SG flows couldn't let the first packet of a related connection pass
Bug #1586369 reported by
yuan wei
This bug affects 1 person
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
DragonFlow |
Fix Released
|
High
|
yuan wei |
Bug Description
in current implement, SG flows don't match packets with both new and rel CT flag, so the first packet of a related connection will be droped.
take egress direction flow as a example:
current flow: table=6, priority=65534, ct_state=
should add flow: table=6, priority=65534, ct_state=
Changed in dragonflow: | |
assignee: | nobody → yuan wei (wei-yuan) |
status: | New → In Progress |
Changed in dragonflow: | |
importance: | Undecided → High |
To post a comment you must log in.
should also take packets with both rel and est CT flag into count. besides adding the flow, the current flow's match should also change to "ct_state= -new+rel- inv+trk"