Skip to content

[action] [PR:18766] [DualToR] enforce same loopback ip and drop bgp pkts on loopback1 for dualtor#18912

Merged
mssonicbld merged 1 commit intosonic-net:202505from
mssonicbld:cherry/202505/18766
Jun 13, 2025
Merged

[action] [PR:18766] [DualToR] enforce same loopback ip and drop bgp pkts on loopback1 for dualtor#18912
mssonicbld merged 1 commit intosonic-net:202505from
mssonicbld:cherry/202505/18766

Conversation

@mssonicbld
Copy link
Collaborator

Description of PR

Summary:
Fixes # (issue)
https://msazure.visualstudio.com/One/_workitems/edit/32910131/

Type of change

  • Bug fix
  • Testbed and Framework(new/improvement)
  • New Test case
  • Skipped for non-supported platforms
  • Test case improvement

Back port request

  • 202205
  • 202305
  • 202311
  • 202405
  • 202411
  • 202505

Approach

What is the motivation for this PR?

This PR updates the DualToR config to enforce the same loopback1 IP address for both ToRs.
Based on a recent Incident 628608070 : [SONiC RCA][SLB_DNC] Gemini Tors dropping vip traffic, we need to block BGP from being established on loopback1.

How did you do it?

Assign the same loopback1 IP to both ToRs.
Added an iptables rules to drop the packets sonic-net/sonic-host-services#262

How did you verify/test it?

Confirmed both ToRs used the same loopback1 IP, and verify the drop rule.

Any platform specific information?

Supported testbed topology if it's a new test case?

Documentation

@mssonicbld
Copy link
Collaborator Author

Original PR: #18766

@mssonicbld
Copy link
Collaborator Author

/azp run

@azure-pipelines
Copy link

Azure Pipelines successfully started running 1 pipeline(s).

… dualtor (sonic-net#18766)

What is the motivation for this PR?
This PR updates the DualToR config to enforce the same loopback1 IP address for both ToRs.
Based on a recent Incident 628608070 : [SONiC RCA][SLB_DNC] Gemini Tors dropping vip traffic, we need to block BGP from being established on loopback1.

How did you do it?
Assign the same loopback1 IP to both ToRs.
Added an iptables rules to drop the packets sonic-net/sonic-host-services#262

How did you verify/test it?
Confirmed both ToRs used the same loopback1 IP, and verify the drop rule.
@mssonicbld mssonicbld force-pushed the cherry/202505/18766 branch from 7162732 to 69cc36d Compare June 12, 2025 04:32
@mssonicbld
Copy link
Collaborator Author

Original PR: #18766

@mssonicbld
Copy link
Collaborator Author

/azp run

@azure-pipelines
Copy link

Azure Pipelines successfully started running 1 pipeline(s).

@yyynini
Copy link
Contributor

yyynini commented Jun 13, 2025

/azp run

@azure-pipelines
Copy link

Commenter does not have sufficient privileges for PR 18912 in repo sonic-net/sonic-mgmt

@mssonicbld mssonicbld merged commit b2b7027 into sonic-net:202505 Jun 13, 2025
17 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants