceara (2):
>   northd: Learn ARP/ND inner MAC addresses in FDB.
>   northd: Allow FDB learning on ports with port security.
>
>  Documentation/ref/ovn-logical-flows.7.rst |  44 ++-
>  NEWS                                      |   7 +
>  northd/northd.c                           | 206 +++++++++++--
>  northd/northd.h                           |   3 -
>  ovn-nb.xml                                |  23 +-
>  tests/ovn-ic.at                           |  72 +++++
>  tests/ovn-northd.at                       | 192 ++++++++++++
>  tests/ovn.at                              | 358 +++++++++++++++++++++-
>  utilities/ovn-nbctl.8.xml                 |   2 +-
>  9 files changed, 860 insertions(+), 47 deletions(-)
>
> --
> 2.55.0
>
>
Looks good to me, thanks.
Acked-by: Ales Musil <[email protected]>
_______________________________________________
dev mailing list
[email protected]
https://mail.openvswitch.org/mailman/listinfo/ovs-dev

Reply via email to