Deliver a Single-Site Service Network

A site groups compute Clusters, hosts, and network configuration. To deliver a service network, first assign compute Clusters to the site, prepare its Fabric configuration, and connect hosts. If the site requires a Layer 3 gateway, prepare an edge cluster and gateways. The following diagram shows how these resources relate.

Figure 1. Site Resource Relationships

A site contains member Clusters and hosts. A host may be connected to Fabric or not yet connected. Once connected, it applies the site Fabric configuration. Depending on network requirements, a site can have an edge cluster or a DCI Gateway. The DCI Gateways at two sites can establish a cross-site connection.
Note: This is a general diagram. The hosts and connection states shown do not reflect the actual configuration of the current site. Check Member Clusters, Host Connections, and Fabric Configuration in the site details.

A site can contain multiple compute Clusters. Each Cluster belongs to only one site, and hosts belong to the site of their Cluster. A host appearing in a member Cluster is not necessarily connected to Fabric. Host B in the diagram belongs to the site but is not yet connected.

The site's Fabric common configuration provides uplink and tunnel parameters. Once connected, a host uses these parameters through mappings between logical Uplink members and physical NICs. Hosts with different requirements can use shared or dedicated configurations. Transport zones are shown as associated resources; you do not need to select them for each host during connection.

An edge cluster hosts the site's Tier-0 gateway. Select its members from hosts already connected to Fabric. Configure DCI Gateways at both sites only when cross-site connectivity is required. The DCI Gateway connection shown in the diagram does not prove that service subnets can communicate. You must also configure a DCI link and a Tier-1 peering connection, then verify connectivity. See Establish Connectivity Between Two Sites.

Create a Site and Associate Clusters

A site groups Clusters. A site can contain multiple Clusters, but each Cluster belongs to only one site. Hosts are associated with the site through their Cluster. Before creating a site, confirm that the target Clusters have been discovered by the compute manager. Clusters assigned to the same site must be in the same physical site (data center) and fault domain, with connectivity over the site's underlay or local network. Sharing a compute manager or Zone does not guarantee these conditions.

  1. Go to ZNS Network Center > Sites.
  2. Click Create Site, and enter a name and an optional description.
  3. Optionally select Clusters that do not belong to another site, and review the selection.

    If you do not select a Cluster now, you can add it later on the Member Clusters tab of the site details. Clusters already assigned to another site are not listed as candidates.

  4. Review the site information, and click OK.
  5. Open the site details, and check the Member Clusters, Host Connections, and Fabric Configuration tabs.

    The site details also show associated transport zones, edge clusters, and DCI Gateways. Transport zones are displayed by site relationship; you do not need to select one manually when connecting a host.

The site and its member Clusters are available in the site details. Continue by configuring the site's Fabric common configuration.

Prepare a VTEP IP Address Pool

The site's Fabric common configuration uses an IP address pool for VTEP addresses. Before creating the pool, confirm the CIDR, address capacity, and relationship to existing networks against the site network plan.

  1. Go to ZNS Network Center > IP Address Pool.
  2. Click Create IP Address Pool, and enter a name and an IPv4 CIDR.

    Use a valid IPv4 network CIDR, such as 192.0.2.0/24. Use the address range planned for your site to avoid overlap with ranges used for other purposes.

  3. Review the settings, click OK, and check the new pool in the list.

When editing the site's Fabric common configuration, you can select this IP address pool as the VTEP address source.

Configure Site Fabric Common Configuration

Maintain the Fabric common configuration in the site details. The configuration applies only to that site. Configure uplinks and VTEP addresses before connecting hosts.

Note: Editing the Fabric common configuration or changing host NIC mappings can affect service network traffic on the hosts. Before making changes, verify NICs, link aggregation (Bond), VLANs, and VTEP addresses, and schedule a maintenance window.
  1. Go to ZNS Network Center > Sites, and open the target site details.
  2. Open the Fabric Configuration tab. Under Common Configuration, check the uplink and tunnel settings.

    Common configuration includes the datapath, Uplink group name, MTU, link aggregation (Bond) algorithm and logical members of the group, VTEP IP address pool, tunnel VLAN, and link failure detection (BFD) parameters. An Uplink group can contain multiple logical members.

  3. Click Edit Common Configuration, and set the Uplink members, VTEP, and BFD parameters according to the network plan.

    For initial configuration, select a VTEP IP address pool and keep at least one Uplink member. If the site already has associated hosts, remove them and wait for the operation to finish before replacing or clearing the VTEP configuration.

  4. Review the scope of changes and the host resynchronization prompt, save the changes, and return to the common configuration page to check the result.

After completing the common configuration, you can prepare a host shared configuration or connect hosts. Refresh the host list and confirm that the configuration has synchronized to the target hosts.

Create a Host Shared Configuration (Optional)

Create a host shared configuration when multiple hosts need the same uplink parameters. If all hosts use the site's Fabric common configuration, you can connect the hosts directly.

  1. Open the target site details, and go to Fabric Configuration > Shared Configuration.
  2. Click Create Host Shared Configuration, and enter a name and an optional description.
  3. Check the datapath, Uplink group, MTU, Bond algorithm, and tunnel VLAN carried over from the site common configuration. Adjust editable fields as needed.

    The Uplink group name is inherited from the site common configuration.

  4. Save the configuration, and check it in the Shared Configuration list.

When connecting a host or editing its configuration, you can select this configuration as the host shared configuration. The page does not allow you to delete a shared configuration while hosts reference it.

Connect Hosts to Site Fabric

Connect compute hosts to the site Fabric on the Host Connections tab of the site details. Before connecting a host, complete the common Uplink and VTEP configuration and confirm that the selected physical NICs can carry service network traffic.

  1. Open the target site details, select the Host Connections tab, and click Connect Hosts.

    You can add hosts only after the Fabric common configuration includes an Uplink and VTEP settings. Hosts already connected to Fabric do not appear in the candidate list.

  2. Select the target hosts, and choose whether to configure them in a batch or individually.
  3. Set the uplink mapping for each host by mapping logical Uplink members in the site common configuration to the host's physical NICs.

    Each host needs at least one valid mapping. Map physical NICs and logical members one to one on each host. You do not need to map every logical member.

  4. Choose a configuration source: inherit the common configuration, use a host shared configuration, or use a host dedicated configuration.

    You cannot use shared and dedicated configurations at the same time. With a dedicated configuration, you can adjust the datapath, Uplink MTU, Bond algorithm, and tunnel VLAN.

  5. Review the selected hosts, NIC mappings, and configuration sources. Submit the configuration and check synchronization status in the list.

The host list shows node type, datapath, synchronization status, and configuration source. Use the page action to resynchronize hosts that are out of sync. A host being removed cannot be removed or edited again until the operation finishes.

Create an Edge Cluster

An edge cluster uses hosts connected to Fabric to provide gateway and network service capabilities. Before creating a Tier-0 gateway, prepare an edge cluster for its site.

  1. Open the target site details, select the Edge Clusters tab, and click Create Edge Cluster.
  2. Confirm the site, and enter an edge cluster name and an optional description.
  3. Select hosts already connected to the site's Fabric as edge cluster members.

    Select hosts that meet the capacity and high availability requirements of the service gateway.

  4. Review the settings, click OK, and check status and membership in the edge cluster list.

The edge cluster is available to subsequent Tier-0 gateways.

Configure a Tier-0 Gateway

Tier-0 Gateway manages the core gateway, edge routing, and high availability mode. Before creating one, configure an edge cluster for its site.

  1. Go to ZNS Network Center > Tier-0 Gateway.
  2. Review existing Tier-0 gateways.

    The list shows Name, Configuration Status, HA Mode, Edge Cluster, Router Link CIDR, Description, and Created At.

  3. To create a Tier-0 gateway, click Create Tier-0 Gateway.
  4. Select an edge cluster.

    An edge cluster is required. The selection page shows its name, configuration status, node count, and creation time.

  5. Enter the Tier-0 gateway name and confirm the HA mode. Optionally enter a router link CIDR and description.

    The HA mode is active-standby. The name is required, cannot exceed 64 characters, and cannot contain spaces. The description cannot exceed 256 characters.

  6. Review the settings, and click OK.

After creation, check whether the configuration status in the Tier-0 gateway list is Deployed.

Configure a Tier-1 Gateway

Tier-1 Gateway manages a tenant or service network gateway and can connect upstream to a Tier-0 gateway. For cross-site connectivity, prepare a standard Tier-1 gateway at each site before creating a peering connection.

  1. Go to ZNS Network Center > Tier-1 Gateway.
  2. Review existing Tier-1 gateways.

    The list shows Name, Site, Configuration Status, HA Mode, Edge Cluster, and Linked Tier-0 Gateway, among other information.

  3. To create a Tier-1 gateway, click Create Tier-1 Gateway.
  4. Select an upstream Tier-0 gateway.

    An upstream Tier-0 gateway is required. The selection page shows the Tier-0 gateway name, configuration status, HA mode, and creation time.

  5. Enter the Tier-1 gateway name, HA mode, and description.

    The HA mode is active-standby. The name is required, cannot exceed 64 characters, and cannot contain spaces. The description cannot exceed 256 characters.

  6. Configure Route Advertisement as needed.
    Setting Description
    All NAT IPs When enabled, advertises routes for external IP addresses used by enabled NAT rules under this Tier-1 gateway through the upstream Tier-0 gateway.
    All LB VIP Routes When enabled, advertises VIP routes for load balancing virtual servers associated with this Tier-1 gateway through the upstream Tier-0 gateway.

    Both switches are off by default and can be set independently. Route advertisement controls only whether the corresponding routes are advertised. It does not change the enabled state of NAT rules or virtual servers.

    Note: Before enabling route advertisement, confirm that the NAT IPs or LB VIPs to be advertised are within the CIDR of the upstream Tier-0 gateway's external interface and are not advertised by another Tier-1 gateway under that Tier-0 gateway.
  7. Optionally select an Ingress QoS Profile and an Egress QoS Profile.

    Ingress and egress QoS profiles are optional. Select them according to your traffic control plan.

  8. Review the settings, and click OK.

After creation, check whether the configuration status in the Tier-1 gateway list is Deployed.

View Segments

Use Segments to view VLAN and Overlay network segments and check their configuration status and address information. Some segments can be created by the ZStack Cloud network creation workflow. ZNS administrators can check their deployment results here.

  1. Go to ZNS Network Center > Segments.
  2. Review the segment list.

    The list shows Name, Segment Type, Configuration Status, Traffic Type, VNI/VLAN ID, Associated Gateway, Peer Segment, and address information.

  3. Locate the target segment by name or associated gateway.
  4. Confirm that the target segment's Configuration Status is Deployed.

After confirming deployment, use the associated gateway, gateway address, IP CIDR, and IP range to investigate the service network state.

Network Services | Network Service · ZCF | ZStack Resource Center