From: George Wilkie <gwilkie@vyatta.att-mail.com>
To: David Ahern <dsahern@gmail.com>
Cc: Shrijeet Mukherjee <shrijeet@gmail.com>,
"David S. Miller" <davem@davemloft.net>,
Alexey Kuznetsov <kuznet@ms2.inr.ac.ru>,
Hideaki YOSHIFUJI <yoshfuji@linux-ipv6.org>,
netdev@vger.kernel.org
Subject: Re: [PATCH net-next] vrf: local route leaking
Date: Mon, 27 May 2019 09:34:02 +0100 [thread overview]
Message-ID: <20190527083402.GA7269@gwilkie-Precision-7520> (raw)
In-Reply-To: <47e25c7c-1dd4-25ee-1d7b-f8c4c0783573@gmail.com>
On Sat, May 25, 2019 at 09:13:13AM -0600, David Ahern wrote:
> > Using a loopback doesn't work, e.g. if 10.1.1.0/24 was on a global interface:
> > ip ro add vrf vrf-a 10.1.1.0/24 dev lo
>
> That works for MPLS when you exit the LSP and deliver locally, so it
> should work here as well. I'll take a look early next week.
OK, thanks.
> I would prefer to avoid it if possible. VRF route leaking for forwarding
> does not have the second lookup and that is the primary use case. VRL
> with local delivery is a 1-off use case and you could just easily argue
> that the connection should not rely on the leaked route. ie., the
> control plane is aware of both VRFs, and the userspace process could use
> the VRF-B path.
>
Although it isn't always possible to change the userspace process -
may be running in a specific vrf by 'ip vrf exec'
next prev parent reply other threads:[~2019-05-27 8:35 UTC|newest]
Thread overview: 10+ messages / expand[flat|nested] mbox.gz Atom feed top
2019-05-24 8:05 [PATCH net-next] vrf: local route leaking George Wilkie
2019-05-24 20:19 ` David Ahern
2019-05-25 7:09 ` George Wilkie
2019-05-25 15:13 ` David Ahern
2019-05-27 8:34 ` George Wilkie [this message]
2019-05-30 3:29 ` David Ahern
2019-05-30 20:52 ` George Wilkie
2019-05-30 21:50 ` David Ahern
2019-05-31 10:38 ` George Wilkie
2019-05-31 14:54 ` David Ahern
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20190527083402.GA7269@gwilkie-Precision-7520 \
--to=gwilkie@vyatta.att-mail.com \
--cc=davem@davemloft.net \
--cc=dsahern@gmail.com \
--cc=kuznet@ms2.inr.ac.ru \
--cc=netdev@vger.kernel.org \
--cc=shrijeet@gmail.com \
--cc=yoshfuji@linux-ipv6.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.