Uploaded image for project: 'Fast Datapath Product'
  1. Fast Datapath Product
  2. FDP-3030

Test Plan: [RFE] Allow configuring custom ipsec connection options

    • Icon: Task Task
    • Resolution: Unresolved
    • Icon: Undefined Undefined
    • None
    • None
    • OVN
    • False
    • Hide

      None

      Show
      None
    • False
    • Hide

      ( ) The new test plan is aligned with the epic's acceptance criteria

      ( ) The test plan/test case pass successfully on all non blocking functions of the feature

      Show
      ( ) The new test plan is aligned with the epic's acceptance criteria ( ) The test plan/test case pass successfully on all non blocking functions of the feature
    • rhel-9
    • None

      This task is tracking the test case writing activities to cover the feature request described below.

      What's the feature?

      Allow setting custom ipsec_<key>=<value> options in northbound db, so they can be passed down to OVS as tunnel ipsec configuration options and end up as part of connection specification in ipsec.conf for OVN tunnels.

      Why is it needed?

      Today OVN allows setting ipsec_encapsulation/ipsec_forceencaps for the tunnels when ipsec is enabled. But it doesn't allow any other options that may be required for the connection to work properly in a particular environment. For example, in an environment where a higher than standard packet reordering is expected it may be necessary to specify a replay-window size. It may also be useful to try different options while debugging ipsec issues. Some of this can be mitigated by setting %default connection options in a separate config file included from ipsec.conf, but it's not always possible, e.g. if ovs-monitor-ipsec owns the root ipsec.conf. It may also be desired to change configuration for OVN tunnels only without affecting N-S ipsec configuration on the node.
       

      Who will benefit?

      Users that require specific configuration for ipsec to work in their environment. Support and developers will be able to try different configuration changes easily while debugging complex ipsec issues like FDP-2940.

              ovn-qe OVN QE
              imaximet@redhat.com Ilya Maximets
              OVN QE OVN QE
              Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

                Created:
                Updated: