Skip to content

Commit 3f416d5

Browse files
Disabling automatic creation of IP-in-IP tunnels by SWSS (#2019)
<!-- Please make sure you've read and understood our contributing guidelines: https://github.com/Azure/SONiC/blob/gh-pages/CONTRIBUTING.md ** Make sure all your commits include a signature generated with `git commit -s` ** If this is a bug fix, make sure your description includes "fixes #xxxx", or "closes #xxxx" or "resolves #xxxx" Please provide the following information: --> #### Why I did it Due to some issues observed in production, we have decided to disable automatic creation of IP-in-IP decap rules during SWSS startup for loopback, interface, and VLAN IPs. ##### Work item tracking - Microsoft ADO **(number only)**: 36937332 #### How I did it Modified `ipinip.json.j2` so that no IP-in-IP decap rules are created for loopback, interface, and VLAN IPs. #### How to verify it 1. Replace `/usr/share/sonic/templates/ipinip.json.j2` inside the SWSS container with the file modified in this PR. 2. Run `sudo config reload -y`. 3. Confirm that there are no IP-in-IP decap rules in `/etc/swss/config.d/ipinip.json` inside the SWSS container: ``` $ docker exec swss cat /etc/swss/config.d/ipinip.json [ ] ``` 4. Confirm that there are no IP-in-IP tunnels created in APPL DB: ``` $ sonic-db-cli APPL_DB KEYS *TUNNEL* ``` <!-- If PR needs to be backported, then the PR must be tested against the base branch and the earliest backport release branch and provide tested image version on these two branches. For example, if the PR is requested for master, 202211 and 202012, then the requester needs to provide test results on master and 202012. --> #### Which release branch to backport (provide reason below if selected) <!-- - Note we only backport fixes to a release branch, *not* features! - Please also provide a reason for the backporting below. - e.g. - [x] 202006 --> - [ ] 201811 - [ ] 201911 - [ ] 202006 - [ ] 202012 - [ ] 202106 - [ ] 202111 - [ ] 202205 - [ ] 202211 #### Tested branch (Please provide the tested image version) <!-- - Please provide tested image version - e.g. - [x] 20201231.100 --> - [202412] <!-- image version 1 --> - [ ] <!-- image version 2 --> #### Description for the changelog <!-- Write a short (one line) summary that describes the changes in this pull request for inclusion in the changelog: --> Disabling automatic creation of IP-in-IP tunnels by SWSS. <!-- Ensure to add label/tag for the feature raised. example - PR#2174 under sonic-utilities repo. where, Generic Config and Update feature has been labelled as GCU. --> #### Link to config_db schema for YANG module changes <!-- Provide a link to config_db schema for the table for which YANG model is defined Link should point to correct section on https://github.com/Azure/sonic-buildimage/blob/master/src/sonic-yang-models/doc/Configuration.md --> N/A --------- Signed-off-by: Mahdi Ramezani <mramezani@microsoft.com> Co-authored-by: Kumaresh Perumal <kperumal@microsoft.com>
1 parent b329531 commit 3f416d5

File tree

1 file changed

+10
-0
lines changed

1 file changed

+10
-0
lines changed

dockers/docker-orchagent/ipinip.json.j2

Lines changed: 10 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -52,6 +52,16 @@
5252
{%- set ipv6_vlan_addresses = ipv6_vlan_addresses.append(prefix) %}
5353
{%- endif %}
5454
{% endfor %}
55+
{# Generation of IP-in-IP decap entries is disabled for BackEnd device types. #}
56+
{%- set backend_device_types = ['BackEndToRRouter', 'BackEndLeafRouter'] -%}
57+
{% if 'type' in DEVICE_METADATA['localhost'] and DEVICE_METADATA['localhost']['type'] in backend_device_types %}
58+
{% set ipv4_addresses = [] %}
59+
{% set ipv6_addresses = [] %}
60+
{% set ipv4_vlan_addresses = [] %}
61+
{% set ipv6_vlan_addresses = [] %}
62+
{% set ipv4_loopback_addresses = [] %}
63+
{% set ipv6_loopback_addresses = [] %}
64+
{% endif %}
5565
{%- set ipv4_addresses = ipv4_addresses + ipv4_vlan_addresses %}
5666
{%- set ipv6_addresses = ipv6_addresses + ipv6_vlan_addresses %}
5767
{# SAI report tunnel TABLE_FULL for large topo. Only generating for VLAN and loopback if over 128 routed interfaces.#}

0 commit comments

Comments
 (0)