Re: [ovs-discuss] OVS 2.9.0 native firewall drops empty payload TCP packets continued

2019-05-03 Thread Gregory Rose
On 5/2/2019 6:03 PM, Zhang, Jing C. (Nokia - CA/Ottawa) wrote: We (our VNFs) continue to observe the same empty payload TCP (ACK) packet drop with native firewall (see original post below) after upgrading to Centos 7.6. This packet drop results in unacceptable TCP performance, by that native

Re: [ovs-discuss] OVS 2.9.0 native firewall drops empty payload TCP packets continued

2019-05-03 Thread Zhang, Jing C. (Nokia - CA/Ottawa)
Thank you Han, I will check out this fix. From: Han Zhou Sent: Thursday, May 2, 2019 10:11 PM To: Zhang, Jing C. (Nokia - CA/Ottawa) Cc: ovs-discuss@openvswitch.org Subject: Re: [ovs-discuss] OVS 2.9.0 native firewall drops empty payload TCP packets continued On Thu, May 2, 2019 at 6:04 PM

Re: [ovs-discuss] OVS 2.9.0 native firewall drops empty payload TCP packets continued

2019-05-02 Thread Han Zhou
On Thu, May 2, 2019 at 6:04 PM Zhang, Jing C. (Nokia - CA/Ottawa) < jing.c.zh...@nokia.com> wrote: > > We (our VNFs) continue to observe the same empty payload TCP (ACK) packet drop with native firewall (see original post below) after upgrading to Centos 7.6. This packet drop results in

[ovs-discuss] OVS 2.9.0 native firewall drops empty payload TCP packets continued

2019-05-02 Thread Zhang, Jing C. (Nokia - CA/Ottawa)
We (our VNFs) continue to observe the same empty payload TCP (ACK) packet drop with native firewall (see original post below) after upgrading to Centos 7.6. This packet drop results in unacceptable TCP performance, by that native firewall still can not be enabled in product.

Re: [ovs-discuss] OVS 2.9.0 native firewall drops empty payload TCP packets

2018-08-27 Thread Zhang, Jing C. (Nokia - CA/Ottawa)
is using our latest lineup which is ovs 2.9. Jing From: Gregory Rose Sent: Monday, August 27, 2018 4:08 PM To: Zhang, Jing C. (Nokia - CA/Ottawa) ; b...@openvswitch.org Subject: Re: [ovs-discuss] OVS 2.9.0 native firewall drops empty payload TCP packets On 8/27/2018 6:20 AM, Zhang, Jing C

Re: [ovs-discuss] OVS 2.9.0 native firewall drops empty payload TCP packets

2018-08-27 Thread Gregory Rose
On 8/27/2018 6:20 AM, Zhang, Jing C. (Nokia - CA/Ottawa) wrote: We have customers reporting sluggish HTTP download with OVS 2.9.0. After debugging, we find the issue is OVS 2.9.0 native firewall drops TCP control packets (TCP ACK) with empty payload. The issue can be avoided by either

Re: [ovs-discuss] OVS 2.9.0 native firewall drops empty payload TCP packets

2018-08-27 Thread Darrell Ball
This seems to be in the kernel datapath and maybe recent issue Greg, do you want to take a look ? On 8/27/18, 9:50 AM, "ovs-discuss-boun...@openvswitch.org on behalf of Darrell Ball" wrote: I can take a look. On 8/27/18, 9:47 AM, "ovs-discuss-boun...@openvswitch.org on behalf of

Re: [ovs-discuss] OVS 2.9.0 native firewall drops empty payload TCP packets

2018-08-27 Thread Darrell Ball
I can take a look. On 8/27/18, 9:47 AM, "ovs-discuss-boun...@openvswitch.org on behalf of Ben Pfaff" wrote: On Mon, Aug 27, 2018 at 01:20:15PM +, Zhang, Jing C. (Nokia - CA/Ottawa) wrote: > We have customers reporting sluggish HTTP download with OVS 2.9.0. After debugging, we

Re: [ovs-discuss] OVS 2.9.0 native firewall drops empty payload TCP packets

2018-08-27 Thread Zhang, Jing C. (Nokia - CA/Ottawa)
Yes, yes, pls help!!! I am desperate now ;-( Jing -Original Message- From: Ben Pfaff Sent: Monday, August 27, 2018 12:47 PM To: Zhang, Jing C. (Nokia - CA/Ottawa) ; Darrell Ball Cc: b...@openvswitch.org Subject: Re: [ovs-discuss] OVS 2.9.0 native firewall drops empty payload TCP

Re: [ovs-discuss] OVS 2.9.0 native firewall drops empty payload TCP packets

2018-08-27 Thread Ben Pfaff
On Mon, Aug 27, 2018 at 01:20:15PM +, Zhang, Jing C. (Nokia - CA/Ottawa) wrote: > We have customers reporting sluggish HTTP download with OVS 2.9.0. After > debugging, we find the issue is OVS 2.9.0 native firewall drops TCP control > packets (TCP ACK) with empty payload. The issue can be

[ovs-discuss] OVS 2.9.0 native firewall drops empty payload TCP packets

2018-08-27 Thread Zhang, Jing C. (Nokia - CA/Ottawa)
We have customers reporting sluggish HTTP download with OVS 2.9.0. After debugging, we find the issue is OVS 2.9.0 native firewall drops TCP control packets (TCP ACK) with empty payload. The issue can be avoided by either reverting back to the legacy Linux bridge firewall or enabling TCP