-
Notifications
You must be signed in to change notification settings - Fork 3.8k
Fragment tracking #10076
Copy link
Copy link
Closed
Labels
area/datapathImpacts bpf/ or low-level forwarding details, including map management and monitor messages.Impacts bpf/ or low-level forwarding details, including map management and monitor messages.kind/enhancementThis would improve or streamline existing functionality.This would improve or streamline existing functionality.
Metadata
Metadata
Labels
area/datapathImpacts bpf/ or low-level forwarding details, including map management and monitor messages.Impacts bpf/ or low-level forwarding details, including map management and monitor messages.kind/enhancementThis would improve or streamline existing functionality.This would improve or streamline existing functionality.
Summary
The datapath is not able to handle IP fragments right now.
Details
On encounter of IP fragments, L4 policy as well as load-balancing breaks as fragments can't be associated correctly. In order to fix the situation, full reassembly is not required. Instead, we can build in tracking of fragments to associate it with the existing connection tracking table.