Red Hat OpenShift Networking offers two options for the network plugin, OpenShift SDN and OVN-Kubernetes, for the network plugin. The following table summarizes the current feature support for both network plugins:
Table 1. Default CNI network plugin feature comparison
Feature |
OpenShift SDN |
OVN-Kubernetes |
Egress IPs |
Supported |
Supported |
Egress firewall |
Supported |
Supported [1] |
Egress router |
Supported |
Supported [2] |
Hybrid networking |
Not supported |
Supported |
IPsec encryption for intra-cluster communication |
Not supported |
Supported |
IPv4 single-stack |
Supported |
Supported |
IPv6 single-stack |
Not supported |
Supported [3] |
IPv4/IPv6 dual-stack |
Not Supported |
Supported [4] |
IPv6/IPv4 dual-stack |
Not supported |
Supported [5] |
Kubernetes network policy |
Supported |
Supported |
Kubernetes network policy logs |
Not supported |
Supported |
Hardware offloading |
Not supported |
Supported |
Multicast |
Supported |
Supported |
-
Egress firewall is also known as egress network policy in OpenShift SDN. This is not the same as network policy egress.
-
Egress router for OVN-Kubernetes supports only redirect mode.
-
IPv6 single-stack networking on a bare-metal platform.
-
IPv4/IPv6 dual-stack networking on bare-metal, VMware vSphere (installer-provisioned infrastructure installations only), IBM Power®, IBM Z®, and OpenStack platforms.
-
IPv6/IPv4 dual-stack networking on bare-metal, VMware vSphere (installer-provisioned infrastructure installations only), and IBM Power® platforms.