VMware VSHIELD MANAGER 4.1.0 UPDATE 1 - API Instrukcja Użytkownika Strona 154

  • Pobierz
  • Dodaj do moich podręczników
  • Drukuj
Przeglądanie stron 153
vShield Administration Guide
154 VMware, Inc.
Port Id isthefirstcolumninallothertables(ActivePorts,SwitchState,andPortstats).Thisisaunique
identifierassignedbythevshdmoduleforeachfenceenabledport.ThisIDisinternalandhasnoexternal
meaning.Itisthedvfilternameforthatporttypecastedto
Uint64.TheportIDisusefultoqueryvaluesfora
specificportusingthefenceutilportInfo <portId>commandwhichoutputsdetailsofonlyoneport.
Active Portsshowsalltheports/vNICswherefencingisactive.ThisincludesthemirrorvNICs.Yourfirst
hosthasfiveportsenabledforfencing,twoofwhich
aremirrorvNICs.ThemirrorvNICscanbeidentifiedby
aspecialfenceIDoffffffe.TheOPIcolumnindicatesthefenceID.Inyoursetup,thefirsthosthasonefence
withID000001.ThenextcolumnindicatesLanId?configuredforthatport.Thisisanindicationofwhich
vSwitchtheportsmightbeconnectedto.Intheoutputbelow,yourfirsthosthastwovSwitches(legacy+
dvswitches).OnehasbeenassignedLanId?1andtheotheronehasLanId?2.Thus,youseetwomirrorvirtual
machinevNICs(oneforeachvSwitch)withdifferentLanIds?inactive
ports.
Switch Stateshowsthelearningtableoftheinternalunicastlearninginfencemodule.InnerMACmeans
theMACofdestinationVM,theouterMACmeansthehostkeyMACofthehostonwhichthisVMispresent.
Thelearningbuildsthistablebylookingatpacketsandittriesto
learnwhichVMisonwhichhost.Thisway,
whenoneVMonthathosttriestoreachanothervirtualmachine,thistableislookedup.Ifthedestination
VMʹsmacisseenintheinnerMACcolumn,thentheOuterMac?isusedasthedestinationhostkeymactobe
put
intheOuterMACheaderaddedbythefencemodule.Ifanentryisnotfoundhere,suchapacketwillbe
broadcast(outerMACheaderʹsdestinationMACwillbesettobroadcast.).Likeanyotherlearningsystem,this
onealsohasmechanismstotimeout/modifylearnt
entries.ThiswilltakecareofthingslikeVMsmovingto
differenthostsortomakesurethatthetabledoesnotgrowtoomuchinsizewithstalemacentries.The
used/age/seenbitsrepresenttheflagsusedbyfencemoduletotrackfrequencyoftheseMACentries.The
learningis
doneonaperportlevel,henceyouwouldseethesameinnerMAC‐outerMACpairsondifferent
ports.ThistablealsoshowssamehostkeymacinouterMACsectionsbecauseevenforVMsonthesamehost,
thesamecodeisusedwhereapacketisencapsulatedand
sentfromsourceportanddecapsulatedonthe
destinationport.ThereisnooptimizationforsamehostVMs.ThusforVMsonthesamehost,theouterMAC
willbehostkeyMACofthesamehost.
Port Statisticsshowspacketstatsonaperportbasis.Oneportperrow.Thefromand
Tovmstatsindicate
packetstoandfromvm.Thesubcategoriesindicatethespecificsaboutthepacket.Thedetailsofeachcounter
areinthefollowingstructure.Letmeknowifyouneedanymoreinfoonthis.
Troubleshooting vShield Edge Issues
Virtual Machines Are Not Getting IP Addresses from the DHCP Server
To determine why protected virtual machines are not being assigned IP addresses by a vShield Edge
1VerifyDHCPconfigurationwassuccessfulonthevShieldEdgebyrunningtheCLIcommand:show
configuration dhcp.
2CheckwhetherDHCPserviceisrunningonthevShieldEdgebyrunningCLIcommand:show service
dhcp
3EnsurethatvmniconvirtualmachineandvShieldEdgeisconnected(vCenter>VirtualMachine>Edit
Settings
>NetworkAdapter>Connected/ConnectatPowerOncheckboxes).
WhenbothavShieldAppandvShieldEdgeareinstalledonthesameESXhost,disconnectionofNICs
canoccurifavShieldAppisinstalledafteravShieldEdge.
Load-Balancer Does Not Work
To determine why the load balancer service on a vShield Edge is not working
1VerifythattheLoadbalancerisrunningbyrunningtheCLIcommand:show service lb.
Loadbalancercanbestartedbyissuingthestartcommand.
2Verifytheloadbalancerconfigurationbyrunningcommand:show configuration lb.
Thiscommandalsoshowsonwhichexternalinterfacesthelistenersarerunning.
Przeglądanie stron 153

Komentarze do niniejszej Instrukcji

Brak uwag