Closed sridhargaddam closed 2 years ago
Do you think it might be related to iptables modes (nft, legacy) ? like the MSS clamping bug?
Do you think it might be related to iptables modes (nft, legacy) ? like the MSS clamping bug?
In case of MSS clamping rules the rules were not properly translated in the automatic translation layer. Whereas these are regular iptable rules which are properly supported, just that it seems to take some time to get sync'ed. So I believe it may not be related.
This issue is fixed and backported, closing it.
In an OCP deployment with Submariner version 0.12, it was seen that after we create a chain, its taking few milliseconds for the chain to be actually programmed on the node. From the Globalnet pod logs...
subctl version: | v0.12.0-rc1 Submariner version: | v0.12.0 Kubernetes Server version: | v1.23.3+e419edf Globalnet enabled.