VLAN configuration for admin partitions
-
A NetScaler appliance deployed on any hypervisor (ESX, KVM, Xen, and Hyper-V) platform must comply with both the following conditions in a partition setup and traffic domain:
-
Enable the promiscuous mode, MAC changes, MAC spoofing, or forged transmit for shared VLANs with partition.
-
Enable the VLAN with port group properties of the virtual switch, if the traffic is through a dedicated VLAN.
-
-
In a partitioned (multitenant) NetScaler appliance, a system administrator can isolate the traffic flowing to a particular partition or partitions. It is done by binding one or more VLANs to each partition. A VLAN can be dedicated to one partition or Shared across multiple partitions.
-
Internal routing between partitions that are hosted on the same NetScaler appliance is not supported.
Dedicated VLANs
-
Add a VLAN (V1).
-
Bind a network interface to VLAN as a tagged network interface.
-
Create a partition (P1).
-
Bind partition (P1) to the dedicated VLAN (V1).
Configure the following by using the CLI
-
Create a VLAN
add vlan <id>
add vlan 100
-
Bind a VLAN
bind vlan <id> -ifnum <interface> -tagged
bind vlan 100 –ifnum 1/8 -tagged
-
Create a partition
Add ns partition <partition name> [-maxBandwidth <positive_integer>][-maxConn <positive_integer>] [-maxMemLimit <positive_integer>]
Add ns partition P1 –maxBandwidth 200 –maxconn 50 –maxmemlimit 90
Done
-
Bind a partition to a VLAN
bind partition <partition-id> -vlan <id>
bind partition P1 –vlan 100
Configure a dedicated VLAN by using the NetScaler GUI
-
Navigate to Configuration > System > Network > VLANs* and click Add to create a VLAN.
-
On the Create VLAN page, set the following parameters:
-
VLAN ID
-
Alias Name
-
Maximum Transmission Unit
-
Dynamic Routing
-
IPv6 Dynamic Routing
-
Partitions Sharing
-
-
In the Interface Bindings section, select one or more interfaces and bind it to the VLAN.
-
In the IP Bindings section, select one or more IP addresses and bind to the VLAN.
-
Click OK and Done.
Shared VLAN
-
Create a VLAN with the sharing option ‘enabled’, or enable the sharing option on an existing VLAN. By default, the option is ‘disabled’.
-
Bind partition interface to shared VLAN.
-
Create the partitions, each with its own PartitionMAC address.
-
Bind the partitions to the shared VLAN.
Configure a shared VLAN by using the CLI
add vlan <id> [-sharing (ENABLED | DISABLED)]
set vlan <id> [-sharing (ENABLED | DISABLED)]
add vlan 100 –sharing ENABLED
set vlan 100 –sharing ENABLED
Bind a partition to a Shared VLAN by using the CLI
bind partition <partition-id> -vlan <id>
bind partition P1 –vlan 100
add ns partition P1 –maxBandwidth 200 –maxconn 50 –maxmemlimit 90 -partitionMAC<mac_addr
Done
Configure a Partition MAC Address by using the CLI
set ns partition <partition name> [-partitionMAC<mac_addr>]
set ns partition P1 –partitionMAC 22:33:44:55:66:77
Bind partitions to a shared VLAN by using the CLI
bind partition <partition-id> -vlan <id>
bind partition <partition-id> -vlan <id>
bind partition P1 –vlan 100
bind partition P2 –vlan 100
bind partition P3 –vlan 100
bind partition P4 –vlan 100
Configure Shared VLAN by using the NetScaler GUI
-
Navigate to Configuration > System > Network > VLANs and then select a VLAN profile and click Edit to set the partition sharing parameter.
-
On the Create VLAN page, select the Partitions Sharing check box.
-
Click OK and then Done.
Dynamic routing over a shared VLAN across admin partitions
Before you begin
-
Dynamic routing is configured on the shared VLAN in the default partition. Configuring dynamic routing on the shared VLAN in the default partition consists of the following steps:
-
Enable dynamic routing on the shared VLAN.
-
Add a SNIP IP address with dynamic routing enabled. This SNIP IP address is used for dynamic routing with the upstream.
-
Bind the SNIP IP subnet to the shared VLAN.
-
-
One or more dynamic routing protocol is configured on the default partition. For more information, see configure dynamic routing protocols.
Configuration steps
-
Add a SNIP IP address in the non-default partition. This SNIP IP address must be in the same subnet of the SNIP IP address that is being used for dynamic routing in the default partition.
-
Set or enable the following parameters for advertising a VIP address, in a non-default partition, using dynamic routing.
-
Host route gateway (hostRtGw). Set this parameter to the SNIP address added in the preceding step.
-
Advertise on default partition (advertiseOnDefaultPartition). Enable this parameter.
-
Sample configuration
| Steps | Sample configuration |
|---|---|
| On default admin partition | - |
| Enable dynamic routing on shared VLAN 100. | set vlan 100 -dynamicRouting enabled |
| Add SNIP IP address 192.0.2.10 with dynamic routing enabled. This SNIP IP address is used for dynamic routing with the upstream. | add ns ip 192.0.2.10 255.255.255.0 -type SNIP -dynamicRouting enabled |
| Bind subnet of 192.0.2.10 to shared VLAN 100. | bind vlan 100 -IPAddress 192.0.2.10 255.255.255.0 |
| On non-default admin partition AP-3 | - |
| Add SNIP IP address 192.0.2.30. This SNIP IP address is in the same subnet as the SNIP IP address 192.0.2.10 on the default partition. | add ns ip 192.0.2.30 255.255.255.0 -type SNIP |
For advertising VIP address 203.0.113.300 using dynamic routing, enable advertiseOnDefaultPartition parameter and set hostRtGw parameter to 192.0.2.30. |
set ns ip 203.0.113.300 255.255.255.255 -hostRoute enabled -advertiseOnDefaultPartition enabled -hostRtGw 192.0.2.30 |
Dynamic routing of IPv6 over a shared VLAN across admin partition
enable ns feature IPv6PT and set L3Param –ipv6DynamicRouting ENABLED commands must be enabled for an IPv6 address to dynamically route over a shared VLAN in an admin partition. The following sample configurations help you to configure dynamic routing of IPv6 over shared VLAN.
Sample configuration
| Steps | Sample configuration |
|---|---|
| On default admin partition | - |
| Enable dynamic routing on shared VLAN 100. | set vlan 100 -dynamicRouting enabled |
| Add SNIP IP address 2001:b:c:d::1/64 with dynamic routing enabled. The SNIP IP address is used for dynamic routing with the upstream. | add ns ip6 2001:b:c:d::1/64 -type SNIP -dynamicRouting enabled |
| Bind subnet of 2001:b:c:d::1/64 to shared VLAN 100. | bind vlan 100 -IPAddress 2001:b:c:d::1/64 |
| On non-default admin partition AP-3 | - |
| Add SNIP IP address 2001:b:c:d::2/64. This SNIP IP address is in the same subnet as the SNIP IP address 2001:b:c:d::2/64 on the default partition. | add ns ip6 2001:b:c:d::2/64 -type SNIP |
For advertising VIP address 2002::1/128 using dynamic routing, enable advertiseOnDefaultPartition parameter and set ip6hostRtGw parameter to 2001:b:c:d::2. |
set ns ip6 2002::1/128 -hostRoute enabled -advertiseOnDefaultPartition enabled -ip6hostRtGw 2001:b:c:d::2 |
> switch partition default
Done
>vtysh
ns#
ns# sh ipv6 route kernel
IPv6 routing table
Codes: K - kernel route, C - connected, S - static, R - RIP, O - OSPF,
IA - OSPF inter area, E1 - OSPF external type 1,
E2 - OSPF external type 2, I - IS-IS, B - BGP
Timers: Uptime
K 2002::1/128 via 2001:b:c:d::2, vlan0, 01:24:15 >> on Default Partition, VIP : 2002::1 present in AP known via SNIP6 : 2001:b:c:d::2 is present in AP as a Kernel Route
ns# sh run router ipv6 ospf
!
router ipv6 ospf 1
redistribute kernel
!
Shared VLAN with admin partition on NetScaler SDX appliance
-
Using a base MAC address
-
Specifying custom MAC addresses
-
Randomly generating MAC addresses
-
The randomly generating MAC addresses are used for other deployments other than high availability.
-
After generating the partition MAC addresses, you must restart the NetScaler instance before configuring the admin partitions. For more information on generating partition MAC addresses from the SDX appliance, see Generating Partition MAC Addresses to Configure Admin Partition on a NetScaler instance in the SDX Appliance.