You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
I think there is no need to process snat lflows in lr_out_snat if the packet has been matched ct_dnat. We can fix it that add one lflow for external ip of dnat_and_snat and pass it use next action like this:
The text was updated successfully, but these errors were encountered:
shylou
changed the title
No need to process snat lflows in lr_out_snat if packet has been matched in lr_out_undnat
No need to process snat lflows in lr_out_snat if reply packet has been matched in lr_out_undnat
Feb 25, 2022
We test dnat_and_snat for logical ip could not work If we has config snat for 0.0.0.0/0.
like this:
table=0 (lr_out_undnat ), priority=100 , match=(ip && ip4.src == 192.168.119.69 && outport == "lrp-b9553715-858b-44f2-8514-75bd2118962d" && is_chassis_resident("cr-lrp-b9553715-858b-44f2-8514-75bd2118962d")), action=(ct_dnat;)
table=0 (lr_out_undnat ), priority=0 , match=(1), action=(next;)
table=1 (lr_out_snat ), priority=161 , match=(ip && ip4.src == 192.168.119.69 && outport == "lrp-b9553715-858b-44f2-8514-75bd2118962d" && is_chassis_resident("cr-lrp-b9553715-858b-44f2-8514-75bd2118962d")), action=(ct_snat(172.16.10.133);)
table=1 (lr_out_snat ), priority=129 , match=(ip && ip4.src == 0.0.0.0/0 && outport == "lrp-b9553715-858b-44f2-8514-75bd2118962d" && is_chassis_resident("cr-lrp-b9553715-858b-44f2-8514-75bd2118962d")), action=(ct_snat(172.16.10.252);)
I think there is no need to process snat lflows in lr_out_snat if the packet has been matched ct_dnat. We can fix it that add one lflow for external ip of dnat_and_snat and pass it use next action like this:
table=0 (lr_out_undnat ), priority=100 , match=(ip && ip4.src == 192.168.119.69 && outport == "lrp-b9553715-858b-44f2-8514-75bd2118962d" && is_chassis_resident("cr-lrp-b9553715-858b-44f2-8514-75bd2118962d")), action=(ct_dnat;)
table=0 (lr_out_undnat ), priority=0 , match=(1), action=(next;)
table=1 (lr_out_snat ), priority=161 , match=(ip && ip4.src == 172.16.10.133 && outport == "lrp-b9553715-858b-44f2-8514-75bd2118962d" && is_chassis_resident("cr-lrp-b9553715-858b-44f2-8514-75bd2118962d")), action=(next;)
table=1 (lr_out_snat ), priority=161 , match=(ip && ip4.src == 192.168.119.69 && outport == "lrp-b9553715-858b-44f2-8514-75bd2118962d" && is_chassis_resident("cr-lrp-b9553715-858b-44f2-8514-75bd2118962d")), action=(ct_snat(172.16.10.133);)
table=1 (lr_out_snat ), priority=129 , match=(ip && ip4.src == 0.0.0.0/0 && outport == "lrp-b9553715-858b-44f2-8514-75bd2118962d" && is_chassis_resident("cr-lrp-b9553715-858b-44f2-8514-75bd2118962d")), action=(ct_snat(172.16.10.252);)
Any one has other opinions?
The text was updated successfully, but these errors were encountered: