mirror of
git://git.proxmox.com/git/pve-network.git
synced 2025-04-30 11:27:11 +02:00
zones: evpn: add disable-arp-nd-suppression option
arp-nd-suppression can break ip mobility, when an ip from a vm is moved to another vm, with different mac. For example, with a keepalived vip, the garp is filtered.
This commit is contained in:
parent
12206ae544
commit
b1a5c31e8f
|
@ -44,6 +44,11 @@ sub properties {
|
|||
type => 'boolean',
|
||||
description => "Advertise evpn subnets if you have silent hosts",
|
||||
optional => 1
|
||||
},
|
||||
'disable-arp-nd-suppression' => {
|
||||
type => 'boolean',
|
||||
description => "Disable ipv4 arp && ipv6 neighbour discovery suppression",
|
||||
optional => 1
|
||||
}
|
||||
};
|
||||
}
|
||||
|
@ -56,6 +61,7 @@ sub options {
|
|||
exitnodes => { optional => 1 },
|
||||
'exitnodes-local-routing' => { optional => 1 },
|
||||
'advertise-subnets' => { optional => 1 },
|
||||
'disable-arp-nd-suppression' => { optional => 1 },
|
||||
mtu => { optional => 1 },
|
||||
mac => { optional => 1 },
|
||||
dns => { optional => 1 },
|
||||
|
@ -99,7 +105,7 @@ sub generate_sdn_config {
|
|||
push @iface_config, "vxlan-id $tag";
|
||||
push @iface_config, "vxlan-local-tunnelip $ifaceip" if $ifaceip;
|
||||
push @iface_config, "bridge-learning off";
|
||||
push @iface_config, "bridge-arp-nd-suppress on";
|
||||
push @iface_config, "bridge-arp-nd-suppress on" if !$plugin_config->{'disable-arp-nd-suppression'};
|
||||
|
||||
push @iface_config, "mtu $mtu" if $mtu;
|
||||
push(@{$config->{$vxlan_iface}}, @iface_config) if !$config->{$vxlan_iface};
|
||||
|
@ -186,7 +192,7 @@ sub generate_sdn_config {
|
|||
push @iface_config, "vxlan-id $vrfvxlan";
|
||||
push @iface_config, "vxlan-local-tunnelip $ifaceip" if $ifaceip;
|
||||
push @iface_config, "bridge-learning off";
|
||||
push @iface_config, "bridge-arp-nd-suppress on";
|
||||
push @iface_config, "bridge-arp-nd-suppress on" if !$plugin_config->{'disable-arp-nd-suppression'};
|
||||
push @iface_config, "mtu $mtu" if $mtu;
|
||||
push(@{$config->{$iface_vrf_vxlan}}, @iface_config) if !$config->{$iface_vrf_vxlan};
|
||||
|
||||
|
|
|
@ -0,0 +1,31 @@
|
|||
log syslog informational
|
||||
ip forwarding
|
||||
ipv6 forwarding
|
||||
frr defaults datacenter
|
||||
service integrated-vtysh-config
|
||||
hostname localhost
|
||||
!
|
||||
!
|
||||
vrf vrf_myzone
|
||||
vni 1000
|
||||
exit-vrf
|
||||
!
|
||||
router bgp 65000
|
||||
bgp router-id 192.168.0.1
|
||||
no bgp default ipv4-unicast
|
||||
coalesce-time 1000
|
||||
neighbor VTEP peer-group
|
||||
neighbor VTEP remote-as 65000
|
||||
neighbor VTEP bfd
|
||||
neighbor 192.168.0.2 peer-group VTEP
|
||||
neighbor 192.168.0.3 peer-group VTEP
|
||||
!
|
||||
address-family l2vpn evpn
|
||||
neighbor VTEP activate
|
||||
advertise-all-vni
|
||||
exit-address-family
|
||||
!
|
||||
router bgp 65000 vrf vrf_myzone
|
||||
!
|
||||
line vty
|
||||
!
|
|
@ -0,0 +1,40 @@
|
|||
#version:1
|
||||
|
||||
auto myvnet
|
||||
iface myvnet
|
||||
address 10.0.0.1/24
|
||||
hwaddress A2:1D:CB:1A:C0:8B
|
||||
bridge_ports vxlan_myvnet
|
||||
bridge_stp off
|
||||
bridge_fd 0
|
||||
mtu 1450
|
||||
ip-forward on
|
||||
arp-accept on
|
||||
vrf vrf_myzone
|
||||
|
||||
auto vrf_myzone
|
||||
iface vrf_myzone
|
||||
vrf-table auto
|
||||
post-up ip route add vrf vrf_myzone unreachable default metric 4278198272
|
||||
|
||||
auto vrfbr_myzone
|
||||
iface vrfbr_myzone
|
||||
bridge-ports vrfvx_myzone
|
||||
bridge_stp off
|
||||
bridge_fd 0
|
||||
mtu 1450
|
||||
vrf vrf_myzone
|
||||
|
||||
auto vrfvx_myzone
|
||||
iface vrfvx_myzone
|
||||
vxlan-id 1000
|
||||
vxlan-local-tunnelip 192.168.0.1
|
||||
bridge-learning off
|
||||
mtu 1450
|
||||
|
||||
auto vxlan_myvnet
|
||||
iface vxlan_myvnet
|
||||
vxlan-id 100
|
||||
vxlan-local-tunnelip 192.168.0.1
|
||||
bridge-learning off
|
||||
mtu 1450
|
7
test/zones/evpn/disable_arp_nd_suppression/interfaces
Normal file
7
test/zones/evpn/disable_arp_nd_suppression/interfaces
Normal file
|
@ -0,0 +1,7 @@
|
|||
auto vmbr0
|
||||
iface vmbr0 inet static
|
||||
address 192.168.0.1/24
|
||||
gateway 192.168.0.254
|
||||
bridge-ports eth0
|
||||
bridge-stp off
|
||||
bridge-fd 0
|
26
test/zones/evpn/disable_arp_nd_suppression/sdn_config
Normal file
26
test/zones/evpn/disable_arp_nd_suppression/sdn_config
Normal file
|
@ -0,0 +1,26 @@
|
|||
{
|
||||
version => 1,
|
||||
vnets => {
|
||||
ids => {
|
||||
myvnet => { tag => "100", type => "vnet", zone => "myzone" },
|
||||
},
|
||||
},
|
||||
|
||||
zones => {
|
||||
ids => { myzone => { ipam => "pve", type => "evpn", controller => "evpnctl", 'vrf-vxlan' => 1000, 'mac' => 'A2:1D:CB:1A:C0:8B', 'disable-arp-nd-suppression' => 1 } },
|
||||
},
|
||||
controllers => {
|
||||
ids => { evpnctl => { type => "evpn", 'peers' => '192.168.0.1,192.168.0.2,192.168.0.3', asn => "65000" } },
|
||||
},
|
||||
|
||||
subnets => {
|
||||
ids => { 'myzone-10.0.0.0-24' => {
|
||||
'type' => 'subnet',
|
||||
'vnet' => 'myvnet',
|
||||
'gateway' => '10.0.0.1',
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
|
Loading…
Reference in a new issue