Uploaded image for project: 'OpenShift Bugs'
  1. OpenShift Bugs
  2. OCPBUGS-24219

Azure - OCP IPI Installation UDP packets are subject to SNAT with LB Service using ETP equals to Local (OVN-Kubernetes as CNI)

    XMLWordPrintable

Details

    • Critical
    • No
    • SDN Sprint 246, SDN Sprint 247, SDN Sprint 248
    • 3
    • False
    • Hide

      None

      Show
      None
    • Users can now use a new way to configure session affinity without a timeout in OVNK which is to set the timeout to 86400 seconds, in which case affinity is treat like permanent unless we have network disruptions like endpoints or nodes going down.
    • Enhancement
    • In Progress
    • Network
    • customers who need session affinity

    Description

      UDP Packets are subject to SNAT in a self-managed OCP 4.13.13 cluster on Azure (OVN-K as CNI) using a Load Balancer Service with `externalTrafficPolicy: Local`. UDP Packets correctly arrive to the Node hosting the Pod but the source IP seen by the Pod is the OVN GW Router of the Node.

      I've reproduced the customer scenario with the following steps:

      This is issue is very critical because it is blocking customer business.

      Attachments

        Issue Links

          Activity

            People

              sseethar Surya Seetharaman
              rhn-support-gizzi Giovanni Luca Izzi
              Arti Sood Arti Sood
              Votes:
              0 Vote for this issue
              Watchers:
              13 Start watching this issue

              Dates

                Created:
                Updated: