Uploaded image for project: 'OpenShift Request For Enhancement'
  1. OpenShift Request For Enhancement
  2. RFE-6220

Disable hw offloading on the interface when ipsec is enabled

XMLWordPrintable

    • Icon: Feature Request Feature Request
    • Resolution: Unresolved
    • Icon: Undefined Undefined
    • None
    • 4.16
    • MCO
    • None
    • False
    • None
    • False
    • Not Selected

      1. Proposed title of this feature request

      Disable hw offloading on the interface when enabling ipsec via machine config operator

      2. What is the nature and description of the request?

      In https://issues.redhat.com/browse/OSDOCS-11827 we are tracking a lack in the documentation that ipsec and hw offloading don't work together in the current GA version. This is captured in bug https://issues.redhat.com/browse/OCPBUGS-25312.

      We document a workaround by using suggested steps in https://issues.redhat.com/browse/SDN-4501.  The better option would be to disable hw offloading on the interface automatically via the MCO when enabling ipsec in the cluster to prevent others to run into a similar problem. 

      3. Why does the customer need this? (List the business requirements here)

      This is not transparent to the customer. They are configuring the interface in nmstate and we don't document how to disable hw offloading at all. It's hard to find the problem especially with the lack in the documentation. 

      4. List any affected packages or components.

      MCO

      Network operator

              rhn-support-mrussell Mark Russell
              rhn-support-afaulhab Anne Faulhaber
              Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

                Created:
                Updated: