Hi Nathan,
  
     Currently our App is VRF-based, maybe we can also put them 
     in the default VRF. 

     Thank you for all your assistance!

Best Regards,
Yacan

Hi Yacan,

That's interesting, we're actually using it for a kube-proxy replacement too [0],
but with CNAT rules being handled in the main VRF. I'd be curious of the
networking model you're targeting.

On the cnat evolution, if it's only adding the ability to create FIB-based VIP
sessions in a specific FIB, that would be fairly easy. But if you aim at
supporting all kube-proxy use-cases, you might require some additional
evolutions.

Kind regards,
-Nathan


Le mer. 7 avr. 2021 à 04:40, liuyacan <liuya...@corp.netease.com> a écrit :
Hi  Nathan,

   We hope to use CNAT to play the role of kube-proxy.  
   Since our applications specifies namespaces,  so we want CNAT rules 
   to take effect in different FIB tables.

Best Regards,
Yacan

Hi Yacan,

There is no particular reason, just that the code for CNAT is quite new, and
we never implemented vrf support. I don't see any blocker to add it if you need it.

What is the use-case you would like to support ? By specifying a table ID, do you
mean for matching traffic ? Also for the rewrite ? Maybe DNATing to a different
table ?

Best regards,
-Nathan



Le mar. 6 avr. 2021 à 11:23, liuyacan <liuya...@corp.netease.com> a écrit :
Hi,
     
    We observed that CNAT translation rule now can only be set in the default table for v4 and v6. 
    Why is there such a restriction ?
 
Best Regards,
Yacan





-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.
View/Reply Online (#19123): https://lists.fd.io/g/vpp-dev/message/19123
Mute This Topic: https://lists.fd.io/mt/81885640/21656
Group Owner: vpp-dev+ow...@lists.fd.io
Unsubscribe: https://lists.fd.io/g/vpp-dev/unsub [arch...@mail-archive.com]
-=-=-=-=-=-=-=-=-=-=-=-

Reply via email to