PVE中VLAN的设置要点

使用这个拓扑进行连接无法直接访问PVE

PVE 设置如下:

核心重点:PVE 的 vmbr0 接口直接绑定了 enp2s0,这会导致 VLAN 流量无法正确处理,因为 PVE 没有专门为 VLAN 3 配置接口。

1.vmbr0 和 vmbr0.3 都是绑定在物理接口 enp2s0 上,PVE 会视它们为两个逻辑接口。

2.如果 vmbr0 和 vmbr0.3 的 CIDR 不同,系统可能会优先使用 vmbr0 的路由表(取决于默认路由或优先级设置),导致无法正确处理通过 VLAN 3 的流量。

将enp2s0的CIDR 删除重新配置

第一种

第二种( Linux bridge 在设置的需要注意,vmbr0.3 在从属于vmbr2 时是不许拥有CIDR的 ) 

综上即可通过192.168.10.4 和192.168.10.3 等任意设置IP随时访问PVE 

优化版拓扑图

The first path (light-blue arrows): Egress mirroring is enabled on Sample port X by EPCL. An EPCL rule matches the packet, assigns it any of the target analyzer IDs (1-7), and triggers a PHA thread to save target information into the copy-reserved descriptor field. The Egress Replication Engine (EREP) duplicates packet descriptor, and assigns the mirrored packet to the target analyzer ID configured by EPCL. Then, the pre-Egress engine (EQ) maps the target analyzer ID to Analyzer port (loopback port Y). A second EPCL rule matches the mirrored packet, and binds it to a second PHA thread. This second PHA thread adds an sFlow header prefixing the mirrored packet; this header incorporate most of the header fields except those of the tunnel header. PTP TSU (TimeStamping Unit) adds a Tx timestamp to the sFlow header. Port Y is set as a loopback port. The second path (blue arrows): Once packet is looped back to pipeline, a Private VLAN Edge (PVE), or an IPCL rule, matches the looped back traffic, and assigns a target ePort with a Tunnel start attribute. The ePort to Physical port (E2PHY) maps the target ePort to an output port, from which it is streamed to a Collector unit. A third EPCL rule matches the looped back traffic, and binds it to a third PHA thread, which sets the tunnel start field in the sFlow header. CPSS Implementation Considerations The application is responsible for setting the following CPSS parameters: Sampling Port, formatted as dev_id/port_num, and sampling rate 1:N Target analyzer ID: ranged 1-7 Target ePort number for Tunnel start Analyzer port number – loopback port Y in illustration Tunnel Start (TS) entry pointer Physical Analyzer port, formatted as dev_id/port_num, connected to the Collector unit – output port A in illustration Analyzer Node IP address – 32bits representing dev_id, and used for setting IP_High and IP_Low fields Second EPCL rule NOTE: The second EPCL rule priority must be higher than that of the first one Match mirrored traffic, and trigger the second PHA thread THR66_enhanced_sFlow Key: UDB Metadata <Egress Mtag Cmd> = TO_ANALYZER UDB Metadata <Analyzer Target ePort> = Analyzer port number (loopback port Y) Action: Disable OAM engine by <OAM Processing En> = 0. PHA counts Packet number with flow ID as index Use analyzer ID as flow index by <Flow-ID> = Target analyzer ID. Flow index is used by second PHA thread THR66_enhanced_sFlow <PHA Thread Number Assignment Enable> = 1 <PHA Thread number> = THR66_enhanced_sFlow 为何在这个过程中禁用OAM 依据是什么 设置flow-ID目的是什么
09-29
评论
成就一亿技术人!
拼手气红包6.0元
还能输入1000个字符
 
红包 添加红包
表情包 插入表情
 条评论被折叠 查看
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值