[ovs-discuss] [OVN] Not working ACLs

2024-04-26 Thread Justin Lamp via discuss
Hey there, we are on OVN 23.06.3 + OVS 3.1.2 and are facing an issue with the ACLs. For some odd reason some UDP Packets are not dropped. I attached all the information I was able to gather. The attached traces show the Wireguard connection between two VMs on Port 51871 (src+dst). This connecti

Re: [ovs-discuss] Urgent Help needed: OVS 3.2.2 Strange TC DROPs

2024-04-26 Thread Gavin McKee via discuss
Thanks for coming back to me on this. Moving kernal versions around is not a straightforward option here - especially when you are using hardware offload . The OFED driver version is coupled to the kernal so if we move from that we are out of support coverage . Doing an ovn-appctl -t ovn-contro

Re: [ovs-discuss] Urgent Help needed: OVS 3.2.2 Strange TC DROPs

2024-04-26 Thread Gavin McKee via discuss
Adrian, Yes , we are using tc-offload using the Nvidia CX6/7 cards (OFED driver aligned to the support kernal matrix). When I do a dump of the tc filter rules when the issue is occuring , I can't see any rule at all relating to the TCP connection thats breaking . Is this because the TC_INGRESS d

[ovs-discuss] icmpv6 jitter increase after upgrade

2024-04-26 Thread Tiago Pires via discuss
Hi all, While testing the upgrade path from OVN 22.03.1/OVS 2.17.2 to OVN 23.03.1/OVS 3.1.3 on Ubuntu 22.04/kernel 5.15 and 6.5 we are seeing a strange behavior for icmpv6 traffic. Before the upgrade a simple north-south or west-east ping between IPv6 hosts would have a low jitter like below: 64

Re: [ovs-discuss] Urgent Help needed: OVS 3.2.2 Strange TC DROPs

2024-04-26 Thread Ilya Maximets via discuss
On 4/26/24 20:12, Gavin McKee wrote: > Thanks for coming back to me on this. > > Moving kernal versions around is not a straightforward option here - > especially when you are using hardware offload . The OFED driver > version is coupled to the kernal so if we move from that we are out of > suppo

Re: [ovs-discuss] Urgent Help needed: OVS 3.2.2 Strange TC DROPs

2024-04-26 Thread Gavin McKee via discuss
Thanks again for coming back on this Ilya, Another option I am looking at here is to switch the kernal path (Open vSwitch kernel module) with OVS-DOCA as we are using the CX6/7 card https://docs.nvidia.com/doca/archive/doca-v2.0.2/ovs-doca/index.html I'm trying to wrangle the documented Known Lim

Re: [ovs-discuss] Urgent Help needed: OVS 3.2.2 Strange TC DROPs

2024-04-26 Thread Ilya Maximets via discuss
On 4/26/24 22:05, Gavin McKee wrote: > Thanks again for coming back on this Ilya, > > Another option I am looking at here is to switch the kernal path (Open > vSwitch kernel module) with OVS-DOCA as we are using the CX6/7 card > https://docs.nvidia.com/doca/archive/doca-v2.0.2/ovs-doca/index.html

Re: [ovs-discuss] icmpv6 jitter increase after upgrade

2024-04-26 Thread Tiago Pires via discuss
Hi all, Enabling the debugging, we can see the following: 2024-04-26T20:54:25.880Z|4|dpif(handler75)|DBG|system@ovs-system: miss upcall: recirc_id(0),dp_hash(0),skb_priority(0),in_port(1706),skb_mark(0),ct_state(0),ct_zone(0),ct_mark(0),ct_label(0),eth(src=fa:16:3e:d7:c9:46,dst=fa:16:3e:9b:b3