Hardware flowtable offload from multiple tables?
Davíð Steinn Geirsson <[email protected]> Fri, 22 Aug 2025 01:58:56 +0000
| Newsgroups | gmane.comp.security.firewalls.netfilter.general |
|---|---|
| Message-ID | <aKfO4E3RwYl0hlIp@mailstore> |
Hi all,
Please CC me on replies as I'm not subscribed to the list.
I've been trying to get hardware flowtable offload going on a ConnectX-6 DX
card. I have managed to create the flowtable (needed to create a SF interface
and apply the flowtable to that - using the PF directly does not work).
However, it seems that a device can only be referenced from one flowtable,
and the scope of the flowtable is only the current table. So if I have separate
`ip` and `ip6` table types, I can't do hardware flowtable offload from both. Is
my understanding correct? Are there any workarounds (other than changing
everything over to a combined `inet` table) available?
I can create either an `ip` or `ip6` table with offloaded flowtable, but doing
both gives "Device or resource busy" error:
```
david@vyos01:~$ sudo nft add 'table ip test { flowtable fttest { hook ingress priority 0; devices = { en1f0pf1sf88 }; flags offload; }; }'
david@vyos01:~$
david@vyos01:~$ sudo nft add 'table ip6 test { flowtable fttest { hook ingress priority 0; devices = { en1f0pf1sf88 }; flags offload; }; }'
Error: Could not process rule: Device or resource busy
add table ip6 test { flowtable fttest { hook ingress priority 0; devices = { en1f0pf1sf88 }; flags offload; }; }
^^^^^^
```
Thanks,
Davíð