Bence, thank you so much for information,but we used linux bridge for security group, i.e firewall_driver = iptables_hybrid. I will tried the fix for bug #1732067 and check if it can fix my issue.
By the way, Rocky also has same issue, we tried to narrow issue domain, if we don't add subnet of VMs into a router, MAC can be learnt, but MAC can't be learnt if we add subnet of VMs to a router. We used DVR and distributed DHCP, every VM's tap interface is attached into a linux bridge which is attached into br-int by veth pair.
Bence, thank you so much for information,but we used linux bridge for security group, i.e firewall_driver = iptables_hybrid. I will tried the fix for bug #1732067 and check if it can fix my issue.
By the way, Rocky also has same issue, we tried to narrow issue domain, if we don't add subnet of VMs into a router, MAC can be learnt, but MAC can't be learnt if we add subnet of VMs to a router. We used DVR and distributed DHCP, every VM's tap interface is attached into a linux bridge which is attached into br-int by veth pair.