Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

fix nat rule #1171

Merged
merged 1 commit into from
Dec 17, 2021
Merged

fix nat rule #1171

merged 1 commit into from
Dec 17, 2021

Conversation

fanriming
Copy link
Member

What type of this PR

Examples of user facing changes:

  • Bug fixes
  1. kube-proxy 已为 cluster ip 包设置 mark 和 MASQUERADE 规则,不需要在cni中再次配置;
  2. 对于通过 ovn0 网卡的流量,增加对源 ip 的判断, 内部流量只需路由、不需要 MASQUERADE。

@zhangzujian zhangzujian merged commit 7919901 into kubeovn:master Dec 17, 2021
@chestack
Copy link
Contributor

chestack commented Dec 20, 2021

"对于通过 ovn0 网卡的流量,增加对源 ip 的判断, 内部流量只需路由、不需要 MASQUERADE" --- 踩到了这条规则的坑,pod回包经过所在node 到 client node做了masq,导致tcp reset

@zhangzujian
Copy link
Member

"对于通过 ovn0 网卡的流量,增加对源 ip 的判断, 内部流量只需路由、不需要 MASQUERADE" --- 踩到了这条规则的坑,pod回包经过所在node 到 client node做了masq,导致tcp reset

能详细描述下复现步骤吗?麻烦提个 issue,尽量避免在 PR 里讨论。: )

@chestack
Copy link
Contributor

@zhangzujian 开了这个相关的issue,请帮忙看下 #1216

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants