Top
ServerView Resource Orchestrator Cloud Edition V3.3.0 Design Guide
FUJITSU Software

2.2.7 Simplifying Networks

VLAN or IP address settings for LAN switch blades, virtual switches, and L2 switches is automatically performed based on the definition information of network resources in Resource Orchestrator. For L2 switches, firewalls, and server load balancers, configuring, modifying, or deleting the definitions that include VLAN settings is automatically performed using scripts. Scripts are prepared for each model of the network devices by infrastructure administrators.


2.2.7.1 Timing of Automatic Network Settings

The simplified network settings will be executed when the following operations are performed:

Table 2.4 Timing of Automatic Network Settings Execution (Network Devices)

Target

Operation

Firewall Devices
(Overall Settings)

Server Load Balancers
(Overall Settings)

Network resources

Creation

-

-

Modification

-

-

Deletion

-

-

Automatic network configuration

-

-

Pool migration

-

-

VM pool

Registering to pools

-

-

Network pool

Tenant migration

-

-

Network devices

Creation

-

-

Modification

-

-

Deletion

-

-

Virtual L-Server

Creation

-

-

Modification

-

-

Addition of NICs

-

-

Deletion of NICs

-

-

Deletion

-

-

Physical L-Server

Creation

-

-

Modification

-

-

Deletion

-

-

L-Platform

Creation

Yes

Yes

Modification

Yes

Yes

Deletion

Yes

Yes

Yes: Available
-: Not available


Table 2.5 Timing of Automatic Network Settings Execution (Switches)

Target

Operation

L2 Switch
(Overall Settings) (*1)

Ethernet Fabric Switches

LAN Switch Blades
(VLAN Settings) (*1)

VLAN Port Profiles (*2)

Internal Connection Ports (*2)(*3)(*4)

VLAN Settings (*5)

Internal Connection Ports

External Connection Ports

Network resources

Creation

Yes

Yes

-

Yes

-

Yes (*6)

Modification

Yes

Yes

Yes (*7)

Yes

-

Yes (*6)

Deletion

Yes

Yes

-

Yes

Yes

-

Automatic network configuration

-

-

-

-

Yes

-

Pool migration

-

-

-

Yes

-

-

VM pool

Registering to pools

-

-

-

-

Yes

-

Network pool

Tenant migration

-

-

-

Yes

-

-

Network devices

Creation

-

-

-

Yes

-

-

Modification

-

-

-

Yes (*10) (*11)

-

-

Deletion

-

-

-

-

-

-

Virtual L-Server

Creation

-

-

Yes

-

Yes

-

Modification

-

-

-

-

-

-

Addition of NICs

-

-

Yes

-

Yes

-

Deletion of NICs

-

-

Yes

-

-

-

Modification of connection destination networks

-

-

Yes

-

Yes

-

Deletion

-

-

Yes

-

-

-

Physical L-Server

Creation

Yes (*8)

-

-

-

Yes

-

Modification

Yes (*8)

-

-

-

Yes

-

Deletion

Yes (*8)

-

-

-

Yes

-

L-Platform

Creation

Yes (*9)

-

Yes

-

Yes

-

Modification

Yes (*9)

-

Yes

-

Yes

-

Deletion

Yes (*9)

-

Yes

-

Yes

-

Yes: Available
-: Not available

*1: When using an Ethernet Fabric switch or an Ethernet Fabric switch blade which constitutes an Ethernet Fabric, the timing of auto-configuration is the same as that of the Ethernet Fabric switch.
*2: It is automatically configured when using an Ethernet fabric switch and "port profile configuration" is set to "Enable".
*3: A VLAN is automatically configured for the internal connection port used for L-Server communications according to the link between the NIC of the L-Server and the VLAN port profile.
*4: It is automatically configured when all of the following conditions are met.
- When using an Ethernet fabric switch and "port profile configuration" is set to "Enable"
- When the VM host connected to the Ethernet fabric switch is VMware or a Hyper-V virtual L-Server
*5: When performing some type of auto-configuration for the Converged Fabric port, the interface group including the relevant port is configured in Converged Fabric.
*6: When automatic network configuration and automatic VLAN configuration for uplink ports are enabled, settings are automatically configured at the point when an external connection port (including an external connection port with link aggregation configured) is added.
*7: If an uplink port of the Ethernet fabric switch is added, the link between the L-Server connected to the network resource and the VLAN port profile will operate.
*8: Available when using rack mount servers.
*9: Available when using rack mount servers and physical LAN segments have been specified.
*10: When deleting tenants related to VFABs by modifying network devices in Converged Fabric, if the tenants to be deleted are not related to any other VFABs, the relevant tenants belong to the default VFAB. At this time, the linking information of the port profiles and the MAC addresses for the L-Server in the tenant will not be configured automatically as the default VFAB is out of the VFAB auto-configuration target.
In this case, log in to the Converged Fabric and modify the linkage between the port profile and the MAC address for the tenant in the relevant tenant using the relevant command.
*11: When deleting a port in dot1ad mode from VFAB by modifying the network device for Converged Fabric, settings for disabling dot1ad mode of the relevant port are not configured. The following is the reason for this:
- When using the port in dot1ad mode for a VFAB operation other than performing auto-configuration, if the dot1ad mode is disabled due to auto-configuration, it may be unable to communicate with the operational system.
When disabling dot1ad mode of the relevant port, log in to the Converged Fabric, and configure it using the relevant command.


Table 2.6 Timing of Automatic Network Settings Execution (Servers)

Target

Operation

Virtual Switch
(Creation/VLAN Settings)

L-Server
(IP Address Settings for OS)

Network resources

Creation

-

-

Modification

-

-

Deletion

Yes

-

Automatic network configuration

Yes (*1)

-

Pool migration

-

-

VM pool

Registering to pools

Yes (*1)

-

Network pool

Tenant migration

-

-

Network devices

Creation

-

-

Modification

-

-

Deletion

-

-

Virtual L-Server

Creation

Yes (*1)

Yes

Modification

-

-

Addition of NICs

Yes (*1)

-

Deletion of NICs

-

-

Modification of connection destination networks

Yes (*1)

-

Deletion

-

-

Physical L-Server

Creation

-

Yes (*2)

Modification

-

Yes (*3)

Deletion

-

-

L-Platform

Creation

Yes (*1) (*4)

Yes

Modification

Yes (*1) (*4)

-

Deletion

-

-

Yes: Available
-: Not available

*1: Available when using rack mount servers and physical LAN segments have been specified.
*2: Requires a script that configures an IP address for the OS.
*3: The IP address is configured or modified when the network resource is modified.
*4: Available when using virtual L-Servers.

2.2.7.2 Scope of Automatic Network Settings

The simplifying network settings will be executed for the following scope.

Figure 2.4 Scope of Automatic Network Settings Execution (For L2 Switches)


Figure 2.5 Scope of Automatic Network Settings Execution (For Ethernet Fabric Switches)

CIR: Clean Interface with Redundancy (Port that connects to an external device)
EP: End Point (Port that connects with the server)

*Note: CIR is not automatically configured.


For details on automatic network settings for virtualized environments, refer to the relevant sections explaining how to prepare and setup server virtualization software in "Chapter 8 Configuration when Creating Virtual L-Servers" in the "Setup Guide CE".


2.2.7.3 Hiding Network Information

The following network information is hidden, depending on the network resource.

CIR: Clean Interface with Redundancy (Port that connects to an external device)
EP: End Point (Port that connects with the server)


2.2.7.4 Network Device Automatic Configuration

There are two types of modes for auto-configuration of network devices.

Information

When performing auto-configuration of NS Appliances, it is recommended to use simple configuration mode. Regarding the selection criteria for which method to use, refer to "2.1.3 Designing the L-Platform Network Environment" in the "NS Option Instruction".

User Customization Mode

The infrastructure administrator creates the ruleset necessary to configure the definitions for the network devices (firewalls, server load balancers, and L2 switches), and registers it in Resource Orchestrator.
In Resource Orchestrator, perform auto-configuration for the target network devices using the ruleset registered by the infrastructure administrator.

For details on preparation for auto-configuration using user customization mode, refer to "Appendix F Preparing for Automatic Configuration and Operation of Network Devices".

For details on operation image of modifying configuration of firewalls using user customization mode, refer to "When an L-Platform that uses a firewall is deployed with the use of a ruleset" in "8.3.9 Setup Firewall" in the "User's Guide for Tenant Administrators CE" or "5.3.8 Setup Firewall" in the "User's Guide for Tenant Users CE".

For details on the operation image of modifying configuration of firewalls using user customization mode, refer to "8.3.11.2 When an L-Platform that Uses a Server Load Balancer (SLB) Is Deployed Using a Ruleset" in the "User's Guide for Tenant Administrators CE" or "5.3.10.2 When an L-Platform that Uses a Server Load Balancer (SLB) Is Deployed Using a Ruleset" in the "User's Guide for Tenant Users CE".

Simple configuration mode

The infrastructure administrator is not required to create the rulesets necessary for configuring definitions for network devices (firewalls and server load balancers) in advance.
In Resource Orchestrator, it is possible to easily perform auto-configuration by using the defined definitions.

Simple configuration mode enables deployment of L-Platforms using firewalls and server load balancers, without using rulesets.
For details on the logical network configuration realized using simple configuration mode, the target devices, or configuration details, refer to "Appendix I Auto-configuration and Operations of Network Devices Using Simple Configuration Mode".

When using simple configuration mode, the virtual IP addresses used for address translation functions of firewalls (public addresses) can be managed, and the IP addresses can be allocated to the L-Platform automatically. When using this function, it is necessary to create the address set resources of global IP addresses.
For details, refer to "14.6 Address Set Resources" in the "User's Guide for Infrastructure Administrators (Resource Management) CE".

For details on operation image of modifying configuration of firewalls using simple configuration mode, refer to "When an L-Platform that uses a firewall is deployed without the use of a ruleset" in "8.3.9 Setup Firewall" in the "User's Guide for Tenant Administrators CE" or "5.3.8 Setup Firewall" in the "User's Guide for Tenant Users CE".

For details on the operation image of modifying configuration of server load balancers using simple configuration mode, refer to "8.3.11.1 When an L-Platform that Uses a Server Load Balancer (SLB) Is Deployed Without Using a Ruleset" in the "User's Guide for Tenant Administrators CE", or "5.3.10.1 When an L-Platform that Uses a Server Load Balancer (SLB) Is Deployed Without Using a Ruleset" in the "User's Guide for Tenant Users CE".

Auto-configuration Timing and Images

This section explains auto-configuration timing and images.

Recovery (deletion of incomplete settings, etc.) of network devices can be performed by preparing a recovery script in advance in case automatic configuration of network devices fails.

Figure 2.9 Network Device Automatic Configuration Image (Recovery Process)


2.2.7.5 Network Device Configuration File Management

The following files are available as network device (firewall, server load balancer and L2 Switch) configuration files.

In this product, a function that manages device configuration files using generations is provided. Using this function modification changes can be checked and restoration of configurations can be performed easily when network devices are exchanged.

The following features are provided by the network device configuration file management function.

2.2.7.6 Simple Network Monitoring

This section provides a brief overview of simple network monitoring.

Visualize Networks (NetworkViewer Function)

Resource Orchestrator provides NetworkViewer, which helps visualize and relate logical networks (within L-Servers and L-Platforms) and physical and virtual networks (comprised of servers, network devices, VLANs, and virtual switches). It has the following features.

For details on NetworkViewer, refer to "Chapter 11 NetworkViewer" in the "User's Guide for Infrastructure Administrators (Resource Management) CE".

Note

For VMware virtual switches, network links are only displayed when using the standard switches.
When using switches other than the standard switches, such as distributed virtual switches, those virtual switches and the network links are not displayed.

Status Monitoring

Resource Orchestrator monitors the status of network devices (Firewalls, server load balancers, and L2 switches) in order to automatically perform network settings for them.