-
Bug
-
Resolution: Done
-
Minor
-
None
-
4.12
-
None
-
Quality / Stability / Reliability
-
False
-
-
None
-
Moderate
-
None
-
None
-
Rejected
-
None
-
None
-
None
-
None
-
None
-
None
-
None
-
None
Description of problem:
Disabling IPSec did not result in higher throughput
Version-Release number of selected component (if applicable):
4.12
How reproducible:
Steps to Reproduce:
1. Enable IPcec 2. Run Throughput Test 3. Disable IPsec 4. Run Throughput Test 6. Delete ovn-ipsec ds 7. Run throughput test
Actual results:
Profile,Same node,Host Network,Service,Duration,# of Samples,Avg Throughput,Throughput Metric,99%tile Observed Latency,Latency Metric TCP_CRR,false,false,true,30,3,1.470000,OP/s,3.1e+06,usec
Expected results:
Profile,Same node,Host Network,Service,Duration,# of Samples,Avg Throughput,Throughput Metric,99%tile Observed Latency,Latency Metric TCP_CRR,false,false,true,30,3,3257.960000,OP/s,518,usec
Additional info:
After deleting the ovn-ipsec ds, we saw the expected throughput. However simply patching things with https://docs.openshift.com/container-platform/4.11/networking/ovn_kubernetes_network_provider/configuring-ipsec-ovn.html#nw-ovn-ipsec-disable_configuring-ipsec-ovn we didn't see the correct throughput, which makes us think the traffic was still going over the ipsec tunnel.