)]}'
{"doc/source/contributor/internals/ovn/pvlan.rst":[{"author":{"_account_id":11975,"name":"Slawek Kaplonski","email":"skaplons@redhat.com","username":"slaweq"},"change_message_id":"df6fdddcfa361ea54ef7fbfb68ef4f5f1ad50e68","unresolved":true,"context_lines":[{"line_number":227,"context_line":"     match because the packet\u0027s source IP is in the address set, which is"},{"line_number":228,"context_line":"     chassis-agnostic. Priority 1011 beats 1010. **Traffic is allowed.**"},{"line_number":229,"context_line":""},{"line_number":230,"context_line":""},{"line_number":231,"context_line":"References"},{"line_number":232,"context_line":"----------"},{"line_number":233,"context_line":""}],"source_content_type":"text/x-rst","patch_set":6,"id":"c3635c49_4d245369","line":230,"updated":"2026-06-26 07:57:22.000000000","message":"I would add one more point in that document. Something like \"Known limitations\" (name may be different) and mention at least that due to local ARP responder in OVN even ports from different communities or isolated will \"reply\" to the ARP requests from other ports in same L2 network","commit_id":"56336b19053a087a0fa5aecdebaeafae1c05457a"},{"author":{"_account_id":32586,"name":"Elvira García Ruiz","display_name":"Elvira","email":"egarciar@redhat.com","username":"elvira"},"change_message_id":"bd166083aee1267976b8bc82c9e15ebfbc15e304","unresolved":true,"context_lines":[{"line_number":227,"context_line":"     match because the packet\u0027s source IP is in the address set, which is"},{"line_number":228,"context_line":"     chassis-agnostic. Priority 1011 beats 1010. **Traffic is allowed.**"},{"line_number":229,"context_line":""},{"line_number":230,"context_line":""},{"line_number":231,"context_line":"References"},{"line_number":232,"context_line":"----------"},{"line_number":233,"context_line":""}],"source_content_type":"text/x-rst","patch_set":6,"id":"0855cdfc_68344605","line":230,"in_reply_to":"c3635c49_4d245369","updated":"2026-06-26 09:30:50.000000000","message":"Good idea, I added a section talking about limitations related to ARP there!","commit_id":"56336b19053a087a0fa5aecdebaeafae1c05457a"},{"author":{"_account_id":11975,"name":"Slawek Kaplonski","email":"skaplons@redhat.com","username":"slaweq"},"change_message_id":"5a8e3e34824510dbdd70548f9d9828571ae40e33","unresolved":true,"context_lines":[{"line_number":237,"context_line":""},{"line_number":238,"context_line":"ARP is not filtered by PVLAN ACLs. The drop ACL only matches ``ip`` traffic."},{"line_number":239,"context_line":"Including ARP in the drop filter would make VMs lose all connectivity, since"},{"line_number":240,"context_line":"ARP communication is needed as a prerequisite for IP connections."},{"line_number":241,"context_line":""},{"line_number":242,"context_line":"References"},{"line_number":243,"context_line":"----------"}],"source_content_type":"text/x-rst","patch_set":7,"id":"8246f4b1_ff252416","line":240,"updated":"2026-06-29 08:52:13.000000000","message":"I\u0027m not sure this is correct statement. Technically we could filter out ARP traffic as any other if it is between ports which can\u0027t talk to each other. The issue is that in OVN we are using local ARP responder so OVN is replying to ARP requests locally on the host where ARP request was sent from. It is done before filtering with ACL happens.","commit_id":"8373fa5ba0c5c0bbcd20139e5d387b359a26d561"}]}
