-
Bug
-
Resolution: Unresolved
-
Minor
-
None
-
4.17.0
-
Quality / Stability / Reliability
-
False
-
-
2
-
None
-
No
-
None
-
None
-
None
-
None
-
None
-
None
-
None
-
None
-
None
-
None
-
None
Description of problem:
We need to explain why portSecurity is set to False.
Port Security functionality does not apply to SR-IOV configurations, even if enabled at the port level. The VF performance depends entirely on the underlying NIC firmware.
With the Neutron ML2-OVN plugin, port_security operates at the OVN conntrack layer and does not apply to SR-IOV VFs, making allowed address pair configurations ineffective.