åæ çãªçŽ¹ä»
管çè ãäºæããªãåé¡ïŒä»¥åã¯åäœããŠããããæŽæ°åŸã«çªç¶åæ¢ããïŒã«ééããå ŽåãæŠéãŸãã¯é£è¡ãšãã2ã€ã®å¯èœãªåäœã¢ã«ãŽãªãºã ããããŸãã ã€ãŸããåé¡ãæåŸãŸã§ç解ãããããã®æ¬è³ªãæãäžããããšãªãåé¡ããè±åºãããã®ããããã§ãã ãœãããŠã§ã¢æŽæ°ã®ã³ã³ããã¹ãã§ã¯ãããŒã«ããã¯ããŸãã
ã¢ããã°ã¬ãŒãã倱æããåŸã«ããŒã«ããã¯ãã-ããã¯æ²ãããã¹ããã©ã¯ãã£ã¹ãšèšããŸãã ããŒã«ããã¯ã®æºåæ¹æ³ãããŒã«ããã¯ã®å®è¡æ¹æ³ãããã³ããŒã«ããã¯ã«å€±æããå Žåã®å¯ŸåŠæ¹æ³ã«é¢ããããã¥ã¢ã«å šäœããããŸãã industryç ãªè¡åã®æ¥çå šäœã
å¥ã®æ¹æ³ã¯ãæåŸãç解ããããšã§ãã ããã¯èª°ãæåãçŽæããªãéåžžã«é£ããæ¹æ³ã§ãããè²»ããããåŽåã®éã¯çµæãšæ¯èŒã§ãããåºåã¯äœãèµ·ãã£ãã®ããå°ãã ãç解ããã ãã§ãã
ãã©ãã®ãããã
Webzillã®ã€ã³ã¹ã¿ã³ããµãŒããŒã¯ã©ãŠãã nova-computeãã¹ãã®å®æçãªæŽæ°ã æ°ããã©ã€ãã€ã¡ãŒãžïŒPXEããŒãã£ã³ã°ã䜿çšïŒããã«ãã£ã«ã¡ã³ãã·ã§ãã ãã¹ãŠé 調ã§ãã çªç¶ãã¯ã©ã€ã¢ã³ãããã®èŠæ ïŒãä»®æ³ãã·ã³ã®1ã€ãå¥åŠã«åäœããåäœããŠããããã«èŠããŸãããå®éã®è² è·ãå§ãŸããšããã¹ãŠãããªãŒãºããŸããã ã¯ã©ã€ã¢ã³ãã€ã³ã¹ã¿ã³ã¹ãå¥ã®ããŒãã«è»¢éãããšãã¯ã©ã€ã¢ã³ãã®åé¡ã¯è§£æ±ºããŸãã åé¡ãå§ãŸããŸãã ãã®ããŒãã§ã€ã³ã¹ã¿ã³ã¹ãèµ·åããŸãã åçïŒCirrosã§ã®sshãã°ã€ã³ãæåããUbuntuã§ã¯ããªãŒãºããŸããã ssh -vã¯ããã¹ãŠããdebug1ïŒSSH2_MSG_KEXINIT sentãã¹ããŒãžã§åæ¢ããããšã瀺ããŸãã
ãã¹ãŠã®å¯èœãªå€éšãããã°æ¹æ³ãæ©èœããŸã-ã¡ã¿ããŒã¿ãååŸãããDHCPãªãŒã¹ãã€ã³ã¹ã¿ã³ã¹ã«ãã£ãŠæŽæ°ãããŸãã ã€ã³ã¹ã¿ã³ã¹ãMTUã§DHCPãªãã·ã§ã³ãåä¿¡ããªããšããçãããããŸãã Tcpdumpã¯ããªãã·ã§ã³ãéä¿¡ãããŠããããšã瀺ããŸãããã€ã³ã¹ã¿ã³ã¹ããããåãå ¥ãããã©ããã¯äžæã§ãã
æ¬åœã«ã€ã³ã¹ã¿ã³ã¹ã«å°éãããã®ã§ãããååŸã§ããCirrosã§ã¯MTUãæ£ãããUbuntuã§ã¯MTUåé¡ã«ã€ããŠç念ããããããååŸã§ããŸããã ããããæ¬åœã«ãããã
ãããMTUã®åé¡ã§ããå Žåãçªç¶ã®ãã«ããŒãããŸãã ããã¯IPv6ã§ãã ãçœããIPv6ãå²ãåœãŠãªããšããäºå®ã«ããããããïŒç³ãèš³ãããŸããããopenstackã§ã¯ãŸã å®çšŒåã«å¯Ÿå¿ããŠããŸããïŒããªã³ã¯ããŒã«ã«IPv6ã¯æ©èœããŸãã
2ã€ã®ã³ã³ãœãŒã«ãéããŸãã ãããã¯ãŒã¯ããŒãããšã«1ã€ã ãããã¯ãŒã¯åå空éã«äŸµå ¥ããŸãã
sudo stdbuf -o0 -e0 ip net exec qrouter-271cf1ec-7f94-4d0a-b4cd-048ab80b53dc / bin / bash
ïŒstdbufã䜿çšãããšãip netã®ãããã¡ãªã³ã°ãç¡å¹ã«ããããšãã§ããŸããããã«ãããç»é¢ã®åºåããªã¢ã«ã¿ã€ã ã§è¡šç€ºãããé 延ã¯çºçããŸãããipnet execã¯ãæå®ããããããã¯ãŒã¯åå空éã§ã³ãŒããå®è¡ããŸããbashã¯ã·ã§ã«ãæäŸããŸãïŒã
2çªç®ã®ã³ã³ãœãŒã«ã§ãcompute-nodeãéããŠãtcpdumpãubuntuã®ã¿ããã«
tcpdump -ni tap87fd85b5-65
ãŸãïŒ
tcpdump -ni tap87fd85b5-65
å éšåå空éããããã¹ãŠã®ããŒãã®ãªã³ã¯ããŒã«ã«ãã«ããã£ã¹ããèŠæ±ããŸãïŒãã®èšäºã¯ipv6ã«é¢ãããã®ã§ã¯ãããŸããããäœãèµ·ãã£ãŠãããã®æ¬è³ªã§ãïŒåããŒãã«ã¯ãFE80 ::ã§å§ãŸãipv6ã¢ãã¬ã¹ãèªåçã«çæãããããã«ãåããŒãã¯ãã«ããã£ã¹ãã¢ãã¬ã¹ããªãã¹ã³ããŠå¿çããŸãããŒãã®åœ¹å²ã«å¿ããŠããã«ããã£ã¹ãã®ãªã¹ãã¯ç°ãªããŸãããåããŒãã¯å°ãªããšãããã¹ãŠã®ããŒããã€ãŸãã¢ãã¬ã¹FF02 :: 1ïŒã«å¿çããŸãã ãã®ããããã«ããã£ã¹ãpingãå®è¡ããŸãã
ping6 -I qr-bda2b276-72 ff02 :: 1 PING ff02 :: 1ïŒff02 :: 1ïŒfrom fe80 :: f816ïŒ3effïŒfe0aïŒc6a8 qr-bda2b276-72ïŒ56ããŒã¿ãã€ã fe80ãã64ãã€ã:: f816ïŒ3effïŒfe0aïŒc6a8ïŒicmp_seq = 1 ttl = 64 time = 0.040 ms fe80ãã64ãã€ã:: f816ïŒ3effïŒfe10ïŒ35e7ïŒicmp_seq = 1 ttl = 64 time = 0.923 msïŒDUPïŒïŒ fe80ãã64ãã€ã:: f816ïŒ3effïŒfe4aïŒ8bcaïŒicmp_seq = 1 ttl = 64 time = 1.23 msïŒDUPïŒïŒ fe80ãã64ãã€ã:: 54e3ïŒ5effïŒfe87ïŒ8637ïŒicmp_seq = 1 ttl = 64 time = 1.29 msïŒDUPïŒïŒ fe80ãã64ãã€ã:: f816ïŒ3effïŒfeecïŒ3ebïŒicmp_seq = 1 ttl = 255 time = 1.43 msïŒDUPïŒïŒ fe80ãã64ãã€ã:: f816ïŒ3effïŒfe42ïŒ8927ïŒicmp_seq = 1 ttl = 64 time = 1.90 msïŒDUPïŒïŒ fe80ãã64ãã€ã:: f816ïŒ3effïŒfe62ïŒe6b9ïŒicmp_seq = 1 ttl = 64 time = 2.01 msïŒDUPïŒïŒ fe80ãã64ãã€ã:: f816ïŒ3effïŒfe4dïŒ53afïŒicmp_seq = 1 ttl = 64 time = 3.66 msïŒDUPïŒïŒ
çåãçããŸã-誰ã誰ã§ããïŒ é çªã«ãå ¥åããããšãããšãäžäŸ¿ã§é·ãã§ãã
次ã®ãŠã£ã³ããŠã®æšªã«ããtcpdumpã¯ãé¢å¿ã®ããã€ã³ã¹ã¿ã³ã¹ã®ã€ã³ã¿ãŒãã§ã€ã¹ããªãã¹ã³ããŠããŸãã ãããŠããã®äžã«ãç§ãã¡ãèå³ãæã£ãŠããIPã§ãã1ã€ã®IPããã®çãããããŸãã ããã¯fe80 :: f816ïŒ3effïŒfeecïŒ3ebã§ããããšãå€æããŸããã
次ã«ãsshãä»ããŠãã®ããŒãã«æ¥ç¶ããŸãã ãããã
ssh fe80::f816:3eff:feec:3eb
ãè©ŠããŠã¿ã人ã¯èª°ã§ãé©ããŸã-ãç¡å¹ãªåŒæ°ãã
ãã®çç±ã¯ããªã³ã¯ããŒã«ã«ã¢ãã¬ã¹ã¯ããã®ããã«ã䜿çšããããšã¯ã§ããããªã³ã¯ïŒã€ã³ã¿ãŒãã§ã€ã¹ïŒå ã§ã®ã¿æå³ãããããã§ãã ãã ããsshã«ã¯ããã®ãããªçºä¿¡IP /ã€ã³ã¿ãŒãã§ã€ã¹ãªã©ã䜿çšããããªãã·ã§ã³ã¯ãããŸããã 幞ããªããšã«ãIPã¢ãã¬ã¹ã«ã€ã³ã¿ãŒãã§ã€ã¹åãæå®ãããªãã·ã§ã³ããããŸãã
ssh fe80::f816:3eff:feec:3eb% qr-bda2b276-72
ãå®è¡ããŸãã ã¯ããã¯ããç§ã¯ããªãã®inããšåœæãç解ããŠããŸãïŒããªãããããæã£ãŠããªãå Žå-ããªãã¯æ¬åœã®ãªã¿ã¯ã§ã¯ãªãããIPv6ã§é·å¹Žä»äºãããŠããŸãïŒã ãFe80 :: f816ïŒ3effïŒfeecïŒ3ebïŒ qr-bda2b276-72ãã¯ãã®ãããªãIPã¢ãã¬ã¹ãã§ãã ãããã®åŒçšç¬Šã§ç®èã®çšåºŠãäŒããã®ã«ååãªèšèªããããŸããã ããŒã»ã³ãããã³ã€ã³ã¿ãŒãã§ãŒã¹åãå«ãIPã¢ãã¬ã¹ã 誰ããhttpïŒ// [fe80 :: f816ïŒ3effïŒfeecïŒ3ebïŒ eth1] /secret.fileã®ãããªãã®ãWebãµãŒããŒãã±ãŒã«ã®ãµãŒããŒããããã€ãã®Webãµã€ãã«ã¢ããããŒããããšã©ããªããã¯èå³æ·±ã...
...ãããŠãç§ãã¡ã¯ä»®æ³ãã·ã³äžã«ããŸãã ãªãã§ïŒ å¿ é ã®PMTUDã®ãããã§ãIPv6ã¯IPv4ãããæªãMTUç¶æ³ãåŠçããã®ã«åªããŠããããã§ãã ãããã£ãŠãä»®æ³ãã·ã³äžã«ããŸãã
ééã£ãMTUå€ã衚瀺ãããcloud-initãã°ã«ã¢ã¯ã»ã¹ããŠããã®çç±ãçªãæ¢ããããšãæåŸ ããŠããŸãã ããããããã«é©ãããããŸã-MTUã¯æ£ããã§ãã ãã£ãš
ãããã°ã®èéã§
çªç¶ãããŒã«ã«ã§ç解å¯èœãªåé¡ãå®å šã«ç解äžèœã«ãªããŸãã MTUã¯æ£ãããããã±ããã¯ããããããŠãã... ...æ éã«èããã°ãåé¡ã¯æåããããã»ã©åçŽã§ã¯ãªãã£ã-ã€ã³ã¹ã¿ã³ã¹ã®ç§»è¡ã«ãã£ãŠMTUãå€æŽãããã¹ãã§ã¯ãªãã£ãã
èŠãããããã°ãå§ãŸããŸãã tcpdumpãpingãããã³2ã€ã®ã€ã³ã¹ã¿ã³ã¹ïŒããã³ãããã¯ãŒã¯ããŒãã®ãããã¯ãŒã¯åå空éïŒã䜿çšããŠã次ã®ããšãããããŸãã
- ããŒã«ã«ã§ã¯ãåãäžã®2ã€ã®ã€ã³ã¹ã¿ã³ã¹ããæ倧ãµã€ãºã®pingã§çžäºã«pingãèšç®ããŸãã
- ãããã¯ãŒã¯ããŒãããã®ã€ã³ã¹ã¿ã³ã¹ãå¿çããŸããïŒä»¥é-æ倧ãµã€ãºã®pingã§ïŒ
- ä»ã®ã³ã³ãã¥ãŒã¿ãŒã®ãããã¯ãŒã¯ããŒãã€ã³ã¹ã¿ã³ã¹pingã
- ã€ã³ã¹ã¿ã³ã¹å ã®tcpdumpã«çŽ°å¿ã®æ³šæãæããšããããã¯ãŒã¯ããŒããã€ã³ã¹ã¿ã³ã¹ã«pingãéä¿¡ãããšãpingã衚瀺ãããŠå¿çããããšãããããŸãã
ãã£ãš 倧ããªè·ç©ãå°çããŸãããåž°ãã«è¿·åã«ãªããŸãã é察称ã«ãŒãã£ã³ã°ãšèšããŸãããé£æ¥ããã¹ã€ããããŒãã«ããå Žåã®ã«ãŒãã£ã³ã°ã¯äœã§ããïŒ
åçã«çŽ°å¿ã®æ³šæãæã£ãŠãã ãããåçã¯ã€ã³ã¹ã¿ã³ã¹ã«è¡šç€ºãããŸãã çãã¯ã¿ããã§è¡šç€ºãããŸãã ããããçãã¯ãããã¯ãŒã¯åå空éã§ã¯èŠããŸããã ãããŠããããã¯ãŒã¯ããŒããšã³ã³ãã¥ãŒã¿ãŒã®éã®mtuãšãã±ããã®ç¶æ³ã¯ã©ãã§ããïŒ ïŒå éšçã«ã¯ãç§ã¯ãã§ã«åå©ãåããŠããããšåœŒãã¯èšããç§ã¯åé¡ãèŠã€ããïŒã Rraz-ããã³ïŒå€§ïŒpingãå®è¡ãããŸãã
ãªã«ïŒ ïŒãããŠé·ãéå°æããäŒæ¢ïŒã
次ã«äœããã¹ããã¯æããã§ã¯ãããŸããã å ã®åé¡ã«æ»ããŸãã MTUã¯æªãã§ãã ã©ã®MTUãè¯ãã§ããïŒ å®éšãéå§ããŸãã åå²ïŒåã®å€ãããã€ãã¹14ãã€ãã ãã€ãã¹14ãã€ãã äžäœã©ãããŠïŒ ãœãããŠã§ã¢ã®ã¢ããã°ã¬ãŒãåŸïŒ ç§ã¯vimdiffãããã±ãŒãžã®ãªã¹ãã«ããŸãããã«ãŒãã«ãovsãlibcãªã©ãå«ãçŽ80åã®æŽæ°ãããããã±ãŒãžãæ±ãèŠèŸŒã¿ããããšæããŸãã ãã®ãããéåŽããã«ã¯2ã€ã®æ¹æ³ããããŸããMTUã14ãã€ãäžããããæŽæ°ãããŒã«ããã¯ããŠéããŸãã
ã¯ã©ã€ã¢ã³ããç£èŠã§ã¯ãªãåé¡ãå ±åããããšãæãåºãããŠãã ããã MTUã¯ã¯ã©ã€ã¢ã³ãèšå®ã§ããããããDFãã©ã°ã§å€§ããªãã±ãããæž¡ããªããããšã¯ãå®å šãªã€ã³ãã©ã¹ãã©ã¯ãã£ã®åé¡ã§ã¯ãããŸããã ããã¯ã€ã³ãã©ã¹ãã©ã¯ãã£ã®åé¡ã§ã¯ãããŸããã ã€ãŸããã¢ããã°ã¬ãŒããåå ã§ã¯ãªãã次ã®æ¥é£ãšæšæ¥ã®éšãåå ã§ããå Žåã誰ããèŠæ ãç³ãç«ãŠããŸã§ãåé¡ãæ»ã£ãŠããããšããããããŸããã æŽæ°ã«ã€ããŠéããæªç¥ã®ãã®ãæããŸããããã¯äºåã«ã¯ããããŸãããïŒ ããããšãããããšããŠã®äººçã倢èŠãŠããèŠéãã ãããŠãMTUãäžããŠãããªã14ãã€ããªã®ã§ããããïŒ ææ¥ã20ã ã£ããã©ããªããŸããïŒ ãŸãã¯ãç³æ²¹ã®äŸ¡æ Œã45ã«äžãããŸããïŒ ãããšäžç·ã«æ®ããã«ã¯ïŒ
ãã ãã確èªããŸãã å®éãMTUã¯DHCPãªãã·ã§ã³ã§ãããã«äœããåèµ·åããã€ã³ã¹ã¿ã³ã¹ã¯æ£åžžã«æ©èœããŸãã ããããããã¯ãªãã·ã§ã³ã§ã¯ãããŸããã ã©ãããŠïŒ
æåããããçŽããŸãã å€ãMTUã§ããtcpdumpãã¬ãŒã¹ããã±ãŒãžãå床è¿ããŸããçãã¯ãã€ã³ã¹ã¿ã³ã¹ã®ã€ã³ã¿ãŒãã§ã€ã¹ãtap'eã«è¡šç€ºãããŸã...ããŒãã®ãããã¯ãŒã¯ã€ã³ã¿ãŒãã§ã€ã¹ã§tcpdumpã確èªããŸãã ããããã®å°ããªè¿·æãªæŽªæ°Žã§ãããgrepã䜿çšãããšããªã¯ãšã¹ããïŒGREå ã§ïŒçºçããããšãããããŸãããçãã¯æ»ããŸããã
ããïŒ
å°ãªããšããããã»ã¹ã®ã©ããã§å€±ãããŠããããšãããããŸãã ããããã©ãã«ïŒ åäœãã©ã€ãããŒããšæ¯èŒããããšã«ããŸããã ãããåé¡ã¯ããã©ã€ããããŒãã§tcpdumpãããã±ãŒãžã衚瀺ããããšã§ãã æ°å人ã ããªç§ã§ã tengigabitethernetæ代ãžããããã Grepã䜿çšãããšããã®æŽªæ°Žããäœãããã£ããã§ããŸãããéåžžã®ãã³ããååŸããããšã¯ã§ããªããªãããã®èšèšã®ããã©ãŒãã³ã¹ã«ã¯çåãçããŸãã
ç§éã¯åé¡ã«çŠç¹ãåãããŸãïŒtcpdumpã䜿çšããŠãã©ãã£ãã¯ããã£ã«ã¿ãªã³ã°ããæ¹æ³ãããããŸããã éä¿¡å ãå®å ãããŒããããããªã©ã§ãã£ã«ã¿ãªã³ã°ããæ¹æ³ã¯ç¥ã£ãŠããŸãããGREå ã§IPã¢ãã¬ã¹ã§ãã±ããããã£ã«ã¿ãªã³ã°ããæ¹æ³ã¯ããããŸããã ããã«ãã°ãŒã°ã«ã¯ãããéåžžã«ããç¥ããªãã
ããæç¹ãŸã§ãç§ã¯ãã®åé¡ãç¡èŠããŸãããä¿®çãããéèŠã§ãããšä¿¡ããŠããŸããããç¥èã®äžè¶³ãéåžžã«çã ããåã¿å§ããŸããã ååïŒç§ã質åã«çããkevitã察åŠããŸããããªã³ã¯
tcpdump -i eth1 'proto gre and ( ip[58:4] = 0x0a050505 or ip[62:4] = 0x0a050505 )'
ã
ãã㌠ç§ã®webdwanolã¯ã©ãŠãã®ç¹ç°ç¹ã«ãããããŒãã³ã¢0xhexã ããã ããªãã¯çããããšãã§ããŸãã
æ®å¿µãªãããã«ãŒã«ã¯æ£ããæ©èœããªãã£ãããæ£ããæ©èœããŸããã§ããã ãã«ãŒããã©ãŒã¹æ³ã䜿çšããŠã¢ã€ãã¢ãã€ãã¿ãå¿ èŠãªãªãã»ãããååŸããŸããïŒéä¿¡å ããã³å®å IPã¢ãã¬ã¹ã®54ããã³58ã ã±ãããã¯ã圌ããªãã»ãããåŸãå Žæã瀺ããŸããããããã¯éåžžã«èª¬åŸåããããŸããã IPããããŒãGREãIPããããŒã
éèŠãªææïŒæ°ã®ã¬ãã€ãã®æŽªæ°Žã§åäžã®ãã±ãããæ£ç¢ºã«èŠãããã®ããŒã«ãåŸãŸããã ããã±ãŒãžãèŠã...ãšã«ãããäœãæ確ã§ã¯ãããŸããã
Tcpdumpã¯ç§ãã¡ã®å人ã§ãããwiresharkã®æ¹ã䟿å©ã§ãã ïŒç§ã¯tsharkã«ã€ããŠç¥ã£ãŠããŸããããããäžäŸ¿ã§ãïŒã ãã±ãããã³ããå®è¡ãïŒtcpdump -w dumpãå®è¡å¯èœã«ãªããŸããïŒããã·ã³ã«ãã©ãã°ããŠæŽçãå§ããŸãã ç§ã¯ïŒäžè¬çãªè é£æ§ããïŒãã€ã¢ã¹ã«å¯ŸåŠããããšã«æ±ºããŸããã Wiresharkã§éããŠãåç §ããŠãã ãã...
ããããŒã®ãµã€ãºã調ã¹ãŠãIPãã±ããã®å é ã®æ£ãããªãã»ããã46ã§ã¯ãªã42ã§ããããšã確èªããŸãããã®ãšã©ãŒã誰ãã®äžæ³šæã«æžãçããŠãç¿æ¥ããããææ¡ãç¶ããããšã«æ±ºããåž°å® ããŸããã
ãã§ã«å®¶ã®è¿ãã®ã©ããã§ããããç§ã«çŸããŸããã ããããŒã®æ§é ã«é¢ããæåã®ä»®å®ãæ£ãããªãå Žåãããã¯ãã³ããªã³ã°æã®GREããã®ãªãŒããŒããããç°ãªãããšãæå³ããŸãã
ã€ãŒãµãããããããŒãVLANãIPããããŒãGREããããŒãã«ãã»ã«åãããIPãã±ãã...
ãã㊠ããããåçã®èŠåºãã¯ãŸã£ããç°ãªããŸãã neutronã®GREã¯IPãã±ãããã«ãã»ã«åããŸããããã€ãŒãµããããã¬ãŒã ãã«ãã»ã«åããŸãã èšãæããã°ãMTU GREã®ã©ã®éšåãããèªäœãé£ã¹ããã«ã€ããŠã®æåã®ä»®å®ã¯ééã£ãŠããŸãã GREã¯ãäºæ³ããã14ãã€ãå€ããåãåãããŸãã
neutronã¯ãGREã䜿çšããŠIPçµç±ã§ãªãŒããŒã¬ã€ãããã¯ãŒã¯ãæ§ç¯ããŸããããã¯L2ãããã¯ãŒã¯ã§ãã ãã¡ãããã«ãã»ã«åãããã€ãŒãµãããããããŒãå¿ èŠã§ãã
ã€ãŸããMTUã¯14ãã€ãå°ãªãããå¿ èŠããããŸãã æåããã ãããã¯ãŒã¯ãèšç»ãããšããGREã«ããMTUã®åæžã«ã€ããŠã®ä»®å®ãééã£ãŠããŸããã ãã±ããã®æçåãåŒãèµ·ãããããããªãæ·±å»ã§ãã
ããŠããšã©ãŒã¯æããã§ãã ããããæŽæ°åŸã«æ©èœããªããªã£ãã®ã¯ãªãã§ããïŒ ä»¥åã®ç 究ã«ãããšãåé¡ã¯MTUãGREããããŒã®èª€ã£ãã«ãŠã³ããGREãã±ããã®ãã©ã°ã¡ã³ããŒã·ã§ã³ã«é¢é£ããŠããããšãæããã«ãªããŸããã æçåããããã±ããã®ééãåæ¢ããã®ã¯ãªãã§ããïŒ
æ éãã€ç¶¿å¯ãªtcpdumpã§çãã瀺ãããŸãããGREã¯DNFïŒæçåããªãïŒãã©ã°ãšãšãã«éä¿¡ããå§ããŸããã ãã©ã°ã¯ãå éšã«DNFãã©ã°ãå«ãIPãã±ãããã«ãã»ã«åããGREãã±ããã«ã®ã¿è¡šç€ºãããŸãããã€ãŸãããã©ã°ã¯ãã€ããŒãããGREã«ã³ããŒãããŸããã
確ãã«ãç§ã¯å€ãããŒããèŠãŸãã-ãããã¯GREãæçåããŸããã ã¡ã€ã³ãã±ãããšã14ãã€ãã®ãã€ããŒããæã€ããŒã«ããããŸããã ããã¯å€±æã§ã...
ã¢ããã°ã¬ãŒãåŸã«éå§ãããçç±ã調ã¹ãããšã¯æ®ã£ãŠããŸãã
ããã¥ã¡ã³ããèªã
æãçãããååž°ããã±ãŒãžã¯LinuxãšOpenvswitchã§ããã Readme / changelog / newsã¯ç¹å¥ãªããšãæ確ã«ããŸããã§ããããgitã€ã³ã¹ãã¯ã·ã§ã³ïŒçãã¯ããã«ãããŸãããªãããã¥ã¡ã³ãã«ã¢ã¯ã»ã¹ããããã«ãªãŒãã³ãœãŒã¹ã³ãŒããå¿ èŠãªã®ãïŒã¯éåžžã«èå³æ·±ãããšãæããã«ããŸããã
ã³ãããbf82d5560e38403b8b33a1a846b2fbf4ab891af8 äœæè ïŒPravin B Shelar <pshelar@nicira.com> æ¥ä»ïŒæ10æ13æ¥02:02:44 2014 -0700 ããŒã¿ãã¹ïŒcompatïŒã³ã³ãã€ã«3.11ãä¿®æ£ ã«ãŒãã«3.11ã¯GRE APIãå©çšå¯èœãªã«ãŒãã«ã®ã¿ã§ããã vxlanã§ã¯ãããŸããã ãã®ã±ãŒã¹ãæ€åºããã«ã¯ãvxlan xmitã®ãã§ãã¯ãè¿œå ããŸãã
ãããèªäœã¯èå³æ·±ããã®ãè¡šããŠããããåé¡ã®æ¬è³ªã«ã¯é©çšãããŸãããããã³ããæäŸããŸãïŒã«ãŒãã«ã®GRE APIã ãããŠã3.8ãã3.13ãžã®ã¢ããã°ã¬ãŒããè¡ãããŸããã Google in bing ...ã«ãŒãã«ã®git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=aa310701e787087dbfbccf1409982a96e16c57a6ã®openvswitchïŒããŒã¿ãã¹ã¢ãžã¥ãŒã«ïŒã«ãããããããŸãã ã€ãŸããã«ãŒãã«ãGREãµãŒãã¹ã®æäŸãéå§ãããšãopenvswitchã«ãŒãã«ã¢ãžã¥ãŒã«ã¯greåŠçãip_greã«ãŒãã«ã¢ãžã¥ãŒã«ã«æž¡ããŸãã ç§ãã¡ã¯ip_gre.cã³ãŒããç 究ããŠããŸãããã®äžã®ã³ã¡ã³ãã«æè¬ããŸããã¯ããç§ãã¡ã¯çãtsiskaããæããŠããŸããã
åæãããã©ã€ã³ã¯ããã«ãããŸãïŒ
static int ipgre_fill_info(struct sk_buff *skb, const struct net_device *dev) { struct ip_tunnel *t = netdev_priv(dev); struct ip_tunnel_parm *p = &t->parms; if (nla_put_u32(skb, IFLA_GRE_LINK, p->link) || .... nla_put_u8(skb, IFLA_GRE_PMTUDISC, !!(p->iph.frag_off & htons(IP_DF))))
ã€ãŸããã«ãŒãã«ã¯ã«ãã»ã«åããããã±ããã®ããããŒããIP_DFãã³ããŒããŸãã
ïŒçªç¶èå³æ·±ãèå³æ·±ããããã¯ïŒLinuxã¯å ã®ããã±ãŒãžããTTLãã³ããŒããŸããã€ãŸããGREãã³ãã«ã¯ã«ãã»ã«åãããããã±ãŒãžããTTLããç¶æ¿ãããŸãïŒ
ãã©ã€ã¹ã¯ã€ãŒãº
ã€ã³ã¹ããŒã«ã®åæã»ããã¢ããäžã«ã誀ã£ãä»®å®ã®äžéšãšããŠä»®æ³ãã·ã³ã®MTUãèšå®ããŸãã ãã©ã°ã¡ã³ããŒã·ã§ã³ã¡ã«ããºã ã«ãããããã©ãŒãã³ã¹ããããã«äœäžããŸããã ã«ãŒãã«ã3.8ãã3.13ã«ã¢ããã°ã¬ãŒãããåŸãOVSã¯ip_gre.cã«ãŒãã«ã¢ãžã¥ãŒã«ã«åãæ¿ããå ã®IPãã±ãããããã©ã°ã¡ã³ãåããªããã©ã°ãã³ããŒããŸãã ããããŒãè¿œå ããåŸã«MTUã«ãé©åãããªãã£ã倧ããªãã±ããã¯ãæçåãããªããªããŸãããããããããããŸããã GREãããããããããã®äžã«ãã±ãããå«ãŸããŠããªãã£ããããTCPã»ãã·ã§ã³ã®åå è ïŒãã±ããã®éä¿¡ïŒã¯ICMPã劚害ãã¢ã©ãŒããåä¿¡ããŸããã§ãããã€ãŸããããå°ããMTUã«é©å¿ã§ããŸããã§ããã 次ã«ãIPv6ã¯ãã©ã°ã¡ã³ããŒã·ã§ã³ãäºæããïŒIPv6ã«ã¯ãªãïŒã倧ããªãã±ããã®æ倱ãæ£ããæ¹æ³ã§åŠçãããã±ããã®ãµã€ãºãçž®å°ããŸããã
誰ã責任ãè² ããäœããã¹ããïŒ
ç§ãã¡ã®ããã§ã-誀ã£ãŠMTUãèšå®ããŸãã ãœãããŠã§ã¢ã®ã»ãšãã©ç®ç«ããªãåäœã¯ããšã©ãŒãIPv4ã®åäœãæ··ä¹±ããå§ãããšããäºå®ã«ã€ãªãããŸããã
ã©ããã dnsmasq-neutron.confèšå®ã®MTUãä¿®æ£ãïŒãªãã·ã§ã³
dhcp-option-force=26,
ïŒãã¯ã©ã€ã¢ã³ãã«ãã¹ã¿ã³ãããäžããŸããïŒãªãã·ã§ã³ãšå ±ã«DHCPçµç±ã§ã¢ãã¬ã¹ã®ãªãŒã¹ãæŽæ°ããŸãïŒãåé¡ã¯å®å šã«è§£æ±ºããŸããã
ãããç£èŠããããšã§äºé²çã«æ€åºã§ããŸããïŒ æ£çŽãªãšãããåççãªãªãã·ã§ã³ã¯ãããŸãã-蚺æã¯éåžžã«ç¹çŽ°ã§è€éã§ãããã¯ã©ã€ã¢ã³ãã€ã³ã¹ã¿ã³ã¹ããã®æ¥µç«¯ãªååãå¿ èŠã§ãïŒããã«é Œãããšã¯ã§ããŸãã-çªç¶ã誰ããã圌èªèº«ã®ããŒãºã«å¿ããŠãiptablesã䜿çšããŠå¥åŠãªããšãæžããŸããïŒïŒ ã
åæ çãªçµè«
ãœãããŠã§ã¢ã®åã®ããŒãžã§ã³ã«coç ã«ããŒã«ããã¯ãããåäœãã-觊ããªããããæŽæ°ãããšäœãå€ãããããããªãã®ã§ãåã³æŽæ°ãããããšã¯ãããŸããããšããç«å Žãåã代ããã«ããããã°ã«1æ¥çŽ2人ãããããŸãããããããããŒã«ã«ïŒå¯èŠïŒååž°ã解決ãããã ãã§ãªããæ¢åã®æ§æã§ãšã©ãŒãæ€åºããã³ä¿®æ£ããããããã¯ãŒã¯ããã®ãªãŒããŒããããå¢å ããŸããã åé¡ã®è§£æ¶ã«å ããŠã䜿çšãããŠããæè¡ã®ç解ãå€§å¹ ã«åäžãããããã¯ãŒã¯ã®åé¡ããããã°ããæè¡ãéçºãããŸããïŒGREå ã®ãã£ãŒã«ãã«ããtcpdumpã®ãã©ãã£ãã¯ã®ãã£ã«ã¿ãªã³ã°ïŒã
ã³ã¡ã³ã-ãã¯ãŒ
çªç¶ãã³ã¡ã³ãã®äžã§ã ildarzã¯ãã®ãããªãã®ãèŠã€ããæ¹æ³ã«ã€ããŠçŽ æŽãããã¢ã€ãã¢ãææ¡ããŸãã-IPçµ±èšãèŠãŠãå¢å ãããã©ã°ã¡ã³ãïŒ/ proc / net / snmpãnetstat -sïŒã«åå¿ããŸãã ãã®åé¡ã«ã€ããŠã¯ãŸã 調æ»ããŠããŸããããéåžžã«ææã§ãã