ip netns add foo python
ip netns linux
ip netns exec foo ip addr git
ip netns exec foo ip link set lo up github
ip netns exec foo ip addr 網絡
ip netns exec foo route –n spa
ip netns exec foo iptables -t nat –S 3d
ip link add tap-foo type veth peer name tap-root rest
ip link router
使用ethtool確認屬於成對設備: xml
ip link set tap-foo netns foo
ip netns exec foo ip link
ip netns exec foo ip link set tap-foo up
root的ns看不到foo-tap了:
ip netns exec foo ip addr add 88.88.88.100/24 dev tap-foo
ip netns exec foo ifconfig
ip addr add 88.88.88.101/24 dev tap-root
ip link set tap-root up
ifconfig
ip netns exec foo ping 10.20.0.88
ip netns exec foo route add -net 0.0.0.0 netmask 0.0.0.0 gw 88.88.88.101
ip netns exec foo route –n
ip netns exec foo ping 10.20.0.88
network1
eth0:10.20.0.201 (management network)
eht1:172.16.0.201 (public/external network)
eht2:192.168.4.201 (private network,gre tunning)
compute1
eth0:10.20.0.202 (management network)
eht1:(disabled)
eht2:192.168.4.202 (private network,gre tunning)
安裝必備軟件包:yum install libvirt openvswitch python-virtinst xauth tigervnc –y
yum install kvm qemu-kvm qemu-kvm-tools
yum install bridge-utils qemu-img
yum install python-virtinst virt-manager virt-viewer
yum install libvirt libvirt-client
reboot -h 0,vm重啓生效。
virsh net-destroy default
virsh net-autostart --disable default
virsh net-undefine default
virsh net-list
vi /etc/sysctl.conf
net.ipv4.ip_forward=1
net.ipv4.conf.all.rp_filter=0
net.ipv4.conf.default.rp_filter=0
sysctl –p,當即生效。
service openvswitch start
chkconfig openvswitch on
brctl addbr qbr01
ip link set qbr01 up
brctl show
ifconfig
mkdir -p /var/tmp/gre
mv instance1.img instance1.xml /var/tmp/gre
instance文件參考:
https://github.com/yongluo2013/osf-openstack-training/blob/master/installation/gre/instance1.xml
cd /var/tmp/gre
virsh define instance1.xml
virsh start instance1
virsh vncdisplay instance1
vncviewer :0
vncviewer進入虛擬機。
sudo ip addr add 192.168.1.11/24 dev eth0
sudo route add default gw 192.168.1.1
ovs-vsctl add-br br-int
ovs-vsctl add-port br-int gre0 -- set interface gre0 type=gre options:remote_ip=192.168.4.202
ip link add qvo01 type veth peer name qvb01
brctl addif qbr01 qvb01,設置qvb01爲qbr01的接口
ovs-vsctl add-port br-int qvo01
ovs-vsctl set port qvo01 tag=100
ip link set qvb01 up
ip link set qvo01 up
br-int如下的網絡設備均up起來了
brctl addbr qbr02
ip link set qbr02 up
virsh define instance2.xml
virsh start instance2
virsh vncdisplay instance2
vncviewer :0
sudo ip addr add 192.168.1.12/24 dev eth0
sudo route add default gw 192.168.1.1
ovs-vsctl add-br br-int
ovs-vsctl add-port br-int gre0 -- set interface gre0 type=gre options:remote_ip=192.168.4.201
ip link add qvo02 type veth peer name qvb02
brctl addif qbr02 qvb02
ovs-vsctl add-port br-int qvo02
ovs-vsctl set port qvo02 tag=100
ip link set qvb02 up
ip link set qvo02 up
vm01:
vm02:
ip netns add dhcp01
ovs-vsctl add-port br-int tapdhcp01 -- set interface tapdhcp01 type=internal
ip link set tapdhcp01 netns dhcp01
ip netns exec dhcp01 ip addr add 192.168.1.2/24 dev tapdhcp01
ip netns exec dhcp01 ip link set tapdhcp01 up
vi /etc/sysconfig/network-scripts/ifcfg-eth1
DEVICE=eth1
ONBOOT=yes
BOOTPROTO=none
PROMISC=yes
MTU=1546
vi /etc/sysconfig/network-scripts/ifcfg-br-ex
DEVICE=br-ex
TYPE=Bridge
ONBOOT=yes
BOOTPROTO=none
IPADDR0=172.16.0.201
PREFIX0=24
ovs-vsctl add-port br-ex eth1
ip link set br-ex up
sudo ip addr add 172.16.0.20/24 dev br-ex
ip netns add router01
ovs-vsctl add-port br-int qr01 -- set interface qr01 type=internal
ovs-vsctl set port qr01 tag=100
ip link set qr01 netns router01
ip netns exec router01 ip addr add 192.168.1.1/24 dev qr01
ip netns exec router01 ip link set qr01 up
ip netns exec router01 ip link set lo up
ovs-vsctl add-port br-ex qg01 -- set interface qg01 type=internal
ip link set qg01 netns router01
ip netns exec router01 ip addr add 172.16.0.100/24 dev qg01
ip netns exec router01 ip link set qg01 up
ip netns exec router01 ip link set lo up
ip netns exec router01 ip addr add 172.16.0.101/32 dev qg01
ip netns exec router01 iptables -t nat -A OUTPUT -d 172.16.0.101/32 -j DNAT --to-destination 192.168.1.11
ip netns exec router01 iptables -t nat -A PREROUTING -d 172.16.0.101/32 -j DNAT --to-destination 192.168.1.11
ip netns exec router01 iptables -t nat -A POSTROUTING -s 192.168.1.11/32 -j SNAT --to-source 172.16.0.101
ip netns exec router01 iptables -t nat -A POSTROUTING -s 192.168.1.0/24 -j SNAT --to-source 172.16.0.100