On 10/6/26 1:50 PM, Ales Musil wrote: > On Tue, Oct 6, 2026 at 11:36 AM Dumitru Ceara <[email protected]> wrote: > >> In such deployments gratuitous ARP/ND packets originated by the VR, >> e.g., on failover may not have matching eth.src and ARP/ND hardware >> address. It's possible that the Ethernet source used is that of the >> physical NIC and the Ethernet address stored in the ARP/ND fields is >> the VMAC of the VR. >> >> In these cases FDB learning didn't work properly because it would never >> learn the "inner" MAC address. Also, FDB learning was completely >> disabled (programatically) for ports with security configured, even if >> they had "unknown" addresses. >> >> This creates an issue because OVN deployments with VRRP running as >> workloads will break. That's because users have no way of configuring >> OVN to dynamically learn where the VMAC resides without giving up on >> the port security settings. >> >> Changes in V2: >> - Addressed Ales' comments: >> - Removed Reported-at in the first patch. >> - Improved test in the first patch. >> - Added missing documentation changes to both patches. >> >> Dumitru Ceara (2): >> northd: Learn ARP/ND inner MAC addresses in FDB. >> northd: Allow FDB learning on ports with port security. >> >> Documentation/ref/ovn-logical-flows.7.rst | 44 ++- >> NEWS | 7 + >> northd/northd.c | 206 +++++++++++-- >> northd/northd.h | 3 - >> ovn-nb.xml | 23 +- >> tests/ovn-ic.at | 72 +++++ >> tests/ovn-northd.at | 192 ++++++++++++ >> tests/ovn.at | 358 +++++++++++++++++++++- >> utilities/ovn-nbctl.8.xml | 2 +- >> 9 files changed, 860 insertions(+), 47 deletions(-) >> >> -- >> 2.55.0 >> >> > Looks good to me, thanks. > Acked-by: Ales Musil <[email protected]> >
Thanks, Ales, for the reviews! Applied to main, 26.09 and 26.03. Regards, Dumitru _______________________________________________ dev mailing list [email protected] https://mail.openvswitch.org/mailman/listinfo/ovs-dev
