Re: [ovs-discuss] OVS 2.9.0 native firewall drops empty payload TCP packets

2018-08-27 Thread Zhang, Jing C. (Nokia - CA/Ottawa)
It is a fresh install, not an upgrade. uname -a Linux overcloud-ovscompute-1 3.10.0-862.9.1.el7.x86_64 #1 SMP Mon Jul 16 16:29:36 UTC 2018 x86_64 x86_64 x86_64 GNU/Linux We have wanted to switch to native firewall since 2.8 but can not do that because of multiple reports of TCP packet drop

Re: [ovs-discuss] OVS 2.9.0 native firewall drops empty payload TCP packets

2018-08-27 Thread Gregory Rose
On 8/27/2018 6:20 AM, Zhang, Jing C. (Nokia - CA/Ottawa) wrote: We have customers reporting sluggish HTTP download with OVS 2.9.0. After debugging, we find the issue is OVS 2.9.0 native firewall drops TCP control packets (TCP ACK) with empty payload. The issue can be avoided by either

Re: [ovs-discuss] Q-in-Q / Q-in-VNI

2018-08-27 Thread Paul de Haas | Routz group
Okay, thanks Ben. Will check if double and or single tagged can be mapped to VNI from OVS. > Op 27 aug. 2018 om 18:24 heeft Ben Pfaff het volgende > geschreven: > > VXLAN and VLANs are both documented. If you use both features, you get > VLANs inside VXLAN. There is no specific

Re: [ovs-discuss] OVS 2.9.0 native firewall drops empty payload TCP packets

2018-08-27 Thread Darrell Ball
This seems to be in the kernel datapath and maybe recent issue Greg, do you want to take a look ? On 8/27/18, 9:50 AM, "ovs-discuss-boun...@openvswitch.org on behalf of Darrell Ball" wrote: I can take a look. On 8/27/18, 9:47 AM, "ovs-discuss-boun...@openvswitch.org on behalf of

Re: [ovs-discuss] Recall: OVS 2.9.0 native firewall drops empty payload TCP packets

2018-08-27 Thread Zhang, Jing C. (Nokia - CA/Ottawa)
Sorry for the confusion, no, the issue is critical and very reproducable, I need help to get it fixed. I recalled as I did not want to show my "desperation" to the list  -Original Message- From: Darrell Ball Sent: Monday, August 27, 2018 12:51 PM To: Zhang, Jing C. (Nokia -

Re: [ovs-discuss] Recall: OVS 2.9.0 native firewall drops empty payload TCP packets

2018-08-27 Thread Darrell Ball
Did you mean to recall the issue ? On 8/27/18, 9:48 AM, "ovs-discuss-boun...@openvswitch.org on behalf of Zhang, Jing C. (Nokia - CA/Ottawa)" wrote: Zhang, Jing C. (Nokia - CA/Ottawa) would like to recall the message, "[ovs-discuss] OVS 2.9.0 native firewall drops empty payload TCP

Re: [ovs-discuss] OVS 2.9.0 native firewall drops empty payload TCP packets

2018-08-27 Thread Darrell Ball
I can take a look. On 8/27/18, 9:47 AM, "ovs-discuss-boun...@openvswitch.org on behalf of Ben Pfaff" wrote: On Mon, Aug 27, 2018 at 01:20:15PM +, Zhang, Jing C. (Nokia - CA/Ottawa) wrote: > We have customers reporting sluggish HTTP download with OVS 2.9.0. After debugging, we

[ovs-discuss] Recall: OVS 2.9.0 native firewall drops empty payload TCP packets

2018-08-27 Thread Zhang, Jing C. (Nokia - CA/Ottawa)
Zhang, Jing C. (Nokia - CA/Ottawa) would like to recall the message, "[ovs-discuss] OVS 2.9.0 native firewall drops empty payload TCP packets". ___ discuss mailing list disc...@openvswitch.org https://mail.openvswitch.org/mailman/listinfo/ovs-discuss

Re: [ovs-discuss] OVS 2.9.0 native firewall drops empty payload TCP packets

2018-08-27 Thread Zhang, Jing C. (Nokia - CA/Ottawa)
Yes, yes, pls help!!! I am desperate now ;-( Jing -Original Message- From: Ben Pfaff Sent: Monday, August 27, 2018 12:47 PM To: Zhang, Jing C. (Nokia - CA/Ottawa) ; Darrell Ball Cc: b...@openvswitch.org Subject: Re: [ovs-discuss] OVS 2.9.0 native firewall drops empty payload TCP

Re: [ovs-discuss] OVS 2.9.0 native firewall drops empty payload TCP packets

2018-08-27 Thread Ben Pfaff
On Mon, Aug 27, 2018 at 01:20:15PM +, Zhang, Jing C. (Nokia - CA/Ottawa) wrote: > We have customers reporting sluggish HTTP download with OVS 2.9.0. After > debugging, we find the issue is OVS 2.9.0 native firewall drops TCP control > packets (TCP ACK) with empty payload. The issue can be

Re: [ovs-discuss] Traffic from newly created bridge to newly created internal port works only after restart of openvswitch-switch service.

2018-08-27 Thread Ben Pfaff
On Sat, Aug 25, 2018 at 01:35:17AM +0200, Stefan Schoerghofer wrote: > Hello, > > Today I've tried to use the following setup using openvswitch. > > > Three servers patched in a ring: > > --- > | server 1|--- > --- | > | | >

Re: [ovs-discuss] Q-in-Q / Q-in-VNI

2018-08-27 Thread Ben Pfaff
VXLAN and VLANs are both documented. If you use both features, you get VLANs inside VXLAN. There is no specific documentation on using the features together. On Mon, Aug 27, 2018 at 04:17:58PM +, Paul de Haas | Routz group wrote: > Okay, any idea where I can find more information on this to

Re: [ovs-discuss] Q-in-Q / Q-in-VNI

2018-08-27 Thread Paul de Haas | Routz group
Okay, any idea where I can find more information on this to deep dive? > Op 27 aug. 2018 om 18:12 heeft Ben Pfaff het volgende > geschreven: > >> On Sun, Aug 26, 2018 at 09:37:33AM +, Paul de Haas | Routz group wrote: >> Hi there, As far as I know Q-in-Q is supported on OVS, but is

Re: [ovs-discuss] Mega-flow generation

2018-08-27 Thread Ben Pfaff
On Mon, Aug 27, 2018 at 02:46:19PM +0300, Sara Gittlin wrote: > Can someone refer me to the code of the megaflow generation process ? > Is this process invoked by an upcall from the kernel module ? like in > microflow ? Did you read the OVS paper? It's all about megaflows.

Re: [ovs-discuss] OVS Faucet tutorial broken

2018-08-27 Thread Ben Pfaff
On Sat, Aug 25, 2018 at 12:57:07PM +1200, Brad Cowie wrote: > On 25 August 2018 at 12:07, Ben Pfaff wrote: > > > On Sat, Aug 25, 2018 at 11:09:41AM +1200, Brad Cowie wrote: > > > By the way we can dynamically generate our openflow pipeline now such > > > that tables are automatically sized (more

[ovs-discuss] OVS 2.9.0 native firewall drops empty payload TCP packets

2018-08-27 Thread Zhang, Jing C. (Nokia - CA/Ottawa)
We have customers reporting sluggish HTTP download with OVS 2.9.0. After debugging, we find the issue is OVS 2.9.0 native firewall drops TCP control packets (TCP ACK) with empty payload. The issue can be avoided by either reverting back to the legacy Linux bridge firewall or enabling TCP

[ovs-discuss] Mega-flow generation

2018-08-27 Thread Sara Gittlin
Hello all Can someone refer me to the code of the megaflow generation process ? Is this process invoked by an upcall from the kernel module ? like in microflow ? Thank you in advance -Sara ___ discuss mailing list disc...@openvswitch.org