Re: [ovs-discuss] OVN Failed Flow Offload

2023-02-14 Thread Lazuardi Nasution via discuss
Hi Ajit, Is there any update on this? If it is firmware matter, what is suggested firmware for enabling flow offload with OVN? Best regards. On Thu, Feb 9, 2023, 12:17 PM Lazuardi Nasution wrote: > Hi Ajit, > > I'm using firmware version 219.0.144.0.of > > I'm not sure that the problem is abou

Re: [ovs-discuss] OVN/OVS tunnel to public cloud provider

2023-02-14 Thread Gavin McKee via discuss
Understood, I already have a working topology that sends external traffic to a vrf on the physical network that provides internet access for VMs , tag=120. So I could probably add a new logical switch for the IPSEC connection set a bridge mapping to br-ipsec-aws (or something like that) and see i

Re: [ovs-discuss] OVN/OVS tunnel to public cloud provider

2023-02-14 Thread Numan Siddique via discuss
On Tue, Feb 14, 2023 at 6:40 PM Gavin McKee via discuss wrote: > > Hi Numan, > > I'd be happy to start with static routes , as long as I can get the > connectivity in place i.e. be able to connect a VM on a logical switch to a > VM in a public cloud via IPSEC tunnel. so you're trying to connect

Re: [ovs-discuss] OVN/OVS tunnel to public cloud provider

2023-02-14 Thread Gavin McKee via discuss
Hi Numan, I'd be happy to start with static routes , as long as I can get the connectivity in place i.e. be able to connect a VM on a logical switch to a VM in a public cloud via IPSEC tunnel. Gav On Tue, Feb 14, 2023 at 3:28 PM Numan Siddique wrote: > Looks like this would require BGP to exch

Re: [ovs-discuss] OVN/OVS tunnel to public cloud provider

2023-02-14 Thread Numan Siddique via discuss
Looks like this would require BGP to exchange the routes ? I'm not sure. I may be wrong. Adding @Daniel Alvarez Sanchez if he has any comments as he worked on supporting BGP in Openstack with OVN. Thanks Numan On Tue, Feb 14, 2023 at 1:50 PM Gavin McKee via discuss wrote: > > Satish, > > We

Re: [ovs-discuss] OVN/OVS tunnel to public cloud provider

2023-02-14 Thread Gavin McKee via discuss
Satish, We are using the Mellanox Connect X6 card / possibly we can use bluefield2 card to do IPSEC hardware offload . So somehow we could build a tunnel to a server with StrongSwan IPSEC . The key thing is to tie this IPSEC interface into the OVN/OVS setup and somehow associate it with a custom

Re: [ovs-discuss] OVN/OVS tunnel to public cloud provider

2023-02-14 Thread Satish Patel via discuss
Seems like OVN does support IPsec tunnel based on doc but may need to figure out how to integrate with your use case [1] [1] https://docs.ovn.org/en/latest/tutorials/ovn-ipsec.html On Tue, Feb 14, 2023 at 8:20 AM Gavin McKee via discuss < ovs-discuss@openvswitch.org> wrote: > Hi , > > Is it poss

Re: [ovs-discuss] openvswitch: ovs-system: deferred action limit reached, drop recirc action

2023-02-14 Thread Satish Patel via discuss
Any thoughts here? On Fri, Feb 10, 2023 at 11:08 AM Satish Patel wrote: > Hi Frode, > > This is my OVN version. > > (ovn-northd)[root@ctrl3 /]# dpkg -l | grep ovn > ii ovn-central22.09.0-0ubuntu1~cloud0 > amd64OVN central components > ii ovn-common 2

[ovs-discuss] Tunnel interface was deleted and recreated during ovs-vswitchd starts up

2023-02-14 Thread 张祖建 via discuss
Hi all, I'm investigating packet drop during ovs restart/upgrade and found that the Gevene interface genev_sys_6082 was deleted and recreated during ovs-vswitchd starts up: root@node1:/root# ip -c a show genev_sys_6081 17: genev_sys_6081: mtu 65000 qdisc noqueue master ovs-system state UNKNOWN g

[ovs-discuss] OVSIntPort not responsing to ARP

2023-02-14 Thread andre--- via discuss
Hello, A configured OVSIntPort with IP address is not responding to ARP, if RSTP is enabled. Without RSTP everything is working fine. When I add RSTP, the OVSIntPort is not responding to ARP requests any more. I can only initiate connections from the host to the other destinations. OVS version

[ovs-discuss] OVN/OVS tunnel to public cloud provider

2023-02-14 Thread Gavin McKee via discuss
Hi , Is it possible to connect an IPSEC tunnel from a Public cloud provider such as Azure, AWS / GCP to an OVN logical router ? I need to be able to route between a subnet in Azure / GCP and a subnet in OVN? Has anyone been able to achieve this , and if so can you provide an example configuratio