2 * Copyright © 2016, 2017 Ericsson India Global Services Pvt Ltd. and others. All rights reserved.
4 * This program and the accompanying materials are made available under the
5 * terms of the Eclipse Public License v1.0 which accompanies this distribution,
6 * and is available at http://www.eclipse.org/legal/epl-v10.html
8 package org.opendaylight.netvirt.natservice.internal;
10 import com.google.common.base.Optional;
11 import com.google.common.util.concurrent.AsyncFunction;
12 import com.google.common.util.concurrent.FutureCallback;
13 import com.google.common.util.concurrent.Futures;
14 import com.google.common.util.concurrent.JdkFutureAdapters;
15 import com.google.common.util.concurrent.ListenableFuture;
16 import com.google.common.util.concurrent.MoreExecutors;
17 import java.math.BigInteger;
18 import java.net.Inet6Address;
19 import java.net.InetAddress;
20 import java.net.UnknownHostException;
21 import java.util.ArrayList;
22 import java.util.Collection;
23 import java.util.Collections;
24 import java.util.HashMap;
25 import java.util.HashSet;
26 import java.util.List;
28 import java.util.Objects;
30 import java.util.concurrent.ExecutionException;
31 import java.util.concurrent.Future;
32 import javax.annotation.Nonnull;
33 import javax.annotation.PostConstruct;
34 import javax.inject.Inject;
35 import javax.inject.Singleton;
36 import org.opendaylight.controller.md.sal.binding.api.DataBroker;
37 import org.opendaylight.controller.md.sal.binding.api.ReadOnlyTransaction;
38 import org.opendaylight.controller.md.sal.binding.api.WriteTransaction;
39 import org.opendaylight.controller.md.sal.common.api.data.LogicalDatastoreType;
40 import org.opendaylight.genius.datastoreutils.AsyncDataTreeChangeListenerBase;
41 import org.opendaylight.genius.mdsalutil.ActionInfo;
42 import org.opendaylight.genius.mdsalutil.BucketInfo;
43 import org.opendaylight.genius.mdsalutil.FlowEntity;
44 import org.opendaylight.genius.mdsalutil.GroupEntity;
45 import org.opendaylight.genius.mdsalutil.InstructionInfo;
46 import org.opendaylight.genius.mdsalutil.MDSALUtil;
47 import org.opendaylight.genius.mdsalutil.MatchInfo;
48 import org.opendaylight.genius.mdsalutil.MetaDataUtil;
49 import org.opendaylight.genius.mdsalutil.NwConstants;
50 import org.opendaylight.genius.mdsalutil.UpgradeState;
51 import org.opendaylight.genius.mdsalutil.actions.ActionGroup;
52 import org.opendaylight.genius.mdsalutil.actions.ActionNxLoadInPort;
53 import org.opendaylight.genius.mdsalutil.actions.ActionNxResubmit;
54 import org.opendaylight.genius.mdsalutil.actions.ActionPopMpls;
55 import org.opendaylight.genius.mdsalutil.actions.ActionPuntToController;
56 import org.opendaylight.genius.mdsalutil.actions.ActionSetFieldTunnelId;
57 import org.opendaylight.genius.mdsalutil.instructions.InstructionApplyActions;
58 import org.opendaylight.genius.mdsalutil.instructions.InstructionGotoTable;
59 import org.opendaylight.genius.mdsalutil.instructions.InstructionWriteMetadata;
60 import org.opendaylight.genius.mdsalutil.interfaces.IMdsalApiManager;
61 import org.opendaylight.genius.mdsalutil.matches.MatchEthernetType;
62 import org.opendaylight.genius.mdsalutil.matches.MatchMetadata;
63 import org.opendaylight.genius.mdsalutil.matches.MatchMplsLabel;
64 import org.opendaylight.genius.mdsalutil.matches.MatchTunnelId;
65 import org.opendaylight.infrautils.jobcoordinator.JobCoordinator;
66 import org.opendaylight.netvirt.bgpmanager.api.IBgpManager;
67 import org.opendaylight.netvirt.elanmanager.api.IElanService;
68 import org.opendaylight.netvirt.fibmanager.api.IFibManager;
69 import org.opendaylight.netvirt.fibmanager.api.RouteOrigin;
70 import org.opendaylight.netvirt.natservice.api.CentralizedSwitchScheduler;
71 import org.opendaylight.netvirt.neutronvpn.interfaces.INeutronVpnManager;
72 import org.opendaylight.netvirt.vpnmanager.api.IVpnManager;
73 import org.opendaylight.yang.gen.v1.urn.ietf.params.xml.ns.yang.ietf.inet.types.rev130715.IpAddress;
74 import org.opendaylight.yang.gen.v1.urn.ietf.params.xml.ns.yang.ietf.inet.types.rev130715.Ipv4Address;
75 import org.opendaylight.yang.gen.v1.urn.ietf.params.xml.ns.yang.ietf.yang.types.rev130715.Uuid;
76 import org.opendaylight.yang.gen.v1.urn.opendaylight.flow.inventory.rev130819.tables.table.Flow;
77 import org.opendaylight.yang.gen.v1.urn.opendaylight.flow.types.rev131026.instruction.list.Instruction;
78 import org.opendaylight.yang.gen.v1.urn.opendaylight.genius.idmanager.rev160406.AllocateIdInput;
79 import org.opendaylight.yang.gen.v1.urn.opendaylight.genius.idmanager.rev160406.AllocateIdInputBuilder;
80 import org.opendaylight.yang.gen.v1.urn.opendaylight.genius.idmanager.rev160406.AllocateIdOutput;
81 import org.opendaylight.yang.gen.v1.urn.opendaylight.genius.idmanager.rev160406.CreateIdPoolInput;
82 import org.opendaylight.yang.gen.v1.urn.opendaylight.genius.idmanager.rev160406.CreateIdPoolInputBuilder;
83 import org.opendaylight.yang.gen.v1.urn.opendaylight.genius.idmanager.rev160406.IdManagerService;
84 import org.opendaylight.yang.gen.v1.urn.opendaylight.genius.interfacemanager.rev160406.TunnelTypeBase;
85 import org.opendaylight.yang.gen.v1.urn.opendaylight.genius.interfacemanager.rev160406.TunnelTypeGre;
86 import org.opendaylight.yang.gen.v1.urn.opendaylight.genius.interfacemanager.rev160406.TunnelTypeVxlan;
87 import org.opendaylight.yang.gen.v1.urn.opendaylight.genius.interfacemanager.rpcs.rev160406.OdlInterfaceRpcService;
88 import org.opendaylight.yang.gen.v1.urn.opendaylight.genius.itm.rpcs.rev160406.GetTunnelInterfaceNameInputBuilder;
89 import org.opendaylight.yang.gen.v1.urn.opendaylight.genius.itm.rpcs.rev160406.GetTunnelInterfaceNameOutput;
90 import org.opendaylight.yang.gen.v1.urn.opendaylight.genius.itm.rpcs.rev160406.ItmRpcService;
91 import org.opendaylight.yang.gen.v1.urn.opendaylight.group.types.rev131018.GroupTypes;
92 import org.opendaylight.yang.gen.v1.urn.opendaylight.netvirt.fib.rpc.rev160121.CreateFibEntryInput;
93 import org.opendaylight.yang.gen.v1.urn.opendaylight.netvirt.fib.rpc.rev160121.CreateFibEntryInputBuilder;
94 import org.opendaylight.yang.gen.v1.urn.opendaylight.netvirt.fib.rpc.rev160121.FibRpcService;
95 import org.opendaylight.yang.gen.v1.urn.opendaylight.netvirt.fib.rpc.rev160121.RemoveFibEntryInput;
96 import org.opendaylight.yang.gen.v1.urn.opendaylight.netvirt.fib.rpc.rev160121.RemoveFibEntryInputBuilder;
97 import org.opendaylight.yang.gen.v1.urn.opendaylight.netvirt.natservice.config.rev170206.NatserviceConfig;
98 import org.opendaylight.yang.gen.v1.urn.opendaylight.netvirt.natservice.config.rev170206.NatserviceConfig.NatMode;
99 import org.opendaylight.yang.gen.v1.urn.opendaylight.netvirt.natservice.rev160111.ExtRouters;
100 import org.opendaylight.yang.gen.v1.urn.opendaylight.netvirt.natservice.rev160111.ExternalIpsCounter;
101 import org.opendaylight.yang.gen.v1.urn.opendaylight.netvirt.natservice.rev160111.IntextIpPortMap;
102 import org.opendaylight.yang.gen.v1.urn.opendaylight.netvirt.natservice.rev160111.NaptSwitches;
103 import org.opendaylight.yang.gen.v1.urn.opendaylight.netvirt.natservice.rev160111.ProtocolTypes;
104 import org.opendaylight.yang.gen.v1.urn.opendaylight.netvirt.natservice.rev160111.ProviderTypes;
105 import org.opendaylight.yang.gen.v1.urn.opendaylight.netvirt.natservice.rev160111.RouterIdName;
106 import org.opendaylight.yang.gen.v1.urn.opendaylight.netvirt.natservice.rev160111.ext.routers.Routers;
107 import org.opendaylight.yang.gen.v1.urn.opendaylight.netvirt.natservice.rev160111.ext.routers.RoutersKey;
108 import org.opendaylight.yang.gen.v1.urn.opendaylight.netvirt.natservice.rev160111.ext.routers.routers.ExternalIps;
109 import org.opendaylight.yang.gen.v1.urn.opendaylight.netvirt.natservice.rev160111.external.ips.counter.ExternalCounters;
110 import org.opendaylight.yang.gen.v1.urn.opendaylight.netvirt.natservice.rev160111.external.ips.counter.external.counters.ExternalIpCounter;
111 import org.opendaylight.yang.gen.v1.urn.opendaylight.netvirt.natservice.rev160111.external.subnets.Subnets;
112 import org.opendaylight.yang.gen.v1.urn.opendaylight.netvirt.natservice.rev160111.intext.ip.map.ip.mapping.IpMap;
113 import org.opendaylight.yang.gen.v1.urn.opendaylight.netvirt.natservice.rev160111.intext.ip.map.ip.mapping.IpMapBuilder;
114 import org.opendaylight.yang.gen.v1.urn.opendaylight.netvirt.natservice.rev160111.intext.ip.map.ip.mapping.IpMapKey;
115 import org.opendaylight.yang.gen.v1.urn.opendaylight.netvirt.natservice.rev160111.intext.ip.port.map.IpPortMapping;
116 import org.opendaylight.yang.gen.v1.urn.opendaylight.netvirt.natservice.rev160111.intext.ip.port.map.IpPortMappingKey;
117 import org.opendaylight.yang.gen.v1.urn.opendaylight.netvirt.natservice.rev160111.intext.ip.port.map.ip.port.mapping.IntextIpProtocolType;
118 import org.opendaylight.yang.gen.v1.urn.opendaylight.netvirt.natservice.rev160111.intext.ip.port.map.ip.port.mapping.intext.ip.protocol.type.IpPortMap;
119 import org.opendaylight.yang.gen.v1.urn.opendaylight.netvirt.natservice.rev160111.intext.ip.port.map.ip.port.mapping.intext.ip.protocol.type.ip.port.map.IpPortExternal;
120 import org.opendaylight.yang.gen.v1.urn.opendaylight.netvirt.natservice.rev160111.napt.switches.RouterToNaptSwitch;
121 import org.opendaylight.yang.gen.v1.urn.opendaylight.netvirt.natservice.rev160111.napt.switches.RouterToNaptSwitchBuilder;
122 import org.opendaylight.yang.gen.v1.urn.opendaylight.netvirt.natservice.rev160111.napt.switches.RouterToNaptSwitchKey;
123 import org.opendaylight.yang.gen.v1.urn.opendaylight.netvirt.natservice.rev160111.router.id.name.RouterIds;
124 import org.opendaylight.yang.gen.v1.urn.opendaylight.netvirt.natservice.rev160111.router.id.name.RouterIdsBuilder;
125 import org.opendaylight.yang.gen.v1.urn.opendaylight.netvirt.natservice.rev160111.router.id.name.RouterIdsKey;
126 import org.opendaylight.yang.gen.v1.urn.opendaylight.netvirt.neutronvpn.rev150602.Subnetmaps;
127 import org.opendaylight.yang.gen.v1.urn.opendaylight.netvirt.neutronvpn.rev150602.subnetmaps.Subnetmap;
128 import org.opendaylight.yang.gen.v1.urn.opendaylight.netvirt.neutronvpn.rev150602.subnetmaps.SubnetmapKey;
129 import org.opendaylight.yang.gen.v1.urn.opendaylight.netvirt.vpn.rpc.rev160201.GenerateVpnLabelInput;
130 import org.opendaylight.yang.gen.v1.urn.opendaylight.netvirt.vpn.rpc.rev160201.GenerateVpnLabelInputBuilder;
131 import org.opendaylight.yang.gen.v1.urn.opendaylight.netvirt.vpn.rpc.rev160201.GenerateVpnLabelOutput;
132 import org.opendaylight.yang.gen.v1.urn.opendaylight.netvirt.vpn.rpc.rev160201.RemoveVpnLabelInput;
133 import org.opendaylight.yang.gen.v1.urn.opendaylight.netvirt.vpn.rpc.rev160201.RemoveVpnLabelInputBuilder;
134 import org.opendaylight.yang.gen.v1.urn.opendaylight.netvirt.vpn.rpc.rev160201.VpnRpcService;
135 import org.opendaylight.yang.gen.v1.urn.opendaylight.neutron.ports.rev150712.ports.attributes.ports.Port;
136 import org.opendaylight.yangtools.yang.binding.DataObject;
137 import org.opendaylight.yangtools.yang.binding.InstanceIdentifier;
138 import org.opendaylight.yangtools.yang.common.RpcResult;
139 import org.slf4j.Logger;
140 import org.slf4j.LoggerFactory;
143 public class ExternalRoutersListener extends AsyncDataTreeChangeListenerBase<Routers, ExternalRoutersListener> {
144 private static final Logger LOG = LoggerFactory.getLogger(ExternalRoutersListener.class);
146 private static final BigInteger COOKIE_TUNNEL = new BigInteger("9000000", 16);
147 private static final BigInteger COOKIE_VM_LFIB_TABLE = new BigInteger("8000022", 16);
149 private final DataBroker dataBroker;
150 private final IMdsalApiManager mdsalManager;
151 private final ItmRpcService itmManager;
152 private final OdlInterfaceRpcService interfaceManager;
153 private final IdManagerService idManager;
154 private final NaptManager naptManager;
155 private final NAPTSwitchSelector naptSwitchSelector;
156 private final IBgpManager bgpManager;
157 private final VpnRpcService vpnService;
158 private final FibRpcService fibService;
159 private final SNATDefaultRouteProgrammer defaultRouteProgrammer;
160 private final NaptEventHandler naptEventHandler;
161 private final NaptPacketInHandler naptPacketInHandler;
162 private final IFibManager fibManager;
163 private final IVpnManager vpnManager;
164 private final EvpnSnatFlowProgrammer evpnSnatFlowProgrammer;
165 private final CentralizedSwitchScheduler centralizedSwitchScheduler;
166 private final NatMode natMode;
167 private final INeutronVpnManager nvpnManager;
168 private final IElanService elanManager;
169 private final JobCoordinator coordinator;
170 private final UpgradeState upgradeState;
173 public ExternalRoutersListener(final DataBroker dataBroker, final IMdsalApiManager mdsalManager,
174 final ItmRpcService itmManager,
175 final OdlInterfaceRpcService interfaceManager,
176 final IdManagerService idManager,
177 final NaptManager naptManager,
178 final NAPTSwitchSelector naptSwitchSelector,
179 final IBgpManager bgpManager,
180 final VpnRpcService vpnService,
181 final FibRpcService fibService,
182 final SNATDefaultRouteProgrammer snatDefaultRouteProgrammer,
183 final NaptEventHandler naptEventHandler,
184 final NaptPacketInHandler naptPacketInHandler,
185 final IFibManager fibManager,
186 final IVpnManager vpnManager,
187 final EvpnSnatFlowProgrammer evpnSnatFlowProgrammer,
188 final INeutronVpnManager nvpnManager,
189 final CentralizedSwitchScheduler centralizedSwitchScheduler,
190 final NatserviceConfig config,
191 final IElanService elanManager,
192 final JobCoordinator coordinator,
193 final UpgradeState upgradeState) {
194 super(Routers.class, ExternalRoutersListener.class);
195 this.dataBroker = dataBroker;
196 this.mdsalManager = mdsalManager;
197 this.itmManager = itmManager;
198 this.interfaceManager = interfaceManager;
199 this.idManager = idManager;
200 this.naptManager = naptManager;
201 this.naptSwitchSelector = naptSwitchSelector;
202 this.bgpManager = bgpManager;
203 this.vpnService = vpnService;
204 this.fibService = fibService;
205 this.defaultRouteProgrammer = snatDefaultRouteProgrammer;
206 this.naptEventHandler = naptEventHandler;
207 this.naptPacketInHandler = naptPacketInHandler;
208 this.fibManager = fibManager;
209 this.vpnManager = vpnManager;
210 this.evpnSnatFlowProgrammer = evpnSnatFlowProgrammer;
211 this.nvpnManager = nvpnManager;
212 this.elanManager = elanManager;
213 this.centralizedSwitchScheduler = centralizedSwitchScheduler;
214 this.coordinator = coordinator;
215 this.upgradeState = upgradeState;
216 if (config != null) {
217 this.natMode = config.getNatMode();
219 this.natMode = NatMode.Controller;
226 LOG.info("{} init", getClass().getSimpleName());
227 registerListener(LogicalDatastoreType.CONFIGURATION, dataBroker);
232 protected InstanceIdentifier<Routers> getWildCardPath() {
233 return InstanceIdentifier.create(ExtRouters.class).child(Routers.class);
237 // TODO Clean up the exception handling
238 @SuppressWarnings("checkstyle:IllegalCatch")
239 protected void add(InstanceIdentifier<Routers> identifier, Routers routers) {
240 // Populate the router-id-name container
241 String routerName = routers.getRouterName();
242 LOG.info("add : external router event for {}", routerName);
243 long routerId = NatUtil.getVpnId(dataBroker, routerName);
244 NatUtil.createRouterIdsConfigDS(dataBroker, routerId, routerName);
245 Uuid bgpVpnUuid = NatUtil.getVpnForRouter(dataBroker, routerName);
246 if (natMode == NatMode.Conntrack && !upgradeState.isUpgradeInProgress()) {
247 if (bgpVpnUuid != null) {
250 List<ExternalIps> externalIps = routers.getExternalIps();
251 // Allocate Primary Napt Switch for this router
252 if (routers.isEnableSnat() && externalIps != null && !externalIps.isEmpty()) {
253 centralizedSwitchScheduler.scheduleCentralizedSwitch(routers);
255 //snatServiceManger.notify(routers, null, Action.ADD);
258 coordinator.enqueueJob(NatConstants.NAT_DJC_PREFIX + routers.getKey(), () -> {
259 WriteTransaction writeFlowInvTx = dataBroker.newWriteOnlyTransaction();
260 LOG.info("add : Installing NAT default route on all dpns part of router {}", routerName);
261 long bgpVpnId = NatConstants.INVALID_ID;
262 if (bgpVpnUuid != null) {
263 bgpVpnId = NatUtil.getVpnId(dataBroker, bgpVpnUuid.getValue());
265 addOrDelDefFibRouteToSNAT(routerName, routerId, bgpVpnId, bgpVpnUuid, true, writeFlowInvTx);
266 List<ListenableFuture<Void>> futures = new ArrayList<>();
267 // Allocate Primary Napt Switch for this router
268 BigInteger primarySwitchId = getPrimaryNaptSwitch(routerName);
269 if (primarySwitchId != null && !primarySwitchId.equals(BigInteger.ZERO)) {
270 if (!routers.isEnableSnat()) {
271 LOG.info("add : SNAT is disabled for external router {} ", routerName);
272 /* If SNAT is disabled on ext-router though L3_FIB_TABLE(21) -> PSNAT_TABLE(26) flow
273 * is required for DNAT. Hence writeFlowInvTx object submit is required.
277 handleEnableSnat(routers, routerId, primarySwitchId, bgpVpnId, writeFlowInvTx);
279 //final submit call for writeFlowInvTx
280 futures.add(NatUtil.waitForTransactionToComplete(writeFlowInvTx));
282 }, NatConstants.NAT_DJC_MAX_RETRIES);
283 } catch (Exception ex) {
284 LOG.error("add : Exception while Installing NAT flows on all dpns as part of router {}",
290 public void handleEnableSnat(Routers routers, long routerId, BigInteger primarySwitchId, long bgpVpnId,
291 WriteTransaction writeFlowInvTx) {
292 String routerName = routers.getRouterName();
293 LOG.info("handleEnableSnat : Handling SNAT for router {}", routerName);
295 naptManager.initialiseExternalCounter(routers, routerId);
296 subnetRegisterMapping(routers, routerId);
298 LOG.debug("handleEnableSnat:About to create and install outbound miss entry in Primary Switch {} for router {}",
299 primarySwitchId, routerName);
301 ProviderTypes extNwProvType = NatEvpnUtil.getExtNwProvTypeFromRouterName(dataBroker, routerName,
302 routers.getNetworkId());
303 if (extNwProvType == null) {
304 LOG.error("handleEnableSnat : External Network Provider Type missing");
308 if (bgpVpnId != NatConstants.INVALID_ID) {
309 installFlowsWithUpdatedVpnId(primarySwitchId, routerName, bgpVpnId, routerId, false, writeFlowInvTx,
312 // write metadata and punt
313 installOutboundMissEntry(routerName, routerId, primarySwitchId, writeFlowInvTx);
314 // Now install entries in SNAT tables to point to Primary for each router
315 List<BigInteger> switches = naptSwitchSelector.getDpnsForVpn(routerName);
316 for (BigInteger dpnId : switches) {
317 // Handle switches and NAPT switches separately
318 if (!dpnId.equals(primarySwitchId)) {
319 LOG.debug("handleEnableSnat : Handle Ordinary switch");
320 handleSwitches(dpnId, routerName, routerId, primarySwitchId);
322 LOG.debug("handleEnableSnat : Handle NAPT switch");
323 handlePrimaryNaptSwitch(dpnId, routerName, routerId, writeFlowInvTx);
328 Collection<String> externalIps = NatUtil.getExternalIpsForRouter(dataBroker, routerId);
329 if (externalIps.isEmpty()) {
330 LOG.error("handleEnableSnat : Internal External mapping not found for router {}", routerName);
333 for (String externalIpAddrPrefix : externalIps) {
334 LOG.debug("handleEnableSnat : Calling handleSnatReverseTraffic for primarySwitchId {}, "
335 + "routerName {} and externalIpAddPrefix {}", primarySwitchId, routerName, externalIpAddrPrefix);
336 handleSnatReverseTraffic(primarySwitchId, routers, routerId, routerName, externalIpAddrPrefix,
340 LOG.debug("handleEnableSnat : Exit");
343 private BigInteger getPrimaryNaptSwitch(String routerName) {
344 // Allocate Primary Napt Switch for this router
345 BigInteger primarySwitchId = NatUtil.getPrimaryNaptfromRouterName(dataBroker, routerName);
346 if (primarySwitchId != null && !primarySwitchId.equals(BigInteger.ZERO)) {
347 LOG.debug("handleEnableSnat : Primary NAPT switch with DPN ID {} is already elected for router {}",
348 primarySwitchId, routerName);
349 return primarySwitchId;
351 // Validating and creating VNI pool during when NAPT switch is selected.
352 // With Assumption this might be the first NAT service comes up.
353 NatOverVxlanUtil.validateAndCreateVxlanVniPool(dataBroker, nvpnManager, idManager,
354 NatConstants.ODL_VNI_POOL_NAME);
355 // Allocated an id from VNI pool for the Router.
356 NatOverVxlanUtil.getRouterVni(idManager, routerName, NatConstants.INVALID_ID);
357 primarySwitchId = naptSwitchSelector.selectNewNAPTSwitch(routerName);
358 LOG.debug("handleEnableSnat : Primary NAPT switch DPN ID {}", primarySwitchId);
360 return primarySwitchId;
363 protected void installNaptPfibExternalOutputFlow(String routerName, Long routerId, BigInteger dpnId,
364 WriteTransaction writeFlowInvTx) {
365 Long extVpnId = NatUtil.getNetworkVpnIdFromRouterId(dataBroker, routerId);
366 if (extVpnId == NatConstants.INVALID_ID) {
367 LOG.error("installNaptPfibExternalOutputFlow - not found extVpnId for router {}", routerId);
370 List<String> externalIps = NatUtil.getExternalIpsForRouter(dataBroker, routerName);
371 if (externalIps.isEmpty()) {
372 LOG.error("installNaptPfibExternalOutputFlow - empty external Ips list for dpnId {} extVpnId {}",
376 for (String ip : externalIps) {
377 Uuid subnetId = getSubnetIdForFixedIp(ip);
378 if (subnetId != null) {
379 long subnetVpnId = NatUtil.getExternalSubnetVpnId(dataBroker, subnetId);
380 if (subnetVpnId != NatConstants.INVALID_ID) {
381 extVpnId = subnetVpnId;
383 LOG.debug("installNaptPfibExternalOutputFlow - dpnId {} extVpnId {} subnetId {}",
384 dpnId, extVpnId, subnetId);
385 FlowEntity postNaptFlowEntity = buildNaptPfibFlowEntity(dpnId, extVpnId);
386 mdsalManager.addFlowToTx(postNaptFlowEntity, writeFlowInvTx);
391 private Uuid getSubnetIdForFixedIp(String ip) {
393 IpAddress externalIpv4Address = new IpAddress(new Ipv4Address(ip));
394 Port port = NatUtil.getNeutronPortForRouterGetewayIp(dataBroker, externalIpv4Address);
395 Uuid subnetId = NatUtil.getSubnetIdForFloatingIp(port, externalIpv4Address);
398 LOG.error("getSubnetIdForFixedIp : ip is null");
402 protected void subnetRegisterMapping(Routers routerEntry, Long segmentId) {
403 List<Uuid> subnetList = null;
404 List<String> externalIps = null;
405 LOG.debug("subnetRegisterMapping : Fetching values from extRouters model");
406 subnetList = routerEntry.getSubnetIds();
407 externalIps = NatUtil.getIpsListFromExternalIps(routerEntry.getExternalIps());
409 int extIpCounter = externalIps.size();
410 LOG.debug("subnetRegisterMapping : counter values before looping counter {} and extIpCounter {}",
411 counter, extIpCounter);
412 for (Uuid subnet : subnetList) {
413 LOG.debug("subnetRegisterMapping : Looping internal subnets for subnet {}", subnet);
414 InstanceIdentifier<Subnetmap> subnetmapId = InstanceIdentifier
415 .builder(Subnetmaps.class)
416 .child(Subnetmap.class, new SubnetmapKey(subnet))
418 Optional<Subnetmap> sn = read(dataBroker, LogicalDatastoreType.CONFIGURATION, subnetmapId);
419 if (sn.isPresent()) {
421 Subnetmap subnetmapEntry = sn.get();
422 String subnetString = subnetmapEntry.getSubnetIp();
423 String[] subnetSplit = subnetString.split("/");
424 String subnetIp = subnetSplit[0];
426 InetAddress address = InetAddress.getByName(subnetIp);
427 if (address instanceof Inet6Address) {
428 // TODO: Revisit when IPv6 external connectivity support is added.
429 LOG.error("subnetRegisterMapping : Skipping ipv6 address {}.", address);
432 } catch (UnknownHostException e) {
433 LOG.error("subnetRegisterMapping : Invalid ip address {}", subnetIp, e);
436 String subnetPrefix = "0";
437 if (subnetSplit.length == 2) {
438 subnetPrefix = subnetSplit[1];
440 IPAddress subnetAddr = new IPAddress(subnetIp, Integer.parseInt(subnetPrefix));
441 LOG.debug("subnetRegisterMapping : subnetAddr is {} and subnetPrefix is {}",
442 subnetAddr.getIpAddress(), subnetAddr.getPrefixLength());
444 LOG.debug("subnetRegisterMapping : counter values counter {} and extIpCounter {}",
445 counter, extIpCounter);
446 if (extIpCounter != 0) {
447 if (counter < extIpCounter) {
448 String[] ipSplit = externalIps.get(counter).split("/");
449 String externalIp = ipSplit[0];
450 String extPrefix = Short.toString(NatConstants.DEFAULT_PREFIX);
451 if (ipSplit.length == 2) {
452 extPrefix = ipSplit[1];
454 IPAddress externalIpAddr = new IPAddress(externalIp, Integer.parseInt(extPrefix));
455 LOG.debug("subnetRegisterMapping : externalIp is {} and extPrefix is {}",
456 externalIpAddr.getIpAddress(), externalIpAddr.getPrefixLength());
457 naptManager.registerMapping(segmentId, subnetAddr, externalIpAddr);
458 LOG.debug("subnetRegisterMapping : Called registerMapping for subnetIp {}, prefix {}, "
459 + "externalIp {}. prefix {}", subnetIp, subnetPrefix, externalIp, extPrefix);
461 counter = 0; //Reset the counter which runs on externalIps for round-robbin effect
462 LOG.debug("subnetRegisterMapping : Counter on externalIps got reset");
463 String[] ipSplit = externalIps.get(counter).split("/");
464 String externalIp = ipSplit[0];
465 String extPrefix = Short.toString(NatConstants.DEFAULT_PREFIX);
466 if (ipSplit.length == 2) {
467 extPrefix = ipSplit[1];
469 IPAddress externalIpAddr = new IPAddress(externalIp, Integer.parseInt(extPrefix));
470 LOG.debug("subnetRegisterMapping : externalIp is {} and extPrefix is {}",
471 externalIpAddr.getIpAddress(), externalIpAddr.getPrefixLength());
472 naptManager.registerMapping(segmentId, subnetAddr, externalIpAddr);
473 LOG.debug("subnetRegisterMapping : Called registerMapping for subnetIp {}, prefix {}, "
474 + "externalIp {}. prefix {}", subnetIp, subnetPrefix,
475 externalIp, extPrefix);
479 LOG.debug("subnetRegisterMapping : Counter on externalIps incremented to {}", counter);
481 LOG.warn("subnetRegisterMapping : No internal subnets present in extRouters Model");
486 private void addOrDelDefFibRouteToSNAT(String routerName, long routerId, long bgpVpnId,
487 Uuid bgpVpnUuid, boolean create, WriteTransaction writeFlowInvTx) {
488 //Check if BGP VPN exists. If exists then invoke the new method.
489 if (bgpVpnId != NatConstants.INVALID_ID) {
490 if (bgpVpnUuid != null) {
491 String bgpVpnName = bgpVpnUuid.getValue();
492 LOG.debug("Populate the router-id-name container with the mapping BGP VPN-ID {} -> BGP VPN-NAME {}",
493 bgpVpnId, bgpVpnName);
494 RouterIds rtrs = new RouterIdsBuilder().setKey(new RouterIdsKey(bgpVpnId))
495 .setRouterId(bgpVpnId).setRouterName(bgpVpnName).build();
496 MDSALUtil.syncWrite(dataBroker, LogicalDatastoreType.CONFIGURATION,
497 getRoutersIdentifier(bgpVpnId), rtrs);
499 addOrDelDefaultFibRouteForSnatWithBgpVpn(routerName, routerId, bgpVpnId, create, writeFlowInvTx);
503 //Router ID is used as the internal VPN's name, hence the vrf-id in VpnInstance Op DataStore
504 addOrDelDefaultFibRouteForSNAT(routerName, routerId, create, writeFlowInvTx);
507 private void addOrDelDefaultFibRouteForSNAT(String routerName, long routerId, boolean create,
508 WriteTransaction writeFlowInvTx) {
509 List<BigInteger> switches = naptSwitchSelector.getDpnsForVpn(routerName);
510 if (switches.isEmpty()) {
511 LOG.info("addOrDelDefaultFibRouteForSNAT : No switches found for router {}", routerName);
514 if (routerId == NatConstants.INVALID_ID) {
515 LOG.error("addOrDelDefaultFibRouteForSNAT : Could not retrieve router Id for {} to program "
516 + "default NAT route in FIB", routerName);
519 for (BigInteger dpnId : switches) {
521 LOG.debug("addOrDelDefaultFibRouteForSNAT : installing default NAT route for router {} in dpn {} "
522 + "for the internal vpn-id {}", routerId, dpnId, routerId);
523 defaultRouteProgrammer.installDefNATRouteInDPN(dpnId, routerId, writeFlowInvTx);
525 LOG.debug("addOrDelDefaultFibRouteForSNAT : removing default NAT route for router {} in dpn {} "
526 + "for the internal vpn-id {}", routerId, dpnId, routerId);
527 defaultRouteProgrammer.removeDefNATRouteInDPN(dpnId, routerId, writeFlowInvTx);
532 private void addOrDelDefaultFibRouteForSnatWithBgpVpn(String routerName, long routerId,
533 long bgpVpnId, boolean create,WriteTransaction writeFlowInvTx) {
534 List<BigInteger> dpnIds = NatUtil.getDpnsForRouter(dataBroker, routerName);
535 if (dpnIds.isEmpty()) {
536 LOG.error("addOrDelDefaultFibRouteForSNATWIthBgpVpn: No dpns are part of router {} to program "
537 + "default NAT flows for BGP-VPN {}", routerName, bgpVpnId);
540 for (BigInteger dpnId : dpnIds) {
542 if (bgpVpnId != NatConstants.INVALID_ID) {
543 LOG.debug("addOrDelDefaultFibRouteForSnatWithBgpVpn : installing default NAT route for router {} "
544 + "in dpn {} for the BGP vpnID {}", routerId, dpnId, bgpVpnId);
545 defaultRouteProgrammer.installDefNATRouteInDPN(dpnId, bgpVpnId, routerId, writeFlowInvTx);
547 LOG.debug("addOrDelDefaultFibRouteForSnatWithBgpVpn : installing default NAT route for router {} "
548 + "in dpn {} for the internal vpn", routerId, dpnId);
549 defaultRouteProgrammer.installDefNATRouteInDPN(dpnId, routerId,writeFlowInvTx);
552 if (bgpVpnId != NatConstants.INVALID_ID) {
553 LOG.debug("addOrDelDefaultFibRouteForSnatWithBgpVpn : removing default NAT route for router {} "
554 + "in dpn {} for the BGP vpnID {}", routerId, dpnId, bgpVpnId);
555 defaultRouteProgrammer.removeDefNATRouteInDPN(dpnId, bgpVpnId, routerId, writeFlowInvTx);
557 LOG.debug("addOrDelDefaultFibRouteForSnatWithBgpVpn : removing default NAT route for router {} "
558 + "in dpn {} for the internal vpn", routerId, dpnId);
559 defaultRouteProgrammer.removeDefNATRouteInDPN(dpnId, routerId, writeFlowInvTx);
565 // TODO Clean up the exception handling
566 @SuppressWarnings("checkstyle:IllegalCatch")
567 public static <T extends DataObject> Optional<T> read(DataBroker broker, LogicalDatastoreType datastoreType,
568 InstanceIdentifier<T> path) {
569 ReadOnlyTransaction tx = broker.newReadOnlyTransaction();
572 return tx.read(datastoreType, path).get();
573 } catch (Exception e) {
574 throw new RuntimeException(e);
578 protected void installOutboundMissEntry(String routerName, long routerId, BigInteger primarySwitchId,
579 WriteTransaction writeFlowInvTx) {
580 LOG.debug("installOutboundMissEntry : Router ID from getVpnId {}", routerId);
581 if (routerId != NatConstants.INVALID_ID) {
582 LOG.debug("installOutboundMissEntry : Creating miss entry on primary {}, for router {}",
583 primarySwitchId, routerId);
584 createOutboundTblEntry(primarySwitchId, routerId, writeFlowInvTx);
586 LOG.error("installOutboundMissEntry : Unable to fetch Router Id for RouterName {}, failed to "
587 + "createAndInstallMissEntry", routerName);
591 public String getFlowRefOutbound(BigInteger dpnId, short tableId, long routerID) {
592 return NatConstants.NAPT_FLOWID_PREFIX + dpnId + NatConstants.FLOWID_SEPARATOR + tableId + NatConstants
593 .FLOWID_SEPARATOR + routerID;
596 private String getFlowRefNaptPreFib(BigInteger dpnId, short tableId, long vpnId) {
597 return NatConstants.NAPT_FLOWID_PREFIX + dpnId + NatConstants.FLOWID_SEPARATOR + tableId + NatConstants
598 .FLOWID_SEPARATOR + vpnId;
601 public BigInteger getCookieOutboundFlow(long routerId) {
602 return NwConstants.COOKIE_OUTBOUND_NAPT_TABLE.add(new BigInteger("0110001", 16)).add(
603 BigInteger.valueOf(routerId));
606 protected FlowEntity buildOutboundFlowEntity(BigInteger dpId, long routerId) {
607 LOG.debug("buildOutboundFlowEntity : called for dpId {} and routerId{}", dpId, routerId);
608 List<MatchInfo> matches = new ArrayList<>();
609 matches.add(MatchEthernetType.IPV4);
610 matches.add(new MatchMetadata(MetaDataUtil.getVpnIdMetadata(routerId), MetaDataUtil.METADATA_MASK_VRFID));
612 List<InstructionInfo> instructions = new ArrayList<>();
613 List<ActionInfo> actionsInfos = new ArrayList<>();
614 actionsInfos.add(new ActionPuntToController());
615 instructions.add(new InstructionApplyActions(actionsInfos));
616 instructions.add(new InstructionWriteMetadata(MetaDataUtil.getVpnIdMetadata(routerId),
617 MetaDataUtil.METADATA_MASK_VRFID));
619 String flowRef = getFlowRefOutbound(dpId, NwConstants.OUTBOUND_NAPT_TABLE, routerId);
620 BigInteger cookie = getCookieOutboundFlow(routerId);
621 FlowEntity flowEntity = MDSALUtil.buildFlowEntity(dpId, NwConstants.OUTBOUND_NAPT_TABLE, flowRef,
623 cookie, matches, instructions);
624 LOG.debug("installOutboundMissEntry : returning flowEntity {}", flowEntity);
628 public void createOutboundTblEntry(BigInteger dpnId, long routerId, WriteTransaction writeFlowInvTx) {
629 LOG.debug("createOutboundTblEntry : called for dpId {} and routerId {}", dpnId, routerId);
630 FlowEntity flowEntity = buildOutboundFlowEntity(dpnId, routerId);
631 LOG.debug("createOutboundTblEntry : Installing flow {}", flowEntity);
632 mdsalManager.addFlowToTx(flowEntity, writeFlowInvTx);
635 protected String getTunnelInterfaceName(BigInteger srcDpId, BigInteger dstDpId) {
636 Class<? extends TunnelTypeBase> tunType = TunnelTypeVxlan.class;
637 RpcResult<GetTunnelInterfaceNameOutput> rpcResult;
639 Future<RpcResult<GetTunnelInterfaceNameOutput>> result =
640 itmManager.getTunnelInterfaceName(new GetTunnelInterfaceNameInputBuilder()
641 .setSourceDpid(srcDpId)
642 .setDestinationDpid(dstDpId)
643 .setTunnelType(tunType)
645 rpcResult = result.get();
646 if (!rpcResult.isSuccessful()) {
647 tunType = TunnelTypeGre.class;
648 result = itmManager.getTunnelInterfaceName(new GetTunnelInterfaceNameInputBuilder()
649 .setSourceDpid(srcDpId)
650 .setDestinationDpid(dstDpId)
651 .setTunnelType(tunType)
653 rpcResult = result.get();
654 if (!rpcResult.isSuccessful()) {
655 LOG.warn("getTunnelInterfaceName : RPC Call to getTunnelInterfaceId returned with Errors {}",
656 rpcResult.getErrors());
658 return rpcResult.getResult().getInterfaceName();
660 LOG.warn("getTunnelInterfaceName : RPC Call to getTunnelInterfaceId returned with Errors {}",
661 rpcResult.getErrors());
663 return rpcResult.getResult().getInterfaceName();
665 } catch (InterruptedException | ExecutionException | NullPointerException e) {
666 LOG.error("getTunnelInterfaceName : Exception when getting tunnel interface Id for tunnel "
667 + "between {} and {}", srcDpId, dstDpId, e);
673 protected void installSnatMissEntryForPrimrySwch(BigInteger dpnId, String routerName, long routerId,
674 WriteTransaction writeFlowInvTx) {
675 LOG.debug("installSnatMissEntry : called for for the primary NAPT switch dpnId {} ", dpnId);
676 // Install miss entry pointing to group
677 FlowEntity flowEntity = buildSnatFlowEntityForPrmrySwtch(dpnId, routerName, routerId);
678 mdsalManager.addFlowToTx(flowEntity, writeFlowInvTx);
681 protected void installSnatMissEntry(BigInteger dpnId, List<BucketInfo> bucketInfo,
682 String routerName, long routerId) {
683 LOG.debug("installSnatMissEntry : called for dpnId {} with primaryBucket {} ",
684 dpnId, bucketInfo.get(0));
685 // Install the select group
686 long groupId = createGroupId(getGroupIdKey(routerName));
687 GroupEntity groupEntity =
688 MDSALUtil.buildGroupEntity(dpnId, groupId, routerName, GroupTypes.GroupAll, bucketInfo);
689 LOG.debug("installSnatMissEntry : installing the SNAT to NAPT GroupEntity:{}", groupEntity);
690 mdsalManager.syncInstallGroup(groupEntity);
691 // Install miss entry pointing to group
692 FlowEntity flowEntity = buildSnatFlowEntity(dpnId, routerName, routerId, groupId);
693 if (flowEntity == null) {
694 LOG.error("installSnatMissEntry : Flow entity received as NULL. "
695 + "Cannot proceed with installation of SNAT Flow in table {} which is pointing to Group "
696 + "on Non NAPT DPN {} for router {}", NwConstants.PSNAT_TABLE, dpnId, routerName);
699 mdsalManager.installFlow(flowEntity);
702 long installGroup(BigInteger dpnId, String routerName, List<BucketInfo> bucketInfo) {
703 long groupId = createGroupId(getGroupIdKey(routerName));
704 GroupEntity groupEntity =
705 MDSALUtil.buildGroupEntity(dpnId, groupId, routerName, GroupTypes.GroupAll, bucketInfo);
706 LOG.debug("installGroup : installing the SNAT to NAPT GroupEntity:{}", groupEntity);
707 mdsalManager.syncInstallGroup(groupEntity);
711 private FlowEntity buildSnatFlowEntity(BigInteger dpId, String routerName, long routerId, long groupId) {
712 LOG.debug("buildSnatFlowEntity : called for dpId {}, routerName {} and groupId {}",
713 dpId, routerName, groupId);
714 List<MatchInfo> matches = new ArrayList<>();
715 matches.add(MatchEthernetType.IPV4);
716 matches.add(new MatchMetadata(MetaDataUtil.getVpnIdMetadata(routerId), MetaDataUtil.METADATA_MASK_VRFID));
718 List<ActionInfo> actionsInfo = new ArrayList<>();
719 long tunnelId = NatUtil.getTunnelIdForNonNaptToNaptFlow(dataBroker, elanManager, idManager, routerId,
721 actionsInfo.add(new ActionSetFieldTunnelId(BigInteger.valueOf(tunnelId)));
722 LOG.debug("buildSnatFlowEntity : Setting the tunnel to the list of action infos {}", actionsInfo);
723 actionsInfo.add(new ActionGroup(groupId));
724 List<InstructionInfo> instructions = new ArrayList<>();
725 instructions.add(new InstructionApplyActions(actionsInfo));
726 String flowRef = getFlowRefSnat(dpId, NwConstants.PSNAT_TABLE, routerName);
727 FlowEntity flowEntity = MDSALUtil.buildFlowEntity(dpId, NwConstants.PSNAT_TABLE, flowRef,
728 NatConstants.DEFAULT_PSNAT_FLOW_PRIORITY, flowRef, 0, 0,
729 NwConstants.COOKIE_SNAT_TABLE, matches, instructions);
731 LOG.debug("buildSnatFlowEntity : Returning SNAT Flow Entity {}", flowEntity);
735 private FlowEntity buildSnatFlowEntityForPrmrySwtch(BigInteger dpId, String routerName, long routerId) {
737 LOG.debug("buildSnatFlowEntityForPrmrySwtch : called for primary NAPT switch dpId {}, routerName {}", dpId,
739 List<MatchInfo> matches = new ArrayList<>();
740 matches.add(MatchEthernetType.IPV4);
741 matches.add(new MatchMetadata(MetaDataUtil.getVpnIdMetadata(routerId), MetaDataUtil.METADATA_MASK_VRFID));
743 List<InstructionInfo> instructions = new ArrayList<>();
744 instructions.add(new InstructionGotoTable(NwConstants.OUTBOUND_NAPT_TABLE));
746 String flowRef = getFlowRefSnat(dpId, NwConstants.PSNAT_TABLE, routerName);
747 FlowEntity flowEntity = MDSALUtil.buildFlowEntity(dpId, NwConstants.PSNAT_TABLE, flowRef,
748 NatConstants.DEFAULT_PSNAT_FLOW_PRIORITY, flowRef, 0, 0,
749 NwConstants.COOKIE_SNAT_TABLE, matches, instructions);
751 LOG.debug("buildSnatFlowEntityForPrmrySwtch : Returning SNAT Flow Entity {}", flowEntity);
755 // TODO : Replace this with ITM Rpc once its available with full functionality
756 protected void installTerminatingServiceTblEntry(BigInteger dpnId, String routerName, long routerId,
757 WriteTransaction writeFlowInvTx) {
758 LOG.debug("installTerminatingServiceTblEntry : for switch {}, routerName {}",
760 FlowEntity flowEntity = buildTsFlowEntity(dpnId, routerName, routerId);
761 if (flowEntity == null) {
762 LOG.error("installTerminatingServiceTblEntry : Flow entity received as NULL. "
763 + "Cannot proceed with installation of Terminating Service table {} which is pointing to table {} "
764 + "on DPN {} for router {}", NwConstants.INTERNAL_TUNNEL_TABLE, NwConstants.OUTBOUND_NAPT_TABLE,
768 mdsalManager.addFlowToTx(flowEntity, writeFlowInvTx);
772 private FlowEntity buildTsFlowEntity(BigInteger dpId, String routerName, long routerId) {
773 List<MatchInfo> matches = new ArrayList<>();
774 matches.add(MatchEthernetType.IPV4);
775 long tunnelId = NatUtil.getTunnelIdForNonNaptToNaptFlow(dataBroker, elanManager, idManager, routerId,
777 matches.add(new MatchTunnelId(BigInteger.valueOf(tunnelId)));
778 String flowRef = getFlowRefTs(dpId, NwConstants.INTERNAL_TUNNEL_TABLE, tunnelId);
779 List<InstructionInfo> instructions = new ArrayList<>();
780 instructions.add(new InstructionWriteMetadata(MetaDataUtil.getVpnIdMetadata(routerId),
781 MetaDataUtil.METADATA_MASK_VRFID));
782 instructions.add(new InstructionGotoTable(NwConstants.OUTBOUND_NAPT_TABLE));
783 FlowEntity flowEntity = MDSALUtil.buildFlowEntity(dpId, NwConstants.INTERNAL_TUNNEL_TABLE, flowRef,
784 NatConstants.DEFAULT_TS_FLOW_PRIORITY, flowRef, 0, 0, NwConstants.COOKIE_TS_TABLE, matches,
789 public String getFlowRefTs(BigInteger dpnId, short tableId, long routerID) {
790 return NatConstants.NAPT_FLOWID_PREFIX + dpnId + NatConstants.FLOWID_SEPARATOR + tableId + NatConstants
791 .FLOWID_SEPARATOR + routerID;
794 public static String getFlowRefSnat(BigInteger dpnId, short tableId, String routerID) {
795 return NatConstants.SNAT_FLOWID_PREFIX + dpnId + NatConstants.FLOWID_SEPARATOR + tableId + NatConstants
796 .FLOWID_SEPARATOR + routerID;
799 private String getGroupIdKey(String routerName) {
800 return "snatmiss." + routerName;
803 protected long createGroupId(String groupIdKey) {
804 AllocateIdInput getIdInput = new AllocateIdInputBuilder()
805 .setPoolName(NatConstants.SNAT_IDPOOL_NAME).setIdKey(groupIdKey)
808 Future<RpcResult<AllocateIdOutput>> result = idManager.allocateId(getIdInput);
809 RpcResult<AllocateIdOutput> rpcResult = result.get();
810 return rpcResult.getResult().getIdValue();
811 } catch (NullPointerException | InterruptedException | ExecutionException e) {
812 LOG.error("Exception While allocating id for group: {}", groupIdKey, e);
817 protected void createGroupIdPool() {
818 CreateIdPoolInput createPool = new CreateIdPoolInputBuilder()
819 .setPoolName(NatConstants.SNAT_IDPOOL_NAME)
820 .setLow(NatConstants.SNAT_ID_LOW_VALUE)
821 .setHigh(NatConstants.SNAT_ID_HIGH_VALUE)
824 Future<RpcResult<Void>> result = idManager.createIdPool(createPool);
825 if (result != null && result.get().isSuccessful()) {
826 LOG.debug("createGroupIdPool : GroupIdPool created successfully");
828 LOG.error("createGroupIdPool : Unable to create GroupIdPool");
830 } catch (InterruptedException | ExecutionException e) {
831 LOG.error("createGroupIdPool : Failed to create PortPool for NAPT Service", e);
835 protected void handleSwitches(BigInteger dpnId, String routerName, long routerId, BigInteger primarySwitchId) {
836 LOG.debug("handleSwitches : Installing SNAT miss entry in switch {}", dpnId);
837 List<ActionInfo> listActionInfoPrimary = new ArrayList<>();
838 String ifNamePrimary = getTunnelInterfaceName(dpnId, primarySwitchId);
839 List<BucketInfo> listBucketInfo = new ArrayList<>();
841 if (ifNamePrimary != null) {
842 LOG.debug("handleSwitches : On Non- Napt switch , Primary Tunnel interface is {}", ifNamePrimary);
843 listActionInfoPrimary = NatUtil.getEgressActionsForInterface(interfaceManager, ifNamePrimary, routerId);
844 if (listActionInfoPrimary.isEmpty()) {
845 LOG.error("handleSwitches : Unable to retrieve output actions on Non-NAPT switch {} for router {}"
846 + " towards Napt-switch {} via tunnel interface {}", dpnId, routerName, primarySwitchId,
850 LOG.error("handleSwitches : Unable to obtain primary tunnel interface to Napt-Switch {} from "
851 + "Non-Napt switch {} for router {}", primarySwitchId, dpnId, routerName);
853 BucketInfo bucketPrimary = new BucketInfo(listActionInfoPrimary);
855 listBucketInfo.add(0, bucketPrimary);
856 installSnatMissEntry(dpnId, listBucketInfo, routerName, routerId);
859 List<BucketInfo> getBucketInfoForNonNaptSwitches(BigInteger nonNaptSwitchId,
860 BigInteger primarySwitchId, String routerName, long routerId) {
861 List<ActionInfo> listActionInfoPrimary = new ArrayList<>();
862 String ifNamePrimary = getTunnelInterfaceName(nonNaptSwitchId, primarySwitchId);
863 List<BucketInfo> listBucketInfo = new ArrayList<>();
865 if (ifNamePrimary != null) {
866 LOG.debug("getBucketInfoForNonNaptSwitches : On Non- Napt switch , Primary Tunnel interface is {}",
868 listActionInfoPrimary = NatUtil.getEgressActionsForInterface(interfaceManager, ifNamePrimary, routerId);
869 if (listActionInfoPrimary.isEmpty()) {
870 LOG.error("getBucketInfoForNonNaptSwitches : Unable to retrieve output actions on Non-NAPT switch {} "
871 + "for router {} towards Napt-switch {} via tunnel interface {}",
872 nonNaptSwitchId, routerName, primarySwitchId, ifNamePrimary);
875 LOG.error("getBucketInfoForNonNaptSwitches : Unable to obtain primary tunnel interface to Napt-Switch {} "
876 + "from Non-Napt switch {} for router {}", primarySwitchId, nonNaptSwitchId, routerName);
878 BucketInfo bucketPrimary = new BucketInfo(listActionInfoPrimary);
880 listBucketInfo.add(0, bucketPrimary);
881 return listBucketInfo;
884 protected void handlePrimaryNaptSwitch(BigInteger dpnId, String routerName, long routerId,
885 WriteTransaction writeFlowInvTx) {
887 * Primary NAPT Switch – bucket Should always point back to its own Outbound Table
890 LOG.debug("handlePrimaryNaptSwitch : Installing SNAT miss entry in Primary NAPT switch {} ", dpnId);
893 List<BucketInfo> listBucketInfo = new ArrayList<>();
894 List<ActionInfo> listActionInfoPrimary = new ArrayList<>();
895 listActionInfoPrimary.add(new ActionNxResubmit(NatConstants.TERMINATING_SERVICE_TABLE));
896 BucketInfo bucketPrimary = new BucketInfo(listActionInfoPrimary);
897 listBucketInfo.add(0, bucketPrimary);
900 installSnatMissEntryForPrimrySwch(dpnId, routerName, routerId, writeFlowInvTx);
901 installTerminatingServiceTblEntry(dpnId, routerName, routerId, writeFlowInvTx);
902 //Install the NAPT PFIB TABLE which forwards the outgoing packet to FIB Table matching on the router ID.
903 installNaptPfibEntry(dpnId, routerId, writeFlowInvTx);
904 Long vpnId = NatUtil.getNetworkVpnIdFromRouterId(dataBroker, routerId);
905 installNaptPfibEntriesForExternalSubnets(routerName, dpnId, writeFlowInvTx);
906 //Install the NAPT PFIB TABLE which forwards the outgoing packet to FIB Table matching on the VPN ID.
907 if (vpnId != null && vpnId != NatConstants.INVALID_ID) {
908 installNaptPfibEntry(dpnId, vpnId, writeFlowInvTx);
912 List<BucketInfo> getBucketInfoForPrimaryNaptSwitch() {
913 List<BucketInfo> listBucketInfo = new ArrayList<>();
914 List<ActionInfo> listActionInfoPrimary = new ArrayList<>();
915 listActionInfoPrimary.add(new ActionNxResubmit(NwConstants.INTERNAL_TUNNEL_TABLE));
916 BucketInfo bucketPrimary = new BucketInfo(listActionInfoPrimary);
917 listBucketInfo.add(0, bucketPrimary);
918 return listBucketInfo;
921 public void installNaptPfibEntry(BigInteger dpnId, long segmentId, WriteTransaction writeFlowInvTx) {
922 LOG.debug("installNaptPfibEntry : called for dpnId {} and segmentId {} ", dpnId, segmentId);
923 FlowEntity naptPfibFlowEntity = buildNaptPfibFlowEntity(dpnId, segmentId);
924 mdsalManager.addFlowToTx(naptPfibFlowEntity, writeFlowInvTx);
927 public FlowEntity buildNaptPfibFlowEntity(BigInteger dpId, long segmentId) {
929 LOG.debug("buildNaptPfibFlowEntity : called for dpId {}, segmentId {}", dpId, segmentId);
930 List<MatchInfo> matches = new ArrayList<>();
931 matches.add(MatchEthernetType.IPV4);
932 matches.add(new MatchMetadata(MetaDataUtil.getVpnIdMetadata(segmentId), MetaDataUtil.METADATA_MASK_VRFID));
934 ArrayList<ActionInfo> listActionInfo = new ArrayList<>();
935 ArrayList<InstructionInfo> instructionInfo = new ArrayList<>();
936 listActionInfo.add(new ActionNxLoadInPort(BigInteger.ZERO));
937 listActionInfo.add(new ActionNxResubmit(NwConstants.L3_FIB_TABLE));
938 instructionInfo.add(new InstructionApplyActions(listActionInfo));
940 String flowRef = getFlowRefTs(dpId, NwConstants.NAPT_PFIB_TABLE, segmentId);
941 FlowEntity flowEntity = MDSALUtil.buildFlowEntity(dpId, NwConstants.NAPT_PFIB_TABLE, flowRef,
942 NatConstants.DEFAULT_PSNAT_FLOW_PRIORITY, flowRef, 0, 0,
943 NwConstants.COOKIE_SNAT_TABLE, matches, instructionInfo);
944 LOG.debug("buildNaptPfibFlowEntity : Returning NaptPFib Flow Entity {}", flowEntity);
948 public void handleSnatReverseTraffic(BigInteger dpnId, Routers router, long routerId, String routerName,
949 String externalIp, WriteTransaction writeFlowInvTx) {
950 LOG.debug("handleSnatReverseTraffic : entry for DPN ID {}, routerId {}, externalIp: {}",
951 dpnId, routerId, externalIp);
952 Uuid networkId = router.getNetworkId();
953 if (networkId == null) {
954 LOG.error("handleSnatReverseTraffic : networkId is null for the router ID {}", routerId);
957 final String vpnName = NatUtil.getAssociatedVPN(dataBroker, networkId);
958 if (vpnName == null) {
959 LOG.error("handleSnatReverseTraffic : No VPN associated with ext nw {} to handle add external ip "
960 + "configuration {} in router {}", networkId, externalIp, routerId);
963 advToBgpAndInstallFibAndTsFlows(dpnId, NwConstants.INBOUND_NAPT_TABLE, vpnName, routerId, routerName,
964 externalIp, networkId, router, writeFlowInvTx);
965 LOG.debug("handleSnatReverseTraffic : exit for DPN ID {}, routerId {}, externalIp : {}",
966 dpnId, routerId, externalIp);
969 public void advToBgpAndInstallFibAndTsFlows(final BigInteger dpnId, final short tableId, final String vpnName,
970 final long routerId, final String routerName, final String externalIp,
971 final Uuid extNetworkId, final Routers router,
972 final WriteTransaction writeFlowInvTx) {
973 LOG.debug("advToBgpAndInstallFibAndTsFlows : entry for DPN ID {}, tableId {}, vpnname {} "
974 + "and externalIp {}", dpnId, tableId, vpnName, externalIp);
975 String nextHopIp = NatUtil.getEndpointIpAddressForDPN(dataBroker, dpnId);
976 String rd = NatUtil.getVpnRd(dataBroker, vpnName);
977 if (rd == null || rd.isEmpty()) {
978 LOG.error("advToBgpAndInstallFibAndTsFlows : Unable to get RD for VPN Name {}", vpnName);
981 ProviderTypes extNwProvType = NatEvpnUtil.getExtNwProvTypeFromRouterName(dataBroker, routerName, extNetworkId);
982 if (extNwProvType == null) {
983 LOG.error("advToBgpAndInstallFibAndTsFlows : External Network Provider Type missing");
986 if (extNwProvType == ProviderTypes.VXLAN) {
987 WriteTransaction writeTx = dataBroker.newWriteOnlyTransaction();
988 evpnSnatFlowProgrammer.evpnAdvToBgpAndInstallFibAndTsFlows(dpnId, tableId, externalIp, vpnName, rd,
989 nextHopIp, writeTx, routerId, routerName, writeFlowInvTx);
992 //Generate VPN label for the external IP
993 GenerateVpnLabelInput labelInput = new GenerateVpnLabelInputBuilder().setVpnName(vpnName)
994 .setIpPrefix(externalIp).build();
995 Future<RpcResult<GenerateVpnLabelOutput>> labelFuture = vpnService.generateVpnLabel(labelInput);
997 //On successful generation of the VPN label, advertise the route to the BGP and install the FIB routes.
998 ListenableFuture<RpcResult<Void>> future =
999 Futures.transformAsync(JdkFutureAdapters.listenInPoolThread(labelFuture),
1000 (AsyncFunction<RpcResult<GenerateVpnLabelOutput>, RpcResult<Void>>) result -> {
1001 if (result.isSuccessful()) {
1002 LOG.debug("advToBgpAndInstallFibAndTsFlows : inside apply with result success");
1003 GenerateVpnLabelOutput output = result.getResult();
1004 final long label = output.getLabel();
1006 int externalIpInDsFlag = 0;
1007 //Get IPMaps from the DB for the router ID
1008 List<IpMap> dbIpMaps = NaptManager.getIpMapList(dataBroker, routerId);
1009 if (dbIpMaps != null) {
1010 for (IpMap dbIpMap : dbIpMaps) {
1011 String dbExternalIp = dbIpMap.getExternalIp();
1012 //Select the IPMap, whose external IP is the IP for which FIB is installed
1013 if (dbExternalIp.contains(externalIp)) {
1014 String dbInternalIp = dbIpMap.getInternalIp();
1015 IpMapKey dbIpMapKey = dbIpMap.getKey();
1016 LOG.debug("advToBgpAndInstallFibAndTsFlows : Setting label {} for internalIp {} "
1017 + "and externalIp {}", label, dbInternalIp, externalIp);
1018 IpMap newIpm = new IpMapBuilder().setKey(dbIpMapKey).setInternalIp(dbInternalIp)
1019 .setExternalIp(dbExternalIp).setLabel(label).build();
1020 MDSALUtil.syncWrite(dataBroker, LogicalDatastoreType.OPERATIONAL,
1021 naptManager.getIpMapIdentifier(routerId, dbInternalIp), newIpm);
1022 externalIpInDsFlag++;
1025 if (externalIpInDsFlag <= 0) {
1026 LOG.debug("advToBgpAndInstallFibAndTsFlows : External Ip {} not found in DS, "
1027 + "Failed to update label {} for routerId {} in DS",
1028 externalIp, label, routerId);
1029 String errMsg = String.format("Failed to update label %s due to external Ip %s not"
1030 + " found in DS for router %s", label, externalIp, routerId);
1031 return Futures.immediateFailedFuture(new Exception(errMsg));
1034 LOG.error("advToBgpAndInstallFibAndTsFlows : Failed to write label {} for externalIp {} for"
1035 + " routerId {} in DS", label, externalIp, routerId);
1039 if (NatUtil.isOpenStackVniSemanticsEnforcedForGreAndVxlan(elanManager, extNwProvType)) {
1040 l3vni = NatOverVxlanUtil.getInternetVpnVni(idManager, vpnName, l3vni).longValue();
1042 Routers extRouter = router != null ? router :
1043 NatUtil.getRoutersFromConfigDS(dataBroker, routerName);
1044 Uuid externalSubnetId = NatUtil.getExternalSubnetForRouterExternalIp(externalIp,
1046 NatUtil.addPrefixToBGP(dataBroker, bgpManager, fibManager, vpnName, rd, externalSubnetId,
1047 externalIp, nextHopIp, extRouter.getNetworkId().getValue(), null, label, l3vni,
1048 RouteOrigin.STATIC, dpnId);
1050 //Install custom FIB routes
1051 List<Instruction> tunnelTableCustomInstructions = new ArrayList<>();
1052 tunnelTableCustomInstructions.add(new InstructionGotoTable(tableId).buildInstruction(0));
1053 makeTunnelTableEntry(dpnId, label, l3vni, tunnelTableCustomInstructions, writeFlowInvTx,
1055 makeLFibTableEntry(dpnId, label, tableId, writeFlowInvTx);
1057 //Install custom FIB routes - FIB table.
1058 List<Instruction> fibTableCustomInstructions = createFibTableCustomInstructions(tableId,
1059 routerName, externalIp);
1060 if (NatUtil.isOpenStackVniSemanticsEnforcedForGreAndVxlan(elanManager, extNwProvType)) {
1061 //Install the flow table 25->44 If there is no FIP Match on table 25 (PDNAT_TABLE)
1062 NatUtil.makePreDnatToSnatTableEntry(mdsalManager, dpnId,
1063 NwConstants.INBOUND_NAPT_TABLE,writeFlowInvTx);
1065 String fibExternalIp = NatUtil.validateAndAddNetworkMask(externalIp);
1066 Optional<Subnets> externalSubnet = NatUtil.getOptionalExternalSubnets(dataBroker,
1068 String externalVpn = vpnName;
1069 if (externalSubnet.isPresent()) {
1070 externalVpn = externalSubnetId.getValue();
1072 CreateFibEntryInput input = new CreateFibEntryInputBuilder()
1073 .setVpnName(externalVpn)
1074 .setSourceDpid(dpnId).setIpAddress(fibExternalIp).setServiceId(label)
1075 .setIpAddressSource(CreateFibEntryInput.IpAddressSource.ExternalFixedIP)
1076 .setInstruction(fibTableCustomInstructions).build();
1077 Future<RpcResult<Void>> future1 = fibService.createFibEntry(input);
1078 return JdkFutureAdapters.listenInPoolThread(future1);
1080 LOG.error("advToBgpAndInstallFibAndTsFlows : inside apply with result failed");
1081 String errMsg = String.format("Could not retrieve the label for prefix %s in VPN %s, %s",
1082 externalIp, vpnName, result.getErrors());
1083 return Futures.immediateFailedFuture(new RuntimeException(errMsg));
1085 }, MoreExecutors.directExecutor());
1087 Futures.addCallback(future, new FutureCallback<RpcResult<Void>>() {
1090 public void onFailure(@Nonnull Throwable error) {
1091 LOG.error("advToBgpAndInstallFibAndTsFlows : Error in generate label or fib install process", error);
1095 public void onSuccess(@Nonnull RpcResult<Void> result) {
1096 if (result.isSuccessful()) {
1097 LOG.info("advToBgpAndInstallFibAndTsFlows : Successfully installed custom FIB routes for prefix {}",
1100 LOG.error("advToBgpAndInstallFibAndTsFlows : Error in rpc call to create custom Fib entries "
1101 + "for prefix {} in DPN {}, {}", externalIp, dpnId, result.getErrors());
1104 }, MoreExecutors.directExecutor());
1107 private List<Instruction> createFibTableCustomInstructions(short tableId, String routerName,
1108 String externalIp) {
1109 List<Instruction> fibTableCustomInstructions = new ArrayList<>();
1110 Routers router = NatUtil.getRoutersFromConfigDS(dataBroker, routerName);
1111 long externalSubnetVpnId = NatUtil.getExternalSubnetVpnIdForRouterExternalIp(dataBroker,
1112 externalIp, router);
1113 int instructionIndex = 0;
1114 if (externalSubnetVpnId != NatConstants.INVALID_ID) {
1115 BigInteger subnetIdMetaData = MetaDataUtil.getVpnIdMetadata(externalSubnetVpnId);
1116 fibTableCustomInstructions.add(new InstructionWriteMetadata(subnetIdMetaData,
1117 MetaDataUtil.METADATA_MASK_VRFID).buildInstruction(instructionIndex));
1121 fibTableCustomInstructions.add(new InstructionGotoTable(tableId).buildInstruction(instructionIndex));
1122 return fibTableCustomInstructions;
1125 private void makeLFibTableEntry(BigInteger dpId, long serviceId, short tableId, WriteTransaction writeFlowInvTx) {
1126 List<MatchInfo> matches = new ArrayList<>();
1127 matches.add(MatchEthernetType.MPLS_UNICAST);
1128 matches.add(new MatchMplsLabel(serviceId));
1130 List<Instruction> instructions = new ArrayList<>();
1131 List<ActionInfo> actionsInfos = new ArrayList<>();
1132 actionsInfos.add(new ActionPopMpls());
1133 Instruction writeInstruction = new InstructionApplyActions(actionsInfos).buildInstruction(0);
1134 instructions.add(writeInstruction);
1135 instructions.add(new InstructionGotoTable(tableId).buildInstruction(1));
1137 // Install the flow entry in L3_LFIB_TABLE
1138 String flowRef = getFlowRef(dpId, NwConstants.L3_LFIB_TABLE, serviceId, "");
1140 Flow flowEntity = MDSALUtil.buildFlowNew(NwConstants.L3_LFIB_TABLE, flowRef,
1142 COOKIE_VM_LFIB_TABLE, matches, instructions);
1144 mdsalManager.addFlowToTx(dpId, flowEntity, writeFlowInvTx);
1146 LOG.debug("makeLFibTableEntry : LFIB Entry for dpID {} : label : {} modified successfully", dpId, serviceId);
1149 private void makeTunnelTableEntry(BigInteger dpnId, long serviceId, long l3Vni,
1150 List<Instruction> customInstructions, WriteTransaction writeFlowInvTx, ProviderTypes extNwProvType) {
1151 List<MatchInfo> mkMatches = new ArrayList<>();
1153 LOG.debug("makeTunnelTableEntry : DpnId = {} and serviceId = {} and actions = {}",
1154 dpnId, serviceId, customInstructions);
1156 if (NatUtil.isOpenStackVniSemanticsEnforcedForGreAndVxlan(elanManager, extNwProvType)) {
1157 mkMatches.add(new MatchTunnelId(BigInteger.valueOf(l3Vni)));
1159 mkMatches.add(new MatchTunnelId(BigInteger.valueOf(serviceId)));
1162 Flow terminatingServiceTableFlowEntity = MDSALUtil.buildFlowNew(NwConstants.INTERNAL_TUNNEL_TABLE,
1163 getFlowRef(dpnId, NwConstants.INTERNAL_TUNNEL_TABLE, serviceId, ""), 5,
1164 String.format("%s:%d", "TST Flow Entry ", serviceId),
1165 0, 0, COOKIE_TUNNEL.add(BigInteger.valueOf(serviceId)), mkMatches, customInstructions);
1167 mdsalManager.addFlowToTx(dpnId, terminatingServiceTableFlowEntity, writeFlowInvTx);
1170 protected InstanceIdentifier<RouterIds> getRoutersIdentifier(long routerId) {
1171 InstanceIdentifier<RouterIds> id = InstanceIdentifier.builder(
1172 RouterIdName.class).child(RouterIds.class, new RouterIdsKey(routerId)).build();
1176 private String getFlowRef(BigInteger dpnId, short tableId, long id, String ipAddress) {
1177 return NatConstants.SNAT_FLOWID_PREFIX + dpnId + NwConstants.FLOWID_SEPARATOR + tableId + NwConstants
1178 .FLOWID_SEPARATOR + id + NwConstants.FLOWID_SEPARATOR + ipAddress;
1182 protected void update(InstanceIdentifier<Routers> identifier, Routers original, Routers update) {
1183 String routerName = original.getRouterName();
1184 Long routerId = NatUtil.getVpnId(dataBroker, routerName);
1185 if (routerId == NatConstants.INVALID_ID) {
1186 LOG.error("update : external router event - Invalid routerId for routerName {}", routerName);
1189 // Check if its update on SNAT flag
1190 boolean originalSNATEnabled = original.isEnableSnat();
1191 boolean updatedSNATEnabled = update.isEnableSnat();
1192 LOG.debug("update :called with originalFlag and updatedFlag for SNAT enabled "
1193 + "as {} and {}", originalSNATEnabled, updatedSNATEnabled);
1194 if (natMode == NatMode.Conntrack && !upgradeState.isUpgradeInProgress()) {
1195 if (originalSNATEnabled != updatedSNATEnabled) {
1196 BigInteger primarySwitchId;
1197 if (originalSNATEnabled) {
1198 //SNAT disabled for the router
1199 centralizedSwitchScheduler.releaseCentralizedSwitch(update);
1201 centralizedSwitchScheduler.scheduleCentralizedSwitch(update);
1203 } else if (updatedSNATEnabled) {
1204 centralizedSwitchScheduler.updateCentralizedSwitch(original,update);
1206 List<ExternalIps> originalExternalIps = original.getExternalIps();
1207 List<ExternalIps> updateExternalIps = update.getExternalIps();
1208 if (!Objects.equals(originalExternalIps, updateExternalIps)) {
1209 if (originalExternalIps == null || originalExternalIps.isEmpty()) {
1210 centralizedSwitchScheduler.scheduleCentralizedSwitch(update);
1214 /* Get Primary Napt Switch for existing router from "router-to-napt-switch" DS.
1215 * if dpnId value is null or zero then go for electing new Napt switch for existing router.
1217 long bgpVpnId = NatConstants.INVALID_ID;
1218 Uuid bgpVpnUuid = NatUtil.getVpnForRouter(dataBroker, routerName);
1219 if (bgpVpnUuid != null) {
1220 bgpVpnId = NatUtil.getVpnId(dataBroker, bgpVpnUuid.getValue());
1222 BigInteger dpnId = getPrimaryNaptSwitch(routerName);
1223 if (dpnId == null || dpnId.equals(BigInteger.ZERO)) {
1224 // Router has no interface attached
1227 final long finalBgpVpnId = bgpVpnId;
1228 coordinator.enqueueJob(NatConstants.NAT_DJC_PREFIX + update.getKey(), () -> {
1229 WriteTransaction writeFlowInvTx = dataBroker.newWriteOnlyTransaction();
1230 WriteTransaction removeFlowInvTx = dataBroker.newWriteOnlyTransaction();
1231 Uuid networkId = original.getNetworkId();
1232 if (originalSNATEnabled != updatedSNATEnabled) {
1233 if (originalSNATEnabled) {
1234 //SNAT disabled for the router
1235 Uuid networkUuid = original.getNetworkId();
1236 LOG.info("update : SNAT disabled for Router {}", routerName);
1237 Collection<String> externalIps = NatUtil.getExternalIpsForRouter(dataBroker, routerId);
1238 handleDisableSnat(original, networkUuid, externalIps, false, null, dpnId, routerId,
1241 LOG.info("update : SNAT enabled for Router {}", original.getRouterName());
1242 handleEnableSnat(original, routerId, dpnId, finalBgpVpnId, removeFlowInvTx);
1245 if (!Objects.equals(original.getExtGwMacAddress(), update.getExtGwMacAddress())) {
1246 NatUtil.installRouterGwFlows(dataBroker, vpnManager, original, dpnId, NwConstants.DEL_FLOW);
1247 NatUtil.installRouterGwFlows(dataBroker, vpnManager, update, dpnId, NwConstants.ADD_FLOW);
1250 //Check if the Update is on External IPs
1251 LOG.debug("update : Checking if this is update on External IPs");
1252 List<String> originalExternalIps = NatUtil.getIpsListFromExternalIps(original.getExternalIps());
1253 List<String> updatedExternalIps = NatUtil.getIpsListFromExternalIps(update.getExternalIps());
1255 //Check if the External IPs are added during the update.
1256 Set<String> addedExternalIps = new HashSet<>(updatedExternalIps);
1257 addedExternalIps.removeAll(originalExternalIps);
1258 if (addedExternalIps.size() != 0) {
1259 LOG.debug("update : Start processing of the External IPs addition during the update operation");
1260 vpnManager.addArpResponderFlowsToExternalNetworkIps(routerName, addedExternalIps,
1261 update.getExtGwMacAddress(), dpnId,
1262 update.getNetworkId(), null);
1264 for (String addedExternalIp : addedExternalIps) {
1266 1) Do nothing in the IntExtIp model.
1267 2) Initialise the count of the added external IP to 0 in the ExternalCounter model.
1269 String[] externalIpParts = NatUtil.getExternalIpAndPrefix(addedExternalIp);
1270 String externalIp = externalIpParts[0];
1271 String externalIpPrefix = externalIpParts[1];
1272 String externalpStr = externalIp + "/" + externalIpPrefix;
1273 LOG.debug("update : Initialise the count mapping of the external IP {} for the "
1274 + "router ID {} in the ExternalIpsCounter model.",
1275 externalpStr, routerId);
1276 naptManager.initialiseNewExternalIpCounter(routerId, externalpStr);
1278 LOG.debug("update : End processing of the External IPs addition during the update operation");
1281 //Check if the External IPs are removed during the update.
1282 Set<String> removedExternalIps = new HashSet<>(originalExternalIps);
1283 removedExternalIps.removeAll(updatedExternalIps);
1284 if (removedExternalIps.size() > 0) {
1285 LOG.debug("update : Start processing of the External IPs removal during the update operation");
1286 vpnManager.removeArpResponderFlowsToExternalNetworkIps(routerName,
1287 removedExternalIps, original.getExtGwMacAddress(),
1290 for (String removedExternalIp : removedExternalIps) {
1292 1) Remove the mappings in the IntExt IP model which has external IP.
1293 2) Remove the external IP in the ExternalCounter model.
1294 3) For the corresponding subnet IDs whose external IP mapping was removed, allocate one of the
1295 least loaded external IP.
1296 Store the subnet IP and the reallocated external IP mapping in the IntExtIp model.
1297 4) Increase the count of the allocated external IP by one.
1298 5) Advertise to the BGP if external IP is allocated for the first time for the router
1299 i.e. the route for the external IP is absent.
1300 6) Remove the NAPT translation entries from Inbound and Outbound NAPT tables for
1301 the removed external IPs and also from the model.
1302 7) Advertise to the BGP for removing the route for the removed external IPs.
1305 String[] externalIpParts = NatUtil.getExternalIpAndPrefix(removedExternalIp);
1306 String externalIp = externalIpParts[0];
1307 String externalIpPrefix = externalIpParts[1];
1308 String externalIpAddrStr = externalIp + "/" + externalIpPrefix;
1310 LOG.debug("update : Clear the routes from the BGP and remove the FIB and TS "
1311 + "entries for removed external IP {}", externalIpAddrStr);
1312 Uuid vpnUuId = NatUtil.getVpnIdfromNetworkId(dataBroker, networkId);
1313 String vpnName = "";
1314 if (vpnUuId != null) {
1315 vpnName = vpnUuId.getValue();
1317 clrRtsFromBgpAndDelFibTs(dpnId, routerId, externalIpAddrStr, vpnName, networkId,
1318 update.getExtGwMacAddress(), removeFlowInvTx);
1320 LOG.debug("update : Remove the mappings in the IntExtIP model which has external IP.");
1321 //Get the internal IPs which are associated to the removed external IPs
1322 List<IpMap> ipMaps = naptManager.getIpMapList(dataBroker, routerId);
1323 List<String> removedInternalIps = new ArrayList<>();
1324 for (IpMap ipMap : ipMaps) {
1325 if (ipMap.getExternalIp().equals(externalIpAddrStr)) {
1326 removedInternalIps.add(ipMap.getInternalIp());
1330 LOG.debug("update : Remove the mappings of the internal IPs from the IntExtIP model.");
1331 for (String removedInternalIp : removedInternalIps) {
1332 LOG.debug("update : Remove the IP mapping of the internal IP {} for the "
1333 + "router ID {} from the IntExtIP model",
1334 removedInternalIp, routerId);
1335 naptManager.removeFromIpMapDS(routerId, removedInternalIp);
1338 LOG.debug("update : Remove the count mapping of the external IP {} for the "
1339 + "router ID {} from the ExternalIpsCounter model.",
1340 externalIpAddrStr, routerId);
1341 naptManager.removeExternalIpCounter(routerId, externalIpAddrStr);
1343 LOG.debug("update : Allocate the least loaded external IPs to the subnets "
1344 + "whose external IPs were removed.");
1345 for (String removedInternalIp : removedInternalIps) {
1346 allocateExternalIp(dpnId, update, routerId, routerName, networkId, removedInternalIp,
1350 LOG.debug("update : Remove the NAPT translation entries from "
1351 + "Inbound and Outbound NAPT tables for the removed external IPs.");
1352 //Get the internalIP and internal Port which were associated to the removed external IP.
1353 List<Integer> externalPorts = new ArrayList<>();
1354 Map<ProtocolTypes, List<String>> protoTypesIntIpPortsMap = new HashMap<>();
1355 InstanceIdentifier<IpPortMapping> ipPortMappingId = InstanceIdentifier
1356 .builder(IntextIpPortMap.class)
1357 .child(IpPortMapping.class, new IpPortMappingKey(routerId)).build();
1358 Optional<IpPortMapping> ipPortMapping =
1359 MDSALUtil.read(dataBroker, LogicalDatastoreType.CONFIGURATION, ipPortMappingId);
1360 if (ipPortMapping.isPresent()) {
1361 List<IntextIpProtocolType> intextIpProtocolTypes = ipPortMapping.get()
1362 .getIntextIpProtocolType();
1363 for (IntextIpProtocolType intextIpProtocolType : intextIpProtocolTypes) {
1364 ProtocolTypes protoType = intextIpProtocolType.getProtocol();
1365 List<IpPortMap> ipPortMaps = intextIpProtocolType.getIpPortMap();
1366 for (IpPortMap ipPortMap : ipPortMaps) {
1367 IpPortExternal ipPortExternal = ipPortMap.getIpPortExternal();
1368 if (ipPortExternal.getIpAddress().equals(externalIp)) {
1369 externalPorts.add(ipPortExternal.getPortNum());
1370 List<String> removedInternalIpPorts = protoTypesIntIpPortsMap.get(protoType);
1371 if (removedInternalIpPorts != null) {
1372 removedInternalIpPorts.add(ipPortMap.getIpPortInternal());
1373 protoTypesIntIpPortsMap.put(protoType, removedInternalIpPorts);
1375 removedInternalIpPorts = new ArrayList<>();
1376 removedInternalIpPorts.add(ipPortMap.getIpPortInternal());
1377 protoTypesIntIpPortsMap.put(protoType, removedInternalIpPorts);
1384 //Remove the IP port map from the intext-ip-port-map model, which were containing
1385 // the removed external IP.
1386 Set<Map.Entry<ProtocolTypes, List<String>>> protoTypesIntIpPorts = protoTypesIntIpPortsMap
1388 Map<String, List<String>> internalIpPortMap = new HashMap<>();
1389 for (Map.Entry protoTypesIntIpPort : protoTypesIntIpPorts) {
1390 ProtocolTypes protocolType = (ProtocolTypes) protoTypesIntIpPort.getKey();
1391 List<String> removedInternalIpPorts = (List<String>) protoTypesIntIpPort.getValue();
1392 for (String removedInternalIpPort : removedInternalIpPorts) {
1393 // Remove the IP port map from the intext-ip-port-map model,
1394 // which were containing the removed external IP
1395 naptManager.removeFromIpPortMapDS(routerId, removedInternalIpPort, protocolType);
1396 //Remove the IP port incomint packer map.
1397 naptPacketInHandler.removeIncomingPacketMap(routerId + NatConstants.COLON_SEPARATOR
1398 + removedInternalIpPort);
1399 String[] removedInternalIpPortParts = removedInternalIpPort
1400 .split(NatConstants.COLON_SEPARATOR);
1401 if (removedInternalIpPortParts.length == 2) {
1402 String removedInternalIp = removedInternalIpPortParts[0];
1403 String removedInternalPort = removedInternalIpPortParts[1];
1404 List<String> removedInternalPortsList = internalIpPortMap.get(removedInternalPort);
1405 if (removedInternalPortsList != null) {
1406 removedInternalPortsList.add(removedInternalPort);
1407 internalIpPortMap.put(removedInternalIp, removedInternalPortsList);
1409 removedInternalPortsList = new ArrayList<>();
1410 removedInternalPortsList.add(removedInternalPort);
1411 internalIpPortMap.put(removedInternalIp, removedInternalPortsList);
1417 // Delete the entry from SnatIntIpPortMap DS
1418 Set<String> internalIps = internalIpPortMap.keySet();
1419 for (String internalIp : internalIps) {
1420 LOG.debug("update : Removing IpPort having the internal IP {} from the "
1421 + "model SnatIntIpPortMap", internalIp);
1422 naptManager.removeFromSnatIpPortDS(routerId, internalIp);
1425 naptManager.removeNaptPortPool(externalIp);
1427 LOG.debug("update : Remove the NAPT translation entries from Inbound NAPT tables for the "
1428 + "removed external IP {}", externalIp);
1429 for (Integer externalPort : externalPorts) {
1430 //Remove the NAPT translation entries from Inbound NAPT table
1431 naptEventHandler.removeNatFlows(dpnId, NwConstants.INBOUND_NAPT_TABLE,
1432 routerId, externalIp, externalPort);
1435 Set<Map.Entry<String, List<String>>> internalIpPorts = internalIpPortMap.entrySet();
1436 for (Map.Entry<String, List<String>> internalIpPort : internalIpPorts) {
1437 String internalIp = internalIpPort.getKey();
1438 LOG.debug("update : Remove the NAPT translation entries from Outbound NAPT tables for "
1439 + "the removed internal IP {}", internalIp);
1440 List<String> internalPorts = internalIpPort.getValue();
1441 for (String internalPort : internalPorts) {
1442 //Remove the NAPT translation entries from Outbound NAPT table
1443 naptPacketInHandler.removeIncomingPacketMap(routerId + NatConstants.COLON_SEPARATOR
1444 + internalIp + NatConstants.COLON_SEPARATOR + internalPort);
1445 naptEventHandler.removeNatFlows(dpnId, NwConstants.OUTBOUND_NAPT_TABLE,
1446 routerId, internalIp, Integer.parseInt(internalPort));
1450 LOG.debug("update : End processing of the External IPs removal during the update operation");
1453 //Check if its Update on subnets
1454 LOG.debug("update : Checking if this is update on subnets");
1455 List<Uuid> originalSubnetIds = original.getSubnetIds();
1456 List<Uuid> updatedSubnetIds = update.getSubnetIds();
1457 Set<Uuid> addedSubnetIds = new HashSet<>(updatedSubnetIds);
1458 addedSubnetIds.removeAll(originalSubnetIds);
1460 //Check if the Subnet IDs are added during the update.
1461 if (addedSubnetIds.size() != 0) {
1462 LOG.debug("update : Start processing of the Subnet IDs addition during the update operation");
1463 for (Uuid addedSubnetId : addedSubnetIds) {
1465 1) Select the least loaded external IP for the subnet and store the mapping of the
1466 subnet IP and the external IP in the IntExtIp model.
1467 2) Increase the count of the selected external IP by one.
1468 3) Advertise to the BGP if external IP is allocated for the first time for the
1469 router i.e. the route for the external IP is absent.
1471 String subnetIp = NatUtil.getSubnetIp(dataBroker, addedSubnetId);
1472 if (subnetIp != null) {
1473 allocateExternalIp(dpnId, update, routerId, routerName, networkId, subnetIp,
1477 LOG.debug("update : End processing of the Subnet IDs addition during the update operation");
1480 //Check if the Subnet IDs are removed during the update.
1481 Set<Uuid> removedSubnetIds = new HashSet<>(originalSubnetIds);
1482 removedSubnetIds.removeAll(updatedSubnetIds);
1483 List<ListenableFuture<Void>> futures = new ArrayList<>();
1484 if (removedSubnetIds.size() != 0) {
1485 LOG.debug("update : Start processing of the Subnet IDs removal during the update operation");
1486 for (Uuid removedSubnetId : removedSubnetIds) {
1487 String[] subnetAddr = NatUtil.getSubnetIpAndPrefix(dataBroker, removedSubnetId);
1488 if (subnetAddr != null) {
1490 1) Remove the subnet IP and the external IP in the IntExtIp map
1491 2) Decrease the count of the coresponding external IP by one.
1492 3) Advertise to the BGP for removing the routes of the corresponding external
1493 IP if its not allocated to any other internal IP.
1497 naptManager.getExternalIpAllocatedForSubnet(routerId, subnetAddr[0] + "/"
1499 if (externalIp == null) {
1500 LOG.error("update : No mapping found for router ID {} and internal IP {}",
1501 routerId, subnetAddr[0]);
1502 futures.add(NatUtil.waitForTransactionToComplete(writeFlowInvTx));
1503 futures.add(NatUtil.waitForTransactionToComplete(removeFlowInvTx));
1507 naptManager.updateCounter(routerId, externalIp, false);
1508 // Traverse entire model of external-ip counter whether external ip is not
1509 // used by any other internal ip in any router
1510 if (!isExternalIpAllocated(externalIp)) {
1511 LOG.debug("update : external ip is not allocated to any other "
1512 + "internal IP so proceeding to remove routes");
1513 clrRtsFromBgpAndDelFibTs(dpnId, routerId, networkId, Collections.singleton(externalIp),
1514 null, update.getExtGwMacAddress(), removeFlowInvTx);
1515 LOG.debug("update : Successfully removed fib entries in switch {} for "
1516 + "router {} with networkId {} and externalIp {}",
1517 dpnId, routerId, networkId, externalIp);
1520 LOG.debug("update : Remove the IP mapping for the router ID {} and "
1521 + "internal IP {} external IP {}", routerId, subnetAddr[0], externalIp);
1522 naptManager.removeIntExtIpMapDS(routerId, subnetAddr[0] + "/" + subnetAddr[1]);
1525 LOG.debug("update : End processing of the Subnet IDs removal during the update operation");
1527 futures.add(NatUtil.waitForTransactionToComplete(writeFlowInvTx));
1528 futures.add(NatUtil.waitForTransactionToComplete(removeFlowInvTx));
1530 }, NatConstants.NAT_DJC_MAX_RETRIES);
1531 } //end of controller based SNAT
1534 private boolean isExternalIpAllocated(String externalIp) {
1535 InstanceIdentifier<ExternalIpsCounter> id = InstanceIdentifier.builder(ExternalIpsCounter.class).build();
1536 Optional<ExternalIpsCounter> externalCountersData =
1537 MDSALUtil.read(dataBroker, LogicalDatastoreType.OPERATIONAL, id);
1538 if (externalCountersData.isPresent()) {
1539 ExternalIpsCounter externalIpsCounters = externalCountersData.get();
1540 List<ExternalCounters> externalCounters = externalIpsCounters.getExternalCounters();
1541 for (ExternalCounters ext : externalCounters) {
1542 for (ExternalIpCounter externalIpCount : ext.getExternalIpCounter()) {
1543 if (externalIpCount.getExternalIp().equals(externalIp)) {
1544 if (externalIpCount.getCounter() != 0) {
1555 private void allocateExternalIp(BigInteger dpnId, Routers router, long routerId, String routerName,
1556 Uuid networkId, String subnetIp, WriteTransaction writeFlowInvTx) {
1557 String[] subnetIpParts = NatUtil.getSubnetIpAndPrefix(subnetIp);
1559 InetAddress address = InetAddress.getByName(subnetIpParts[0]);
1560 if (address instanceof Inet6Address) {
1561 // TODO: Revisit when IPv6 external connectivity support is added.
1562 LOG.warn("allocateExternalIp : Currently skipping ipv6 address {}.", address);
1565 } catch (UnknownHostException e) {
1566 LOG.error("allocateExternalIp : Invalid ip address {}", subnetIpParts[0], e);
1569 String leastLoadedExtIpAddr = NatUtil.getLeastLoadedExternalIp(dataBroker, routerId);
1570 if (leastLoadedExtIpAddr != null) {
1571 String[] externalIpParts = NatUtil.getExternalIpAndPrefix(leastLoadedExtIpAddr);
1572 String leastLoadedExtIp = externalIpParts[0];
1573 String leastLoadedExtIpPrefix = externalIpParts[1];
1574 IPAddress externalIpAddr = new IPAddress(leastLoadedExtIp, Integer.parseInt(leastLoadedExtIpPrefix));
1575 subnetIp = subnetIpParts[0];
1576 String subnetIpPrefix = subnetIpParts[1];
1577 IPAddress subnetIpAddr = new IPAddress(subnetIp, Integer.parseInt(subnetIpPrefix));
1578 LOG.debug("allocateExternalIp : Add the IP mapping for the router ID {} and internal "
1579 + "IP {} and prefix {} -> external IP {} and prefix {}",
1580 routerId, subnetIp, subnetIpPrefix, leastLoadedExtIp, leastLoadedExtIpPrefix);
1581 naptManager.registerMapping(routerId, subnetIpAddr, externalIpAddr);
1584 // Check if external IP is already assigned a route. (i.e. External IP is previously
1585 // allocated to any of the subnets)
1586 // If external IP is already assigned a route, (, do not re-advertise to the BGP
1587 String leastLoadedExtIpAddrStr = leastLoadedExtIp + "/" + leastLoadedExtIpPrefix;
1588 Long label = checkExternalIpLabel(routerId, leastLoadedExtIpAddrStr);
1589 if (label != null) {
1591 String internalIp = subnetIpParts[0] + "/" + subnetIpParts[1];
1592 IpMapKey ipMapKey = new IpMapKey(internalIp);
1593 LOG.debug("allocateExternalIp : Setting label {} for internalIp {} and externalIp {}",
1594 label, internalIp, leastLoadedExtIpAddrStr);
1595 IpMap newIpm = new IpMapBuilder().setKey(ipMapKey).setInternalIp(internalIp)
1596 .setExternalIp(leastLoadedExtIpAddrStr).setLabel(label).build();
1597 MDSALUtil.syncWrite(dataBroker, LogicalDatastoreType.OPERATIONAL,
1598 naptManager.getIpMapIdentifier(routerId, internalIp), newIpm);
1602 // Re-advertise to the BGP for the external IP, which is allocated to the subnet
1603 // for the first time and hence not having a route.
1604 //Get the VPN Name using the network ID
1605 final String vpnName = NatUtil.getAssociatedVPN(dataBroker, networkId);
1606 if (vpnName != null) {
1607 LOG.debug("allocateExternalIp : Retrieved vpnName {} for networkId {}", vpnName, networkId);
1608 if (dpnId == null || dpnId.equals(BigInteger.ZERO)) {
1609 LOG.debug("allocateExternalIp : Best effort for getting primary napt switch when router i/f are"
1610 + "added after gateway-set");
1611 dpnId = NatUtil.getPrimaryNaptfromRouterId(dataBroker, routerId);
1612 if (dpnId == null || dpnId.equals(BigInteger.ZERO)) {
1613 LOG.error("allocateExternalIp : dpnId is null or Zero for the router {}", routerName);
1617 advToBgpAndInstallFibAndTsFlows(dpnId, NwConstants.INBOUND_NAPT_TABLE, vpnName, routerId, routerName,
1618 leastLoadedExtIp + "/" + leastLoadedExtIpPrefix, networkId, router,
1624 protected Long checkExternalIpLabel(long routerId, String externalIp) {
1625 List<IpMap> ipMaps = naptManager.getIpMapList(dataBroker, routerId);
1626 for (IpMap ipMap : ipMaps) {
1627 if (ipMap.getExternalIp().equals(externalIp)) {
1628 if (ipMap.getLabel() != null) {
1629 return ipMap.getLabel();
1633 LOG.error("checkExternalIpLabel : no ipMaps found for routerID:{} and externalIP:{}", routerId, externalIp);
1638 protected void remove(InstanceIdentifier<Routers> identifier, Routers router) {
1639 LOG.trace("remove : Router delete method");
1642 ROUTER DELETE SCENARIO
1643 1) Get the router ID from the event.
1644 2) Build the cookie information from the router ID.
1645 3) Get the primary and secondary switch DPN IDs using the router ID from the model.
1646 4) Build the flow with the cookie value.
1647 5) Delete the flows which matches the cookie information from the NAPT outbound, inbound tables.
1648 6) Remove the flows from the other switches which points to the primary and secondary
1649 switches for the flows related the router ID.
1650 7) Get the list of external IP address maintained for the router ID.
1651 8) Use the NaptMananager removeMapping API to remove the list of IP addresses maintained.
1652 9) Withdraw the corresponding routes from the BGP.
1655 if (identifier == null || router == null) {
1656 LOG.error("remove : returning without processing since routers is null");
1660 String routerName = router.getRouterName();
1661 if (natMode == NatMode.Conntrack) {
1662 if (router.isEnableSnat()) {
1663 centralizedSwitchScheduler.releaseCentralizedSwitch(router);
1666 coordinator.enqueueJob(NatConstants.NAT_DJC_PREFIX + router.getKey(), () -> {
1667 LOG.info("remove : Removing default NAT route from FIB on all dpns part of router {} ", routerName);
1668 List<ListenableFuture<Void>> futures = new ArrayList<>();
1669 Long routerId = NatUtil.getVpnId(dataBroker, routerName);
1670 if (routerId == NatConstants.INVALID_ID) {
1671 LOG.error("remove : Remove external router event - Invalid routerId for routerName {}",
1675 long bgpVpnId = NatConstants.INVALID_ID;
1676 Uuid bgpVpnUuid = NatUtil.getVpnForRouter(dataBroker, routerName);
1677 if (bgpVpnUuid != null) {
1678 bgpVpnId = NatUtil.getVpnId(dataBroker, bgpVpnUuid.getValue());
1680 WriteTransaction removeFlowInvTx = dataBroker.newWriteOnlyTransaction();
1681 addOrDelDefFibRouteToSNAT(routerName, routerId, bgpVpnId, bgpVpnUuid, false, removeFlowInvTx);
1682 Uuid networkUuid = router.getNetworkId();
1684 BigInteger primarySwitchId = NatUtil.getPrimaryNaptfromRouterName(dataBroker, routerName);
1685 if (primarySwitchId == null || primarySwitchId.equals(BigInteger.ZERO)) {
1686 // No NAPT switch for external router, probably because the router is not attached to any
1687 // internal networks
1688 LOG.debug("No NAPT switch for router {}, check if router is attached to any internal network",
1692 NatUtil.installRouterGwFlows(dataBroker, vpnManager, router, primarySwitchId,
1693 NwConstants.DEL_FLOW);
1694 Collection<String> externalIps = NatUtil.getExternalIpsForRouter(dataBroker, routerId);
1695 handleDisableSnat(router, networkUuid, externalIps, true, null, primarySwitchId,
1696 routerId, removeFlowInvTx);
1698 NatOverVxlanUtil.releaseVNI(routerName, idManager);
1699 futures.add(NatUtil.waitForTransactionToComplete(removeFlowInvTx));
1701 }, NatConstants.NAT_DJC_MAX_RETRIES);
1706 // TODO Clean up the exception handling
1707 @SuppressWarnings("checkstyle:IllegalCatch")
1708 public void handleDisableSnat(Routers router, Uuid networkUuid, @Nonnull Collection<String> externalIps,
1709 boolean routerFlag, String vpnName, BigInteger naptSwitchDpnId,
1710 long routerId, WriteTransaction removeFlowInvTx) {
1711 LOG.info("handleDisableSnat : Entry");
1712 String routerName = router.getRouterName();
1715 removeNaptSwitch(routerName);
1717 updateNaptSwitch(routerName, BigInteger.ZERO);
1720 LOG.debug("handleDisableSnat : Remove the ExternalCounter model for the router ID {}", routerId);
1721 naptManager.removeExternalCounter(routerId);
1723 LOG.debug("handleDisableSnat : got primarySwitch as dpnId {}", naptSwitchDpnId);
1724 if (naptSwitchDpnId == null || naptSwitchDpnId.equals(BigInteger.ZERO)) {
1725 LOG.error("handleDisableSnat : Unable to retrieve the primary NAPT switch for the "
1726 + "router ID {} from RouterNaptSwitch model", routerId);
1729 ProviderTypes extNwProvType = NatEvpnUtil.getExtNwProvTypeFromRouterName(dataBroker, routerName,
1731 if (extNwProvType == null) {
1732 LOG.error("handleDisableSnat : External Network Provider Type missing");
1735 Collection<Uuid> externalSubnetList = NatUtil.getExternalSubnetIdsFromExternalIps(router.getExternalIps());
1736 removeNaptFlowsFromActiveSwitch(routerId, routerName, naptSwitchDpnId, networkUuid, vpnName, externalIps,
1737 externalSubnetList, removeFlowInvTx, extNwProvType);
1738 removeFlowsFromNonActiveSwitches(routerId, routerName, naptSwitchDpnId, removeFlowInvTx);
1740 String externalSubnetVpn = null;
1741 for (Uuid externalSubnetId : externalSubnetList) {
1742 Optional<Subnets> externalSubnet = NatUtil.getOptionalExternalSubnets(dataBroker, externalSubnetId);
1743 // externalSubnet data model will exist for FLAT/VLAN external netowrk UCs.
1744 if (externalSubnet.isPresent()) {
1745 externalSubnetVpn = externalSubnetId.getValue();
1746 clrRtsFromBgpAndDelFibTs(naptSwitchDpnId, routerId, networkUuid, externalIps, externalSubnetVpn,
1747 router.getExtGwMacAddress(), removeFlowInvTx);
1750 if (externalSubnetVpn == null) {
1751 clrRtsFromBgpAndDelFibTs(naptSwitchDpnId, routerId, networkUuid, externalIps, vpnName,
1752 router.getExtGwMacAddress(), removeFlowInvTx);
1754 } catch (Exception ex) {
1755 LOG.error("handleDisableSnat : Failed to remove fib entries for routerId {} in naptSwitchDpnId {}",
1756 routerId, naptSwitchDpnId, ex);
1758 // Use the NaptMananager removeMapping API to remove the entire list of IP addresses maintained
1759 // for the router ID.
1760 LOG.debug("handleDisableSnat : Remove the Internal to external IP address maintained for the "
1761 + "router ID {} in the DS", routerId);
1762 naptManager.removeMapping(routerId);
1763 } catch (Exception ex) {
1764 LOG.error("handleDisableSnat : Exception while handling disableSNAT for router :{}", routerName, ex);
1766 LOG.info("handleDisableSnat : Exit");
1769 // TODO Clean up the exception handling
1770 @SuppressWarnings("checkstyle:IllegalCatch")
1771 public void handleDisableSnatInternetVpn(String routerName, long routerId, Uuid networkUuid,
1772 @Nonnull Collection<String> externalIps,
1773 String vpnId, WriteTransaction writeFlowInvTx) {
1774 LOG.debug("handleDisableSnatInternetVpn: Started to process handle disable snat for router {} "
1775 + "with internet vpn {}", routerName, vpnId);
1777 BigInteger naptSwitchDpnId = null;
1778 InstanceIdentifier<RouterToNaptSwitch> routerToNaptSwitch =
1779 NatUtil.buildNaptSwitchRouterIdentifier(routerName);
1780 Optional<RouterToNaptSwitch> rtrToNapt =
1781 read(dataBroker, LogicalDatastoreType.CONFIGURATION, routerToNaptSwitch);
1782 if (rtrToNapt.isPresent()) {
1783 naptSwitchDpnId = rtrToNapt.get().getPrimarySwitchId();
1785 LOG.debug("handleDisableSnatInternetVpn : got primarySwitch as dpnId{} ", naptSwitchDpnId);
1787 removeNaptFlowsFromActiveSwitchInternetVpn(routerId, routerName, naptSwitchDpnId, networkUuid, vpnId,
1790 String extGwMacAddress = NatUtil.getExtGwMacAddFromRouterName(dataBroker, routerName);
1791 if (extGwMacAddress != null) {
1792 LOG.debug("handleDisableSnatInternetVpn : External Gateway MAC address {} found for "
1793 + "External Router ID {}", extGwMacAddress, routerId);
1795 LOG.error("handleDisableSnatInternetVpn : No External Gateway MAC address found for "
1796 + "External Router ID {}", routerId);
1799 clrRtsFromBgpAndDelFibTs(naptSwitchDpnId, routerId, networkUuid, externalIps, vpnId, extGwMacAddress,
1801 } catch (Exception ex) {
1802 LOG.error("handleDisableSnatInternetVpn : Failed to remove fib entries for routerId {} "
1803 + "in naptSwitchDpnId {}", routerId, naptSwitchDpnId, ex);
1805 NatOverVxlanUtil.releaseVNI(vpnId, idManager);
1806 } catch (Exception ex) {
1807 LOG.error("handleDisableSnatInternetVpn: Exception while handling disableSNATInternetVpn for router {} "
1808 + "with internet vpn {}", routerName, vpnId, ex);
1810 LOG.debug("handleDisableSnatInternetVpn: Processed handle disable snat for router {} with internet vpn {}",
1814 // TODO Clean up the exception handling
1815 @SuppressWarnings("checkstyle:IllegalCatch")
1816 public void updateNaptSwitch(String routerName, BigInteger naptSwitchId) {
1817 RouterToNaptSwitch naptSwitch = new RouterToNaptSwitchBuilder().setKey(new RouterToNaptSwitchKey(routerName))
1818 .setPrimarySwitchId(naptSwitchId).build();
1820 MDSALUtil.syncWrite(dataBroker, LogicalDatastoreType.CONFIGURATION,
1821 NatUtil.buildNaptSwitchRouterIdentifier(routerName), naptSwitch);
1822 } catch (Exception ex) {
1823 LOG.error("updateNaptSwitch : Failed to write naptSwitch {} for router {} in ds",
1824 naptSwitchId, routerName);
1826 LOG.debug("updateNaptSwitch : Successfully updated naptSwitch {} for router {} in ds",
1827 naptSwitchId, routerName);
1830 protected void removeNaptSwitch(String routerName) {
1831 // Remove router and switch from model
1832 InstanceIdentifier<RouterToNaptSwitch> id =
1833 InstanceIdentifier.builder(NaptSwitches.class)
1834 .child(RouterToNaptSwitch.class, new RouterToNaptSwitchKey(routerName)).build();
1835 LOG.debug("removeNaptSwitch : Removing NaptSwitch and Router for the router {} from datastore", routerName);
1836 MDSALUtil.syncDelete(dataBroker, LogicalDatastoreType.CONFIGURATION, id);
1837 //Release allocated router_lPort_tag from the ID Manager if Router is on L3VPNOverVxlan
1838 NatEvpnUtil.releaseLPortTagForRouter(dataBroker, idManager, routerName);
1841 public void removeNaptFlowsFromActiveSwitch(long routerId, String routerName,
1842 BigInteger dpnId, Uuid networkId, String vpnName,
1843 @Nonnull Collection<String> externalIps,
1844 Collection<Uuid> externalSubnetList,
1845 WriteTransaction removeFlowInvTx, ProviderTypes extNwProvType) {
1846 LOG.debug("removeNaptFlowsFromActiveSwitch : Remove NAPT flows from Active switch");
1847 BigInteger cookieSnatFlow = NatUtil.getCookieNaptFlow(routerId);
1849 //Remove the PSNAT entry which forwards the packet to Outbound NAPT Table (For the
1850 // traffic which comes from the VMs of the NAPT switches)
1851 String preSnatFlowRef = getFlowRefSnat(dpnId, NwConstants.PSNAT_TABLE, routerName);
1852 FlowEntity preSnatFlowEntity = NatUtil.buildFlowEntity(dpnId, NwConstants.PSNAT_TABLE, preSnatFlowRef);
1854 LOG.info("removeNaptFlowsFromActiveSwitch : Remove the flow in the {} for the active switch with the DPN ID {} "
1855 + "and router ID {}", NwConstants.PSNAT_TABLE, dpnId, routerId);
1856 mdsalManager.removeFlowToTx(preSnatFlowEntity, removeFlowInvTx);
1858 //Remove the Terminating Service table entry which forwards the packet to Outbound NAPT Table (For the
1859 // traffic which comes from the VMs of the non NAPT switches)
1860 long tunnelId = NatUtil.getTunnelIdForNonNaptToNaptFlow(dataBroker, elanManager, idManager, routerId,
1862 String tsFlowRef = getFlowRefTs(dpnId, NwConstants.INTERNAL_TUNNEL_TABLE, tunnelId);
1863 FlowEntity tsNatFlowEntity = NatUtil.buildFlowEntity(dpnId, NwConstants.INTERNAL_TUNNEL_TABLE, tsFlowRef);
1864 LOG.info("removeNaptFlowsFromActiveSwitch : Remove the flow in the {} for the active switch with the DPN ID {} "
1865 + "and router ID {}", NwConstants.INTERNAL_TUNNEL_TABLE, dpnId, routerId);
1866 mdsalManager.removeFlowToTx(tsNatFlowEntity, removeFlowInvTx);
1868 //Remove the flow table 25->44 from NAPT Switch
1869 if (NatUtil.isOpenStackVniSemanticsEnforcedForGreAndVxlan(elanManager, extNwProvType)) {
1870 NatUtil.removePreDnatToSnatTableEntry(mdsalManager, dpnId, removeFlowInvTx);
1873 //Remove the Outbound flow entry which forwards the packet to FIB Table
1874 String outboundNatFlowRef = getFlowRefOutbound(dpnId, NwConstants.OUTBOUND_NAPT_TABLE, routerId);
1875 FlowEntity outboundNatFlowEntity = NatUtil.buildFlowEntity(dpnId, NwConstants.OUTBOUND_NAPT_TABLE,
1876 outboundNatFlowRef);
1878 LOG.info("removeNaptFlowsFromActiveSwitch : Remove the flow in the {} for the active switch with the DPN ID {}"
1879 + " and router ID {}", NwConstants.OUTBOUND_NAPT_TABLE, dpnId, routerId);
1880 mdsalManager.removeFlowToTx(outboundNatFlowEntity, removeFlowInvTx);
1882 removeNaptFibExternalOutputFlows(routerId, dpnId, networkId, externalIps, removeFlowInvTx);
1883 //Remove the NAPT PFIB TABLE (47->21) which forwards the incoming packet to FIB Table matching on the
1884 // External Subnet Vpn Id.
1885 for (Uuid externalSubnetId : externalSubnetList) {
1886 long subnetVpnId = NatUtil.getVpnId(dataBroker, externalSubnetId.getValue());
1887 if (subnetVpnId != -1) {
1888 String natPfibSubnetFlowRef = getFlowRefTs(dpnId, NwConstants.NAPT_PFIB_TABLE, subnetVpnId);
1889 FlowEntity natPfibFlowEntity = NatUtil.buildFlowEntity(dpnId, NwConstants.NAPT_PFIB_TABLE,
1890 natPfibSubnetFlowRef);
1891 mdsalManager.removeFlowToTx(natPfibFlowEntity, removeFlowInvTx);
1892 LOG.debug("removeNaptFlowsFromActiveSwitch : Removed the flow in table {} with external subnet "
1893 + "Vpn Id {} as metadata on Napt Switch {} and vpnId {}", NwConstants.NAPT_PFIB_TABLE,
1894 subnetVpnId, dpnId);
1898 //Remove the NAPT PFIB TABLE which forwards the incoming packet to FIB Table matching on the router ID.
1899 String natPfibFlowRef = getFlowRefTs(dpnId, NwConstants.NAPT_PFIB_TABLE, routerId);
1900 FlowEntity natPfibFlowEntity = NatUtil.buildFlowEntity(dpnId, NwConstants.NAPT_PFIB_TABLE, natPfibFlowRef);
1902 LOG.info("removeNaptFlowsFromActiveSwitch : Remove the flow in the {} for the active switch with the DPN ID {} "
1903 + "and router ID {}", NwConstants.NAPT_PFIB_TABLE, dpnId, routerId);
1904 mdsalManager.removeFlowToTx(natPfibFlowEntity, removeFlowInvTx);
1906 // Long vpnId = NatUtil.getVpnId(dataBroker, routerId);
1907 // - This does not work since ext-routers is deleted already - no network info
1908 //Get the VPN ID from the ExternalNetworks model
1910 if (vpnName == null || vpnName.isEmpty()) {
1911 // ie called from router delete cases
1912 Uuid vpnUuid = NatUtil.getVpnIdfromNetworkId(dataBroker, networkId);
1913 LOG.debug("removeNaptFlowsFromActiveSwitch : vpnUuid is {}", vpnUuid);
1914 if (vpnUuid != null) {
1915 vpnId = NatUtil.getVpnId(dataBroker, vpnUuid.getValue());
1916 LOG.debug("removeNaptFlowsFromActiveSwitch : vpnId {} for external network {} router delete or "
1917 + "disableSNAT scenario", vpnId, networkId);
1920 // ie called from disassociate vpn case
1921 LOG.debug("removeNaptFlowsFromActiveSwitch : This is disassociate nw with vpn case with vpnName {}",
1923 vpnId = NatUtil.getVpnId(dataBroker, vpnName);
1924 LOG.debug("removeNaptFlowsFromActiveSwitch : vpnId for disassociate nw with vpn scenario {}", vpnId);
1927 if (vpnId != NatConstants.INVALID_ID) {
1928 //Remove the NAPT PFIB TABLE which forwards the outgoing packet to FIB Table matching on the VPN ID.
1929 String natPfibVpnFlowRef = getFlowRefTs(dpnId, NwConstants.NAPT_PFIB_TABLE, vpnId);
1930 FlowEntity natPfibVpnFlowEntity =
1931 NatUtil.buildFlowEntity(dpnId, NwConstants.NAPT_PFIB_TABLE, natPfibVpnFlowRef);
1932 LOG.info("removeNaptFlowsFromActiveSwitch : Remove the flow in {} for the active switch with the DPN ID {} "
1933 + "and VPN ID {}", NwConstants.NAPT_PFIB_TABLE, dpnId, vpnId);
1934 mdsalManager.removeFlowToTx(natPfibVpnFlowEntity, removeFlowInvTx);
1937 //For the router ID get the internal IP , internal port and the corresponding external IP and external Port.
1938 IpPortMapping ipPortMapping = NatUtil.getIportMapping(dataBroker, routerId);
1939 if (ipPortMapping == null) {
1940 LOG.error("removeNaptFlowsFromActiveSwitch : Unable to retrieve the IpPortMapping");
1944 List<IntextIpProtocolType> intextIpProtocolTypes = ipPortMapping.getIntextIpProtocolType();
1945 for (IntextIpProtocolType intextIpProtocolType : intextIpProtocolTypes) {
1946 List<IpPortMap> ipPortMaps = intextIpProtocolType.getIpPortMap();
1947 for (IpPortMap ipPortMap : ipPortMaps) {
1948 String ipPortInternal = ipPortMap.getIpPortInternal();
1949 String[] ipPortParts = ipPortInternal.split(":");
1950 if (ipPortParts.length != 2) {
1951 LOG.error("removeNaptFlowsFromActiveSwitch : Unable to retrieve the Internal IP and port");
1954 String internalIp = ipPortParts[0];
1955 String internalPort = ipPortParts[1];
1957 //Build the flow for the outbound NAPT table
1958 naptPacketInHandler.removeIncomingPacketMap(routerId + NatConstants.COLON_SEPARATOR + internalIp
1959 + NatConstants.COLON_SEPARATOR + internalPort);
1960 String switchFlowRef = NatUtil.getNaptFlowRef(dpnId, NwConstants.OUTBOUND_NAPT_TABLE,
1961 String.valueOf(routerId), internalIp, Integer.parseInt(internalPort));
1962 FlowEntity outboundNaptFlowEntity =
1963 NatUtil.buildFlowEntity(dpnId, NwConstants.OUTBOUND_NAPT_TABLE, cookieSnatFlow, switchFlowRef);
1965 LOG.info("removeNaptFlowsFromActiveSwitch : Remove the flow in the {} for the active switch "
1966 + "with the DPN ID {} and router ID {}", NwConstants.OUTBOUND_NAPT_TABLE, dpnId, routerId);
1967 mdsalManager.removeFlowToTx(outboundNaptFlowEntity, removeFlowInvTx);
1969 IpPortExternal ipPortExternal = ipPortMap.getIpPortExternal();
1970 String externalIp = ipPortExternal.getIpAddress();
1971 int externalPort = ipPortExternal.getPortNum();
1973 //Build the flow for the inbound NAPT table
1974 switchFlowRef = NatUtil.getNaptFlowRef(dpnId, NwConstants.INBOUND_NAPT_TABLE,
1975 String.valueOf(routerId), externalIp, externalPort);
1976 FlowEntity inboundNaptFlowEntity =
1977 NatUtil.buildFlowEntity(dpnId, NwConstants.INBOUND_NAPT_TABLE, cookieSnatFlow, switchFlowRef);
1979 LOG.info("removeNaptFlowsFromActiveSwitch : Remove the flow in the {} for the active active switch "
1980 + "with the DPN ID {} and router ID {}", NwConstants.INBOUND_NAPT_TABLE, dpnId, routerId);
1981 mdsalManager.removeFlowToTx(inboundNaptFlowEntity, removeFlowInvTx);
1986 protected void removeNaptFibExternalOutputFlows(long routerId, BigInteger dpnId, Uuid networkId,
1987 @Nonnull Collection<String> externalIps,
1988 WriteTransaction writeFlowInvTx) {
1989 long extVpnId = NatConstants.INVALID_ID;
1990 if (networkId != null) {
1991 Uuid vpnUuid = NatUtil.getVpnIdfromNetworkId(dataBroker, networkId);
1992 if (vpnUuid != null) {
1993 extVpnId = NatUtil.getVpnId(dataBroker, vpnUuid.getValue());
1995 LOG.debug("removeNaptFibExternalOutputFlows : vpnUuid is null");
1998 LOG.debug("removeNaptFibExternalOutputFlows : networkId is null");
1999 extVpnId = NatUtil.getNetworkVpnIdFromRouterId(dataBroker, routerId);
2001 if (extVpnId == NatConstants.INVALID_ID) {
2002 LOG.warn("removeNaptFibExternalOutputFlows : extVpnId not found for routerId {}", routerId);
2003 extVpnId = routerId;
2005 for (String ip : externalIps) {
2006 String extIp = removeMaskFromIp(ip);
2007 String naptFlowRef = getFlowRefNaptPreFib(dpnId, NwConstants.NAPT_PFIB_TABLE, extVpnId);
2008 LOG.info("removeNaptFlowsFromActiveSwitch : Remove the flow in the for the active switch"
2009 + " with the DPN ID {} and router ID {} and IP {} flowRef {}",
2010 NwConstants.NAPT_PFIB_TABLE, dpnId, routerId, extIp, naptFlowRef);
2011 FlowEntity natPfibVpnFlowEntity = NatUtil.buildFlowEntity(dpnId, NwConstants.NAPT_PFIB_TABLE, naptFlowRef);
2012 mdsalManager.removeFlowToTx(natPfibVpnFlowEntity, writeFlowInvTx);
2016 private String removeMaskFromIp(String ip) {
2017 if (ip != null && !ip.trim().isEmpty()) {
2018 return ip.split("/")[0];
2023 public void removeNaptFlowsFromActiveSwitchInternetVpn(long routerId, String routerName,
2024 BigInteger dpnId, Uuid networkId, String vpnName,
2025 WriteTransaction writeFlowInvTx) {
2026 LOG.debug("removeNaptFlowsFromActiveSwitchInternetVpn : Remove NAPT flows from Active switch Internet Vpn");
2027 BigInteger cookieSnatFlow = NatUtil.getCookieNaptFlow(routerId);
2029 //Remove the NAPT PFIB TABLE entry
2031 if (vpnName != null) {
2032 // ie called from disassociate vpn case
2033 LOG.debug("removeNaptFlowsFromActiveSwitchInternetVpn : This is disassociate nw with vpn case "
2034 + "with vpnName {}", vpnName);
2035 vpnId = NatUtil.getVpnId(dataBroker, vpnName);
2036 LOG.debug("removeNaptFlowsFromActiveSwitchInternetVpn : vpnId for disassociate nw with vpn scenario {}",
2040 if (vpnId != NatConstants.INVALID_ID && !NatUtil.checkForRoutersWithSameExtNetAndNaptSwitch(dataBroker,
2041 networkId, routerName, dpnId)) {
2042 //Remove the NAPT PFIB TABLE which forwards the outgoing packet to FIB Table matching on the VPN ID.
2043 String natPfibVpnFlowRef = getFlowRefTs(dpnId, NwConstants.NAPT_PFIB_TABLE, vpnId);
2044 FlowEntity natPfibVpnFlowEntity =
2045 NatUtil.buildFlowEntity(dpnId, NwConstants.NAPT_PFIB_TABLE, natPfibVpnFlowRef);
2046 LOG.info("removeNaptFlowsFromActiveSwitchInternetVpn : Remove the flow in the {} for the active switch "
2047 + "with the DPN ID {} and VPN ID {}", NwConstants.NAPT_PFIB_TABLE, dpnId, vpnId);
2048 mdsalManager.removeFlowToTx(natPfibVpnFlowEntity, writeFlowInvTx);
2050 // Remove IP-PORT active NAPT entries and release port from IdManager
2051 // For the router ID get the internal IP , internal port and the corresponding
2052 // external IP and external Port.
2053 IpPortMapping ipPortMapping = NatUtil.getIportMapping(dataBroker, routerId);
2054 if (ipPortMapping == null) {
2055 LOG.error("removeNaptFlowsFromActiveSwitchInternetVpn : Unable to retrieve the IpPortMapping");
2058 List<IntextIpProtocolType> intextIpProtocolTypes = ipPortMapping.getIntextIpProtocolType();
2059 for (IntextIpProtocolType intextIpProtocolType : intextIpProtocolTypes) {
2060 List<IpPortMap> ipPortMaps = intextIpProtocolType.getIpPortMap();
2061 for (IpPortMap ipPortMap : ipPortMaps) {
2062 String ipPortInternal = ipPortMap.getIpPortInternal();
2063 String[] ipPortParts = ipPortInternal.split(":");
2064 if (ipPortParts.length != 2) {
2065 LOG.error("removeNaptFlowsFromActiveSwitchInternetVpn : Unable to retrieve the Internal IP "
2069 String internalIp = ipPortParts[0];
2070 String internalPort = ipPortParts[1];
2072 //Build the flow for the outbound NAPT table
2073 naptPacketInHandler.removeIncomingPacketMap(routerId + NatConstants.COLON_SEPARATOR + internalIp
2074 + NatConstants.COLON_SEPARATOR + internalPort);
2075 String switchFlowRef = NatUtil.getNaptFlowRef(dpnId, NwConstants.OUTBOUND_NAPT_TABLE,
2076 String.valueOf(routerId), internalIp, Integer.parseInt(internalPort));
2077 FlowEntity outboundNaptFlowEntity =
2078 NatUtil.buildFlowEntity(dpnId, NwConstants.OUTBOUND_NAPT_TABLE, cookieSnatFlow, switchFlowRef);
2080 LOG.info("removeNaptFlowsFromActiveSwitchInternetVpn : Remove the flow in the {} for the "
2081 + "active switch with the DPN ID {} and router ID {}",
2082 NwConstants.OUTBOUND_NAPT_TABLE, dpnId, routerId);
2083 mdsalManager.removeFlowToTx(outboundNaptFlowEntity, writeFlowInvTx);
2085 IpPortExternal ipPortExternal = ipPortMap.getIpPortExternal();
2086 String externalIp = ipPortExternal.getIpAddress();
2087 int externalPort = ipPortExternal.getPortNum();
2089 //Build the flow for the inbound NAPT table
2090 switchFlowRef = NatUtil.getNaptFlowRef(dpnId, NwConstants.INBOUND_NAPT_TABLE,
2091 String.valueOf(routerId), externalIp, externalPort);
2092 FlowEntity inboundNaptFlowEntity =
2093 NatUtil.buildFlowEntity(dpnId, NwConstants.INBOUND_NAPT_TABLE, cookieSnatFlow, switchFlowRef);
2095 LOG.info("removeNaptFlowsFromActiveSwitchInternetVpn : Remove the flow in the {} for the "
2096 + "active active switch with the DPN ID {} and router ID {}",
2097 NwConstants.INBOUND_NAPT_TABLE, dpnId, routerId);
2098 mdsalManager.removeFlowToTx(inboundNaptFlowEntity, writeFlowInvTx);
2100 // Finally release port from idmanager
2101 String internalIpPort = internalIp + ":" + internalPort;
2102 naptManager.removePortFromPool(internalIpPort, externalIp);
2104 //Remove sessions from models
2105 naptManager.removeIpPortMappingForRouterID(routerId);
2106 naptManager.removeIntIpPortMappingForRouterID(routerId);
2110 LOG.error("removeNaptFlowsFromActiveSwitchInternetVpn : Invalid vpnId {}", vpnId);
2114 public void removeFlowsFromNonActiveSwitches(long routerId, String routerName,
2115 BigInteger naptSwitchDpnId, WriteTransaction removeFlowInvTx) {
2116 LOG.debug("removeFlowsFromNonActiveSwitches : Remove NAPT related flows from non active switches");
2118 // Remove the flows from the other switches which points to the primary and secondary switches
2119 // for the flows related the router ID.
2120 List<BigInteger> allSwitchList = naptSwitchSelector.getDpnsForVpn(routerName);
2121 if (allSwitchList.isEmpty()) {
2122 LOG.error("removeFlowsFromNonActiveSwitches : Unable to get the swithces for the router {}", routerName);
2125 for (BigInteger dpnId : allSwitchList) {
2126 if (!naptSwitchDpnId.equals(dpnId)) {
2127 LOG.info("removeFlowsFromNonActiveSwitches : Handle Ordinary switch");
2129 //Remove the PSNAT entry which forwards the packet to Terminating Service table
2130 String preSnatFlowRef = getFlowRefSnat(dpnId, NwConstants.PSNAT_TABLE, String.valueOf(routerName));
2131 FlowEntity preSnatFlowEntity = NatUtil.buildFlowEntity(dpnId, NwConstants.PSNAT_TABLE, preSnatFlowRef);
2133 LOG.info("removeFlowsFromNonActiveSwitches : Remove the flow in the {} for the non active switch "
2134 + "with the DPN ID {} and router ID {}", NwConstants.PSNAT_TABLE, dpnId, routerId);
2135 mdsalManager.removeFlowToTx(preSnatFlowEntity, removeFlowInvTx);
2137 //Remove the group entry which forwards the traffic to the out port (VXLAN tunnel).
2138 long groupId = createGroupId(getGroupIdKey(routerName));
2139 List<BucketInfo> listBucketInfo = new ArrayList<>();
2140 GroupEntity preSnatGroupEntity =
2141 MDSALUtil.buildGroupEntity(dpnId, groupId, routerName, GroupTypes.GroupAll, listBucketInfo);
2143 LOG.info("removeFlowsFromNonActiveSwitches : Remove the group {} for the non active switch with "
2144 + "the DPN ID {} and router ID {}", groupId, dpnId, routerId);
2145 mdsalManager.removeGroup(preSnatGroupEntity);
2151 public void clrRtsFromBgpAndDelFibTs(final BigInteger dpnId, Long routerId, Uuid networkUuid,
2152 @Nonnull Collection<String> externalIps, String vpnName,
2153 String extGwMacAddress, WriteTransaction removeFlowInvTx) {
2154 //Withdraw the corresponding routes from the BGP.
2155 //Get the network ID using the router ID.
2156 LOG.debug("clrRtsFromBgpAndDelFibTs : Advertise to BGP and remove routes for externalIps {} with routerId {},"
2157 + "network Id {} and vpnName {}", externalIps, routerId, networkUuid, vpnName);
2158 if (networkUuid == null) {
2159 LOG.error("clrRtsFromBgpAndDelFibTs : networkId is null");
2163 if (externalIps.isEmpty()) {
2164 LOG.error("clrRtsFromBgpAndDelFibTs : externalIps is empty");
2168 if (vpnName == null) {
2169 //Get the VPN Name using the network ID
2170 vpnName = NatUtil.getAssociatedVPN(dataBroker, networkUuid);
2171 if (vpnName == null) {
2172 LOG.error("clrRtsFromBgpAndDelFibTs : No VPN associated with ext nw {} for the router {}",
2173 networkUuid, routerId);
2177 LOG.debug("clrRtsFromBgpAndDelFibTs : Retrieved vpnName {} for networkId {}", vpnName, networkUuid);
2179 //Remove custom FIB routes
2180 //Future<RpcResult<java.lang.Void>> removeFibEntry(RemoveFibEntryInput input);
2181 for (String extIp : externalIps) {
2182 clrRtsFromBgpAndDelFibTs(dpnId, routerId, extIp, vpnName, networkUuid, extGwMacAddress, removeFlowInvTx);
2186 protected void clrRtsFromBgpAndDelFibTs(final BigInteger dpnId, long routerId, String extIp, final String vpnName,
2187 final Uuid networkUuid, String extGwMacAddress,
2188 WriteTransaction removeFlowInvTx) {
2189 clearBgpRoutes(extIp, vpnName);
2190 delFibTsAndReverseTraffic(dpnId, routerId, extIp, vpnName, networkUuid, extGwMacAddress, false,
2194 protected void delFibTsAndReverseTraffic(final BigInteger dpnId, long routerId, String extIp,
2195 final String vpnName, Uuid extNetworkId, long tempLabel,
2196 String gwMacAddress, boolean switchOver,
2197 WriteTransaction removeFlowInvTx) {
2198 LOG.debug("delFibTsAndReverseTraffic : Removing fib entry for externalIp {} in routerId {}", extIp, routerId);
2199 String routerName = NatUtil.getRouterName(dataBroker,routerId);
2200 if (routerName == null) {
2201 LOG.error("delFibTsAndReverseTraffic : Could not retrieve Router Name from Router ID {} ", routerId);
2204 ProviderTypes extNwProvType = NatEvpnUtil.getExtNwProvTypeFromRouterName(dataBroker, routerName, extNetworkId);
2205 if (extNwProvType == null) {
2206 LOG.error("delFibTsAndReverseTraffic : External Network Provider Type Missing");
2209 /* Remove the flow table19->44 and table36->44 entries for SNAT reverse traffic flow if the
2210 * external network provided type is VxLAN
2212 if (extNwProvType == ProviderTypes.VXLAN) {
2213 evpnSnatFlowProgrammer.evpnDelFibTsAndReverseTraffic(dpnId, routerId, extIp, vpnName, gwMacAddress,
2217 if (tempLabel < 0) {
2218 LOG.error("delFibTsAndReverseTraffic : Label not found for externalIp {} with router id {}",
2223 final long label = tempLabel;
2224 final String externalIp = NatUtil.validateAndAddNetworkMask(extIp);
2225 RemoveFibEntryInput input = new RemoveFibEntryInputBuilder().setVpnName(vpnName)
2226 .setSourceDpid(dpnId).setIpAddress(externalIp).setServiceId(label)
2227 .setIpAddressSource(RemoveFibEntryInput.IpAddressSource.ExternalFixedIP).build();
2228 Future<RpcResult<Void>> future = fibService.removeFibEntry(input);
2230 removeTunnelTableEntry(dpnId, label, removeFlowInvTx);
2231 removeLFibTableEntry(dpnId, label, removeFlowInvTx);
2232 if (NatUtil.isOpenStackVniSemanticsEnforcedForGreAndVxlan(elanManager, extNwProvType)) {
2233 //Remove the flow table 25->44 If there is no FIP Match on table 25 (PDNAT_TABLE)
2234 NatUtil.removePreDnatToSnatTableEntry(mdsalManager, dpnId, removeFlowInvTx);
2237 ListenableFuture<RpcResult<Void>> labelFuture =
2238 Futures.transformAsync(JdkFutureAdapters.listenInPoolThread(future),
2239 (AsyncFunction<RpcResult<Void>, RpcResult<Void>>) result -> {
2241 if (result.isSuccessful()) {
2242 NatUtil.removePreDnatToSnatTableEntry(mdsalManager, dpnId, removeFlowInvTx);
2243 RemoveVpnLabelInput labelInput = new RemoveVpnLabelInputBuilder()
2244 .setVpnName(vpnName).setIpPrefix(externalIp).build();
2245 Future<RpcResult<Void>> labelFuture1 = vpnService.removeVpnLabel(labelInput);
2246 return JdkFutureAdapters.listenInPoolThread(labelFuture1);
2249 String.format("RPC call to remove custom FIB entries on dpn %s for "
2250 + "prefix %s Failed - %s", dpnId, externalIp, result.getErrors());
2252 return Futures.immediateFailedFuture(new RuntimeException(errMsg));
2256 Futures.addCallback(labelFuture, new FutureCallback<RpcResult<Void>>() {
2259 public void onFailure(@Nonnull Throwable error) {
2260 LOG.error("delFibTsAndReverseTraffic : Error in removing the label:{} or custom fib entries"
2261 + "got external ip {}", label, extIp, error);
2265 public void onSuccess(@Nonnull RpcResult<Void> result) {
2266 if (result.isSuccessful()) {
2267 LOG.debug("delFibTsAndReverseTraffic : Successfully removed the label for the prefix {} "
2268 + "from VPN {}", externalIp, vpnName);
2270 LOG.error("delFibTsAndReverseTraffic : Error in removing the label for prefix {} "
2271 + " from VPN {}, {}", externalIp, vpnName, result.getErrors());
2274 }, MoreExecutors.directExecutor());
2276 LOG.debug("delFibTsAndReverseTraffic: switch-over is happened on DpnId {}. No need to release allocated "
2277 + "label {} for external fixed ip {} for router {}", dpnId, label, externalIp, routerId);
2281 private void delFibTsAndReverseTraffic(final BigInteger dpnId, long routerId, String extIp, final String vpnName,
2282 final Uuid networkUuid, String extGwMacAddress, boolean switchOver,
2283 WriteTransaction removeFlowInvTx) {
2284 LOG.debug("delFibTsAndReverseTraffic : Removing fib entry for externalIp {} in routerId {}", extIp, routerId);
2285 String routerName = NatUtil.getRouterName(dataBroker,routerId);
2286 if (routerName == null) {
2287 LOG.error("delFibTsAndReverseTraffic : Could not retrieve Router Name from Router ID {} ", routerId);
2290 //Get the external network provider type from networkId
2291 ProviderTypes extNwProvType = NatUtil.getProviderTypefromNetworkId(dataBroker, networkUuid);
2292 if (extNwProvType == null) {
2293 LOG.error("delFibTsAndReverseTraffic : Could not retrieve provider type for external network {} ",
2297 /* Remove the flow table19->44 and table36->44 entries for SNAT reverse traffic flow if the
2298 * external network provided type is VxLAN
2300 if (extNwProvType == ProviderTypes.VXLAN) {
2301 evpnSnatFlowProgrammer.evpnDelFibTsAndReverseTraffic(dpnId, routerId, extIp, vpnName, extGwMacAddress,
2305 //Get IPMaps from the DB for the router ID
2306 List<IpMap> dbIpMaps = NaptManager.getIpMapList(dataBroker, routerId);
2307 if (dbIpMaps.isEmpty()) {
2308 LOG.error("delFibTsAndReverseTraffic : IPMaps not found for router {}", routerId);
2312 long tempLabel = NatConstants.INVALID_ID;
2313 for (IpMap dbIpMap : dbIpMaps) {
2314 String dbExternalIp = dbIpMap.getExternalIp();
2315 LOG.debug("delFibTsAndReverseTraffic : Retrieved dbExternalIp {} for router id {}", dbExternalIp, routerId);
2316 //Select the IPMap, whose external IP is the IP for which FIB is installed
2317 if (extIp.equals(dbExternalIp)) {
2318 tempLabel = dbIpMap.getLabel();
2319 LOG.debug("delFibTsAndReverseTraffic : Retrieved label {} for dbExternalIp {} with router id {}",
2320 tempLabel, dbExternalIp, routerId);
2324 if (tempLabel == NatConstants.INVALID_ID) {
2325 LOG.error("delFibTsAndReverseTraffic : Label not found for externalIp {} with router id {}",
2330 final long label = tempLabel;
2331 final String externalIp = NatUtil.validateAndAddNetworkMask(extIp);
2332 RemoveFibEntryInput input = new RemoveFibEntryInputBuilder()
2333 .setVpnName(vpnName).setSourceDpid(dpnId).setIpAddress(externalIp)
2334 .setIpAddressSource(RemoveFibEntryInput.IpAddressSource.ExternalFixedIP).setServiceId(label).build();
2335 Future<RpcResult<Void>> future = fibService.removeFibEntry(input);
2337 removeTunnelTableEntry(dpnId, label, removeFlowInvTx);
2338 removeLFibTableEntry(dpnId, label, removeFlowInvTx);
2339 if (NatUtil.isOpenStackVniSemanticsEnforcedForGreAndVxlan(elanManager, extNwProvType)) {
2340 //Remove the flow table 25->44 If there is no FIP Match on table 25 (PDNAT_TABLE)
2341 NatUtil.removePreDnatToSnatTableEntry(mdsalManager, dpnId, removeFlowInvTx);
2344 ListenableFuture<RpcResult<Void>> labelFuture =
2345 Futures.transformAsync(JdkFutureAdapters.listenInPoolThread(future),
2346 (AsyncFunction<RpcResult<Void>, RpcResult<Void>>) result -> {
2348 if (result.isSuccessful()) {
2349 RemoveVpnLabelInput labelInput = new RemoveVpnLabelInputBuilder()
2350 .setVpnName(vpnName).setIpPrefix(externalIp).build();
2351 Future<RpcResult<Void>> labelFuture1 = vpnService.removeVpnLabel(labelInput);
2352 return JdkFutureAdapters.listenInPoolThread(labelFuture1);
2355 String.format("RPC call to remove custom FIB entries on dpn %s for "
2356 + "prefix %s Failed - %s",
2357 dpnId, externalIp, result.getErrors());
2359 return Futures.immediateFailedFuture(new RuntimeException(errMsg));
2363 Futures.addCallback(labelFuture, new FutureCallback<RpcResult<Void>>() {
2366 public void onFailure(@Nonnull Throwable error) {
2367 LOG.error("delFibTsAndReverseTraffic : Error in removing the label or custom fib entries", error);
2371 public void onSuccess(@Nonnull RpcResult<Void> result) {
2372 if (result.isSuccessful()) {
2373 LOG.debug("delFibTsAndReverseTraffic : Successfully removed the label for the prefix {} "
2374 + "from VPN {}", externalIp, vpnName);
2376 LOG.error("delFibTsAndReverseTraffic : Error in removing the label for prefix {} "
2377 + " from VPN {}, {}", externalIp, vpnName, result.getErrors());
2380 }, MoreExecutors.directExecutor());
2382 LOG.debug("delFibTsAndReverseTraffic: switch-over is happened on DpnId {}. No need to release allocated "
2383 + "label {} for external fixed ip {} for router {}", dpnId, label, externalIp, routerId);
2387 protected void clearFibTsAndReverseTraffic(final BigInteger dpnId, Long routerId, Uuid networkUuid,
2388 List<String> externalIps, String vpnName, String extGwMacAddress,
2389 WriteTransaction writeFlowInvTx) {
2390 //Withdraw the corresponding routes from the BGP.
2391 //Get the network ID using the router ID.
2392 LOG.debug("clearFibTsAndReverseTraffic : for externalIps {} with routerId {},"
2393 + "network Id {} and vpnName {}", externalIps, routerId, networkUuid, vpnName);
2394 if (networkUuid == null) {
2395 LOG.error("clearFibTsAndReverseTraffic : networkId is null");
2399 if (externalIps == null || externalIps.isEmpty()) {
2400 LOG.error("clearFibTsAndReverseTraffic : externalIps is null");
2404 if (vpnName == null) {
2405 //Get the VPN Name using the network ID
2406 vpnName = NatUtil.getAssociatedVPN(dataBroker, networkUuid);
2407 if (vpnName == null) {
2408 LOG.error("clearFibTsAndReverseTraffic : No VPN associated with ext nw {} for the router {}",
2409 networkUuid, routerId);
2413 LOG.debug("Retrieved vpnName {} for networkId {}", vpnName, networkUuid);
2415 //Remove custom FIB routes
2416 //Future<RpcResult<java.lang.Void>> removeFibEntry(RemoveFibEntryInput input);
2417 for (String extIp : externalIps) {
2418 delFibTsAndReverseTraffic(dpnId, routerId, extIp, vpnName, networkUuid, extGwMacAddress, false,
2423 protected void clearBgpRoutes(String externalIp, final String vpnName) {
2424 //Inform BGP about the route removal
2425 LOG.info("clearBgpRoutes : Informing BGP to remove route for externalIP {} of vpn {}", externalIp, vpnName);
2426 String rd = NatUtil.getVpnRd(dataBroker, vpnName);
2427 NatUtil.removePrefixFromBGP(bgpManager, fibManager, rd, externalIp, vpnName, LOG);
2430 private void removeTunnelTableEntry(BigInteger dpnId, long serviceId, WriteTransaction writeFlowInvTx) {
2431 LOG.info("removeTunnelTableEntry : called with DpnId = {} and label = {}", dpnId, serviceId);
2432 List<MatchInfo> mkMatches = new ArrayList<>();
2433 // Matching metadata
2434 mkMatches.add(new MatchTunnelId(BigInteger.valueOf(serviceId)));
2435 Flow flowEntity = MDSALUtil.buildFlowNew(NwConstants.INTERNAL_TUNNEL_TABLE,
2436 getFlowRef(dpnId, NwConstants.INTERNAL_TUNNEL_TABLE, serviceId, ""),
2437 5, String.format("%s:%d", "TST Flow Entry ", serviceId), 0, 0,
2438 COOKIE_TUNNEL.add(BigInteger.valueOf(serviceId)), mkMatches, null);
2439 mdsalManager.removeFlowToTx(dpnId, flowEntity, writeFlowInvTx);
2440 LOG.debug("removeTunnelTableEntry : dpID {} : label : {} removed successfully", dpnId, serviceId);
2443 private void removeLFibTableEntry(BigInteger dpnId, long serviceId, WriteTransaction writeFlowInvTx) {
2444 List<MatchInfo> matches = new ArrayList<>();
2445 matches.add(MatchEthernetType.MPLS_UNICAST);
2446 matches.add(new MatchMplsLabel(serviceId));
2448 String flowRef = getFlowRef(dpnId, NwConstants.L3_LFIB_TABLE, serviceId, "");
2450 LOG.debug("removeLFibTableEntry : with flow ref {}", flowRef);
2452 Flow flowEntity = MDSALUtil.buildFlowNew(NwConstants.L3_LFIB_TABLE, flowRef,
2454 COOKIE_VM_LFIB_TABLE, matches, null);
2456 mdsalManager.removeFlowToTx(dpnId, flowEntity, writeFlowInvTx);
2458 LOG.debug("removeLFibTableEntry : dpID : {} label : {} removed successfully", dpnId, serviceId);
2462 * router association to vpn.
2464 * @param routerName - Name of router
2465 * @param routerId - router id
2466 * @param bgpVpnName BGP VPN name
2468 public void changeLocalVpnIdToBgpVpnId(String routerName, long routerId, String bgpVpnName,
2469 WriteTransaction writeFlowInvTx, ProviderTypes extNwProvType) {
2470 LOG.debug("changeLocalVpnIdToBgpVpnId : Router associated to BGP VPN");
2471 if (chkExtRtrAndSnatEnbl(new Uuid(routerName))) {
2472 long bgpVpnId = NatUtil.getVpnId(dataBroker, bgpVpnName);
2474 LOG.debug("changeLocalVpnIdToBgpVpnId : BGP VPN ID value {} ", bgpVpnId);
2476 if (bgpVpnId != NatConstants.INVALID_ID) {
2477 LOG.debug("changeLocalVpnIdToBgpVpnId : Populate the router-id-name container with the "
2478 + "mapping BGP VPN-ID {} -> BGP VPN-NAME {}", bgpVpnId, bgpVpnName);
2479 RouterIds rtrs = new RouterIdsBuilder().setKey(new RouterIdsKey(bgpVpnId))
2480 .setRouterId(bgpVpnId).setRouterName(bgpVpnName).build();
2481 MDSALUtil.syncWrite(dataBroker, LogicalDatastoreType.CONFIGURATION,
2482 getRoutersIdentifier(bgpVpnId), rtrs);
2484 // Get the allocated Primary NAPT Switch for this router
2485 LOG.debug("changeLocalVpnIdToBgpVpnId : Router ID value {} ", routerId);
2487 LOG.debug("changeLocalVpnIdToBgpVpnId : Update the Router ID {} to the BGP VPN ID {} ",
2488 routerId, bgpVpnId);
2489 addOrDelDefaultFibRouteForSnatWithBgpVpn(routerName, routerId, bgpVpnId, true, writeFlowInvTx);
2492 BigInteger primarySwitchId = NatUtil.getPrimaryNaptfromRouterName(dataBroker, routerName);
2493 createGroupId(getGroupIdKey(routerName));
2494 installFlowsWithUpdatedVpnId(primarySwitchId, routerName, bgpVpnId, routerId, true, writeFlowInvTx,
2501 * router disassociation from vpn.
2503 * @param routerName - Name of router
2504 * @param routerId - router id
2505 * @param bgpVpnName BGP VPN name
2507 public void changeBgpVpnIdToLocalVpnId(String routerName, long routerId, String bgpVpnName,
2508 WriteTransaction writeFlowInvTx, ProviderTypes extNwProvType) {
2509 LOG.debug("changeBgpVpnIdToLocalVpnId : Router dissociated from BGP VPN");
2510 if (chkExtRtrAndSnatEnbl(new Uuid(routerName))) {
2511 long bgpVpnId = NatUtil.getVpnId(dataBroker, bgpVpnName);
2512 LOG.debug("changeBgpVpnIdToLocalVpnId : BGP VPN ID value {} ", bgpVpnId);
2514 // Get the allocated Primary NAPT Switch for this router
2515 LOG.debug("changeBgpVpnIdToLocalVpnId : Router ID value {} ", routerId);
2517 LOG.debug("changeBgpVpnIdToLocalVpnId : Update the BGP VPN ID {} to the Router ID {}", bgpVpnId, routerId);
2518 addOrDelDefaultFibRouteForSnatWithBgpVpn(routerName, routerId, NatConstants.INVALID_ID,
2519 true, writeFlowInvTx);
2522 createGroupId(getGroupIdKey(routerName));
2523 BigInteger primarySwitchId = NatUtil.getPrimaryNaptfromRouterName(dataBroker, routerName);
2524 installFlowsWithUpdatedVpnId(primarySwitchId, routerName, NatConstants.INVALID_ID, routerId, true,
2525 writeFlowInvTx, extNwProvType);
2529 boolean chkExtRtrAndSnatEnbl(Uuid routerUuid) {
2530 InstanceIdentifier<Routers> routerInstanceIndentifier =
2531 InstanceIdentifier.builder(ExtRouters.class)
2532 .child(Routers.class, new RoutersKey(routerUuid.getValue())).build();
2533 Optional<Routers> routerData = read(dataBroker, LogicalDatastoreType.CONFIGURATION, routerInstanceIndentifier);
2534 return routerData.isPresent() && routerData.get().isEnableSnat();
2537 public void installFlowsWithUpdatedVpnId(BigInteger primarySwitchId, String routerName, long bgpVpnId,
2538 long routerId, boolean isSnatCfgd, WriteTransaction writeFlowInvTx,
2539 ProviderTypes extNwProvType) {
2540 long changedVpnId = bgpVpnId;
2541 String logMsg = "installFlowsWithUpdatedVpnId : Update the BGP VPN ID {}";
2542 if (bgpVpnId == NatConstants.INVALID_ID) {
2543 changedVpnId = routerId;
2544 logMsg = "installFlowsWithUpdatedVpnId : Update the router ID {}";
2547 List<BigInteger> switches = NatUtil.getDpnsForRouter(dataBroker, routerName);
2548 if (switches.isEmpty()) {
2549 LOG.error("installFlowsWithUpdatedVpnId : No switches found for router {}", routerName);
2552 for (BigInteger dpnId : switches) {
2553 // Update the BGP VPN ID in the SNAT miss entry to group
2554 if (!dpnId.equals(primarySwitchId)) {
2555 LOG.debug("installFlowsWithUpdatedVpnId : Install group in non NAPT switch {}", dpnId);
2556 List<BucketInfo> bucketInfoForNonNaptSwitches =
2557 getBucketInfoForNonNaptSwitches(dpnId, primarySwitchId, routerName, routerId);
2558 long groupId = createGroupId(getGroupIdKey(routerName));
2560 groupId = installGroup(dpnId, routerName, bucketInfoForNonNaptSwitches);
2563 LOG.debug("{} in the SNAT miss entry pointing to group {} in the non NAPT switch {}",
2564 logMsg, changedVpnId, groupId, dpnId);
2565 FlowEntity flowEntity = buildSnatFlowEntityWithUpdatedVpnId(dpnId, routerName, groupId, changedVpnId);
2566 mdsalManager.addFlowToTx(flowEntity, writeFlowInvTx);
2568 LOG.debug("{} in the SNAT miss entry pointing to group in the primary switch {}",
2569 logMsg, changedVpnId, primarySwitchId);
2570 FlowEntity flowEntity =
2571 buildSnatFlowEntityWithUpdatedVpnIdForPrimrySwtch(primarySwitchId, routerName, changedVpnId);
2572 mdsalManager.addFlowToTx(flowEntity, writeFlowInvTx);
2574 LOG.debug("{} in the Terminating Service table (table ID 36) which forwards the packet"
2575 + " to the table 46 in the Primary switch {}", logMsg, changedVpnId, primarySwitchId);
2576 installTerminatingServiceTblEntryWithUpdatedVpnId(primarySwitchId, routerName, routerId,
2577 changedVpnId, writeFlowInvTx, extNwProvType);
2579 LOG.debug("{} in the Outbound NAPT table (table ID 46) which punts the packet to the"
2580 + " controller in the Primary switch {}", logMsg, changedVpnId, primarySwitchId);
2581 createOutboundTblEntryWithBgpVpn(primarySwitchId, routerId, changedVpnId, writeFlowInvTx);
2583 LOG.debug("{} in the NAPT PFIB TABLE which forwards the outgoing packet to FIB Table in the"
2584 + "Primary switch {}", logMsg, changedVpnId, primarySwitchId);
2585 installNaptPfibEntryWithBgpVpn(primarySwitchId, routerId, changedVpnId, writeFlowInvTx);
2587 LOG.debug("{} in the NAPT flows for the Outbound NAPT table (table ID 46) and the "
2588 + "INBOUND NAPT table (table ID 44) in the Primary switch {}",
2589 logMsg, changedVpnId, primarySwitchId);
2590 updateNaptFlowsWithVpnId(primarySwitchId, routerName, routerId, bgpVpnId);
2592 LOG.debug("installFlowsWithUpdatedVpnId : Installing SNAT PFIB flow in the primary switch {}",
2594 Long vpnId = NatUtil.getNetworkVpnIdFromRouterId(dataBroker, routerId);
2595 //Install the NAPT PFIB TABLE which forwards the outgoing packet to FIB Table matching on the VPN ID.
2596 if (vpnId != NatConstants.INVALID_ID) {
2597 installNaptPfibEntry(primarySwitchId, vpnId, writeFlowInvTx);
2603 public void updateNaptFlowsWithVpnId(BigInteger dpnId, String routerName, long routerId, long bgpVpnId) {
2604 //For the router ID get the internal IP , internal port and the corresponding external IP and external Port.
2605 IpPortMapping ipPortMapping = NatUtil.getIportMapping(dataBroker, routerId);
2606 if (ipPortMapping == null) {
2607 LOG.error("updateNaptFlowsWithVpnId : Unable to retrieve the IpPortMapping");
2610 // Get the External Gateway MAC Address
2611 String extGwMacAddress = NatUtil.getExtGwMacAddFromRouterName(dataBroker, routerName);
2612 if (extGwMacAddress != null) {
2613 LOG.debug("updateNaptFlowsWithVpnId : External Gateway MAC address {} found for External Router ID {}",
2614 extGwMacAddress, routerId);
2616 LOG.error("updateNaptFlowsWithVpnId : No External Gateway MAC address found for External Router ID {}",
2620 List<IntextIpProtocolType> intextIpProtocolTypes = ipPortMapping.getIntextIpProtocolType();
2621 for (IntextIpProtocolType intextIpProtocolType : intextIpProtocolTypes) {
2622 List<IpPortMap> ipPortMaps = intextIpProtocolType.getIpPortMap();
2623 for (IpPortMap ipPortMap : ipPortMaps) {
2624 String ipPortInternal = ipPortMap.getIpPortInternal();
2625 String[] ipPortParts = ipPortInternal.split(":");
2626 if (ipPortParts.length != 2) {
2627 LOG.error("updateNaptFlowsWithVpnId : Unable to retrieve the Internal IP and port");
2630 String internalIp = ipPortParts[0];
2631 String internalPort = ipPortParts[1];
2632 LOG.debug("updateNaptFlowsWithVpnId : Found Internal IP {} and Internal Port {}",
2633 internalIp, internalPort);
2634 ProtocolTypes protocolTypes = intextIpProtocolType.getProtocol();
2635 NAPTEntryEvent.Protocol protocol;
2636 switch (protocolTypes) {
2638 protocol = NAPTEntryEvent.Protocol.TCP;
2641 protocol = NAPTEntryEvent.Protocol.UDP;
2644 protocol = NAPTEntryEvent.Protocol.TCP;
2646 SessionAddress internalAddress = new SessionAddress(internalIp, Integer.parseInt(internalPort));
2647 SessionAddress externalAddress =
2648 naptManager.getExternalAddressMapping(routerId, internalAddress, protocol);
2649 long internetVpnid = NatUtil.getNetworkVpnIdFromRouterId(dataBroker, routerId);
2650 naptEventHandler.buildAndInstallNatFlows(dpnId, NwConstants.INBOUND_NAPT_TABLE, internetVpnid,
2651 routerId, bgpVpnId, externalAddress, internalAddress, protocol, extGwMacAddress);
2652 naptEventHandler.buildAndInstallNatFlows(dpnId, NwConstants.OUTBOUND_NAPT_TABLE, internetVpnid,
2653 routerId, bgpVpnId, internalAddress, externalAddress, protocol, extGwMacAddress);
2658 public FlowEntity buildSnatFlowEntityWithUpdatedVpnId(BigInteger dpId, String routerName, long groupId,
2659 long changedVpnId) {
2661 LOG.debug("buildSnatFlowEntityWithUpdatedVpnId : called for dpId {}, routerName {} groupId {} "
2662 + "changed VPN ID {}", dpId, routerName, groupId, changedVpnId);
2663 List<MatchInfo> matches = new ArrayList<>();
2664 matches.add(MatchEthernetType.IPV4);
2665 matches.add(new MatchMetadata(MetaDataUtil.getVpnIdMetadata(changedVpnId), MetaDataUtil.METADATA_MASK_VRFID));
2667 List<ActionInfo> actionsInfo = new ArrayList<>();
2668 long tunnelId = NatUtil.getTunnelIdForNonNaptToNaptFlow(dataBroker, elanManager, idManager, changedVpnId,
2670 actionsInfo.add(new ActionSetFieldTunnelId(BigInteger.valueOf(tunnelId)));
2671 LOG.debug("buildSnatFlowEntityWithUpdatedVpnId : Setting the tunnel to the list of action infos {}",
2673 actionsInfo.add(new ActionGroup(groupId));
2674 List<InstructionInfo> instructions = new ArrayList<>();
2675 instructions.add(new InstructionApplyActions(actionsInfo));
2676 String flowRef = getFlowRefSnat(dpId, NwConstants.PSNAT_TABLE, routerName);
2677 FlowEntity flowEntity = MDSALUtil.buildFlowEntity(dpId, NwConstants.PSNAT_TABLE, flowRef,
2678 NatConstants.DEFAULT_PSNAT_FLOW_PRIORITY, flowRef, 0, 0,
2679 NwConstants.COOKIE_SNAT_TABLE, matches, instructions);
2681 LOG.debug("buildSnatFlowEntityWithUpdatedVpnId : Returning SNAT Flow Entity {}", flowEntity);
2685 public FlowEntity buildSnatFlowEntityWithUpdatedVpnIdForPrimrySwtch(BigInteger dpId, String routerName,
2686 long changedVpnId) {
2688 LOG.debug("buildSnatFlowEntityWithUpdatedVpnIdForPrimrySwtch : called for dpId {}, routerName {} "
2689 + "changed VPN ID {}", dpId, routerName, changedVpnId);
2690 List<MatchInfo> matches = new ArrayList<>();
2691 matches.add(MatchEthernetType.IPV4);
2692 matches.add(new MatchMetadata(MetaDataUtil.getVpnIdMetadata(changedVpnId), MetaDataUtil.METADATA_MASK_VRFID));
2694 List<InstructionInfo> instructions = new ArrayList<>();
2695 instructions.add(new InstructionGotoTable(NwConstants.OUTBOUND_NAPT_TABLE));
2697 String flowRef = getFlowRefSnat(dpId, NwConstants.PSNAT_TABLE, routerName);
2698 FlowEntity flowEntity = MDSALUtil.buildFlowEntity(dpId, NwConstants.PSNAT_TABLE, flowRef,
2699 NatConstants.DEFAULT_PSNAT_FLOW_PRIORITY, flowRef, 0, 0,
2700 NwConstants.COOKIE_SNAT_TABLE, matches, instructions);
2702 LOG.debug("buildSnatFlowEntityWithUpdatedVpnIdForPrimrySwtch : Returning SNAT Flow Entity {}", flowEntity);
2706 // TODO : Replace this with ITM Rpc once its available with full functionality
2707 protected void installTerminatingServiceTblEntryWithUpdatedVpnId(BigInteger dpnId, String routerName,
2708 long routerId, long changedVpnId, WriteTransaction writeFlowInvTx, ProviderTypes extNwProvType) {
2709 LOG.debug("installTerminatingServiceTblEntryWithUpdatedVpnId : called for switch {}, "
2710 + "routerName {}, BGP VPN ID {}", dpnId, routerName, changedVpnId);
2711 FlowEntity flowEntity = buildTsFlowEntityWithUpdatedVpnId(dpnId, routerName, routerId, changedVpnId,
2713 mdsalManager.addFlowToTx(flowEntity, writeFlowInvTx);
2716 private FlowEntity buildTsFlowEntityWithUpdatedVpnId(BigInteger dpId, String routerName,
2717 long routerIdLongVal, long changedVpnId, ProviderTypes extNwProvType) {
2718 LOG.debug("buildTsFlowEntityWithUpdatedVpnId : called for switch {}, routerName {}, BGP VPN ID {}",
2719 dpId, routerName, changedVpnId);
2720 List<MatchInfo> matches = new ArrayList<>();
2721 matches.add(MatchEthernetType.IPV4);
2723 BigInteger tunnelId = BigInteger.valueOf(changedVpnId);
2724 if (NatUtil.isOpenStackVniSemanticsEnforcedForGreAndVxlan(elanManager, extNwProvType)) {
2725 tunnelId = NatOverVxlanUtil.getRouterVni(idManager, routerName, changedVpnId);
2727 matches.add(new MatchTunnelId(tunnelId));
2729 List<InstructionInfo> instructions = new ArrayList<>();
2730 instructions.add(new InstructionWriteMetadata(MetaDataUtil.getVpnIdMetadata(changedVpnId),
2731 MetaDataUtil.METADATA_MASK_VRFID));
2732 instructions.add(new InstructionGotoTable(NwConstants.OUTBOUND_NAPT_TABLE));
2733 BigInteger routerId = BigInteger.valueOf(routerIdLongVal);
2734 String flowRef = getFlowRefTs(dpId, NwConstants.INTERNAL_TUNNEL_TABLE, routerId.longValue());
2735 FlowEntity flowEntity = MDSALUtil.buildFlowEntity(dpId, NwConstants.INTERNAL_TUNNEL_TABLE, flowRef,
2736 NatConstants.DEFAULT_TS_FLOW_PRIORITY, flowRef, 0, 0,
2737 NwConstants.COOKIE_TS_TABLE, matches, instructions);
2741 public void createOutboundTblEntryWithBgpVpn(BigInteger dpnId, long routerId, long changedVpnId,
2742 WriteTransaction writeFlowInvTx) {
2743 LOG.debug("createOutboundTblEntryWithBgpVpn : called for dpId {} and routerId {}, BGP VPN ID {}",
2744 dpnId, routerId, changedVpnId);
2745 FlowEntity flowEntity = buildOutboundFlowEntityWithBgpVpn(dpnId, routerId, changedVpnId);
2746 LOG.debug("createOutboundTblEntryWithBgpVpn : Installing flow {}", flowEntity);
2747 mdsalManager.addFlowToTx(flowEntity, writeFlowInvTx);
2750 protected FlowEntity buildOutboundFlowEntityWithBgpVpn(BigInteger dpId, long routerId, long changedVpnId) {
2751 LOG.debug("buildOutboundFlowEntityWithBgpVpn : called for dpId {} and routerId {}, BGP VPN ID {}",
2752 dpId, routerId, changedVpnId);
2753 List<MatchInfo> matches = new ArrayList<>();
2754 matches.add(MatchEthernetType.IPV4);
2755 matches.add(new MatchMetadata(MetaDataUtil.getVpnIdMetadata(changedVpnId), MetaDataUtil.METADATA_MASK_VRFID));
2757 List<InstructionInfo> instructions = new ArrayList<>();
2758 List<ActionInfo> actionsInfos = new ArrayList<>();
2759 actionsInfos.add(new ActionPuntToController());
2760 instructions.add(new InstructionApplyActions(actionsInfos));
2761 instructions.add(new InstructionWriteMetadata(MetaDataUtil.getVpnIdMetadata(changedVpnId),
2762 MetaDataUtil.METADATA_MASK_VRFID));
2764 String flowRef = getFlowRefOutbound(dpId, NwConstants.OUTBOUND_NAPT_TABLE, routerId);
2765 BigInteger cookie = getCookieOutboundFlow(routerId);
2766 FlowEntity flowEntity = MDSALUtil.buildFlowEntity(dpId, NwConstants.OUTBOUND_NAPT_TABLE,
2767 flowRef, 5, flowRef, 0, 0, cookie, matches, instructions);
2768 LOG.debug("createOutboundTblEntryWithBgpVpn : returning flowEntity {}", flowEntity);
2772 public void installNaptPfibEntryWithBgpVpn(BigInteger dpnId, long segmentId, long changedVpnId,
2773 WriteTransaction writeFlowInvTx) {
2774 LOG.debug("installNaptPfibEntryWithBgpVpn : called for dpnId {} and segmentId {} ,BGP VPN ID {}",
2775 dpnId, segmentId, changedVpnId);
2776 FlowEntity naptPfibFlowEntity = buildNaptPfibFlowEntityWithUpdatedVpnId(dpnId, segmentId, changedVpnId);
2777 mdsalManager.addFlowToTx(naptPfibFlowEntity, writeFlowInvTx);
2780 public FlowEntity buildNaptPfibFlowEntityWithUpdatedVpnId(BigInteger dpId, long segmentId, long changedVpnId) {
2782 LOG.debug("buildNaptPfibFlowEntityWithUpdatedVpnId : called for dpId {}, "
2783 + "segmentId {}, BGP VPN ID {}", dpId, segmentId, changedVpnId);
2784 List<MatchInfo> matches = new ArrayList<>();
2785 matches.add(MatchEthernetType.IPV4);
2786 matches.add(new MatchMetadata(MetaDataUtil.getVpnIdMetadata(changedVpnId), MetaDataUtil.METADATA_MASK_VRFID));
2788 ArrayList<ActionInfo> listActionInfo = new ArrayList<>();
2789 ArrayList<InstructionInfo> instructionInfo = new ArrayList<>();
2790 listActionInfo.add(new ActionNxLoadInPort(BigInteger.ZERO));
2791 listActionInfo.add(new ActionNxResubmit(NwConstants.L3_FIB_TABLE));
2792 instructionInfo.add(new InstructionApplyActions(listActionInfo));
2794 String flowRef = getFlowRefTs(dpId, NwConstants.NAPT_PFIB_TABLE, segmentId);
2795 FlowEntity flowEntity = MDSALUtil.buildFlowEntity(dpId, NwConstants.NAPT_PFIB_TABLE, flowRef,
2796 NatConstants.DEFAULT_PSNAT_FLOW_PRIORITY, flowRef, 0, 0,
2797 NwConstants.COOKIE_SNAT_TABLE, matches, instructionInfo);
2798 LOG.debug("buildNaptPfibFlowEntityWithUpdatedVpnId : Returning NaptPFib Flow Entity {}", flowEntity);
2803 protected ExternalRoutersListener getDataTreeChangeListener() {
2804 return ExternalRoutersListener.this;
2807 protected void installNaptPfibEntriesForExternalSubnets(String routerName, BigInteger dpnId,
2808 WriteTransaction writeFlowInvTx) {
2809 Collection<Uuid> externalSubnetIdsForRouter = NatUtil.getExternalSubnetIdsForRouter(dataBroker,
2811 for (Uuid externalSubnetId : externalSubnetIdsForRouter) {
2812 long subnetVpnId = NatUtil.getVpnId(dataBroker, externalSubnetId.getValue());
2813 if (subnetVpnId != -1) {
2814 LOG.debug("installNaptPfibEntriesForExternalSubnets : called for dpnId {} "
2815 + "and vpnId {}", dpnId, subnetVpnId);
2816 installNaptPfibEntry(dpnId, subnetVpnId, writeFlowInvTx);