[ovs-discuss] ipsec_gre broken after ovs v1.4 - inconsistent pkt mark?

Jesse Gross jesse at nicira.com
Mon Dec 30 22:46:18 UTC 2013


On Fri, Dec 27, 2013 at 5:50 PM, Daniel Hiltgen <daniel at netkine.com> wrote:
> I'm on ubuntu, and had ipsec gre tunnels working with ovs version 1.4, but
> recently upgraded to 1.10, and now my ipsec tunnels aren't working.  Regular
> gre tunnels work fine.  (I also tried ovs 2.0.1 built from source but I see
> the same behavior.)
>
> The racoon logs imply the ipsec connection is working properly.
>
> In the ovs-vswitchd.log file I see errors like the following:
>
> 2013-12-27T21:41:26.907Z|00001|tunnel(miss_handler)|WARN|receive tunnel port
> not found (192.168.122.192->10.4.10.32, key=0, dp port=2, pkt mark=0)
> 2013-12-27T21:41:26.907Z|00002|ofproto_dpif_upcall(miss_handler)|INFO|received
> packet on unassociated datapath port 2

Ansis, this requires iptables to set the mark, right? Do the scripts
set that up automatically?



More information about the discuss mailing list