Re: [PATCH net 1/2] openvswitch: support asymmetric conntrack
From: Pravin Shelar <hidden>
Date: 2019-11-09 22:15:46
Also in:
lkml
From: Pravin Shelar <hidden>
Date: 2019-11-09 22:15:46
Also in:
lkml
On Fri, Nov 8, 2019 at 1:07 PM Aaron Conole [off-list ref] wrote:
The openvswitch module shares a common conntrack and NAT infrastructure
exposed via netfilter. It's possible that a packet needs both SNAT and
DNAT manipulation, due to e.g. tuple collision. Netfilter can support
this because it runs through the NAT table twice - once on ingress and
again after egress. The openvswitch module doesn't have such capability.
Like netfilter hook infrastructure, we should run through NAT twice to
keep the symmetry.
Fixes: 05752523e565 ("openvswitch: Interface with NAT.")
Signed-off-by: Aaron Conole <aconole@redhat.com>The patch looks ok. But I am not able apply it. can you fix the encoding.