Re: flowtable usable or not

[ Available lists | Index of freebsd-current | Month of Mar 2012 | Week of 1 Mar 2012 | Raw email | View thread | Wrap long lines | Reply | Tag ]
From
Doug Barton <dougb@FreeBSD.org>
Date
1 Mar 2012 23:52:29
Subject
Re: flowtable usable or not
Message-ID
4F500BB9.4040307@FreeBSD.org

Referenced by
K. Macy (freebsd-stable) , K. Macy, Doug Barton (freebsd-stable) , Doug Barton, K. Macy (freebsd-stable) , K. Macy, Doug Barton, Doug Barton (freebsd-stable) , K. Macy (freebsd-stable) , K. Macy, Doug Barton (freebsd-stable) , Doug Barton, K. Macy, K. Macy (freebsd-stable) , H, H (freebsd-stable) , Andriy Gapon, Andriy Gapon (freebsd-stable) , Doug Barton, Doug Barton (freebsd-stable) , Andriy Gapon (freebsd-stable) , Andriy Gapon, Adrian Chadd (freebsd-stable) , Adrian Chadd, H (freebsd-stable) , Julian Elischer, Julian Elischer (freebsd-stable) , Andriy Gapon (freebsd-stable) , H (freebsd-stable) , H (freebsd-stable) , perryh@pluto.rain.com (freebsd-stable) , Bruce Cran (freebsd-stable) , O. Hartmann, O. Hartmann (freebsd-stable) , O. Hartmann (freebsd-stable) , Bas Smeelen (freebsd-stable) , Bas Smeelen (freebsd-stable) , H (freebsd-stable) , Adam Strohl (freebsd-stable) , Garrett Cooper (freebsd-stable) , Garrett Cooper, Ian Lepore (freebsd-stable) , H (freebsd-stable) , K. Macy, Ian Lepore (freebsd-stable) , K. Macy (freebsd-stable) , Mark Linimon (freebsd-stable) , Doug Barton, Doug Barton (freebsd-stable) , Doug Barton, Doug Barton (freebsd-stable) , K. Macy (freebsd-stable) , K. Macy, Doug Barton (freebsd-stable) , Doug Barton, K. Macy, K. Macy (freebsd-stable) , perryh@pluto.rain.com (freebsd-stable) , Bas Smeelen (freebsd-stable) , Adrian Chadd, Adrian Chadd (freebsd-stable) , Doug Barton, Doug Barton (freebsd-stable) , Adrian Chadd (freebsd-stable) , Adrian Chadd, Doug Barton, Doug Barton (freebsd-stable)

[ Hide this part ]
On 2/29/2012 6:01 PM, Steve Wills wrote:
> On 02/29/12 13:17, K. Macy wrote:
>> .
>>>
>>> I tried it, on both FreeBSD routers, web systems, and database
>>> servers; all on 8.2+. It still causes massive instability.
>>> Disabling the sysctl, and/or removing it from the kernel solved
>>> the problems.
>
>> Routing I can believe, but I'm wondering how close attention you
>> paid to the workload. There are CDN networks with high uptimes and
>> shipping firewall products that use flowtable, so your mention of
>> web systems forces makes me ask for specifics.
>
>
> The failure I experienced was with web servers running 8.0 behind a F5
> load balancer in an HA setup. Whenever the failover happened, the web
> servers would continue sending to the wrong MAC address, despite the
> arp table updating. Disabling flowtable via the sysctl solved the
> problem. Maybe Doug's failure was similar, maybe not, but I thought
> I'd throw my $0.02 in.

Yes, that was part of it. On the web and db systems we had what I can
only describe as "general wackiness" with systems suddenly becoming
unreachable, etc. This was with a moderately complex network setup with
a combination of different VLANs, multiple interfaces, etc. The FreeBSD
routers would just plain panic on a semi-regular interval. Removing
flowtable made all this go away, and we've been quite stable since then.


hth,

Doug

--

This .signature sanitized for your protection


Elapsed time: 0.391 seconds