Re: [**EXTERNAL**] Re: DNAT with VRF support in Linux Kernel

2018-07-20 Thread D'Souza, Nelson
Hi David, Assuming your setup is as follows: eth (ingress interface) --> br0 (bridge) --> mgmt (vrf) is it possible that the DNAT rule matches on the eth ingress interface and not the mgmt. vrf device? If the LOG rule does not match with dev == mgmt, it seems like the DNAT rule with dev ==mgm

Re: DNAT with VRF support in Linux Kernel

2018-07-19 Thread David Ahern
On 7/19/18 7:52 PM, D'Souza, Nelson wrote: > Hi, > >   > > I'm seeing a VRF/Netfilter related issue on a system running a 4.14.52 > Linux kernel. > >   > > I have an eth interface enslaved to l3mdev mgmtvrf device. > >   > > After reviewing > https://netdevconf.org/1.2/papers/ahern-what-is-l3