"Open vSwitch"의 두 판 사이의 차이

오픈소스 비즈니스 컨설팅
둘러보기로 가기 검색하러 가기
잔글
잔글
 
(같은 사용자의 중간 판 2개는 보이지 않습니다)
83번째 줄: 83번째 줄:
 
OpenFlow Controller 지정
 
OpenFlow Controller 지정
 
<pre>ovs-vsctl set-controller br0 tcp:133.1.134.167</pre>
 
<pre>ovs-vsctl set-controller br0 tcp:133.1.134.167</pre>
 +
<parsererror style="display: block; white-space: pre; border: 2px solid #c77; padding: 0 1em 0 1em; margin: 1em; background-color: #fdd; color: black">
 +
=== This page contains the following errors: ===
 +
<div style="font-family:monospace;font-size:12px">error on line 1 at column 102: attributes construct error </div>
 +
=== Below is a rendering of the page up to the first error. ===
 +
</parsererror>
 
=== GRE 터널 설정 ===
 
=== GRE 터널 설정 ===
 
Server A (eth0&nbsp;: 192.168.0.2)
 
<pre>brctl addbr docker0
 
ip addr add 10.0.0.1/24 dev docker0  #--- Container의 IP는 10.0.0.nnn 사용
 
 
ovs-vsctl add-br br0
 
ovs-vsctl add-port br0 gre0 -- set interface gre0 type=gre options:remote_ip=192.168.0.3
 
ovs-vsctl add-port br0 docker0
 
# brctl addif docker0 br0
 
</pre>
 
Server B (eth0&nbsp;: 192.168.0.3)
 
<pre>brctl addbr docker0
 
ip addr add 10.0.0.2/24 dev docker1  #--- Container의 IP는 10.0.0.nnn 사용
 
 
ovs-vsctl add-br br0
 
ovs-vsctl add-port br0 gre0 -- set interface gre0 type=gre options:remote_ip=192.168.0.2
 
ovs-vsctl add-port br0 docker0
 
# brctl addif docker0 br0
 
</pre>
 
방화벽 설정
 
<pre>iptables -t nat -A POSTROUTING -s 10.0.0.1/24&nbsp;! -d 10.0.0.1/24 -j MASQUERADE        #--- NAT 사용 설정
 
iptables -A FORWARD -o docker0 -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT  #--- Container로 들어오는 트래픽 허용
 
iptables -A FORWARD -i docker0&nbsp;! -o docker0 -j ACCEPT                                #-- Container에서 나가는 트래픽 허용
 
iptables -A FORWARD -i docker0 -o docker0 -j ACCEPT                                  #--- 나가는 트래픽 모두 허용
 
</pre>
 
<br/>참고 문헌
 
 
*[http://openvswitch.org/support/config-cookbooks/port-tunneling/ http://openvswitch.org/support/config-cookbooks/port-tunneling/]
 
*[http://www.yongbok.net/blog/tag/open-vswitch-gre-tunnel/ http://www.yongbok.net/blog/tag/open-vswitch-gre-tunnel/]
 
  
 
=== VLAN 설정 ===
 
=== VLAN 설정 ===
124번째 줄: 100번째 줄:
 
<pre>ovs–vsctl add–port br1 vx1 — set interface vx1 type=vxlan options:remote_ip=192.168.1.10
 
<pre>ovs–vsctl add–port br1 vx1 — set interface vx1 type=vxlan options:remote_ip=192.168.1.10
 
ovs–vsctl add–port br1 vx1 — set interface vx1 type=vxlan options:remote_ip=192.168.1.11</pre>
 
ovs–vsctl add–port br1 vx1 — set interface vx1 type=vxlan options:remote_ip=192.168.1.11</pre>
 +
=== LACP 설정 ===
 +
 +
참고 문헌
 +
 +
*[http://blog.remibergsma.com/2015/03/26/connecting-two-open-vswitches-to-create-a-l2-connection/ http://blog.remibergsma.com/2015/03/26/connecting-two-open-vswitches-to-create-a-l2-connection/]
 +
*http://blog.remibergsma.com/tag/openvswitch/
  
 
== OVN ==
 
== OVN ==

2016년 9월 27일 (화) 16:32 기준 최신판

Distributed Virtual Switch인 OVS (Open vSwitch)를 정리 합니다.

OVS 개요

Linux의 상단에서 가상의 L2 Switch를 생성합니다. 정교한 패킷 제어 기능을 제공하는 OpenFlow 프로토콜을 지원 합니다.

  • NetFlow, sFlow, SPAN, RSPAN, CLI, LACP, 802.1ag 지원

Open vSwitch 설치

Source로 설치

  • RPM 생성을 위한 환경 구성
yum install -y rpm-build
yum groupinstall -y "Development Tools"

yum install -y openssl-devel
yum install kernel-devel

mkdir -p $HOME/rpmbuild/SOURCES
$HOME/rpmbuild/SOURCES/
wget http://openvswitch.org/releases/openvswitch-2.3.0.tar.gz
tar xvfz openvswitch-2.3.0.tar.gz
cd openvswitch-2.3.0

vi rhel/openvswitch.spec
 ### Requires: openvswitch-kmod, logrotate, python
 Requires: logrotate, python

rpmbuild -bb -D `uname -r` rhel/openvswitch.spec
### rpmbuild -bb rhel/openvswitch.spec
### rpmbuild -bb rhel/openvswitch-kmod-rhel6.spec

cd $HOME/rpmbuild/RPMS/x86_64
ls -alF

yum localinstall openvswitch-2.3.0-1.x86_64.rpm

RPM으로 설치

wget [http://cbs.centos.org/kojifiles/packages/openvswitch/2.3.1/2.el7/x86_64/openvswitch-2.3.1-2.el7.x86_64.rpm http://cbs.centos.org/kojifiles/packages/openvswitch/2.3.1/2.el7/x86_64/openvswitch-2.3.1-2.el7.x86_64.rpm]                    
rpm -ivh openvswitch-2.3.1-2.el7.x86_64.rpm

vi /etc/sysconfig/openvswitch

service openvswitch restart

OVS 명령어

Bridge와 Port 설정

ovs-vsctl add-br br0                  #--- br0 Bridge 추가
ovs-vsctl del-br br0                  #--- br0 Bridge 삭제
ovs-vsctl list-br
# vi /etc/sysconfig/network-scripts/ifcfg-br0

ovs-vsctl set bridge br0 stp_enable=true     #--- STP 활성화

ovs-vsctl add-port br0 eth0           #--- br0 Bridge에 eth0 NIC 연결
ovs-vsctl del-port br0 eth0
ovs-vsctl list-ports br0
​# ethtool -K eth0 gro off

newview
ovs-vsctl show                        #--- Bridge 상세 조회

OpenFlow 설정

OpenFlow Controller 지정

ovs-vsctl set-controller br0 tcp:133.1.134.167

<parsererror style="display: block; white-space: pre; border: 2px solid #c77; padding: 0 1em 0 1em; margin: 1em; background-color: #fdd; color: black">

This page contains the following errors:

error on line 1 at column 102: attributes construct error

Below is a rendering of the page up to the first error.

</parsererror>

GRE 터널 설정

VLAN 설정

ovs-vsctl add-port br0 tap0 tag=100

참고 문헌

VxLAN 설정

ovs–vsctl add–port br1 vx1 — set interface vx1 type=vxlan options:remote_ip=192.168.1.10
ovs–vsctl add–port br1 vx1 — set interface vx1 type=vxlan options:remote_ip=192.168.1.11

LACP 설정

참고 문헌

OVN

OVN (Open Virtual Network)

  • L2 segments
  • L3 forwarding
  • Security Group

참고 문헌