Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
bpf: skip policy check for IPv6 NDP traffic
Previously, our policy check for IPv6 NDP traffic caused issues such as #23852 and #23910 because this traffic was identified as WORLD_ID, which would be given a verdict of drop when CiliumNetworkPolicy is applied for per-endpoint routing. To resolve this issue, we pass all IPv6 NDP traffic to the stack without policy check. This change aligns with how we handle IPv4 ARP: the cilium bpf never performs policy check for ARP, regardless of whether we enable `ENABLE_ARP_PASSTHROUGH` or `ENABLE_ARP_RESPONDER`. Fixes: #23852 Fixes: #23910 Signed-off-by: Zhichuan Liang <gray.liang@isovalent.com>
- Loading branch information