Configure Services and Policies for Service Networks

After delivering a service network, configure NAT, load balancing, and network policies as needed. NAT translates traffic addresses on a Tier-0 or Tier-1 gateway. Load balancing distributes TCP or UDP traffic through a VIP on a Tier-1 gateway to pool members. QoS profiles control traffic, and SpoofGuard profiles prevent address spoofing.

Before configuring services and policies, complete Fabric, gateway, and segment configuration for the site. For NAT, select a rule type based on the access direction. For load balancing, create resources in dependency order: health monitors and profiles, server pools, pool members, and virtual servers.

Before combining a DNAT rule on a Tier-0 gateway with a load balancing service on a Tier-1 gateway, confirm that the network segments and routes meet the requirements. For details, see Create a DNAT Rule.

NAT

NAT rules are associated with a Tier-0 gateway or Tier-1 gateway. Before you create a rule, verify that the target gateway is deployed, select a rule type based on the traffic direction, and prepare the IPv4 addresses, protocol, and ports required for translation.

Rule Type Use Case Translation
SNAT Access from an internal network to an external network Translates the source IP of internal traffic to the source IP used for outbound traffic.
DNAT Access from an external network to an internal service Translates the destination IP used for external access to the internal service IP and can also translate the destination port.
Reflexive NAT One-to-one bidirectional mapping between an internal IP and an external IP Creates a bidirectional translation between one internal IPv4 address and one external IPv4 address.

Create an SNAT Rule

Create an SNAT rule to translate the source IP of matching traffic to an IP used for outbound traffic.

  • A Tier-0 gateway or Tier-1 gateway for the SNAT rule is created and deployed.
  • The internal IPv4 address or CIDR that requires external access and the translated IPv4 address used for outbound traffic are available.
  1. Navigate to ZNS Network Center > NAT.
  2. Click Create NAT Rule and set Rule Type to SNAT.
  3. Enter a Name and Description, and select a Gateway.

    The name must be 1–64 characters and cannot contain spaces. The description cannot exceed 255 characters.

    After you select a gateway, you can optionally select an Apply To interface. Only logical router interfaces on the selected gateway are available. If you leave this field blank, the rule uses the default forwarding scope of the gateway. Changing the gateway clears the selected interface.

  4. Configure the addresses under Translation.
    1. In Source IP, enter the internal IPv4 address or CIDR.
    2. In Translated IP, enter one IPv4 address to use for outbound traffic.
  5. Optionally configure Match criteria.

    Destination IP accepts one IPv4 CIDR or multiple IPv4 addresses separated by commas. Leave it blank to match any destination.

    If you specify a Destination Port, enter a value from 1 through 65535 and select TCP or UDP for Protocol.

  6. Under Rule Settings, set the Priority.

    Priority must be an integer from 0 through 32767. This value does not determine the NAT rule match order.

  7. Review the configuration and click OK.

The SNAT rule appears on the NAT page. Check Address Translation, State, and Deployment Status to verify the configuration.

Create a DNAT Rule

Create a DNAT rule to translate the destination IP or port of external traffic to an internal service IP or port.

  • A Tier-0 gateway or Tier-1 gateway for the DNAT rule is created and deployed.
  • The IPv4 address for external access and the IPv4 address of the internal service are available. If port translation is required, prepare the external and internal service ports.
Note: When a DNAT rule on a Tier-0 gateway forwards traffic to the VIP of a load balancing virtual server on a Tier-1 gateway, place the Tier-0 external network and the Tier-1 load balancing service network on different segments and do not use identical or overlapping CIDRs. Make sure that the associated gateways can reach the backend network and that the forward and return paths are symmetric. If the two service networks use the same segment or CIDR, TCP connections might fail.
  1. Navigate to ZNS Network Center > NAT.
  2. Click Create NAT Rule and set Rule Type to DNAT.
  3. Enter a Name and Description, select a Gateway, and optionally select an Apply To interface.

    The name must be 1–64 characters and cannot contain spaces. The description cannot exceed 255 characters.

    Only logical router interfaces on the selected gateway are available for Apply To. If you leave this field blank, the rule uses the default forwarding scope of the gateway. Changing the gateway clears the selected interface.

  4. Configure the addresses under Translation.
    1. In Destination IP, enter the IPv4 address that external users access.
    2. In Translated IP, enter the IPv4 address of the internal service.
  5. Configure source matching or port translation as required.

    To match traffic by source, enter one IPv4 CIDR or multiple IPv4 addresses separated by commas in Source IP. Leave it blank to match any source.

    To translate the destination port, specify both Destination Port and Translated Port, and select TCP or UDP for Protocol. Each port must be from 1 through 65535. Only single-port mapping is supported.

    Note: Port mapping does not support source IP matching. When either destination port is specified, Source IP is cleared and disabled.
  6. Review the configuration and click OK.

The DNAT rule appears on the NAT page. Check Address Translation, State, and Deployment Status to verify the configuration.

Create a Reflexive NAT Rule

Create a Reflexive NAT rule to establish a one-to-one bidirectional translation between an internal IP and an external IP.

  • A Tier-0 gateway or Tier-1 gateway for the Reflexive NAT rule is created and deployed.
  • The internal and external IPv4 addresses for the one-to-one mapping are available.
  1. Navigate to ZNS Network Center > NAT.
  2. Click Create NAT Rule and set Rule Type to Reflexive NAT.
  3. Enter a Name and Description, select a Gateway, and optionally select an Apply To interface.

    The name must be 1–64 characters and cannot contain spaces. The description cannot exceed 255 characters.

    Only logical router interfaces on the selected gateway are available for Apply To. If you leave this field blank, the rule uses the default forwarding scope of the gateway. Changing the gateway clears the selected interface.

  4. In Source IP, enter one IPv4 address to map.
  5. In Translated IP, enter one IPv4 address to use externally.
    Note: Reflexive NAT supports a one-to-one mapping between individual IPv4 addresses. CIDRs and multiple addresses are not supported.
  6. Review the configuration and click OK.

The Reflexive NAT rule appears on the NAT page. Address Translation displays the source and translated IPs as a bidirectional mapping.

Manage NAT Rules

As network requirements change, you can edit the translation settings and match criteria of a NAT rule, or enable, disable, or delete the rule. Enable, disable, and delete operations support both individual and bulk actions.

Before you modify a rule, use its Gateway, Rule Type, and Address Translation values to verify that you selected the correct rule and avoid affecting other address translation services.

Edit a NAT Rule

Modify the basic information, apply-to interface, translation settings, or match criteria of a NAT rule.

The NAT rule that you want to modify is created.

  1. Navigate to ZNS Network Center > NAT and locate the rule by name or gateway.
  2. In the Actions column for the rule, select Edit.
  3. Modify the settings for the rule type.
    • For all rules, you can modify Name, Description, and Apply To.
    • For an SNAT rule, you can modify Priority (0–32767), Source IP, Translated IP, Destination IP, Protocol, and Destination Port.
    • For a DNAT rule, you can modify Destination IP, Translated IP, Source IP, Protocol, Destination Port, and Translated Port.
    • For a Reflexive NAT rule, you can modify Source IP and Translated IP.
    Note: You cannot modify Gateway or Rule Type. To change these settings, create a new rule and delete the original rule after you verify that the new rule is available.
  4. Review the configuration and click OK.

The updated rule appears on the NAT page. Check Address Translation, State, and Deployment Status to verify the update.

Enable or Disable NAT Rules

Enable or disable NAT rules to control whether they process NAT traffic.

The NAT rules that you want to enable or disable are created.

  1. Navigate to ZNS Network Center > NAT.
  2. Enable or disable the required rules.
    • For one rule, select Enable or Disable from the Actions column.
    • For multiple rules in the same state, select the rules, click Bulk Action, and select Enable or Disable.

    You can enable only disabled rules and disable only enabled rules.

    Note: After you disable a rule, it no longer processes NAT traffic. The rule configuration is retained, and you can enable the rule again when required.
  3. In the confirmation dialog box, verify the rules and click Enable or Disable.

State on the NAT page shows the new state. After the rule is deployed, check Deployment Status to verify the operation.

Delete NAT Rules

Delete NAT rules that are no longer required so that they no longer provide address translation.

  • Verify that the target rules no longer carry service traffic.
  • Use the gateway, rule type, and address translation values to verify the scope of the deletion.
  1. Navigate to ZNS Network Center > NAT.
  2. Select the rules to delete.
    • To delete one rule, select Delete from the Actions column.
    • To delete multiple rules, select the rules, click Bulk Action, and select Delete.
  3. In the confirmation dialog box, verify the rules and click OK.
    Note: Deleting a NAT rule removes its configuration. Before you delete a rule, verify that no services depend on the rule for address or port translation.

The rules are removed from the NAT page.

Load Balancing

Load balancing provides Layer 4 access to TCP or UDP services through a VIP, protocol, and listener port, and forwards traffic to pool members in a server pool. Load balancing resources are associated with a Tier-1 gateway.

Resource Purpose Requirement
Health Monitor Checks whether the service on a pool member is available. Optional. Create before the server pool.
Profile Maintains sessions based on the source IP, source port, destination IP, or destination port. Optional. Create before the virtual server.
Server Pool Associates with a Tier-1 gateway and groups pool members that receive traffic. Required.
Pool Member Consists of the IP address of a segment port and a service port. Required. Add after the server pool is created.
Virtual Server Defines the VIP, listener port, and protocol that clients use and associates them with a server pool. Required. Create last.

For a minimum configuration, you can omit the health monitor and profile. Create a server pool, add pool members, and then create a virtual server.

Create a Health Monitor

To monitor pool member availability, create a health monitor and associate it with a server pool.

  1. Navigate to ZNS Network Center > Load Balancer and select the Health Monitors tab.
  2. Click Create Health Monitor, and enter a Name and Description.

    The name must be 1–64 characters and cannot contain spaces. The description cannot exceed 1024 characters.

  3. Configure the health monitor.
    1. Verify that Type is set to OVN.
    2. Set Monitoring Interval (seconds) and Timeout Period (seconds).
    3. Set Rise Count and Fall Count.

    All four values must be integers greater than 0. The timeout period cannot exceed the monitoring interval.

    Rise Count specifies the number of consecutive successful checks required to mark a pool member as available. Fall Count specifies the number of consecutive failed checks required to mark a pool member as unavailable.

  4. Review the configuration and click OK.

The health monitor appears on the Health Monitors tab and is available when you create a server pool.

Create a Load Balancing Profile

To configure session persistence, create a profile that forwards traffic with the same characteristics to the same pool member.

  1. Navigate to ZNS Network Center > Load Balancer and select the Profiles tab.
  2. Click Create Profile, and enter a Name and Description.

    The name must be 1–64 characters and cannot contain spaces. The description cannot exceed 1024 characters.

  3. Verify that Type is set to Session Persistence.
  4. Select at least one Persistence Criteria.

    You can select Source IP, Source Port, Destination IP, and Destination Port. The system identifies sessions to persist by the selected combination of fields.

  5. Optionally set Persistence Timeout (seconds).

    Leave the field blank to use the system default. A custom value must be an integer from 1 through 65535.

  6. Review the configuration and click OK.

The profile appears on the Profiles tab and is available when you create a virtual server.

Create a Server Pool and Add Pool Members

Create a server pool associated with a Tier-1 gateway and add pool members that receive traffic.

  • A Tier-1 gateway for load balancing is created and deployed.
  • A service network connected to the Tier-1 gateway is created, and the segment ports of the backend VMs have IPv4 addresses.
  1. Navigate to ZNS Network Center > Load Balancer and select the Server Pools tab.
  2. Click Create Server Pool, and enter a Name and Description.

    The name must be 1–64 characters and cannot contain spaces. The description cannot exceed 1024 characters.

  3. Select the Tier-1 Gateway that hosts the server pool.
  4. Optionally select a Health Monitor.
  5. Click OK.
  6. On the Server Pools page, click the name of the new server pool and select the Pool Members tab.
  7. Click Add Pool Member and select one or more Segment Ports.

    Segment ports associated with the gateway and assigned an IP address are available. You can add up to 100 pool members at a time.

  8. Verify the IP address of each pool member and set the service Port.

    The default port is 80. You can enter an integer from 1 through 65535. An IP address and port combination cannot be duplicated in the same server pool.

  9. Review the configuration and click OK.

The pool members appear on the Pool Members tab for the server pool. Verify each member's IP Address, Port, VM Name, and NIC Name, and verify that State is Enabled.

Create a Virtual Server

Create a virtual server that receives client traffic on a VIP and listener port and forwards the traffic to an associated server pool.

  • A server pool is created and contains at least one enabled pool member.
  • The VIP, listener port, and protocol that clients use to access the load balancing service are available.
  1. Navigate to ZNS Network Center > Load Balancer and select the Virtual Servers tab.
  2. Click Create Virtual Server, and enter a Name and Description.

    The name must be 1–64 characters and cannot contain spaces. The description cannot exceed 1024 characters.

  3. Select the Tier-1 Gateway that hosts the virtual server.
    Note: Changing the Tier-1 gateway clears the selected server pool. Select the gateway before you select the server pool.
  4. Enter the VIP and set Listener Port and Protocol.

    The VIP must be one IPv4 address. The listener port must be an integer from 1 through 65535. TCP and UDP are supported.

  5. Select a Server Pool.

    After you select a Tier-1 gateway, the Server Pool field appears. Only server pools associated with the selected Tier-1 gateway are available.

  6. Optionally select a Profile for session persistence.
  7. Review the configuration and click OK.

The virtual server appears on the Virtual Servers tab. The list displays VIP, Listener Port, Protocol, Tier-1 Gateway, Server Pool, Profile, and State.

Manage Load Balancing Resources

As service requirements change, you can modify virtual servers, server pools, pool members, health monitors, and profiles. You can also enable or disable virtual servers and pool members to control whether they receive or forward traffic.

Before changing the association between a segment that contains pool members and a Tier-1 gateway, disable or delete the affected pool members. After the change, access the VIP from a client to verify load balancing connectivity.

Before you delete a load balancing resource, check its resource relationships and the impact on services. To manage multiple resources, use the bulk actions available on the resource page.

Modify Load Balancing Configuration

Modify the basic information and service settings of load balancing resources.

The load balancing resource that you want to modify is created.

  1. Navigate to ZNS Network Center > Load Balancer.
  2. Open the page for the target resource and select Edit.
    • To edit a virtual server, server pool, health monitor, or profile, select the corresponding tab and select Edit from the Actions column for the resource.
    • To edit a pool member, select the Server Pools tab, click the server pool name, select the Pool Members tab, and select Edit from the Actions column for the member.
  3. Modify the settings for the resource type.
    Resource Editable Settings
    Virtual Server Name, Description, VIP, Listener Port, Protocol, Server Pool, and Profile
    Server Pool Name, Description, and Health Monitor
    Pool Member Port
    Health Monitor Name, Description, Monitoring Interval (seconds), Timeout Period (seconds), Rise Count, and Fall Count
    Profile Name, Description, Persistence Criteria, and Persistence Timeout (seconds)
  4. Review the configuration and click OK.

The resource page displays the updated configuration. For a virtual server or pool member, also verify that State meets the service requirements.

Control Load Balancing Traffic

Enable or disable virtual servers and pool members to control load balancing traffic.

The virtual servers or pool members that you want to enable or disable are created.

  1. Navigate to ZNS Network Center > Load Balancer.
  2. Open the page for the target resource.
    • To manage virtual servers, select the Virtual Servers tab.
    • To manage pool members, select the Server Pools tab, click the server pool name, and select the Pool Members tab.
  3. Enable or disable the required resources.
    • For one resource, select Enable or Disable from the Actions column.
    • For multiple resources, select the resources, click Bulk Action, and select Enable or Disable.

    You can enable only disabled virtual servers or pool members and disable only enabled virtual servers or pool members.

    For a bulk enable operation, the confirmation dialog box lists only disabled resources in the selection. For a bulk disable operation, it lists only enabled resources.

    • After you disable a virtual server, it no longer forwards traffic. The VIP, listener port, and resource associations are retained.
    • After you disable a pool member, it no longer participates in traffic distribution for the server pool. The member configuration is retained.
  4. In the confirmation dialog box, verify the resources and click Enable or Disable.

State on the Virtual Servers or Pool Members page shows the new state.

Prepare Pool Members for Backend Network Changes

Disable or delete affected pool members before you detach their segment from a Tier-1 gateway.

  • Identify the segment to change and the affected virtual servers, server pools, and pool members.
  • Determine the impact of the network change on load balancing services and schedule an appropriate maintenance window.

Detaching a segment from a Tier-1 gateway does not automatically disable or delete the pool members on that segment. After the segment is detached, Pool Member Status on the virtual server details page might continue to show Up even when clients can no longer access the backend service through the VIP.

Note: Pool Member Status and the pool member State represent different information. After a network topology change, access the VIP from a client to verify that the load balancing service is available. Do not rely solely on Pool Member Status.
  1. Navigate to ZNS Network Center > Load Balancer, and select the Virtual Servers tab.
  2. Click the target virtual server name. On the virtual server details page, check Pool Member Status and identify the affected pool members by their IP addresses and ports.
  3. Return to the Load Balancing page, select the Server Pools tab, click the target server pool name, and select the Pool Members tab.
  4. Process the affected pool members according to the planned network change.
    • For a temporary detachment, select Disable from the Actions column for the target pool member. To process multiple pool members, select them, click Bulk Action, and select Disable.
    • For a permanent detachment, select Delete from the Actions column for the target pool member. To process multiple pool members, select them, click Bulk Action, and select Delete.
  5. In the confirmation dialog box, verify the target pool members and confirm the operation.
  6. Verify that temporarily disabled pool members show State as Disabled, or that permanently deleted pool members are removed from the page.

The affected pool members no longer participate in traffic distribution for the server pool or are removed from the server pool.

  • After you process the pool members, follow the applicable network management workflow to detach the segment from the Tier-1 gateway.
  • After the network change, access the VIP from a client and verify that the load balancing service meets the service requirements.

Delete Load Balancing Resources

Delete virtual servers, server pools, pool members, health monitors, or profiles that are no longer required.

  • Verify that the target resources no longer carry service traffic.
  • Check the relationships between the target resources and other load balancing resources.
  1. Navigate to ZNS Network Center > Load Balancer.
  2. Open the page for the target resource.
    • To delete a virtual server, server pool, health monitor, or profile, select the corresponding tab.
    • To delete a pool member, select the Server Pools tab, click the server pool name, and select the Pool Members tab.
  3. Select the resources to delete.
    • To delete one resource, select Delete from the Actions column.
    • To delete multiple resources, select the resources, click Bulk Action, and select Delete.
  4. In the confirmation dialog box, verify the resources and click OK.
    Note: Before you delete resources, verify their relationships and the impact on services. Deleting a virtual server removes its VIP access point. Deleting a pool member removes it from the server pool.

The resources are removed from the corresponding resource page.

Configure Network Policies

Network Policies include Router QoS, Segment QoS, and SpoofGuard profiles. ZNS administrators can create profiles as needed and select them for gateways, segments, or service networks.

QoS profiles control network traffic bandwidth and burst capability. SpoofGuard profiles prevent VM IP/MAC address spoofing.

Create a Router QoS Profile

The Router QoS Profile page configures traffic shaping rules in the router direction.

  1. Go to ZNS Network Center > Router QoS Profile.
  2. Click Create Router QoS Profile.
  3. Enter profile parameters.

    The form fields include Name, Direction, Description, Action, Bandwidth (kbps), and Burst Size (kb).

    Direction is required. Empty bandwidth and burst size values mean that no value is specified. If you enter a value, it cannot be negative.

  4. After you confirm that the parameters are correct, click OK.

After the profile is created, you can view profile name, direction, action, default profile, bandwidth, burst size, description, and creation time in the list.

Note: Default profiles cannot be deleted. Before you delete a profile, confirm that it is no longer used by service gateways.

Create a Segment QoS Profile

The Segment QoS Profile page configures ingress and egress rate limiting rules for segments.

  1. Go to ZNS Network Center > Segment QoS Profile.
  2. Click Create Segment QoS Profile.
  3. Enter basic information.

    Basic information includes Name and Description.

  4. Enter ingress configuration.

    Ingress configuration includes Action, Average Bandwidth (kbps), Peak Bandwidth (kbps), and Burst Size (kb).

    When you enter average bandwidth, peak bandwidth, or burst size, the value cannot be negative.

  5. Enter egress configuration.

    Egress configuration includes Action, Average Bandwidth (kbps), Peak Bandwidth (kbps), and Burst Size (kb).

    When you enter average bandwidth, peak bandwidth, or burst size, the value cannot be negative.

  6. After you confirm that the parameters are correct, click OK.

After the profile is created, you can view default profile, ingress average bandwidth, ingress peak bandwidth, ingress burst size, egress average bandwidth, egress peak bandwidth, egress burst size, description, and creation time in the list.

Note: Default profiles cannot be deleted. Before you delete a profile, confirm that it is no longer used by service segments.

Create a SpoofGuard Profile

The SpoofGuard Profile page prevents VM IP/MAC address spoofing.

  1. Go to ZNS Network Center > SpoofGuard Profile.
  2. Click Create SpoofGuard Profile.
  3. Enter basic information.

    Basic information includes Name and Description.

  4. Set State.

    You can enable or disable the profile based on service security requirements. The default state is Enabled.

  5. After you confirm that the parameters are correct, click OK.

After the profile is created, you can view profile name, state, default profile, description, and creation time in the list.

Note: Default profiles cannot be deleted. Before you delete a profile, confirm that it is no longer used by service networks.
Network Services | Network Service · ZCF | ZStack Resource Center