-
Feature Request
-
Resolution: Unresolved
-
Undefined
-
None
-
4.16
-
None
-
False
-
None
-
False
-
Not Selected
-
-
-
1. Proposed title of this feature request
Disable hw offloading on the interface when enabling ipsec via machine config operator
2. What is the nature and description of the request?
In https://issues.redhat.com/browse/OSDOCS-11827 we are tracking a lack in the documentation that ipsec and hw offloading don't work together in the current GA version. This is captured in bug https://issues.redhat.com/browse/OCPBUGS-25312.
We document a workaround by using suggested steps in https://issues.redhat.com/browse/SDN-4501. The better option would be to disable hw offloading on the interface automatically via the MCO when enabling ipsec in the cluster to prevent others to run into a similar problem.
3. Why does the customer need this? (List the business requirements here)
This is not transparent to the customer. They are configuring the interface in nmstate and we don't document how to disable hw offloading at all. It's hard to find the problem especially with the lack in the documentation.
4. List any affected packages or components.
MCO
Network operator