Packet loss over libreswan tunnel in RHEL7 when using xen virtualization
Issue
- Packet loss (~5%) experienced with a point to point libreswan ipsec tunnel under the following conditions:
- The 'right' side of the tunnel runs RHEL 7 (as opposed to RHEL 6)
- The 'right' side of the tunnel is a Xen guest using xen-netfront NIC (identified problem in amazon aws ec2 env.)
- Packet loss is only seen when the 'left' side tries to reach a third host on the 'right' subnet via the tunnel (if the 'left' side talks directly to the 'right', there is no loss seen)
- If the 'right' side runs RHEL 7 but with a different NIC type (Intel SR-IOV, for example), the problem is not seen.
Environment
- Red Hat Enterprise Linux 7
- xen-netfront (vif) module
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.