public inbox for pve-user@lists.proxmox.com
 help / color / mirror / Atom feed
* Re: [PVE-User] Mapping of VLAN tags to Linux bridges: Is that possible?
@ 2024-07-22 18:39 David der Nederlanden | ITTY via pve-user
  0 siblings, 0 replies; 6+ messages in thread
From: David der Nederlanden | ITTY via pve-user @ 2024-07-22 18:39 UTC (permalink / raw)
  To: Proxmox VE user list; +Cc: David der Nederlanden | ITTY, PVE User List

[-- Attachment #1: Type: message/rfc822, Size: 14760 bytes --]

From: David der Nederlanden | ITTY <david@itty.nl>
To: Proxmox VE user list <pve-user@lists.proxmox.com>
Cc: PVE User List <pve-user@pve.proxmox.com>
Subject: Re: [PVE-User] Mapping of VLAN tags to Linux bridges: Is that possible?
Date: Mon, 22 Jul 2024 18:39:27 +0000
Message-ID: <6a5e5310-b807-4711-8625-e7e93b637047@email.android.com>

Hi Frank,

You can definitely accomplish this with SDN in PVE 8.x,
if you prefer a video explanation of it, I can recommend these two:
https://youtu.be/PyJXRwqg494?si=RAEZx5sbooqlzxiX
https://youtu.be/_lIk9p_SyvU?si=v9CAgKmG42xy1_ze

Also I recommend upgrading to PVE 8, 7 is EOL soon, which means it won't receive updates anymore, even though it will likely still work fine.

It brings great new features.

Kind regards
David der Nederlanden

On 22 Jul 2024 19:50, Frank Thommen <f.thommen@dkfz-heidelberg.de> wrote:
Dear list members,

our current three-node PVE cluster hosts VMs from three different
subnets/VLANs. Each host has - besides the network ports for the Ceph
cluster - eight physical network ports (two for the host itself and two
for each of the three VLANs). Always two ports are configured like this:

    switch port - host port (1 Gbit) \
                                      +- bond - bridge
    switch port - host port (1 Gbit) /

This is nice, because when configuring a VM, we can choose the
appropriate bridge from the network menu, which also shows me the
bridge's description, so that there can't be any mistakes as to which
brigde has to be selected. However that comes with too many cables and
too many NICs. Especially as we expect to have to support more subnets
in the near future.

Our networking department has suggested to move from dedicated switch
ports to VLAN tags. This would reduce the eight 1 Gbit ports to two 25
Gbit ports per host (LACP bonded), but as far as I can see, we would
then have to - manually - enter the correct VLAN tag number for each
virtual network device. I expect this to be very error prone and
unintuitive. Best would be, if it would be possible to create Linux
bridges which map to individual VLAN tags like this:

    switch port - host port (25 Gbit) \         / VLAN 12 - bridge1
                                       +- bond -- VLAN 56 - bridge2
    switch port - host port (25 Gbit) /         \ VLAN 25 - bridge3


but unfortunately with PVE 7.x I could not find a way to achieve this.
Is such a setup possible at all?

I've read, that PVE 8.x greatly enhances the SDN capabilities of PVE.
Will these SDN capabilities enable us, to achieve the VLAN-bridge mapping?

Thanks for any hint or pointer
Frank

_______________________________________________
pve-user mailing list
pve-user@lists.proxmox.com
https://lists.proxmox.com/cgi-bin/mailman/listinfo/pve-user



[-- Attachment #2: Type: text/plain, Size: 157 bytes --]

_______________________________________________
pve-user mailing list
pve-user@lists.proxmox.com
https://lists.proxmox.com/cgi-bin/mailman/listinfo/pve-user

^ permalink raw reply	[flat|nested] 6+ messages in thread
[parent not found: <6aee1ef2-47f5-4d1c-8600-88cd796be6e7@dkfz-heidelberg.de>]
* Re: [PVE-User] Mapping of VLAN tags to Linux bridges: Is that possible?
@ 2024-07-22 18:39 David der Nederlanden | ITTY via pve-user
  0 siblings, 0 replies; 6+ messages in thread
From: David der Nederlanden | ITTY via pve-user @ 2024-07-22 18:39 UTC (permalink / raw)
  To: Proxmox VE user list; +Cc: David der Nederlanden | ITTY, PVE User List

[-- Attachment #1: Type: message/rfc822, Size: 14753 bytes --]

From: David der Nederlanden | ITTY <david@itty.nl>
To: Proxmox VE user list <pve-user@lists.proxmox.com>
Cc: PVE User List <pve-user@pve.proxmox.com>
Subject: Re: [PVE-User] Mapping of VLAN tags to Linux bridges: Is that possible?
Date: Mon, 22 Jul 2024 18:39:27 +0000
Message-ID: <6a5e5310-b807-4711-8625-e7e93b637047@email.android.com>

Hi Frank,

You can definitely accomplish this with SDN in PVE 8.x,
if you prefer a video explanation of it, I can recommend these two:
https://youtu.be/PyJXRwqg494?si=RAEZx5sbooqlzxiX
https://youtu.be/_lIk9p_SyvU?si=v9CAgKmG42xy1_ze

Also I recommend upgrading to PVE 8, 7 is EOL soon, which means it won't receive updates anymore, even though it will likely still work fine.

It brings great new features.

Kind regards
David der Nederlanden

On 22 Jul 2024 19:50, Frank Thommen <f.thommen@dkfz-heidelberg.de> wrote:
Dear list members,

our current three-node PVE cluster hosts VMs from three different
subnets/VLANs. Each host has - besides the network ports for the Ceph
cluster - eight physical network ports (two for the host itself and two
for each of the three VLANs). Always two ports are configured like this:

    switch port - host port (1 Gbit) \
                                      +- bond - bridge
    switch port - host port (1 Gbit) /

This is nice, because when configuring a VM, we can choose the
appropriate bridge from the network menu, which also shows me the
bridge's description, so that there can't be any mistakes as to which
brigde has to be selected. However that comes with too many cables and
too many NICs. Especially as we expect to have to support more subnets
in the near future.

Our networking department has suggested to move from dedicated switch
ports to VLAN tags. This would reduce the eight 1 Gbit ports to two 25
Gbit ports per host (LACP bonded), but as far as I can see, we would
then have to - manually - enter the correct VLAN tag number for each
virtual network device. I expect this to be very error prone and
unintuitive. Best would be, if it would be possible to create Linux
bridges which map to individual VLAN tags like this:

    switch port - host port (25 Gbit) \         / VLAN 12 - bridge1
                                       +- bond -- VLAN 56 - bridge2
    switch port - host port (25 Gbit) /         \ VLAN 25 - bridge3


but unfortunately with PVE 7.x I could not find a way to achieve this.
Is such a setup possible at all?

I've read, that PVE 8.x greatly enhances the SDN capabilities of PVE.
Will these SDN capabilities enable us, to achieve the VLAN-bridge mapping?

Thanks for any hint or pointer
Frank

_______________________________________________
pve-user mailing list
pve-user@lists.proxmox.com
https://lists.proxmox.com/cgi-bin/mailman/listinfo/pve-user



[-- Attachment #2: Type: text/plain, Size: 157 bytes --]

_______________________________________________
pve-user mailing list
pve-user@lists.proxmox.com
https://lists.proxmox.com/cgi-bin/mailman/listinfo/pve-user

^ permalink raw reply	[flat|nested] 6+ messages in thread

end of thread, other threads:[~2024-07-22 19:28 UTC | newest]

Thread overview: 6+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2024-07-22 18:39 [PVE-User] Mapping of VLAN tags to Linux bridges: Is that possible? David der Nederlanden | ITTY via pve-user
     [not found] <6aee1ef2-47f5-4d1c-8600-88cd796be6e7@dkfz-heidelberg.de>
2024-07-22 19:18 ` Bastian Sebode via pve-user
2024-07-22 19:23   ` David der Nederlanden | ITTY via pve-user
2024-07-22 19:27     ` Gilberto Ferreira
     [not found]   ` <7de79cbf-90d0-40e2-87ec-dde2f6b21f0c@email.android.com>
2024-07-22 19:28     ` Bastian Sebode via pve-user
  -- strict thread matches above, loose matches on Subject: below --
2024-07-22 18:39 David der Nederlanden | ITTY via pve-user

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
Service provided by Proxmox Server Solutions GmbH | Privacy | Legal