â ã¯ããã«
ããã«ã¡ã¯ãããŒãããŒSEã®å·åŽã§ããæ¬ã·ãªãŒãºã§ã¯ãååã«åŒãç¶ããããã¯ãŒã¯ä»®æ³åããããã¯ãŒã¯ã®åºæ¬ããçè§£ãããšããå§¿å¢ã§ãç©çç°å¢ãšæ¯èŒããªããé²ããŸãã第3åãšãªãä»åã¯ã¬ã€ã€3ã®ã«ãŒãã£ã³ã°ã«é¢ããŠèŠãŠãããŸãã
â ã¯ããã«
â ç©çãããã¯ãŒã¯ç°å¢ã«ãããã«ãŒãã£ã³ã°
â ãããã¯ãŒã¯ä»®æ³åç°å¢ã«ããã忣ã«ãŒãã£ã³ã°
â ç©çãããã¯ãŒã¯ç°å¢ãšãããã¯ãŒã¯ä»®æ³åç°å¢ã®æ¯èŒ
â è£è¶³æ
å ±
â ã¯ããã«
ããŒã¿ã»ã³ã¿ãŒã«ããããããã¯ãŒã¯ã§ã¯ãEast-West ãã©ãã£ãã¯ãšåŒã°ãããµãŒãéã®æ°Žå¹³æ¹åã®éä¿¡ãããã©ãã£ãã¯éå
šäœã®çŽ7 å²ãå ããŠãããšèšãããŠããŸãã忣ã«ãŒãã£ã³ã°ã¯ããã€ããŒãã€ã¶å
ã§ã«ãŒãã£ã³ã°ã®åŠçãè¡ãããšã§ããã® East-West ãã©ãã£ãã¯ãæé©åããŸãã
忣ã«ãŒãã£ã³ã°ã®èšå®ã¯ãVMware NSX ã®ç®¡çç»é¢ããè¡ããŸããç©çãµãŒããç©çãããã¯ãŒã¯æ©åšæ°åå°ã«ãŸããããããªåæ£ã«ãŒãã£ã³ã°ç°å¢ãæ§æããéããåã
ã®ç©çã³ã³ããŒãã³ãã«èšå®ãè¡ãå¿
èŠã¯ãããŸããã
忣ã«ãŒãã£ã³ã°ç°å¢ãæ§æããããã«ã¯ãè«çã«ãŒã¿ã³ã³ãããŒã«VMãšåŒã°ããã³ã³ããŒãã³ããäœæããŸããè«çã«ãŒã¿ã³ã³ãããŒã«VM ã¯ã NSX Edge ã®æ§æãŠã£ã¶ãŒããããã€ã³ã¹ããŒã«ã¿ã€ãããè«çïŒåæ£ïŒã«ãŒã¿ããšããŠæ§æããŸãã
è«çã«ãŒã¿ã³ã³ãããŒã«VM ã«èšå®ããã€ã³ã¿ãŒãã§ã€ã¹ãã«ãŒãã£ã³ã°ã®æ
å ±ã¯ãå VMware ESXi ãã¹ãã«å±éãããŸããäŸãã°è«çã«ãŒã¿ã³ã³ãããŒã«VM ã«ã«ãŒãã£ã³ã°èšå®ã远å ãããšããã®æ
å ±ãå ESXi ãã¹ãå
ã®è«çã«ãŒã¿ã«ãŒãã«ã¢ãžã¥ãŒã«ã«å±éãããããšã«ãªããŸãã
äžè¿°ã®éã忣ã«ãŒãã£ã³ã°ã«é¢ããèšå®ã¯GUI ããç°¡åã«è¡ãããšãã§ããŸãããAPIãä»ããèšå®ãå¯èœã§ãããCMPïŒã¯ã©ãŠããããžã¡ã³ããã©ãããã©ãŒã ïŒãšé£æºããããšã§èšå®äœæ¥ãèªååã§ããŸãã
â ç©çãããã¯ãŒã¯ç°å¢ã«ãããã«ãŒãã£ã³ã°
忣ã«ãŒãã£ã³ã°ã®èª¬æã«å
¥ãåã«ãç©çãããã¯ãŒã¯ç°å¢ã§ã®ã«ãŒãã£ã³ã°ã®èª¬æãè¡ããŸãã
ãããã¯ãŒã¯ç°å¢ã«ãããŠãç°ãªããããã¯ãŒã¯ã»ã°ã¡ã³ãå
ã«ååšãã端æ«éã§éä¿¡ãè¡ãªãå ŽåãèããŸãã端æ«A ãšç«¯æ«C ã¯ããããã172.16.10.0/24, 172.16.20.0/24ã®ãããã¯ãŒã¯ã«ååšããç©çã«ãŒã¿ïŒL3SWïŒã«æ¥ç¶ãããŠããŸããç°ãªããããã¯ãŒã¯ã»ã°ã¡ã³ãéã®éä¿¡ã§ã¯ãã«ãŒã¿ã«ããã«ãŒãã£ã³ã°åŠçãè¡ãªãããŸãã
ã«ãŒãã£ã³ã°ãè¡ãã®ã¯ããããã¯ãŒã¯æ©åšã ãã§ã¯ãããŸããã端æ«AïŒ172.16.10.11/24ïŒ ã端æ«CïŒ172.16.20.11/24ïŒ ãšéä¿¡ãè¡ããšããæåã«ç«¯æ«A ã¯ç«¯æ«C ãç°ãªããµããããã«ããããšãèªèããŸãã端æ«A ã¯ãèªèº«ã®ã«ãŒãã£ã³ã°ããŒãã«ãåç
§ããããã©ã«ãGW ã§ããã«ãŒã¿ã«ãã©ãã£ãã¯ã転éããŸãã
ã«ãŒã¿ã¯ããããã®ãããã¯ãŒã¯ã»ã°ã¡ã³ãã«ã€ã³ã¿ãŒãã§ã€ã¹F0, F1 ãæã¡ãåä¿¡ããéä¿¡ããå¥ã®ã€ã³ã¿ãŒãã§ã€ã¹ããéä¿¡ããŸããéä¿¡ããã€ã³ã¿ãŒãã§ã€ã¹ã決å®ããéã«ã«ãŒãã£ã³ã°ããŒãã«ãåç
§ããŸããå®éã«ã«ãŒã¿ã®ã«ãŒãã£ã³ã°ããŒãã«ã確ãããŠã¿ãŸãããã
> show ip route
C 172.16.10.0/24 is directly connected, F0
C 172.16.20.0/24 is directly connected, F1
S 0.0.0.0/0 via <å€éšã«ãŒã¿IP>
端æ«CïŒ172.16.20.11ïŒã®æå±ãã172.16.20.0/24 ã¯ãã«ãŒã¿ã®ã€ã³ã¿ãŒãã§ã€ã¹ F1 ã«çŽæ¥æ¥ç¶ããŠããããšã確èªã§ããŸããã«ãŒã¿ã¯ãã€ã³ã¿ãŒãã§ã€ã¹ F1 ãã端æ«C ã«ãã±ããã転éããŸãã
ç©çãããã¯ãŒã¯ç°å¢ã§ã¯ãç©çã«ãŒã¿ãã«ãŒãã£ã³ã°ããŒãã«ãæã¡ãåäžã®ãã€ã³ãã§ã«ãŒãã£ã³ã°åŠçã宿œããŸãããŸããè€æ°ã®ç©çããã€ã¹ãããå Žåã¯ãåã
ã®ããã€ã¹ã«å¯ŸããŠèšå®äœæ¥ãè¡ãããšã«ãªããŸãã
ã«ãŒãã£ã³ã°ã®èãæ¹åã³ã端æ«åŽã®åäœã¯ãããã¯ãŒã¯ä»®æ³åç°å¢ã«ãªã£ãŠãå€ãããŸãããããããã¯ãŒã¯ä»®æ³åç°å¢ã§ã¯ç©çã«ãŒã¿ã®æã€ã«ãŒãã£ã³ã°æ©èœãã忣ã«ãŒãã£ã³ã°ãšããŠãã€ããŒãã€ã¶ã«å®è£
ããããšãã§ããŸãã忣ã«ãŒãã£ã³ã°ã®ã¢ãŒããã¯ãã£ã«ã€ããŠããã«ãŒãã£ã³ã°ããŒãã«ãã«æ³šç®ãã圢ã§ãã®åŸèŠãŠãããŸãã
â ãããã¯ãŒã¯ä»®æ³åç°å¢ã«ããã忣ã«ãŒãã£ã³ã°
ãããã¯ãŒã¯ä»®æ³åç°å¢ã§ã®ã«ãŒãã£ã³ã°ãèŠãŠãããŸãããµãŒãä»®æ³åç°å¢ã§ãã£ãŠãéåžžã®æ§æã§ããã°ãã«ãŒãã£ã³ã°åŠçã¯å€éšã®ã«ãŒã¿ã§è¡ãããããšã«ãªããŸããããã«å¯Ÿãã忣ã«ãŒãã£ã³ã°ãæå¹ãªç°å¢ã§ã¯ãå ESXi ãã¹ãå
ã«è«çã«ãŒã¿ã«ãŒãã«ã¢ãžã¥ãŒã«ãé
眮ããããã¹ãå
ã§ã«ãŒãã£ã³ã°åŠçãè¡ãããšãå¯èœã«ãªããŸãã
äžèšã¯ã2å°ã® ESXi ãã¹ããååšãããããã¯ãŒã¯ä»®æ³åãšåæ£ã«ãŒãã£ã³ã°ãæå¹ãšãªã£ãç°å¢ã衚ããŠããŸããå ESXi ãã¹ãå
ã«è«çã«ãŒã¿ã«ãŒãã«ã¢ãžã¥ãŒã«ãæ§æããã2ã€ã®ãããã¯ãŒã¯ãæ¥ç¶ãããŠããŸããè«çã«ãŒã¿ã«ãŒãã«ã¢ãžã¥ãŒã«ã¯ã«ãŒãã£ã³ã°ããŒãã«ãæã¡ãç°ãªãL2ãããã¯ãŒã¯éã®éä¿¡ãè¡ãªãããéã«ã«ãŒãã£ã³ã°åŠçãè¡ãªããŸãã
å®éã«åæ£ã«ãŒãã£ã³ã°ãè¡ãªãããç¶æ³ãèŠãŠã¿ãŸããããäžèšã¯åäžã® ESXi ãã¹ãäžã«ååšãã2ã€ã®ä»®æ³ãã·ã³ VM-AãVM-C ãéä¿¡ãè¡ãªãæ§åã瀺ããŠããŸããVM-A 㯠VXLAN 5001 (172.16.10.0/24) ã«æ¥ç¶ãVM-C ã¯VXLAN 5002 (172.16.20.0/24) ã«æ¥ç¶ããŠããããã2ã€ã®ä»®æ³ãã·ã³éã§éä¿¡ããããã«ã¯ã«ãŒãã£ã³ã°ãå¿
èŠã§ããVM-A ããéä¿¡ããããã±ãã㯠ESXi ãã¹ãå
ã®è«çã€ã³ã¿ãŒãã§ã€ã¹ïŒLIFïŒãå®å
ãšãã L2 ããããã€ããããŠéä¿¡ãããè«çã«ãŒã¿ã«ãŒãã«ã¢ãžã¥ãŒã«ã«å±ããŸããè«çã«ãŒã¿ã«ãŒãã«ã¢ãžã¥ãŒã«ã¯åãåã£ããã±ãããã«ãŒãã£ã³ã°åŠçã VM-C ã«å±ããŸãã
ã§ã¯ãå®éã«åæ£ã«ãŒãã£ã³ã°ç°å¢ã®ã«ãŒãã£ã³ã°ããŒãã«ã確èªããŸããããããã§ã¯ããŒãã«ã®æ
å ±ãã©ãããå
±æãããŠãããããšããç¹ã確èªããããã«ãè«çã«ãŒã¿ã³ã³ãããŒã«VMãNSX ã³ã³ãããŒã©ãå ESXi ãã¹ãå
ã®è«çã«ãŒã¿ã«ãŒãã«ã¢ãžã¥ãŒã«ããããã«ã€ããŠã«ãŒãã£ã³ã°ããŒãã«ã確èªããŸãã
è«çã«ãŒã¿ã«ãŒãã«ã¢ãžã¥ãŒã«ã®æã€ã«ãŒãã£ã³ã°æ
å ±ã¯ãè«çã«ãŒã¿ã³ã³ãããŒã«VM ã«èšå®ããè«çã€ã³ã¿ãŒãã§ã€ã¹ïŒLIFïŒæ
å ±ãéçã«èšå®ãããã«ãŒãã£ã³ã°æ
å ±ãåçã«åŸãããã«ãŒãã£ã³ã°æ
å ±ãåºã«ãªã£ãŠããŸããè«çã«ãŒã¿ã³ã³ãããŒã«VM ã®è«çã€ã³ã¿ãŒãã§ã€ã¹ãšéçãªã«ãŒãã£ã³ã°ã¯ vSphere Web Client ããèšå®ããããšãã§ãããã®æ
å ±ã¯ NSX Manager ãä»ããŠè«çã«ãŒã¿ã³ã³ãããŒã«VM ã«äŒããããŸããåçã«ãŒãã£ã³ã°ã«ã€ããŠã¯ãè«çã«ãŒã¿ã³ã³ãããŒã«VM ãå€éšã®ã«ãŒã¿ãšãã€ãããã¯ã«ãŒãã£ã³ã°ãããã³ã«ïŒOSPF, BGPïŒãä»ããŠæ
å ±ã亀æããŸãã
ãã®ããã«ããŠåŸãããè«çã«ãŒã¿ã³ã³ãããŒã«VM ã®æã€ã«ãŒãã£ã³ã°ããŒãã«ã瀺ããŸãã
> show ip route
S 0.0.0.0/0 [1/1] via <å€éšã«ãŒã¿IP>
C 172.16.10.0/24 [0/0] via 172.16.10.254
C 172.16.20.0/24 [0/0] via 172.16.20.254
ã«ãŒãã£ã³ã°ããŒãã«ïŒè«çã«ãŒã¿ã³ã³ãããŒã«VMïŒ
è«çã«ãŒã¿ã³ã³ãããŒã«VM ãåŸãã«ãŒãã£ã³ã°ããŒãã«æ
å ±ã¯ãNSX ã³ã³ãããŒã©ã¯ã©ã¹ã¿ãä»ããŠå ESXi ãã¹ãã«äŒããããŸããã³ã³ãããŒã©ã¯ã©ã¹ã¿ã¯åœ¹å²ãåæ
ããŠãããããè«çã«ãŒã¿ã³ã³ãããŒã«VM ã®ã«ãŒãã£ã³ã°ããŒãã«ã¯ãã®ç®¡çãæ
ã NSX ã³ã³ãããŒã© ã®ã¿ãæã¡ãŸããè©²åœ ã® NSX ã³ã³ãããŒã© ãããã«ãŒãã£ã³ã°ããŒãã«æ
å ±ã確èªã§ããŸãã
# show control-cluster logical-routers routes 0x570d4554
LR -Id Destination Next-Hop[] Preference
0x570d4554 0.0.0.0/0 <å€éšã«ãŒã¿IP> 1
ã«ãŒãã£ã³ã°ããŒãã«ïŒNSX ã³ã³ãããŒã©ïŒ
# show control-cluster logical-routers interface-summary 0x570d4554
Interface Type Id IP[]
570d455400000002 vxlan 0x1388 172.16.10.254/24
570d45540000000a vxlan 0x138d 172.16.20.254/24
è«çã€ã³ã¿ãŒãã§ã€ã¹ïŒNSX ã³ã³ãããŒã©ïŒ
NSX ã³ã³ãããŒã©ãæã€ã«ãŒãã£ã³ã°æ
å ±ãå ESXi ãã¹ãå
ã«ååšããè«çã«ãŒã¿ã«ãŒãã«ã¢ãžã¥ãŒã«ã«é
ä¿¡ãããŸãã
# net-vdr --route default+edge-2 -l
Destination GenMask Gateway Flags Ref Origin Uptime Interface
----------- ------- ------- ----- --- ------ ------ ---------
0.0.0.0 0.0.0.0 å€éšã«ãŒã¿IP UG 1 AUTO 1960358 570d455400000002
172.16.10.0 255.255.255.0 0.0.0.0 UCI 9 MANUAL 1971591 570d45540000000a
172.16.20.0 255.255.255.0 0.0.0.0 UCI 1 MANUAL 1971560 570d45540000000b
ã«ãŒãã£ã³ã°ããŒãã«ïŒESXi ãã¹ãïŒ
ïŒè£è¶³ïŒäžå³ã忣ã«ãŒãã£ã³ã°ç°å¢ã§ã®ã«ãŒãã£ã³ã°æ
å ±ã®äŒéãã®æ§æã§ã¯ãè«çã«ãŒã¿ã³ã³ãããŒã«VM ããå€éšã«ãŒã¿ã«å¯ŸããOSPF çµç±ã§å
éšãããã¯ãŒã¯æ
å ±ïŒ172.16.10.0/24 åã³172.16.20.0/24ïŒãéç¥ããŠããŸããããã«ãããå€éšãããã¯ãŒã¯ãšå
éšãããã¯ãŒã¯éã®éä¿¡ãå¯èœã«ãªããŸãã
â ç©çãããã¯ãŒã¯ç°å¢ãšãããã¯ãŒã¯ä»®æ³åç°å¢ã®æ¯èŒ
ç©çãããã¯ãŒã¯ç°å¢ãšãããã¯ãŒã¯ä»®æ³åç°å¢ã«ã€ããŠãã«ãŒãã£ã³ã°ã®é¢ã§æ¯èŒããŸãã
ç©çãããã¯ãŒã¯ç°å¢ã§ã¯ãã«ãŒãã£ã³ã°ããŒãã«ã¯ç©çã«ãŒã¿ãæã¡ãåäžã®ãã€ã³ãã§ã«ãŒãã£ã³ã°åŠçã宿œããŠããŸããïŒéäžåŠçïŒããŸããè€æ°ã®ç©çã«ãŒã¿ããããããªæ§æã§ã¯åã
ã®ããŒããŠã§ã¢ã«å¯ŸããŠèšå®äœæ¥ãè¡ãããšã«ãªããŸãïŒåæ£ç®¡çïŒã
äžæ¹ã§ãããã¯ãŒã¯ä»®æ³åç°ã®åæ£ã«ãŒãã£ã³ã°ã¯ããã€ããŒãã€ã¶å
ã§ã«ãŒãã£ã³ã°ããŒãã«ã忣ããŠæã€ããšã§ãè€æ°ã®ãã€ã³ãã§ã«ãŒãã£ã³ã°åŠçã宿œããŸãã
ãã€ã³ã1 ãã€ããŒãã€ã¶ã§ã«ãŒãã£ã³ã°æ
å ±ãæã¡ãåäž ESXi ãã¹ãäžã®ä»®æ³ãã·ã³éã®ã«ãŒãã£ã³ã°ã¯ãã¹ãå
ã§åŠçããããšãã§ãããããEast-West ãã©ãã£ãã¯ãæé©åã§ããïŒããŒã¿ãã¬ãŒã³ã«ããã忣åŠçïŒ
åãã€ããŒãã€ã¶ã®æã€ã«ãŒãã£ã³ã°ããŒãã«ã®å¶åŸ¡ã¯ãè«çã«ãŒã¿ã³ã³ãããŒã«VM åã³ NSX ã³ã³ãããŒã©ã¯ã©ã¹ã¿ã§éçŽããŠè¡ããŸãã
ãã€ã³ã2 è«çã«ãŒã¿ã³ã³ãããŒã«VM åã³ NSX ã³ã³ãããŒã©ã¯ã©ã¹ã¿ã§ã«ãŒãã£ã³ã°æ
å ±ãéäžããŠå¶åŸ¡ããããšã«ãããè€æ°ã®ãã€ããŒãã€ã¶éã§ã«ãŒãã£ã³ã°ããŒãã«ãå
±æããããšãã§ããïŒã³ã³ãããŒã«ãã¬ãŒã³ã«ãããéäžå¶åŸ¡ïŒ
忣ã«ãŒãã£ã³ã°ç°å¢ã®ã»ããã¢ããã¯ãNSX Manager ãä»ããŠãGUI ãããã¯API çµç±ã§ç°¡åã«è¡ãããšãåºæ¥ãŸãã
ãã€ã³ã3 NSX Manager ããäžæ¬ããŠèšå®ç®¡çãè¡ãããšã§ãéçšç®¡çæ§ãæãªãããšãªã容æã«å®è£
ã§ããïŒãããžã¡ã³ããã¬ãŒã³ã«ãããéäžç®¡çïŒ
ãããã¯ãŒã¯ä»®æ³åç°å¢ã«ããã忣ã«ãŒãã£ã³ã°ã¯ã忣åŠçãéäžå¶åŸ¡ãéäžç®¡çã®ã¢ãããŒãããšãããšã§ãéçšç®¡çæ§ãç¶æãã€ã€ãå¹çãã East-West ãã©ãã£ãã¯ãåŠçããããšãå¯èœã«ããŠããŸãã
â è£è¶³æ
å ± 忣ã«ãŒãã£ã³ã°ãæäŸãã VMware NSX ã®ã³ã³ããŒãã³ã
忣ã«ãŒãã£ã³ã°ç°å¢ã§ãNSX ãæ§æããåã³ã³ããŒãã³ããã©ããã£ã圹å²ãæãããŠããã®ã解説ãè¡ããŸãã
ã»NSX ManagerïŒãããžã¡ã³ããã¬ãŒã³ïŒ
NSX ãæ§ç¯ããéã«æåã«å±éããã³ã³ããŒãã³ãã§ãä»®æ³ã¢ãã©ã€ã¢ã³ã¹ãšããŠæäŸãããŠããŸããNSX Manager ã¯åææ§ç¯æã® ESXi ãã¹ããžã®ã«ãŒãã«ã¢ãžã¥ãŒã«ã®ã€ã³ã¹ããŒã«ããè«çã«ãŒã¿ã³ã³ãããŒã«VM ãNSX Edge ãšãã£ãä»®æ³ã¢ãã©ã€ã¢ã³ã¹ã®æãåºããæ
ããŸãããŸããNSX Manager ã¯API ã®ãšã³ããªãã€ã³ããšãªããGUI ã ãã§ãªãAPI çµç±ã§NSX ç°å¢ã®èšå®ãå¯èœã«ããŸãã
ã»NSX ã³ã³ãããŒã©ã¯ã©ã¹ã¿ïŒã³ã³ãããŒã«ãã¬ãŒã³ïŒ
NSX ã³ã³ãããŒã©ã¯ã©ã¹ã¿ã¯ãçŸæç¹ã§3å°ã®ä»®æ³ã¢ãã©ã€ã¢ã³ã¹ã§æ§æããããšãæšå¥šããŠããã忣ã«ãŒãã£ã³ã°ç°å¢ã«ãããŠãåçš®æ
å ±ïŒè«çã€ã³ã¿ãŒãã§ã€ã¹ãã«ãŒãã£ã³ã°ããŒãã«ïŒãéäžç®¡çãããã€ã³ãã«ãªããŸããåŸè¿°ã®è«çã«ãŒã¿ã³ã³ãããŒã«VM æ¯ã«æ
åœããã³ã³ãããŒã©ã決ããããäŸãã°2ã€ã®ããã³ããããå Žåãè«çã«ãŒã¿ã³ã³ãããŒã«VM ïŒããã³ãAïŒã¯ã³ã³ãããŒã©1çªãïŒããã³ãBïŒã¯ã³ã³ãããŒã©2çªãšããããã«åœ¹å²ãå²ãåœãŠãããŸããããŒãã«æ
å ±ã¯ãæ
åœããã³ã³ãããŒã©ã®ã¿ãä¿æããŸãã
3å°ã®ã³ã³ãããŒã©ïŒ192.168.110.201,192.168.110.202,192.168.110.203ïŒã§æ§æãããŠããç°å¢ã§ãè«çã«ãŒã¿ã®æ
å ±ã確èªããæé ã¯äžèšã®ãšããã§ãã
# show control-cluster logical-routers instance all
LR-Id LR-Name Hosts[] Edge-Connection Service-Controller
0x570d4554 default+edge-2 192.168.210.51 192.168.110.201
192.168.110.52
192.168.110.51
192.168.210.52
192.168.210.56
0x570d4553 default+edge-3 192.168.110.202
ãã®åºåçµæãããè«çã«ãŒã¿ã³ã³ãããŒã«VM ã®ã€ã³ã¹ã¿ã³ã¹ã2ã€ããããšãåãããŸããdefault+edge-2ïŒ0x0x570d4554ïŒã¯ã192.168.110.201 ã管çããdefault+edge-3ïŒ0x570d4553ïŒã¯ã192.168.110.202 ã®ã³ã³ãããŒã©ã管çããŠããããšãåãããŸããè«çã«ãŒã¿ã®æ
å ±ãèŠãããã«ã¯è©²åœã®ã³ã³ãããŒã©ã«ãã°ã€ã³ããå¿
èŠããããŸããïŒ192.168.110.201 ã®ã³ã³ãããŒã©ã§æ
å ±ãåºåããŠãããããèªèº«ã®æ
åœããŠããã€ã³ã¹ã¿ã³ã¹ default+edge-2 ã«é¢é£ãã ESXi ãã¹ãã® IP æ
å ±ãåºåãããŠããŸãïŒ
è«çã«ãŒã¿ default+edge-2ïŒ0x0x570d4554ïŒã®ç®¡çããã«ãŒãã£ã³ã°ããŒãã«ã®ç¢ºèª
# show control-cluster logical-routers routes 0x570d4554
LR-Id Destination Next-Hop[] Preference
0x570d4554 0.0.0.0/0 192.168.10.1 1
è«çã«ãŒã¿default+edge-2ïŒ0x0x570d4554ïŒã®ç®¡çããè«çã€ã³ã¿ãŒãã§ã€ã¹ã®ç¢ºèª
# show control-cluster logical-routers interface-summary 0x570d4554
Interface Type Id IP[]
570d455400000002 vxlan 0x1388 192.168.10.5/29
570d45540000000a vxlan 0x138d 1.1.1.254/24
ã»è«çã«ãŒã¿ã³ã³ãããŒã«VMïŒã³ã³ãããŒã«ãã¬ãŒã³ïŒ
è«çã«ãŒã¿ã³ã³ãããŒã«VMã¯åæ£ã«ãŒãã£ã³ã°ç°å¢ã«ãããŠãã«ãŒãã£ã³ã°ã®åŠçãéäžããŠè¡ãããã®ä»®æ³ã¢ãã©ã€ã¢ã³ã¹ã§ããèšå®ããã¹ã¿ãã£ãã¯ã«ãŒãã£ã³ã°æ
å ±ãããã€ãããã¯ã«ãŒãã£ã³ã°ãããã³ã«ïŒOSPF, BGPïŒçµç±ã§å€éšã®ãããã¯ãŒã¯æ©åšããåŠç¿ããã«ãŒãã£ã³ã°æ
å ±ããã³ã³ãããŒã©ã¯ã©ã¹ã¿çµç±ã§ESXi ãã¹ãã«é
ä¿¡ããŸãã
è«çã«ãŒã¿default+edge-2ïŒ0x0x570d4554ïŒã®ç®¡çããã«ãŒãã£ã³ã°ããŒãã«ã®ç¢ºèª
>ãshow ip route
S 0.0.0.0/0 [1/1] via 192.168.10.1
C 192.168.10.0/29 [0/0] via 192.168.10.5
C 1.1.1.0/24 [0/0] via 1.1.1.254
è«çã«ãŒã¿ã³ã³ãããŒã«VM ã¯ããã³ãåäœïŒã«ãŒãã£ã³ã°ããŒãã«ã®ç®¡çåäœïŒã§è€æ°ããŠãããšãã§ããŸãã
ã»è«çã«ãŒã¿ã«ãŒãã«ã¢ãžã¥ãŒã«ïŒããŒã¿ãã¬ãŒã³ïŒ
NSX ç°å¢ãæ§ç¯ããéããã¹ãã®æºåã®ã¹ãããã§å ESXi ã«ã€ã³ã¹ããŒã«ãããã«ãŒãã«ã¢ãžã¥ãŒã«ãšãªããŸããVIB(vSphere Installation Bundle)ãã¡ã€ã«ãšããŠã€ã³ã¹ããŒã«ãããã«ãŒãã«ã¢ãžã¥ãŒã«ïŒvdrbïŒãšããŠããŒããããŸããã«ãŒãã«ã¢ãžã¥ãŒã«ã¯ããã€ããŒãã€ã¶å
ã§è«çã«ãŒã¿ã®ããŒãã«ã®ç®¡çãšã«ãŒãã£ã³ã°åŠçãè¡ããŸãã
è«çã«ãŒã¿ default+edge-2ïŒ0x0x570d4554ïŒã®ç®¡çããã«ãŒãã£ã³ã°ããŒãã«ã®ç¢ºèª
# net-vdr -l --route default+edge-2
VDR default+edge-2 Route Table
Legend: [U: Up], [G: Gateway], [C: Connected], [I: Interface]
Legend: [H: Host], [F: Soft Flush] [!: Reject] [E: ECMP]
Destination GenMask Gateway Flags Ref Origin UpTime Interface
----------- ------- ------- ----- --- ------ ------ ---------
0.0.0.0 0.0.0.0 192.168.10.1 UG 1 AUTO 1724 570d455400000002
1.1.1.0 255.255.255.0 0.0.0.0 UCI 1 MANUAL 1832038 570d45540000000a
192.168.10.0 255.255.255.248 0.0.0.0 UCI 1 MANUAL 2701981 570d455400000002
ãã€ããŒãã€ã¶ããã¯ãNSX ã³ã³ãããŒã©ã¯ã©ã¹ã¿ãšãNSX Manager ã«ã³ãã¯ã·ã§ã³ã匵ããæ
å ±ã®ã¢ããããŒããè¡ããŸããNSX ã³ã³ãããŒã©ã¯ã©ã¹ã¿ãžã®ã³ãã¯ã·ã§ã³ã¯ãã€ããŒãã€ã¶å
ã® UWA (User World Agent) netcpa (TCP/1234) ãä»ããŠç¢ºç«ããNSX Manager ãžã®ã³ãã¯ã·ã§ã³ã¯ UWA vsfwd (TCP/5671) ãä»ããŠç¢ºç«ããŸãã
ã³ã³ãããŒã©ã¯ã©ã¹ã¿ãšã®æ¥ç¶ç¢ºèª
# esxcli network ip connection list | grep 1234
Proto Local Address Foreign Address State World Name
----- -------------------- -------------------- ----------- ----------
tcp 192.168.210.51:59453 192.168.110.201:1234 ESTABLISHED netcpa-worker
tcp 192.168.210.51:61471 192.168.110.202:1234 ESTABLISHED netcpa-worker
tcp 192.168.210.51:61397 192.168.110.203:1234 ESTABLISHED netcpa-worker
äžèšåºåãããESXi ãã¹ãã®ç®¡ççš IP ã¢ãã¬ã¹ãã3å°ã®ã³ã³ãããŒã©ïŒ192.168.110.201,192.168.110.202,192.168.110.203ïŒã«ãnetcpa ãä»ããŠæ¥ç¶ããŠããããšã確èªã§ããŸããã³ã³ãããŒã©ãšã®éã§åçš®ããŒãã«æ
å ±ã®äº€æãè¡ããŸãã
NSX Manager ãšã®æ¥ç¶ç¢ºèª
# esxcli network ip connection list | grep 5671
Proto Local Address Foreign Address State World Name
----- -------------------- -------------------- ----------- ----------
tcp 192.168.210.51:23251 192.168.110.42:5671 ESTABLISHED vsfwd
äžèšåºåãããESXi ãã¹ãã®ç®¡ççšIP ã¢ãã¬ã¹ãã NSX Manager ã«ãvsfwd ãä»ããŠæ¥ç¶ããŠããããšã確èªã§ããŸããNSX Manager ããã¯ã³ã³ãããŒã©ã®IP ã¢ãã¬ã¹æ
å ±ãååŸããŸãã
ãªããè«çã«ãŒã¿ã³ã³ãããŒã«VM ããã¹ãããŠããESXi ã¯ãVMCI ïŒVirtual Machine Communication InterfaceïŒ ãšåŒã°ããä»®æ³ãã·ã³-ãã€ããŒãã€ã¶éå°çšã®ãã¹ã䜿çšããã«ãŒãã£ã³ã°æ
å ±ãè«çã«ãŒã¿ã³ã³ãããŒã«VM ããååŸãESXi ãååŸããæ
å ±ãã³ã³ãããŒã©ã« netcpa çµç±ã§éç¥ããŸããã³ã³ãããŒã«ãã¬ãŒã³ã®éä¿¡ã«è«çã«ãŒã¿ã³ã³ãããŒã«VM ã®ç®¡çã€ã³ã¿ãŒãã§ã€ã¹ã¯äœ¿çšããŸããã
ã»NSX Edge ïŒããŒã¿ãã¬ãŒã³ïŒ
ä»®æ³ã¢ãã©ã€ã¢ã³ã¹ãšããŠæäŸãããåäœã§åçš®ãããã¯ãŒã¯ãµãŒãã¹æ©èœïŒããŒããã©ã³ãµãã«ãŒãã£ã³ã°ãNATããã¡ã€ã¢ãŠã©ãŒã«ãVPNã DHCP çïŒãæäŸãããã¹ã€ã¹ã®ã¢ãŒããŒãã€ããã®ãããªã³ã³ããŒãã³ãã§ããåŸæ¥ã®ç©çã®ãããã¯ãŒã¯æ©åšãä»®æ³ã¢ãã©ã€ã¢ã³ã¹ãšããŠçœ®ãæãã£ãã€ã¡ãŒãžã§ããå€éšãããã¯ãŒã¯æ©åšãšããŠè«çã«ãŒã¿ã³ã³ãããŒã«VM ãšãã€ãããã¯ã«ãŒãã£ã³ã°ãããã³ã«ã䜿çšãã«ãŒãã£ã³ã°æ
å ±ã亀æããå ŽåããããŸãããè«çã«ãŒã¿ã®æäŸãã忣ã«ãŒãã£ã³ã°ã®æ©èœãã®ãã®ã«ã¯çŽæ¥é¢äžããŸããã
â ã³ã©ã
æ°åããèŠããããã¯ãŒã¯ä»®æ³å
åœåãããã¯ãŒã¯ä»®æ³åãšèããŠéåžžã«é£ãããã«æããŸããããµãŒãä»®æ³åããŸã å匷äžã§ããããããã¯ãŒã¯ã«ã€ããŠã¯ããã«ç¥ã£ãŠããããšãå°ãªãç¶æ
ã§ããããããªãããããå匷ãé²ããŠãããšãäžå¿ãšãªã L2ãL3 ã®éä¿¡ã¯ããŒãã«ãåç
§ããŠãã±ãããæµããŠãããšããç¹ã§ã¯ç©çç°å¢ãšã»ãšãã©å€ãããŸããã§ãããå®éãç©çãããã¯ãŒã¯ãšæ¯èŒããŠæããŠããããšã§ããããã¯ãŒã¯ä»®æ³åãç©çãããã¯ãŒã¯ã®åçŸã§ãããä»®æ³ãã·ã³ãæµãããã±ããããããã°åæ§ã«åäœã§ããç°å¢ãäœãããŠããããšãããã£ãŠããŸãããNSX ã«ã¯ Manager ãã³ã³ãããŒã©ãè«çã«ãŒã¿ã³ã³ãããŒã«VM ãªã©è€æ°ã®ã³ã³ããŒãã³ãããããŸãããããããã®æã€åœ¹å²ãææ¡ããããšã§ãã¹ã ãŒãºã«çè§£ããŠãããããã«æããŸããçæ§ããã²ãäžç·ã«ãããã¯ãŒã¯ä»®æ³åãåŠãã§ãããŸãããã
â é¢é£ãªã³ã¯
ä»åã玹ä»ããå
容ããªã³ã©ã€ã³ã®ãã³ãºãªã³ç°å¢äžã§ç¢ºèªããããšãã§ããŸããã³ãã³ãã©ã€ã³ã®åºåã¯ãã³ãºãªã³ç°å¢ãããŒã¹ã«äœæããŠããŸãã
http://labs.hol.vmware.com/HOL/
VMware HOL Online
HOL-SDC-1403 - VMware NSX Introduction
NSX ã®æ©èœå
šè¬åã³ããããã¯ãŒã¯ä»®æ³åç°å¢ã®èšèšã«èå³ã®ããããã¯äžèšããã¯ããŒããŒãåç
§ãã ããã
http://www.vmware.com/files/pdf/products/nsx/vmw-nsx-network-virtualization-design-guide.pdf
VMware® NSX for vSphere (NSX-V) Network Virtualization Design Guide
ãããã¯ãŒã¯ä»®æ³åããããã¯ãŒã¯ã®åºæ¬ããçè§£ãã
第1åïŒçè§£ããããã«å¿
èŠãªããšãæŽçãã
第2åïŒè«çã¹ã€ããïŒVXLANïŒâLayer2 ã®äžç
第3åïŒåæ£ã«ãŒãã£ã³ã° âLayer3 ã®äžçïŒæ¬çš¿ïŒ
第4åïŒåæ£ãã¡ã€ã¢ãŠã©ãŒã« -Layer4 ã®äžç