Skip to content

CSCwr85402 Ignore frag filter#648

Merged
tbachman merged 1 commit intommr-6.1.1from
frag-ignore-mmr-6.1.1
Nov 13, 2025
Merged

CSCwr85402 Ignore frag filter#648
tbachman merged 1 commit intommr-6.1.1from
frag-ignore-mmr-6.1.1

Conversation

@mchalla
Copy link
Contributor

@mchalla mchalla commented Nov 13, 2025

If "fragmentFlags" is present in a rule simply ignore them.

The fragmentFlags are supposed to match on second packet on that has a fragment bit set. The issue with this match is that since its a fragment it cannot match on ports so it effectively becomes an ip allow all filter without regard to ports that overrides any other filter with specific ports.

Its assumed that a frag filter will be applied as an independent filter and not merged with any port specific filter.

If CT is also enabled as such with a port match, Ovs will automatically reassemble / refragment all the packets for that port match to work. So there is no specific need of a fragment filter.

Of course if the frag filter is the only allow rule configured that also will not be supported.

If "fragmentFlags" is present in a rule simply ignore them.

The fragmentFlags are supposed to match on second packet on that
has a fragment bit set. The issue with this match is that since its
a fragment it cannot match on ports so it effectively becomes an
ip allow all filter without regard to ports that overrides any other
filter with specific ports.

Its assumed that a frag filter will be applied as an independent filter
and not merged with any port specific filter.

If CT is also enabled as such with a port match, Ovs will automatically
reassemble / refragment all the packets for that port match to work. So
there is no specific need of a fragment filter.

Of course if the frag filter is the only allow rule configured that also
will not be supported.
@mchalla mchalla requested a review from tbachman November 13, 2025 12:42
@tbachman tbachman merged commit 5f64804 into mmr-6.1.1 Nov 13, 2025
2 of 4 checks passed
@tbachman tbachman deleted the frag-ignore-mmr-6.1.1 branch November 13, 2025 12:43
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants