Acropolis open vSwitch

Userlevel 2
Badge +17


\nCompletely different construct from the typical vSwitch, where you program the vSwitch, then attach VM's to pre-configured \"port groups\".
\nTraffic shaping it not yet available. If you have a use case for it, please submit a support ticket with priority RFE Request for Enhancement, so we can track demand for the feature.","className":"post__content__best_answer"}">
Userlevel 6
Badge +29
Keep in mind that when you configure a VLAN in Acropolis, it doesn't program it to any sort of OVS until a VM is provisioned on a host. When that happens, we configure a Tap device on that OVS, and program the VLAN to that tap device.


Userlevel 2
Badge +17
Thanks How many VLAN we can create on single host / maximum vlan allowed?
Badge +4
Valid ID's are 0-4094, so the max number of VLANs allowed would be 4095 if you include a VLAN that doesn't tag (id 0).
Badge +2
您能确认是否已将交通塑料用于Acrocolis Open Vswitch?谢谢你。
Userlevel 6
Badge +29

For most use cases, keep in mind that in Nutanix, each node has full network access, such that (for example) a 3 node cluster would have (at minimum) 60 Gbits of bandwidth going into it (assuming 2x 10Gbits per node). That math, of course, goes up linearly with node count or with an increase in NIC speed (like 25/40/100g interfaces).

For folks like Service Providers, this makes more sense, so that they can shape the traffic of specific tenants or applications within a tenant, which is where we've been exploring this use internally.

On a related note, we're releasing service chaining with OVS in the very next release as part of the microsegmentation feature, which is quite interesting.
Badge +2

Thank you for your quick reply. My organization is new to Nutanix and HCI, my apologies if I'm asking basic questions...

我们是VMware商店,但我们正在建造的群集之一仅是AHV。由于目前在AHV Open VSWitch上无法使用网络I/O控制或流量构成,因此您可以为客户提供处理VM实时迁移的建议,因为它可能会使10GB链接饱和(正如我们在VMware VMotion中看到的那样事件)还携带数据和复制流量?还是您在对我的问题的初步答复中所说的那样,这不是Nutanix的问题?再次感谢。
Userlevel 6
Badge +29
No worries, everyone's gotta start somewhere.


We're huge fans of the kiss principle here at nutanix, as most things "just work", which is quite nice.

也就是说,很高兴知道什么并知道我们所做的原因,因此我建议您在此处查看AHV网络指南:伟德国际 391

That should give you some good background. After you read that, you'll find that you'll likely want to use either balance-slb or balance-tcp for load balancing policy on the OVS side, which does give you better load distribution than the default (active/backup), which is the default simply because its the most compatible for almost anyones network setup, so its very easy to get going.

Even if you kept the default though, you'll still have copius amounts of bandwidth that scales linearly per node.
Badge +2

我们决定仅使用2x10GB适配器进行我们的部署,并将使用OVS Balance-SLB LB策略。通过这种配置,是否可以将实时迁移流量,管理流量等固定到特定主机NIC?如果是这样,当链接失败以及链接返回在线时,固定作业会发生什么?我了解Nutanix希望保持简单,但只是想知道此选项是否可用。

Again, I'd like to express my sincere gratitude for all the information you've provided.
Userlevel 6
Badge +29


- 乔恩
Badge +2
Userlevel 6
Badge +29

Badge +2
Userlevel 6
Badge +29

Doing an unsupported change like that would very likely break every time you do any sort of operation on a given VM, like power on/power off, migration, high availability restarts, cloning, etc. This is because it would be a change that our control plane didn't program in, so it would just override it as it went about its business. Thats best case. Worst case, we haven't tested it, so we dont know any unintended side effects.

也就是说 - 您能否扩大希望在这里完成的工作?我知道您在说什么技术,但是我想知道您的特定用例是什么,所以我可以将其带回这里。
Badge +2
这是我们的用例...在同一网络段上的同一主机上的2 VM相互交谈。我们如何捕获这两个VM之间的流量?
Userlevel 3
Badge +14
Network function chains can do this today in AHV. You would create a tap mode network function VM and put it in the network that these VMs use. This would allow you to capture traffic between VMs on the same "Network" regardless of whether or not they were on the same host. All traffic to and from a VM MUST flow through the network function chain when it's enabled.

I'm working on a blog post to cover this use case. Here is an image to show how it would work. You can do an inline port or a tap port.

Badge +2
Thank you Jason. I have a few questions...

Userlevel 3
Badge +14


此NFV VM可以在TAP模式下接收,检查和捕获。在内联模式下,它可以执行这些功能并决定拒绝或传输流量。在上面的示例图中,想象一下VM作为Palo Alto Networks VM系列防火墙。我还在自己的实验室中使用了Snort ID。

通过在网络函数链中配置的这种类型的NFV,您只能捕获在AHV上运行的VMS发送或接收的流量。您无法捕获物理主机发送的流量,也无法将ERSPAN类型流量发送到NFV VM。

Userlevel 6
Badge +29
When we say network function VM, in your case we'd be referring to Viavi. It would have to be running on the same host as the system(s) you want to capture traffic from.

需要明确的是,这不是我们提供的特殊VM。AHV中的链接功能使您可以在获取本地镜子的地方放置“ TAP模式”设备


in-line mode devices, which would be like a IDS/IPS/Firewall type setup
