L3 Network

L3 Network

An L3 network is a collection of network configurations for VM instances, including the network range, gateway, DNS, and network services.
  • A network range includes an IP range (start IP and end IP), netmask, and gateway. For example, you can specify the IP range from 172.20.12.2 to 172.20.12.255, set the netmask to 255.255.0.0, and set the gateway to 172.20.0.1. In addition, you can use a CIDR to specify a network range, such as 192.168.1.0/24.
  • DNS provides DNS resolution services used for configuring VM networks.

Concepts

  • Public network: Generally, a public network is a logical network that is connected to the Internet. However, in an environment that has no access to the Internet, you can also create a public network.
    • A public network can be used in the flat network environment to create VM instances.
    • A public network can be used in the VPC network environment to create VM instances that work with public networks.
  • Flat network: A flat network is connected to the network where the host is located and has direct access to the Internet. VM instances in a flat network can access public networks by using elastic IP addresses.
    • A flat network supports multiple network services, including DHCP, User Data, EIP, security group, and port mirroring.
    • The network services provided by a flat network use the distributed DHCP and the distributed EIP structure.
    • The DHCP service provided by a flat network also includes the DNS feature.
    • The network model used in the wizard is a flat network.
    • The flat network architecture based on VxlanNetwork or HardwareVxlanNetwork is supported.
  • VPC network: A VPC network is a private network where VM instances can be created. A VM instance in a VPC network can access the Internet through a VPC vRouter.
    • A VPC network provides the following network services: DHCP, User Data, DNS, SNAT, route table, EIP, port forwarding, load balancing, IPsec tunnel, security group, dynamic routing, multicast routing, VPC firewall, port mirroring, and netflow.
    • The DHCP service of the VPC network uses DHCP by default.
    • VPC networks mainly use custom Linux VM instances as VPC vRouters to provide network services.
    • Network services can act on multiple subnets of a VPC at the same time, further improving network efficiencies.
    • Supports VxlanNetwork-based VPC network architecture.
    • Supports distributed routing, optimizing east-west network traffic and effectively reducing network latency.
  • Dedicated network:
    • Management network: A management network is used to manage physical resources in the Cloud. For example, you can create a management network to manage access to hosts, primary storage, image storage, and VPC vRouters.
      Note: When you create a VPC vRouter, you need an IP address that can be interconnected between the management nodes of the VPC vRouter. With this IP address, you can deploy an agent and obtain messages returned by the agent.
    • Flow network: A flow network is a dedicated network for port mirror transmission. You can use a flow network to transmit the mirrors of data packets of NIC ports to the target ports. A flow network cannot be used for other purposes, such as creating VM instances.
  • Specific network scenarios:
    • Storage network: A storage network is the network specified by the shared storage. You can use a storage network to check the health state of a VM instance. We recommend that you plan for an independent storage network in advance to avoid potential risks.
    • VDI network: When you create a cluster, you can specify CIDR for the VDI network in the cluster. In the VDI scenario, the network traffics generated by the protocol communication between the server side and client side use the VDI network. If you do not make any configuration to the VDI network, notice that the management network will be used by default.
    • Migration network: When you create a cluster, you can specify CIDR for the migration network in the cluster. The migration network is used to migrate VM instances in the Cloud. If you do not make any configuration to the migration network, notice that the management network will be used for VM migrations.
    • Image synchronization network: An image synchronization network is used to synchronize images among ImageStore image storage in the same management node.
      • If you deployed an independent network for synchronizing images, you can specify CIDR for the image synchronization network when you add an ImageStore image storage.
      • If you do not make any configuration to the image synchronization network, notice that the management network will be used by default.
      • If you set an image synchronization network for both the source ImageStore image storage and target one, only the image synchronization network in the target ImageStore image storage takes effect.
    • Data network: A data network is the network where data can transfer between a compute node and an image storage.
      • Using an independent data network can avoid network congestion and improve the data transfer rate.
      • If you do not make any configuration to the data network, notice that the management network will be used by default.
    • Backup network: If you are using the Backup Service or the Continuous Data Protection (CDP) service, in the local backup scenario,both the data backup and recovery are implemented by using the backup network.
      • If you deploy an independent network for local backups, you can specify CIDR for the backup network when you add a local backup server.
      • Using an independent backup network can avoid network congestion and improve the data transfer rate.
      • If you do not make any configuration to the backup network, notice that the management network will be used for local backup by default.
      Note:

      The Backup Service and the CDP Service are separately provided in a separate module. To use this feature, purchase both the Base License and the Plus License. Note that a Base License is required before you can install a Plus License.

Considerations

  • When you create a VM instance, you can specify multiple L3 networks, including flat networks, VPC networks, or a combination of flat networks and VPC networks.
  • The Cloud supports multi-layer networks. In addition, the L2 networks of multi-layer networks can intercommunicate. Therefore, you need to pay a special attention to avoid the conflict of IP address spaces.
  • You can use an L2 network to create multiple L3 networks. However, we recommend that unless necessary you do not create multiple L3 networks from an L2 network. This may cause the DHCP services of these L3 networks unable to work as expected.
  • The network services and features supported by an L3 network are related to the network architecture model (flat network, VPC network) and the configured network protocol version (IPv4, IPv6). If a network is configured with both IPv4 and IPv6 protocols, servers of these two protocol types are loaded at the same time to provide corresponding services.
    IPv4 IPv6
    Flat network Supported network services: DHCP, User Data, EIP, security group, and port mirroring Supported network services: DHCP, DNS, EIP, and security group
    VPC network Supported network services: DHCP, User Data, DNS, SNAT, route table, EIP, port forwarding, load balancing, IPsec tunnel, security group, dynamic routing, multicast routing, VPC firewall, port mirroring, and Netflow Supported network services: DHCP, DNS, and security group
    Supported network service: VPC vRouter HA group Supported network service: VPC vRouter HA group

Create a Public Network

Log in to ZCF, switch to the corresponding region, and then on the main menu, choose Resource Center > Network Resource > L3 Network Resources > Public Network. On the Public Network page, click Create Public Network. The Create Public Network page appears.

The following lists the two public network creation scenarios:
  • Create an IPv4 public network
  • Create an IPv6 public network

Create IPv4 Public Network

On the displayed page, set the following parameters:
  • Name: Enter a name for the public network.
  • Description: Optional. Enter a description for the public network.
  • L2 Network: Select an L2 network for the public network.
    Note: ZStack Cloud allows you to use an L2 network to create multiple L3 networks. However, we recommend that you do not use an L2 network to create multiple L3 networks if not for specific business needs.
    On the Select L2 Network page, two tabs are displayed:
    • Recommended: lists L2 networks in the current zone that are not attached to an L3 network.
    • All: lists all L2 networks in the current zone.
  • Network Address Type: Select IPv4.
  • Network Range Method: Select a method to add a network range for the public network. You can select IP Range or CIDR.
    If you select IP Range, you need to set the following parameters:
    • Start IP: Set a start IP address for the network range, for example, 172.20.108.100.
    • End IP: Set an end IP address for the network range, for example, 172.20.108.200.
    • Netmask: Set a netmask for the network range, for example, 255.255.0.0.
    • Gateway: Set a gateway for the network range, for example, 172.20.0.1.
    • DHCP Service: Choose whether to enable the DHCP service.
      Note:
      • The DHCP service is a built-in distributed service of the Cloud, which assigns IP addresses only to resources in the Cloud and does not conflict with your existing DHCP server.
      • By default, the DHCP service is enabled so that the NICs using this L3 network acquire IP addresses in a DHCP mode. You can customize a DHCP IP or use the DHCP IP that the system assigned according to the IP allocation policy.
      • If you disable this option, NICs using this L3 network acquire IP addresses in a Static mode. The Cloud does not assign IP addresses to NICs automatically. If the NICs need IP addresses, you need to configure IP addresses for them manually. In addition, you cannot specify a DHCP IP. Neither can the system allocate one.
      • IP Allocation Policy: Optional. If the DHCP service is enabled, IP addresses can be assigned according to the following three allocation policies:
        • Random: The system randomly assigns IP addresses from the network range.
        • Allocate in Order:
          • The system assigns all available IP addresses from the network range in ascending order. Released IP addresses are assigned in the next allocation.
          • Example: Assume that the network range is 192.168.0.101~192.168.0.120, within which 192.168.0.101~192.168.0.108 are allocated. If 192.168.0.106 is released, it will be assigned first in the next allocation.
        • Allocate in Cycle:
          • The system assigns available IP addresses to VM instances from the network range in ascending order. Released IP addresses are assigned when currently available IP addresses are used up.
          • Example: Assume that the network range is 192.168.0.101~192.168.0.120, within which 192.168.0.101~192.168.0.108 are allocated. If 192.168.0.106 is released, it will be assigned after 192.168.0.120 is used.
      • DHCP IP: Optional. Set an IP address for the DHCP server, for example, 172.20.108.10.
        Note:
        • A DHCP IP is an IP address used by the DHCP service to assign IP addresses to resources that use this L3 network.
        • If you create an L3 network for the first time with the DHCP service enabled, or if you add the first network range to an L3 network with the DHCP service enabled, you can customize the DHCP IP.
        • If the L3 network has a DHCP IP, you cannot customize the DHCP IP when you add a network range.
        • The DHCP IP can be in or outside the added IP range, but it must be an unoccupied IP address in the CIDR block of the added IP range
        • The IP range determined by the start IP and end IP cannot contain the link-local address 169.254.0.0/16.
        • If you select random as the IP allocation policy and this field is left blank, the system randomly assigns IP addresses from the added network range.
        • If you select allocate in order/allocate in cycle as the IP allocation policy and this field is left blank, the system uses the start IP address in the network range as the DHCP IP.
    • DNS: Add a DNS server to provide domain name resolution services for the public network. You can specify 223.5.5.5, 8.8.8.8, or 114.114.114.114.
    Note: When you add an IP range for an IPv4 L3 network, note that:
    • The IP range cannot contain gateway IP addresses, broadcast addresses, or network addresses.
    • The IP range of a private network cannot overlap with the IP range of a public network used to create a vRouter offering or of a management network.
    Figure 1. Create IPv4 Public Network Using IP Range




    If you select CIDR, you need to set the following parameters:
    • CIDR: Set a CIDR block for the public network, for example, 192.168.108.1/24.
    • Gateway: Set a gateway for the public network, for example, 192.168.108.1.
      Note:
      • We recommend that you use the first or last IP address in the specified CIDR block as the gateway.
      • If left blank, the first IP address in the specified CIDR block is used as the gateway.
    • DHCP Service: Choose whether to enable the DHCP service.
      Note:
      • The DHCP service is a built-in distributed service of the Cloud, which assigns IP addresses only to resources in the Cloud and does not conflict with your existing DHCP server.
      • By default, the DHCP service is enabled so that the NICs using this L3 network acquire IP addresses in a DHCP mode. You can customize a DHCP IP or use the DHCP IP that the system assigned according to the IP allocation policy.
      • If you disable this option, NICs using this L3 network acquire IP address in a Static mode. The Cloud does not assign IP addresses automatically. If the NICs need IP addresses, you need to configure IP addresses for them manually. In addition, you cannot specify a DHCP IP. Neither can the system allocate one.
      • IP Allocation Policy: Optional. If the DHCP service is enabled, IP addresses can be assigned according to the following three allocation policies:
        • Random: The system randomly assigns IP addresses from the network range.
        • Allocate in Order:
          • The system assigns all available IP addresses from the network range in ascending order. Released IP addresses are assigned in the next allocation.
          • Example: Assume that the network range is 192.168.0.101~192.168.0.120, within which 192.168.0.101~192.168.0.108 are allocated. If 192.168.0.106 is released, it will be assigned first in the next allocation.
        • Allocate in Cycle:
          • The system assigns available IP addresses to VM instances from the network range in ascending order. Released IP addresses are assigned when currently available IP addresses are used up.
          • Example: Assume that the network range is 192.168.0.101~192.168.0.120, within which 192.168.0.101~192.168.0.108 are allocated. If 192.168.0.106 is released, it will be assigned after 192.168.0.120 is used.
      • DHCP IP: Optional. Set an IP address for the DHCP server, for example, 172.20.108.10.
        Note:
        • A DHCP IP is an IP address used by the DHCP service to assign IP addresses to resources that use this L3 network.
        • If you create an L3 network for the first time with the DHCP service enabled, or if you add the first network range to an L3 network with the DHCP service enabled, you can customize the DHCP IP.
        • If the L3 network has a DHCP IP, you cannot customize the DHCP IP when you add a network range.
        • The DHCP IP can be in or outside the added IP range, but it must be an unoccupied IP address in the CIDR block of the added IP range
        • The IP range determined by the start IP and end IP cannot contain the link-local address 169.254.0.0/16.
        • If you select random as the IP allocation policy and this field is left blank, the system randomly assigns IP addresses from the added network range.
        • If you select allocate in order/allocate in cycle as the IP allocation policy and this field is left blank, the system uses the start IP address in the network range as the DHCP IP.
    • DNS: Add a DNS server to provide domain name resolution services for the public network. You can specify 223.5.5.5, 8.8.8.8, or 114.114.114.114.
    Note: When you add a CIDR block for an IPv4 L3 network, note that:
    • The CIDR block cannot contain the link-local address 169.254.0.0/16.
    • The CIDR block of a private network cannot overlap with the IP range of a public network used to create a vRouter offering or of a management network.
    Figure 2. Create IPv4 Public Network Using CIDR Block




Create IPv6 Public Network

On the displayed page, set the following parameters:
  • Name: Enter a name for the public network.
  • Description: Optional. Enter a description for the public network.
  • L2 Network: Select an L2 network for the public network.
    Note: ZStack Cloud allows you to use an L2 network to create multiple L3 networks. However, we recommend that you do not use an L2 network to create multiple L3 networks if not for specific business needs.
    On the Select L2 Network page, two tabs are displayed:
    • Recommended: lists L2 networks in the current zone that are not attached to an L3 network.
    • All: lists all L2 networks in the current zone.
  • Network Address Type: Select IPv6.
  • Network Range Method: Select a method to add a network range for the public network. You can select IP Range or CIDR.
    If you select IP Range, you need to set the following parameters:
    • IP Configuration Mode: Select the IP distribution mode:
      • Stateful-DHCP: The interface address and other parameters are all configured through DHCP. The IP range method supports stateful DHCP.
    • Start IP: Set a start IP address for the network range, for example, 2000:910A:2222:5498:8475:1111:3900:2002.
    • End IP: Set an end IP address for the network range, for example, 2000:910A:2222:5498:8475:1111:3900:2009.
    • Prefix Length: Set a prefix length for the network range, for example, 64.
      Note: The prefix length ranges from 64 to 126. If you set a length smaller than 64, VM creation may fail.
    • Gateway: Set a gateway for the network range, for example, 2000:910A:2222:5498:8475:1111:3900:2001.
    • DHCP Service: Choose whether to enable the DHCP service.
      Note:
      • The DHCP service is a built-in distributed service of the Cloud, which assigns IP addresses only to resources in the Cloud and does not conflict with your existing DHCP server.
      • By default, the DHCP service is enabled so that the NICs using this L3 network acquire IP addresses in a DHCP mode. You can customize a DHCP IP or use the DHCP IP that the system assigned according to the IP allocation policy.
      • If you disable this option, NICs using this L3 network acquire IP address in a Static mode. The Cloud does not assign IP addresses to NICs automatically. If the NICs need IP addresses, you need to configure IP addresses for them manually. In addition, you cannot specify a DHCP IP. Neither can the system allocate one.
      • DHCP IP: Optional. Set an IP address for the DHCP server, for example, 2000:910A:2222:5498:8475:1111:3900:2006.
        Note:
        • When you create an L3 network and enable the DHCP service for the first time, or when you add the first network range for an L3 network that has the DHCP service enabled, you can specify an IP address for the DHCP server.
        • If a DHCP IP is specified for an L3 network, you cannot specify another DHCP IP when you add a network range for the network.
        • The DHCP IP can be within or out of the added IP range. However, the IP address must be within the CIDR block to which the added IP range belongs and must not be in use.
        • The IP range determined by the start IP and end IP cannot contain the link-local address fe80::/10.
        • If not specified, the system would randomly specify a DHCP IP within the added IP range for the DHCP server.
    • DNS: Add a DNS server to provide domain name resolution services for the public network. You can specify 240C::6644 or 240C::6666.
    Note: When you add an IP range for an IPv6 L3 network, note that:
    • The IP range cannot contain gateway IP addresses.
    • The IP range determined by the start IP and end IP cannot contain the link-local address fe80::/10.
    • The IP range of a private network cannot overlap with the IP range of a public network used to create a vRouter offering or of a management network.
    Figure 3. Create IPv6 Public Network Using IP Range




    If you select CIDR, you need to set the following parameters:
    • IP Configuration Mode: Select the IP distribution mode:
      • Stateful-DHCP: The interface address and other parameters are all configured through DHCP. The IP range method supports stateful DHCP.
      • Stateless-DHCP: The interface address is automatically derived from the route advertisement prefix and the interface MAC address. Other parameters are configured through DHCP.
      • SLAAC: The interface address is automatically derived from the prefix of the route advertisement that also contains other parameters.
    • CIDR: Set a CIDR block for the public network, for example, 234E:2457:3D::/64.
    • DHCP Service: Choose whether to enable the DHCP service.
      Note:
      • The DHCP service is a built-in distributed service of the Cloud, which assigns IP addresses only to resources in the Cloud and does not conflict with your existing DHCP server.
      • By default, the DHCP service is enabled so that the NICs using this L3 network acquire IP addresses in a DHCP mode. You can customize a DHCP IP or use the DHCP IP that the system assigned according to the IP allocation policy.
      • If you disable this option, NICs using this L3 network acquire IP address in a Static mode. The Cloud does not assign IP addresses to NICs automatically. If the NICs need IP addresses, you need to configure IP addresses for them manually. In addition, you cannot specify a DHCP IP. Neither can the system allocate one.
      • DHCP IP: Optional. Set an IP address for the DHCP server, for example, 234E:2457:3D::F.
        Note:
        • When you create an L3 network and enable the DHCP service for the first time, or when you add the first network range for an L3 network that has the DHCP service enabled, you can specify an IP address for the DHCP server.
        • If a DHCP IP is specified for an L3 network, you cannot specify another DHCP IP when you add a network range for the network.
        • The DHCP IP must be within the CIDR block and must not be in use.
        • If not specified, the system would randomly specify a DHCP IP within the added IP range for the DHCP server.
        • The first IP address in the CIDR block is predefined as the default gateway and cannot be used as a DHCP server IP.
      • DNS: Add a DNS server to provide domain name resolution services for the public network. You can specify 240C::6644 or 240C::6666.
    Note: When you add a CIDR block for an IPv6 L3 network, note that:
    • The first IP address in the CIDR block is used as the default gateway.
    • The CIDR block cannot contain the link-local address fe80::/10.
    • The IP range of a private network cannot overlap with the IP range of a public network used to create a vRouter offering or of a management network.
    Figure 5. Create IPv6 Public Network Using CIDR Block




Considerations

Make sure that the network range of the public network is connected to the external networks. Otherwise, VPC vRouters may not work as expected.

Manage a Public Network

Log in to ZCF, switch to the corresponding region, and then on the main menu, choose Resource Center > Network Resource > L3 Network Resources > Public Network. The Public Network page appears.

The following table lists the actions that you can perform on a public network.
Action Description
Create Public Network Create a public network.
Add IPv4 Range Add a range of IPv4 addresses.
  • You can specify the network range method, including IP range and CIDR.
  • IPv4 public network supports address pools. You can add both normal network ranges and address pool at the same time.
    Note: An address pool network range must co-exist with a normal network range.
  • You can specify a gateway and DHCP IP for the added IP range.
Add IPv6 Range Add a range of IPv6 addresses.
  • You can specify the network range method, including IP range and CIDR.
  • IPv6 supports the three IP allocation modes: Stateful-DHCP (default), Stateless-DHCP, and SLACC.
  • You can specify a gateway and DHCP IP for the added IP range.
Reserve IPv4 Range Specify a reserved network range of IPv4 addresses. After specified, the system will not assign these addresses to your newly created resources.
  • If the specified IP range includes IP addresses that are already in use, the system will skip these used IP addresses.
  • Make sure the specified IP range is within the network range of this public network.
Reserve IPv6 Range Specify a reserved network range of IPv6 addresses. After specified, the system will not assign these addresses to your newly created resources.
  • If the specified IP range includes IP addresses that are already in use, the system will skip these used IP addresses.
  • Make sure the specified IP range is within the network range of this public network.
Modify DHCP Service Set whether to enable DHCP service, modify DHCP IP, or modify IP allocation policy.
Enable DHCP service
  • After enabled, you need to specify the IP allocation policy and DHCP server IP.
  • After enabled, VM instances in this public network may need to obtain IP addresses again, which may result in IP change. Proceed with caution.
  • If you have configured a static IP inside the VM instance before enabling the DHCP service and the VM instance does not install GuestTools, then after enabled, redistributing the IP will result in two IPs on the VM NIC. It is recommended to install GuestTools for VM instance in advance and read the IP configuration before enabling the DHCP service.
Disable DHCP service
  • After disabled, if VM instances in this public network do not have static IP addresses, proceed with caution as these VM instances may encounter network disruptions upon reboot. It is recommended to install GuestTools for VM instance in advance, configure static IP addresses, and synchronize configurations.
  • After disabled, the VM instance will not be assigned an IP address when a new VM instance is created on the public network.

For more information about how to install GuestTools, see VM GuestTools.

Add DNS Add an IPv4 or IPv6 DNS server address:
  • IPv4 address: 223.5.5.5, 8.8.8.8, or 114.114.114.114.
  • IPv6 address: 240C::6644 or 240C::6666.
Set Sharing Mode Set the sharing mode of a public network. The platform provides the following sharing modes:
  • Share Globally: shares a public network with all projects and normal accounts that have the Tenant Management license.
  • Share to Specified Projects/Accounts: shares a public network with specified projects and normal accounts that have the Tenant Management license.
  • Not Share: The public network is not shared with projects or normal accounts and can be used only by the admin.
Note:
  • Modifying the sharing mode will also modify the permissions on shared public networks.
  • Public networks that are used by projects or accounts before a modification are not affected until the public networks are released.
Delete Public Network Delete a public network.
Note: Deleting a public network detaches the VM NICs that are using this network and deletes the network services, vRouter offerings, load balancer instance offerings, SDN instance offerings, advanced monitoring server offerings using this network, and associated instances. Proceed with caution.

Create a Flat Network

Log in to ZCF, switch to the corresponding region, and then on the main menu, choose Resource Center > Network Resource > L3 Network Resources > Flat Network. On the Flat Network page, click Create Flat Network. The Create Flat Network page appears.

The following lists the three flat network creation scenarios:
  • Create an IPv4 flat network
  • Create an IPv6 flat network
  • Create a flat network disabled with IP Address Management

Create IPv4 Flat Network

On the displayed page, set the following parameters:
  • Name: Enter a name for the flat network.
  • Description: Optional. Enter a description for the flat network.
  • L2 Network: Select an L2 network for the flat network.
    Note: ZStack Cloud allows you to use an L2 network to create multiple L3 networks. However, we recommend that you do not use an L2 network to create multiple L3 networks if not for specific business needs.
    On the Select L2 Network page, two tabs are displayed:
    • Recommended: lists L2 networks in the current zone that are not attached to an L3 network.
    • All: lists all L2 networks in the current zone.
  • IP Address Management: Choose whether to enable the IP Address Management (IPAM) service for the L3 network. If you enable IPAM, you can add network ranges to the L3 network and enable the DHCP service. Enable IPAM here.
  • Network Address Type: Select IPv4.
  • Network Range Method: Select a method to add a network range for the flat network. You can select IP Range or CIDR.
    If you select IP Range, you need to set the following parameters:
    • Start IP: Set a start IP address for the network range, for example, 172.20.108.100.
    • End IP: Set an end IP address for the network range, for example, 172.20.108.200.
    • Netmask: Set a netmask for the network range, for example, 255.255.0.0.
    • Gateway: Set a gateway for the network range, for example, 172.20.0.1.
    • DHCP Service: Choose whether to enable the DHCP service.
      Note:
      • The DHCP service is a built-in distributed service of the Cloud, which assigns IP addresses only to resources in the Cloud and does not conflict with your existing DHCP server.
      • By default, the DHCP service is enabled so that the NICs using this L3 network acquire IP addresses in a DHCP mode. You can customize a DHCP IP or use the DHCP IP that the system assigned according to the IP allocation policy.
      • If you disable this option, NICs using this L3 network acquire IP address in a Static mode. The Cloud does not assign IP addresses to NICs automatically. If the NICs need IP addresses, you need to configure IP addresses for them manually. In addition, you cannot specify a DHCP IP. Neither can the system allocate one.
      • IP Allocation Policy: Optional. If the DHCP service is enabled, IP addresses can be assigned according to the following three allocation policies:
        • Random: The system randomly assigns IP addresses from the network range.
        • Allocate in Order:
          • The system assigns all available IP addresses from the network range in ascending order. Released IP addresses are assigned in the next allocation.
          • Example: Assume that the network range is 192.168.0.101~192.168.0.120, within which 192.168.0.101~192.168.0.108 are allocated. If 192.168.0.106 is released, it will be assigned first in the next allocation.
        • Allocate in Cycle:
          • The system assigns available IP addresses to VM instances from the network range in ascending order. Released IP addresses are assigned when currently available IP addresses are used up.
          • Example: Assume that the network range is 192.168.0.101~192.168.0.120, within which 192.168.0.101~192.168.0.108 are allocated. If 192.168.0.106 is released, it will be assigned after 192.168.0.120 is used.
      • DHCP IP: Optional. Set an IP address for the DHCP server, for example, 172.20.108.10.
        Note:
        • A DHCP IP is an IP address used by the DHCP service to assign IP addresses to resources that use this L3 network.
        • If you create an L3 network for the first time with the DHCP service enabled, or if you add the first network range to an L3 network with the DHCP service enabled, you can customize the DHCP IP.
        • If the L3 network has a DHCP IP, you cannot customize the DHCP IP when you add a network range.
        • The DHCP IP can be in or outside the added IP range, but it must be an unoccupied IP address in the CIDR block of the added IP range
        • The IP range determined by the start IP and end IP cannot contain the link-local address 169.254.0.0/16.
        • If you select random as the IP allocation policy and this field is left blank, the system randomly assigns IP addresses from the added network range.
        • If you select allocate in order/allocate in cycle as the IP allocation policy and this field is left blank, the system uses the start IP address in the network range as the DHCP IP.
    • DNS: Add a DNS server to provide domain name resolution services for the flat network. You can specify 223.5.5.5, 8.8.8.8, or 114.114.114.114.
    Note: When you add an IP range for an IPv4 L3 network, note that:
    • The IP range cannot contain gateway IP addresses, broadcast addresses, or network addresses.
    • The IP range of a flat network cannot overlap with the IP range of a public network used to create a vRouter offering or of a management network.
    Figure 7. Create IPv4 Flat Network Using IP Range




    If you select CIDR, you need to set the following parameters:
    • CIDR: Set a CIDR block for the flat network, for example, 192.168.108.1/24.
    • Gateway: Set a gateway for the flat network, for example, 192.168.108.1.
      Note:
      • We recommend that you use the first or last IP address in the specified CIDR block as the gateway.
      • If left blank, the first IP address in the specified CIDR block is used as the gateway.
    • DHCP Service: Choose whether to enable the DHCP service.
      Note:
      • The DHCP service is a built-in distributed service of the Cloud, which assigns IP addresses only to resources in the Cloud and does not conflict with your existing DHCP server.
      • By default, the DHCP service is enabled so that the NICs using this L3 network acquire IP addresses in a DHCP mode. You can customize a DHCP IP or use the DHCP IP that the system assigned according to the IP allocation policy.
      • If you disable this option, NICs using this L3 network acquire IP address in a Static mode. The Cloud does not assign IP addresses to NICs automatically. If the NICs need IP addresses, you need to configure IP addresses for them manually. In addition, you cannot specify a DHCP IP. Neither can the system allocate one.
      • IP Allocation Policy: Optional. If the DHCP service is enabled, IP addresses can be assigned according to the following three allocation policies:
        • Random: The system randomly assigns IP addresses from the network range.
        • Allocate in Order:
          • The system assigns all available IP addresses from the network range in ascending order. Released IP addresses are assigned in the next allocation.
          • Example: Assume that the network range is 192.168.0.101~192.168.0.120, within which 192.168.0.101~192.168.0.108 are allocated. If 192.168.0.106 is released, it will be assigned first in the next allocation.
        • Allocate in Cycle:
          • The system assigns available IP addresses to VM instances from the network range in ascending order. Released IP addresses are assigned when currently available IP addresses are used up.
          • Example: Assume that the network range is 192.168.0.101~192.168.0.120, within which 192.168.0.101~192.168.0.108 are allocated. If 192.168.0.106 is released, it will be assigned after 192.168.0.120 is used.
      • DHCP IP: Optional. Set an IP address for the DHCP server, for example, 172.20.108.10.
        Note:
        • A DHCP IP is an IP address used by the DHCP service to assign IP addresses to resources that use this L3 network.
        • If you create an L3 network for the first time with the DHCP service enabled, or if you add the first network range to an L3 network with the DHCP service enabled, you can customize the DHCP IP.
        • If the L3 network has a DHCP IP, you cannot customize the DHCP IP when you add a network range.
        • The DHCP IP can be in or outside the added IP range, but it must be an unoccupied IP address in the CIDR block of the added IP range
        • The IP range determined by the start IP and end IP cannot contain the link-local address 169.254.0.0/16.
        • If you select random as the IP allocation policy and this field is left blank, the system randomly assigns IP addresses from the added network range.
        • If you select allocate in order/allocate in cycle as the IP allocation policy and this field is left blank, the system uses the start IP address in the network range as the DHCP IP.
    • DNS: Add a DNS server to provide domain name resolution services for the flat network. You can specify 223.5.5.5, 8.8.8.8, or 114.114.114.114.
    Note: When you add a CIDR block for an IPv4 L3 network, note that:
    • The CIDR block cannot contain the link-local address 169.254.0.0/16.
    • The CIDR block of a flat network cannot overlap with the IP range of a public network used to create a vRouter offering or of a management network.
    Figure 8. Create IPv4 Flat Network Using CIDR Block




Create IPv6 Flat Network

On the displayed page, set the following parameters:
  • Name: Enter a name for the flat network.
  • Description: Optional. Enter a description for the flat network.
  • L2 Network: Select an L2 network for the flat network.
    Note: ZStack Cloud allows you to use an L2 network to create multiple L3 networks. However, we recommend that you do not use an L2 network to create multiple L3 networks if not for specific business needs.
    On the Select L2 Network page, two tabs are displayed:
    • Recommended: lists L2 networks in the current zone that are not attached to an L3 network.
    • All: lists all L2 networks in the current zone.
  • IP Address Management: Choose whether to enable the IP Address Management (IPAM) service for the L3 network. If you enable IPAM, you can add network ranges to the L3 network and enabled the DHCP service. Enable IPAM here.
  • Network Address Type: Select IPv6.
  • Network Range Method: Select a method to add a network range for the flat network. You can select IP Range or CIDR.
    If you select IP Range, you need to set the following parameters:
    • IP Configuration Mode: Select the IP distribution mode:
      • Stateful-DHCP: The interface address and other parameters are all configured through DHCP. The IP range method supports stateful DHCP.
    • Start IP: Set a start IP address for the network range, for example, 2000:910A:2222:5498:8475:1111:3900:2002.
    • End IP: Set an end IP address for the network range, for example, 2000:910A:2222:5498:8475:1111:3900:2009.
    • Prefix Length: Set a prefix length for the network range, for example, 64.
      Note: The prefix length ranges from 64 to 126. If you set a length smaller than 64, VM creation may fail.
    • Gateway: Set a gateway for the network range, for example, 2000:910A:2222:5498:8475:1111:3900:2001.
    • DHCP Service: Choose whether to enable the DHCP service.
      Note:
      • The DHCP service is a built-in distributed service of the Cloud, which assigns IP addresses only to resources in the Cloud and does not conflict with your existing DHCP server.
      • By default, the DHCP service is enabled so that the NICs using this L3 network acquire IP addresses in a DHCP mode. You can customize a DHCP IP or use the DHCP IP that the system assigned according to the IP allocation policy.
      • If you disable this option, NICs using this L3 network acquire IP address in a Static mode. The Cloud does not assign IP addresses to NICs automatically. If the NICs need IP addresses, you need to configure IP addresses for them manually. In addition, you cannot specify a DHCP IP. Neither can the system allocate one.
      • DHCP IP: Optional. Set an IP address for the DHCP server, for example, 2000:910A:2222:5498:8475:1111:3900:2006.
        Note:
        • When you create an L3 network and enable the DHCP service for the first time, or when you add the first network range for an L3 network that has the DHCP service enabled, you can specify an IP address for the DHCP server.
        • If a DHCP IP is specified for an L3 network, you cannot specify another DHCP IP when you add a network range for the network.
        • The DHCP IP can be within or out of the added IP range. However, the IP address must be within the CIDR block to which the added IP range belongs and must not be in use.
        • The IP range determined by the start IP and end IP cannot contain the link-local address fe80::/10.
        • If not specified, the system would randomly specify a DHCP IP within the added IP range for the DHCP server.
    • DNS: Add a DNS server to provide domain name resolution services for the public network. You can specify 240C::6644 or 240C::6666.
    Note: When you add an IP range for an IPv6 L3 network, note that:
    • The IP range cannot contain gateway IP addresses.
    • The IP range determined by the start IP and end IP cannot contain the link-local address fe80::/10.
    • The IP range of a flat network cannot overlap with the IP range of a public network used to create a vRouter offering or of a management network.
    Figure 9. Create IPv6 Flat Network Using IP Range




    If you select CIDR, you need to set the following parameters:
    • IP Configuration Mode: Select the IP distribution mode:
      • Stateful-DHCP: The interface address and other parameters are all configured through DHCP. The IP range method supports stateful DHCP.
      • Stateless-DHCP: The interface address is automatically derived from the route advertisement prefix and the interface Mac address. Other parameters are configured through DHCP.
      • SLAAC: The interface address is automatically derived from the prefix of the route advertisement that also contains other parameters.
    • CIDR: Set a CIDR block for the flat network, for example, 234E:2457:3D::/64.
    • DHCP Service: Choose whether to enable the DHCP service.
      Note:
      • The DHCP service is a built-in distributed service of the Cloud, which assigns IP addresses only to resources in the Cloud and does not conflict with your existing DHCP server.
      • By default, the DHCP service is enabled so that the NICs using this L3 network acquire IP addresses in a DHCP mode. You can customize a DHCP IP or use the DHCP IP that the system assigned according to the IP allocation policy.
      • If you disable this option, NICs using this L3 network acquire IP address in a Static mode. The Cloud does not assign IP addresses to NICs automatically. If the NICs need IP addresses, you need to configure IP addresses for them manually. In addition, you cannot specify a DHCP IP. Neither can the system allocate one.
      • DHCP IP: Optional. Set an IP address for the DHCP server, for example, 234E:2457:3D::F.
        Note:
        • When you create an L3 network and enable the DHCP service for the first time, or when you add the first network range for an L3 network that has the DHCP service enabled, you can specify an IP address for the DHCP server.
        • If a DHCP IP is specified for an L3 network, you cannot specify another DHCP IP when you add a network range for the network.
        • The DHCP IP must be within the CIDR block and must not be in use.
        • If not specified, the system would randomly specify a DHCP IP within the added IP range for the DHCP server.
        • The first IP address in the CIDR block is predefined as the default gateway and cannot be used as a DHCP server IP.
      • DNS: Add a DNS server to provide domain name resolution services for the public network. You can specify 240C::6644 or 240C::6666.
    Note: When you add a CIDR block for an IPv6 L3 network, note that:
    • The first IP address in the CIDR block is used as the default gateway.
    • The CIDR block cannot contain the link-local address fe80::/10.
    • The IP range of a flat network cannot overlap with the IP range of a public network used to create a vRouter offering or of a management network.
    Figure 10. Create IPv6 Flat Network Using CIDR Block




Create an Flat Network Disabled with IP Address Management

On the displayed page, set the following parameters:
  • Name: Enter a name for the flat network.
  • Description: Optional. Enter a description for the flat network.
  • L2 Network: Select an L2 network for the flat network.
    Note: ZStack Cloud allows you to use an L2 network to create multiple L3 networks. However, we recommend that you do not use an L2 network to create multiple L3 networks if not for specific business needs.
    On the Select L2 Network page, two tabs are displayed:
    • Recommended: lists L2 networks in the current zone that are not attached to an L3 network.
    • All: lists all L2 networks in the current zone.
  • IP Address Management: Choose whether to enable the IP Address Management (IPAM) service for the L3 network. Disable IPAM here.
    Note:
    • If you disable IPAM for an L3 network, you cannot add network ranges or enable DHCP service for the L3 network. The system does not assign IP addresses to resources on this network automatically. You can configure and manage IP addresses for the NICs on this L3 network by yourself.
    • You can disable IPAM only for flat networks.
  • DHCP Service: The DHCP service is disabled by default after you disable IPAM and cannot be enabled.
  • DNS: Optional. Add a DNS server to provide the DNS service for the L3 network.
Figure 11. Create Flat Network Disabled with IP Address Management


Manage a Flat Network

Log in to ZCF, switch to the corresponding region, and then on the main menu, choose Resource Center > Network Resource > L3 Network Resources > Flat Network. The Flat Network page appears.

The following table lists the actions that you can perform on a flat network.
Action Description
Create Flat Network Create a flat network.
Add IPv4 Range Add a range of IPv4 addresses.
  • You can specify the network range method, including IP range and CIDR.
  • You can specify a gateway and DHCP IP for the added IP range.
Add IPv6 Range Add a range of IPv6 addresses.
  • You can specify the network range method, including IP range and CIDR.
  • IPv6 supports the three IP allocation modes: Stateful-DHCP (default), Stateless-DHCP, and SLACC.
  • You can specify a gateway and DHCP IP for the added IP range.
Reserve IPv4 Range Specify a reserved network range of IPv4 addresses. After specified, the system will not assign these addresses to your newly created resources.
  • If the specified IP range includes IP addresses that are already in use, the system will skip these used IP addresses.
  • Make sure the specified IP range is within the network range of this flat network.
Reserve IPv6 Range Specify a reserved network range of IPv6 addresses. After specified, the system will not assign these addresses to your newly created resources.
  • If the specified IP range includes IP addresses that are already in use, the system will skip these used IP addresses.
  • Make sure the specified IP range is within the network range of this flat network.
Modify DHCP Service Set whether to enable DHCP service, modify DHCP IP, or modify IP allocation policy.
Enable DHCP service
  • After enabled, you need to specify the IP allocation policy and DHCP server IP.
  • After enabled, VM instances in this flat network may need to obtain IP addresses again, which may result in IP change. Proceed with caution.
  • If you have configured a static IP inside the VM instance before enabling the DHCP service and the VM instance does not install GuestTools, then after enabled, redistributing the IP will result in two IPs on the VM NIC. It is recommended to install GuestTools for VM instance in advance and read the IP configuration before enabling the DHCP service.
Disable DHCP service
  • After disabled, if VM instances in this flat network do not have static IP addresses, proceed with caution as these VM instances may encounter network disruptions upon reboot. It is recommended to install GuestTools for VM instance in advance, configure static IP addresses, and synchronize configurations.
  • After disabled, the VM instance will not be assigned an IP address when a new VM instance is created on the flat network.

For more information about how to install GuestTools, see VM GuestTools.

Add DNS Add an IPv4 or IPv6 DNS server address:
  • IPv4 address: 223.5.5.5, 8.8.8.8, or 114.114.114.114.
  • IPv6 address: 240C::6644 or 240C::6666.
Set Sharing Mode Set the sharing mode of a flat network. The platform provides the following sharing modes:
  • Share Globally: shares a flat network with all projects and normal accounts that have the Tenant Management license.
  • Share to Specified Projects/Accounts: shares a flat network with specified projects and normal accounts that have the Tenant Management license.
  • Not Share: The flat network is not shared with projects or normal accounts and can be used only by the admin.
Note:
  • Modifying the sharing mode will also modify the permissions on shared flat networks.
  • Flat networks that are used by projects or accounts before a modification are not affected until the flat networks are released.
Delete Flat Network Delete a flat network.
Note: Deleting a flat network also detaches the VM NICs that are using this network, and deletes the corresponding vRouters, network services, and vRouter offerings. Proceed with caution.

Create a VPC Network

Log in to ZCF, switch to the corresponding region, and then on the main menu, choose Resource Center > Network Resource > L3 Network Resources > VPC Network. On the VPC Network page, click Create VPC Network. The Create VPC Network page appears.

The following lists the two VPC network creation scenarios:
  • Create an IPv4 VPC network
  • Create an IPv6 VPC network

Create IPv4 VPC Network

On the displayed page, set the following parameters:
  • Name: Enter a name for the VPC network.
  • Description: Optional. Enter a description for the VPC network.
  • L2 Network: Select an L2 network for the VPC network.
    Note: ZStack Cloud allows you to use an L2 network to create multiple L3 networks. However, we recommend that you do not use an L2 network to create multiple L3 networks if not for specific business needs.
    On the Select L2 Network page, two tabs are displayed:
    • Recommended: lists L2 networks in the current zone that are not attached to an L3 network.
    • All: lists all L2 networks in the current zone.
  • VPC vRouter: Optional. You can specify a VPC vRouter when you create a VPC network or attach a VPC vRouter after you create the VPC network.
    Note:
    • This parameter will not be displayed if the selected L2 network is created based on H3C VCFC R6506.
    • This parameter will not be displayed if the selected L2 network is created based on the HUAWEI SDN controller. In addition, you need to configure the Logical Router parameter.
  • Network Address Type: Select IPv4.
  • Network Range Method: Select a method to add a network range for the VPC network. You can select IP Range or CIDR.
    If you select IP Range, you need to set the following parameters:
    • Start IP: Set a start IP address for the network range, for example, 172.20.108.100.
    • End IP: Set an end IP address for the network range, for example, 172.20.108.200.
    • Netmask: Set a netmask for the network range, for example, 255.255.0.0.
    • Gateway: Set a gateway for the network range, for example, 172.20.0.1.
    • DHCP Service: Choose whether to enable the DHCP service.
      Note:
      • The DHCP service is a built-in distributed service of the Cloud, which assigns IP addresses only to resources in the Cloud and does not conflict with your existing DHCP server.
      • By default, the DHCP service is enabled so that the NICs using this L3 network acquire IP addresses in a DHCP mode. You can customize a DHCP IP or use the DHCP IP that the system assigned according to the IP allocation policy.
      • If you disable this option, NICs using this L3 network acquire IP address in a Static mode. The Cloud does not assign IP addresses to NICs automatically. If the NICs need IP addresses, you need to configure IP addresses for them manually. In addition, you cannot specify a DHCP IP. Neither can the system allocate one.
      • IP Allocation Policy: Optional. If the DHCP service enabled, IP addresses can be assigned according to the following three allocation policies:
        • Random: The system randomly assigns IP addresses from the network range.
        • Allocate in Order:
          • The system assigns all available IP addresses from the network range in ascending order. Released IP addresses are assigned in the next allocation.
          • Example: Assume that the network range is 192.168.0.101~192.168.0.120, within which 192.168.0.101~192.168.0.108 are allocated. If 192.168.0.106 is released, it will be assigned first in the next allocation.
        • Allocate in Cycle:
          • The system assigns available IP addresses to VM instances from the network range in ascending order. Released IP addresses are assigned when currently available IP addresses are used up.
          • Example: Assume that the network range is 192.168.0.101~192.168.0.120, within which 192.168.0.101~192.168.0.108 are allocated. If 192.168.0.106 is released, it will be assigned after 192.168.0.120 is used.
      • DHCP IP: Optional. Set an IP address for the DHCP server, for example, 172.20.108.10.
        Note:
        • A DHCP IP is an IP address used by the DHCP service to assign IP addresses to resources that use this L3 network.
        • If you create an L3 network for the first time with the DHCP service enabled, or if you add the first network range to an L3 network with the DHCP service enabled, you can customize the DHCP IP.
        • If the L3 network has a DHCP IP, you cannot customize the DHCP IP when you add a network range.
        • The DHCP IP can be in or outside the added IP range, but it must be an unoccupied IP address in the CIDR block of the added IP range
        • The IP range determined by the start IP and end IP cannot contain the link-local address 169.254.0.0/16.
        • If you select random as the IP allocation policy and this field is left blank, the system randomly assigns IP addresses from the added network range.
        • If you select allocate in order/allocate in cycle as the IP allocation policy and this field is left blank, the system uses the start IP address in the network range as the DHCP IP.
    • DNS: Provide DNS services for an L3 network. If you do not specify a DNS address manually, the VPC network uses its gateway address as the DNS address by default. This DNS cannot be deleted and prohibits you from adding other DNS after the creation.
    Note: When you add an IP range for an IPv4 L3 network, note that:
    • The IP range cannot contain gateway IP addresses, broadcast addresses, or network addresses.
    • The IP range of a VPC network cannot overlap with the IP range of a public network used to create a vRouter offering or of a management network.
    Figure 12. Create IPv4 VPC Network Using IP Range




    If you select CIDR, you need to set the following parameters:
    • CIDR: Set a CIDR block for the VPC network, for example, 192.168.108.1/24.
    • Gateway: Set a gateway for the VPC network, for example, 192.168.108.1.
      Note:
      • We recommend that you use the first or last IP address in the specified CIDR block as the gateway.
      • If left blank, the first IP address in the specified CIDR block is used as the gateway.
    • DHCP Service: Choose whether to enable the DHCP service.
      Note:
      • The DHCP service is a built-in distributed service of the Cloud, which assigns IP addresses only to resources in the Cloud and does not conflict with your existing DHCP server.
      • By default, the DHCP service is enabled so that the NICs using this L3 network acquire IP addresses in a DHCP mode. You can customize a DHCP IP or use the DHCP IP that the system assigned according to the IP allocation policy.
      • If you disable this option, NICs using this L3 network acquire IP address in a Static mode. The Cloud does not assign IP addresses to NICs automatically. If the NICs need IP addresses, you need to configure IP addresses for them manually. In addition, you cannot specify a DHCP IP. Neither can the system allocate one.
      • IP Allocation Policy: Optional. If the DHCP service is enabled, IP addresses can be assigned according to the following three allocation policies:
        • Random: The system randomly assigns IP addresses from the network range.
        • Allocate in Order:
          • The system assigns all available IP addresses from the network range in ascending order. Released IP addresses are assigned in the next allocation.
          • Example: Assume that the network range is 192.168.0.101~192.168.0.120, within which 192.168.0.101~192.168.0.108 are allocated. If 192.168.0.106 is released, it will be assigned first in the next allocation.
        • Allocate in Cycle:
          • The system assigns available IP addresses to VM instances from the network range in ascending order. Released IP addresses are assigned when currently available IP addresses are used up.
          • Example: Assume that the network range is 192.168.0.101~192.168.0.120, within which 192.168.0.101~192.168.0.108 are allocated. If 192.168.0.106 is released, it will be assigned after 192.168.0.120 is used.
      • DHCP IP: Optional. Set an IP address for the DHCP server, for example, 172.20.108.10.
        Note:
        • A DHCP IP is an IP address used by the DHCP service to assign IP addresses to resources that use this L3 network.
        • If you create an L3 network for the first time with the DHCP service enabled, or if you add the first network range to an L3 network with the DHCP service enabled, you can customize the DHCP IP.
        • If the L3 network has a DHCP IP, you cannot customize the DHCP IP when you add a network range.
        • The DHCP IP can be in or outside the added IP range, but it must be an unoccupied IP address in the CIDR block of the added IP range
        • The IP range determined by the start IP and end IP cannot contain the link-local address 169.254.0.0/16.
        • If you select random as the IP allocation policy and this field is left blank, the system randomly assigns IP addresses from the added network range.
        • If you select allocate in order/allocate in cycle as the IP allocation policy and this field is left blank, the system uses the start IP address in the network range as the DHCP IP.
    • DNS: Provide DNS services for an L3 network. If you do not specify a DNS address manually, theVPC network uses its gateway address as the DNS address by default. This DNS cannot be deleted and prohibits you from adding other DNS after the creation.
    Note: When you add a CIDR block for an IPv4 L3 network, note that:
    • The CIDR block cannot contain the link-local address 169.254.0.0/16.
    • The CIDR block of a VPC network cannot overlap with the IP range of a public network used to create a vRouter offering or of a management network.
    Figure 13. Create IPv4 VPC Network Using CIDR Block




Create IPv6 VPC Network

On the displayed page, set the following parameters:
  • Name: Enter a name for the VPC network.
  • Description: Optional. Enter a description for the VPC network.
  • L2 Network: Select an L2 network for the VPC network.
    Note: ZStack Cloud allows you to use an L2 network to create multiple L3 networks. However, we recommend that you do not use an L2 network to create multiple L3 networks if not for specific business needs.
    On the Select L2 Network page, two tabs are displayed:
    • Recommended: lists L2 networks in the current zone that are not attached to an L3 network.
    • All: lists all L2 networks in the current zone.
  • VPC vRouter: Optional. You can specify a VPC vRouter when you create a VPC network or attach a VPC vRouter to a created VPC network.
    Note:
    • This parameter will not be displayed if the selected L2 network is created based on H3C VCFC R6506.
    • This parameter will not be displayed if the selected L2 network is created based on the HUAWEI SDN controller. In addition, you need to configure the Logical Router parameter.
  • Network Address Type: Select IPv6.
  • Network Range Method: Select a method to add a network range for the VPC network. You can select IP Range or CIDR.
    If you select IP Range, you need to set the following parameters:
    • IP Configuration Mode: Select the IP distribution mode:
      • Stateful-DHCP: The interface address and other parameters are all configured through DHCP. The IP range method supports stateful DHCP.
    • Start IP: Set a start IP address for the network range, for example, 2000:910A:2222:5498:8475:1111:3900:2002.
    • End IP: Set an end IP address for the network range, for example, 2000:910A:2222:5498:8475:1111:3900:2009.
    • Prefix Length: Set a prefix length for the network range, for example, 64.
      Note: The prefix length ranges from 64 to 126. If you set a length smaller than 64, VM creation may fail.
    • Gateway: Set a gateway for the network range, for example, 2000:910A:2222:5498:8475:1111:3900:2001.
    • DHCP Service: Choose whether to enable the DHCP service.
      Note:
      • The DHCP service is a built-in distributed service of the Cloud, which assigns IP addresses only to resources in the Cloud and does not conflict with your existing DHCP server.
      • By default, the DHCP service is enabled so that the NICs using this L3 network acquire IP addresses in a DHCP mode. You can customize a DHCP IP or use the DHCP IP that the system assigned according to the IP allocation policy.
      • If you disable this option, NICs using this L3 network acquire IP address in a Static mode. The Cloud does not assign IP addresses to NICs automatically. If the NICs need IP addresses, you need to configure IP addresses for them manually. In addition, you cannot specify a DHCP IP. Neither can the system allocate one.
      • DHCP IP: Optional. Set an IP address for the DHCP server, for example, 2000:910A:2222:5498:8475:1111:3900:2006.
        Note:
        • When you create an L3 network and enable the DHCP service for the first time, or when you add the first network range for an L3 network that has the DHCP service enabled, you can specify an IP address for the DHCP server.
        • If a DHCP IP is specified for an L3 network, you cannot specify another DHCP IP when you add a network range for the network.
        • The DHCP IP can be within or out of the added IP range. However, the IP address must be within the CIDR block to which the added IP range belongs and must not be in use.
        • The IP range determined by the start IP and end IP cannot contain the link-local address fe80::/10.
        • If not specified, the system would randomly specify a DHCP IP within the added IP range for the DHCP server.
    • DNS: Provide DNS services for an L3 network. If you do not specify a DNS address manually, the VPC network uses its gateway address as the DNS address by default. This DNS cannot be deleted and prohibits you from adding other DNS after the creation.
    Note: When you add an IP range for an IPv6 L3 network, note that:
    • The IP range cannot contain gateway IP addresses.
    • The IP range determined by the start IP and end IP cannot contain the link-local address fe80::/10.
    • The IP range of a VPC network cannot overlap with the IP range of a public network used to create a vRouter offering or of a management network.
    Figure 14. Create IPv6 VPC Network Using IP Range




    If you select CIDR, you need to set the following parameters:
    • IP Configuration Mode: Select the IP distribution mode:
      • Stateful-DHCP: The interface address and other parameters are all configured through DHCP. The IP range method supports stateful DHCP.
      • Stateless-DHCP: The interface address is automatically derived from the route advertisement prefix and the interface Mac address. Other parameters are configured through DHCP.
      • SLAAC: The interface address is automatically derived from the prefix of the route advertisement that also contains other parameters.
    • CIDR: Set a CIDR block for the VPC network, for example, 234E:2457:3D::/64.
    • DHCP Service: Choose whether to enable the DHCP service.
      Note:
      • The DHCP service is a built-in distributed service of the Cloud, which assigns IP addresses only to resources in the Cloud and does not conflict with your existing DHCP server.
      • By default, the DHCP service is enabled so that the NICs using this L3 network acquire IP addresses in a DHCP mode. You can customize a DHCP IP or use the DHCP IP that the system assigned according to the IP allocation policy.
      • If you disable this option, NICs using this L3 network acquire IP address in a Static mode. The Cloud does not assign IP addresses to NICs automatically. If the NICs need IP addresses, you need to configure IP addresses for them manually. In addition, you cannot specify a DHCP IP. Neither can the system allocate one.
      • DHCP IP: Optional. Set an IP address for the DHCP server, for example, 234E:2457:3D::F.
        Note:
        • When you create an L3 network and enable the DHCP service for the first time, or when you add the first network range for an L3 network that has the DHCP service enabled, you can specify an IP address for the DHCP server.
        • If a DHCP IP is specified for an L3 network, you cannot specify another DHCP IP when you add a network range for the network.
        • The DHCP IP must be within the CIDR block and must not be in use.
        • If not specified, the system would randomly specify a DHCP IP within the added IP range for the DHCP server.
        • The first IP address in the CIDR block is predefined as the default gateway and cannot be used as a DHCP server IP.
    • DNS: Provide DNS services for an L3 network. If you do not specify a DNS address manually, the VPC network uses its gateway address as the DNS address by default. This DNS cannot be deleted and prohibits you from adding other DNS after the creation.
    Note: When you add a CIDR block for an IPv6 L3 network, note that:
    • The first IP address in the CIDR block is used as the default gateway.
    • The CIDR block cannot contain the link-local address fe80::/10.
    • The IP range of a VPC network cannot overlap with the IP range of a public network used to create a vRouter offering or of a management network.
    Figure 15. Create IPv6 VPC Network Using CIDR Block




Manage a VPC Network

Log in to ZCF, switch to the corresponding region, and then on the main menu, choose Resource Center > Network Resource > L3 Network Resources > VPC Network. The VPC Network page appears.

The following table lists the actions that you can perform on a VPC network.
Action Description
Create VPC Network Create a VPC network.
Reserve IPv4 Range Specify a reserved network range of IPv4 addresses. After specified, the system will not assign these addresses to your newly created resources.
  • If the specified IP range includes IP addresses that are already in use, the system will skip these used IP addresses.
  • Make sure the specified IP range is within the network range of this VPC network.
Reserve IPv6 Range Specify a reserved network range of IPv6 addresses. After specified, the system will not assign these addresses to your newly created resources.
  • If the specified IP range includes IP addresses that are already in use, the system will skip these used IP addresses.
  • Make sure the specified IP range is within the network range of this VPC network.
Set Sharing Mode Set the sharing mode of a VPC network. The platform provides the following sharing modes:
  • Share Globally: shares a VPC network with all projects and normal accounts that have the Tenant Management license.
  • Share to Specified Projects/Accounts: shares a VPC network with specified projects and normal accounts that have the Tenant Management license.
  • Not Share: The VPC network is not shared with projects or normal accounts and can be used only by the admin.
Note:
  • Modifying the sharing mode will also modify the permissions on shared VPC networks.
  • VPC networks that are used by projects or accounts before a modification are not affected until the VPC networks are released.
Attach VPC vRouter Attach a VPC vRouter to the VPC network.
Detach VPC vRouter Detach a VPC vRouter from the VPC network.
Delete VPC Network Delete a VPC network.
Note: Deleting a VPC network also detaches the VM NICs that are using this network.

Create a Management Network

Log in to ZCF, switch to the corresponding region, and then on the main menu, choose Resource Center > Network Resource > Dedicated Network > Management Network. On the Management Network page, click Create Management Network. Then, the Create Management Network page is displayed.

Create Management Network

On the displayed page, set the following parameters:
  • Name: Enter a name for the management network.
  • Description: Optional. Enter a description for the management network.
  • L2 Network: Select an L2 network for the management network.
    Note: ZStack Cloud allows you to use an L2 network to create multiple L3 networks. However, we recommend that you do not use an L2 network to create multiple L3 networks if not for specific business needs.
    On the Select L2 Network page, two tabs are displayed:
    • Recommended: lists L2 networks in the current zone that are not attached to an L3 network.
    • All: lists all L2 networks in the current zone.
  • Network Range Method: Select a method to add a network range for the management network. You can select IP Range or CIDR.
    If you select IP Range, you need to set the following parameters:
    • Start IP: Set a start IP address for the network range, for example, 172.20.108.100.
    • End IP: Set an end IP address for the network range, for example, 172.20.108.200.
    • Netmask: Set a netmask for the network range, for example, 255.255.0.0.
    • Gateway: Set a gateway for the network range, for example, 172.20.0.1.
    Note: When you add an IP range for an L3 network, note that:
    • The IP range cannot contain gateway IP addresses in the format of xxx.xxx.xxx.1, broadcast addresses in the format of xxx.xxx.xxx.255, or network addresses in the format of xxx.xxx.xxx.0.
    • The IP range of a private network cannot overlap with the IP range of a public network used to create a vRouter offering or of a management network.
    Figure 16. Create Management Network Using IP Range


    If you select CIDR, you need to set the following parameters:
    • CIDR: Set a CIDR block for the management network, for example, 192.168.1.1/24.
    • Gateway: Set a gateway for the management network, for example, 192.168.1.1.
      Note:
      • We recommend that you use the first or last IP address in the specified CIDR block as the gateway.
      • If left blank, the first IP address in the specified CIDR block is used as the gateway.
    Note: When you add a CIDR block for an L3 network, note that:
    • The CIDR block cannot contain the link-local address 169.254.0.0/16.
    • The CIDR block of a private network cannot overlap with the IP range of a public network used to create a vRouter offering or of a management network.
    Figure 17. Create Management Network Using CIDR Block


Considerations

Make sure that the network range of the public network is different from the network range of the management network when you create a vRouter offering.

Manage a Management Network

Log in to ZCF, switch to the corresponding region, and then on the main menu, choose Resource Center > Network Resource > Dedicated Network > Management Network. Then, the Management Network page is displayed.

The following table lists the actions that you can perform on a management network.
Action Description
Create Management Network Create a management network.
Delete Management Network Delete a management network.
Note: Deleting a management network detaches the VM NICs that are using this network and deletes the network services, vRouter offerings, load balancer instance offerings, SDN instance offerings, advanced monitoring server offerings using this network, and associated instances. Proceed with caution.

Create a Flow Network

Log in to ZCF, switch to the corresponding region, and then on the main menu, choose Resource Center > Network Resource > Dedicated Network > Flow Network. On the Flow Network page, click Create Flow Network. Then, the Create Flow Network page is displayed.

Create a Flow Network

On the displayed page, set the following parameters:
  • Name: Enter a name for the flow network.
  • Description: Optional. Enter a description for the flow network.
  • L2 Network: Select an L2 network for the flow network.
    Note: ZStack Cloud allows you to use an L2 network to create multiple L3 networks. However, we recommend that you do not use an L2 network to create multiple L3 networks if not for specific business needs.
    On the Select L2 Network page, two tabs are displayed:
    • Recommended: lists L2 networks in the current zone that are not attached to an L3 network.
    • All: lists all L2 networks in the current zone.
  • Network Range Method: Select a method to add a network range for the flow network. You can select IP Range or CIDR.
    If you select IP Range, you need to set the following parameters:
    • Start IP: Set a start IP address for the network range, for example, 172.20.108.100.
    • End IP: Set an end IP address for the network range, for example, 172.20.108.200.
    • Netmask: Set a netmask for the network range, for example, 255.255.0.0.
    • Gateway: Set a gateway for the network range, for example, 172.20.0.1.
    Note: When you add an IP range for an L3 network, note that:
    • The IP range cannot contain gateway IP addresses in the format of xxx.xxx.xxx.1, broadcast addresses in the format of xxx.xxx.xxx.255, or network addresses in the format of xxx.xxx.xxx.0.
    • The IP range of a private network cannot overlap with the IP range of a public network used to create a vRouter offering or of a management network.
    Figure 18. Create Flow Network Using IP Range


    If you select CIDR, you need to set the following parameters:
    • CIDR: Set a CIDR block for the flow network, for example, 192.168.1.1/24.
    • Gateway: Set a gateway for the flow network, for example, 192.168.1.1.
      Note:
      • We recommend that you use the first or last IP address in the specified CIDR block as the gateway.
      • If left blank, the first IP address in the specified CIDR block is used as the gateway.
    Note: When you add a CIDR block for an L3 network, note that:
    • The CIDR block cannot contain the link-local address 169.254.0.0/16.
    • The CIDR block of a private network cannot overlap with the IP range of a public network used to create a vRouter offering or of a management network.
    Figure 19. Create Flow Network Using CIDR Block


Manage a Flow Network

Log in to ZCF, switch to the corresponding region, and then on the main menu, choose Resource Center > Network Resource > L2 Network Resources > Dedicated Network > Flow Network. Then, the Flow Network page is displayed.

The following table lists the actions that you can perform on a flow network.
Action Description
Create Flow Network Create a flow network.
Delete Flow Network Delete a flow network.
Note: Deleting a flow network also deletes the associated VPC vRouter.

Best Practices

Deploy an IPv4 Flat Network

IPv4, known as Internet Protocol version 4 which defines IP addresses in a 32-bit format, is the most popular Internet Protocol version across the globe. ZStack Cloud flat networks support the IPv4 protocol. This topic mainly describes the basic deployment of IPv4 flat networks.

The following table lists the assumed environment configurations.
Flat Network Configurations
NIC em01
VLAN ID No VLAN
IP Range 172.20.108.40-172.20.108.50
Netmask 255.255.0.0
Gateway 172.20.0.1
DHCP IP 172.20.180.41
To create an IPv4 flat network, follow these steps:
  1. Create an L2 network corresponded by an IPv4 flat network, and attach the L2 network to the corresponding cluster.
  2. Create an L3 network corresponded by an IPv4 flat network.
  3. Create a VM instance by using this IPv4 flat network.
  4. Validate the connectivity of this IPv4 flat network.
  1. Create an L2 network corresponded by an IPv4 flat network, and attach this L2 network to the corresponding cluster.
    Log in to ZCF, switch to the corresponding region, and then on the main menu, choose Resource Center > Network Resource > L2 Network Resources > L2 Network. On the L2 Network page, click Create L2 Network. Then, the Create L2 Network page is displayed. On the displayed Create L2 Network page, set the following parameters by referring to IPv4 Flat Network Configuration:
    • Zone: By default, the current zone is displayed.
    • Name: Enter a name for the L2 flat network.
    • Description: Optional. Enter a description for the L2 flat network.
    • Switch Type: Select Linux Bridge.
    • Network Type: Select L2NoVlanNetwork.
    • Cluster: Optional. Select the cluster to be attached, for example, Cluster-1.
    • NIC Name: Select or enter an NIC name for the L2 network. For example, em01.
    Figure 20. Create L2 Flat Network


  2. Create an L3 network corresponded by an IPv4 flat network.
    Log in to ZCF, switch to the corresponding region, and then on the main menu, choose Resource Center > Network Resource > L3 Network Resources > Flat Network. On the Flat Network page, click Create Flat Network. The Create Flat Network page appears. On the displayed Create Private Network page, set the following parameters by referring to IPv4 Flat Network Configuration:
    • Name: Enter a name for the L3 flat network.
    • Description: Optional. Enter a description for the L3 flat network.
    • L2 Network: Select an L2 flat network that you created.
    • IP Address Management: Select whether to enable IP Address Management (IPAM) for the L3 flat network. If you enable IPAM, you can set network ranges, IP allocation policy, and DHCP service for the L3 network. Enable IPAM here.
    • Network Address Type: Select IPv4.
    • Network Range Method: Select a method to add a network range for the flat network. Here, select IP Range.
    • Start IP: Set a start IP address for the network range, for example, 172.20.108.40.
    • End IP: Set an end IP address for the network range, for example, 172.20.108.50.
    • Netmask: Set a netmask for the network range, for example, 255.255.0.0.
    • Gateway: Set a gateway for the network range, for example, 172.20.0.1.
    • DHCP Service: Choose whether to enable the DHCP service.
      Note:
      • The DHCP service is a built-in distributed service of the Cloud, which assigns IP addresses only to resources in the Cloud and does not conflict with your existing DHCP server.
      • By default, the DHCP service is enabled so that IP addresses are automatically assigned to resources in the Cloud. You can customize a DHCP IP or use the DHCP IP that the system assigned according to the IP allocation policy.
      • If you disable this option, IP addresses are not automatically assigned to resources that use this network. Therefore, you need to manually assign IP addresses to these resources. In addition, you cannot specify a DHCP IP. Neither can the system allocate one.
      • IP Allocation Policy: Optional. After the DHCP service is enabled, IP addresses can be assigned according to the following three allocation policies:
        • Random: The system randomly assigns IP addresses from the network range.
        • Allocate in Order:
          • The system assigns all available IP addresses from the network range in ascending order. Released IP addresses are assigned in the next allocation.
          • Example: Assume that the network range is 192.168.0.101~192.168.0.120, within which 192.168.0.101~192.168.0.108 are allocated. If 192.168.0.106 is released, it will be assigned first in the next allocation.
        • Allocate in Cycle:
          • The system assigns available IP addresses to VM instances from the network range in ascending order. Released IP addresses are assigned when currently available IP addresses are used up.
          • Example: Assume that the network range is 192.168.0.101~192.168.0.120, within which 192.168.0.101~192.168.0.108 are allocated. If 192.168.0.106 is released, it will be assigned after 192.168.0.120 is used.
      • DHCP IP: Optional. Set an IP address for the DHCP server, for example, 172.20.180.41.
        Note:
        • A DHCP IP is an IP address used by the DHCP service to assign IP addresses to resources that use this L3 network.
        • If you create an L3 network for the first time with the DHCP service enabled, or if you add the first network range to an L3 network with the DHCP service enabled, you can customize the DHCP IP.
        • If the L3 network has a DHCP IP, you cannot customize the DHCP IP when you add a network range.
        • The DHCP IP can be in or outside the added IP range, but it must be an unoccupied IP address in the CIDR block of the added IP range
        • The IP range determined by the start IP and end IP cannot contain the link-local address 169.254.0.0/16.
        • If you select random as the IP allocation policy and this field is left blank, the system randomly assigns IP addresses from the added network range.
        • If you select allocate in order/allocate in cycle as the IP allocation policy and this field is left blank, the system uses the start IP address in the network range as the DHCP IP.
    • DNS: Optional. Enter a DNS, such as 114.114.114.114.
    Figure 21. Create L3 Flat Network


  3. Create a VM instance by using this IPv4 flat network.

    Log in to ZCF, switch to the corresponding region, and then on the main menu, choose Resource Center > Resource Pool > Virtual Resource > VM Instance. On the VM Instance page, click Create VM Instance. Then, the Create VM Instance page is displayed. On the displayed page, create two VM instances by using the IPv4 flat network, for example, VM-1 and VM-2.

  4. Validate the connectivity of this IPv4 flat network.

    Expected result: The two VM instances (VM-1 and VM-2) on the same network range can communicate with each other.

    Validate the connectivity:
    • Log in to VM-1 and validate whether VM-1 can ping VM-2.
      Figure 22. VM-1 Pings VM-2


    • Log in to VM-2 and validate whether VM-2 can ping VM-1.
      Figure 23. VM-2 Pings VM-1


    So far, we have introduced the basic deployments of the IPv4 flat network.

Deploy an IPv6 Flat Network

IPv6 is Internet Protocol version 6 that defines IP addresses in a 128-bit format. IPv6 resolves the long-anticipated problem of IPv4 address exhaustion, so many devices can be connected to the Internet. ZStack Cloud flat networks support the IPv6 protocol. This topic describes the basic deployment of IPv6 flat networks.

The following table lists the assumed environment configurations.
Flat Network Configurations
NIC em1
VLAN ID 2002
IP Range 234e:0:4567::2-234e:0:4567:0:ffff:ffff:ffff:ffff
Prefix length 64
Gateway 234e:0:4567::1
DHCP IP 234e:0:4567::3
DNS 240c::6644
To create an IPv6 flat network, follow these steps:
  1. Create an L2 network corresponded by an IPv6 flat network, and attach this L2 network to the corresponding cluster.
  2. Create an L3 network corresponded by the IPv6 flat network.
  3. Create two VM instances by using the IPv6 flat network.
  4. Obtain IPv6 addresses of the VM instances.
  5. Validate the connectivity of the IPv6 flat network.
  1. Create an L2 network corresponded by an IPv6 flat network, and attach this L2 network to the corresponding cluster.
    Log in to ZCF, switch to the corresponding region, and then on the main menu, choose Resource Center > Network Resource > L2 Network Resources > L2 Network. On the L2 Network page, click Create L2 Network. Then, the Create L2 Network page is displayed. On the displayed Create L2 Network page, set the following parameters by referring to IPv6 Flat Network Configuration:
    • Zone: By default, the current zone is displayed.
    • Name: Enter a name for the L2 flat network, for example, L2-IPv6-Flat Network.
    • Description: Optional. Enter a description for the L2 flat network.
    • Switch Type: Select Linux Bridge.
    • Network Type: Select L2VlanNetwork.
    • Cluster: Optional. Select the cluster to be attached, for example, Cluster-1.
    • VLAN ID: Enter a VLAN ID, for example, 2002.
    • NIC Name: Select or enter an NIC name for the L2 network. For example, em1.
    • PVLAN (Isolated): Disable the switch.
    Figure 24. Create L2-IPv6-Flat Network


  2. Create an L3 network corresponded by the IPv6 flat network.
    Log in to ZCF, switch to the corresponding region, and then on the main menu, choose Resource Center > Network Resource > L3 Network Resources > Flat Network. On the Flat Network page, click Create Flat Network. The Create Flat Network page appears. On the displayed Create Private Network page, set the following parameters by referring to IPv6 Flat Network Configuration.
    • Name: Enter a name for the L3 network, such as L3-IPv6-Flat Network.
    • Description: Optional. Enter a description for the L3 flat network.
    • L2 Network: Select an L2 flat network that you created, such as L2-IPv6-Flat Network.
    • IP Address Management: Select whether to enable IP Address Management (IPAM) for the L3 flat network. If you enable IPAM, you can set network ranges, IP allocation policy, and DHCP service for the L3 network. Enable IPAM here.
    • Network Address Type: Select IPv6.
    • Network Range Method: Select a method to add a network range for the flat network. Here, select IP Range.
    • IP Configuration Mode: Select Stateful-DHCP.
    • Start IP: Set a start IP address for the network range, for example, 234e:0:4567::2.
    • End IP: Set an end IP address for the network range, for example, 234e:0:4567:0:ffff:ffff:ffff:ffff.
    • Prefix Length: Set a prefix length for the network range, for example, 64.
    • Gateway: Set a gateway for the network range, for example, 234e:0:4567::1.
    • DHCP Service: Choose whether to enable the DHCP service.
      Note:
      • The DHCP service is enabled by default. This service automatically assigns an IP address to a VM instance. You can specify an IP address for the DHCP server. If you do not specify, the system assigns a random IP address for the DHCP server.
      • If you disable the DHCP service, no IP address is automatically assigned to VM instances in the flat network. You need to manually configure IP addresses for the VM instances.
      • DHCP IP: Optional. Set an IP address for the DHCP server, for example, 234e:0:4567::3.
        Note:
        • When you create an L3 network and enable the DHCP service for the first time, or when you add the first network range for an L3 network that has the DHCP service enabled, you can specify an IP address for the DHCP server.
        • If a DHCP IP is specified for an L3 network, you cannot specify another DHCP IP when you add a network range for the network.
        • The DHCP IP can be within or out of the added IP range. However, the IP address must be within the CIDR block to which the added IP range belongs and must not be in use.
        • The IP range determined by the start IP and end IP cannot contain the link-local address fe80::/10.
        • If not specified, the system would randomly specify a DHCP IP within the added IP range for the DHCP server.
    • DNS: Set a DNS address for the L3 network, for example, 240c::6644.
    Figure 25. Create L3-IPv6-Flat Network


  3. Create two VM instances by using the IPv6 flat network.

    Log in to ZCF, switch to the corresponding region, and then on the main menu, choose Resource Center > Resource Pool > Virtual Resource > VM Instance. On the VM Instance page, click Create VM Instance. Then, the Create VM Instance page is displayed. On the displayed page, create two VM instances by using the IPv6 flat network, for example, VM-1 and VM-2.

  4. Obtain IPv6 addresses of the VM instances.
    By default, ZStack Cloud can automatically obtain IP addresses for the IPv4 network, while you must manually configure IP addresses for VM instances that use the IPv6 network. Launch the consoles of these two VM instances respectively, and run the following commands to obtain IPv6 addresses:
    [root@loaclhost~]# dhclient -6 eth0  //eth0 indicates the NIC name.
    Note: The address that begins with FE80 is the link-local address instead of the expected address.
    Figure 26. Obtain IPv6 Address


    In this scenario, you will obtain the following IPv6 addresses:
    • VM-1 IP address: 234e:0:4567::63:ab4d
    • VM-2 IP address: 234e:0:4567::31:3c6e
  5. Validate the connectivity of the IPv6 flat network.

    Expected result: The two VM instances (VM-1 and VM-2) on the same network range can communicate with each other.

    Validate the connectivity:
    • Log in to VM-1 and validate whether VM-1 can ping VM-2.
      Figure 27. VM-1 Pings VM-2


    • Log in to VM-2 and validate whether VM-2 can ping VM-1.
      Figure 28. VM-2 Pings VM-1


    So far, we have introduced the basic deployments of the IPv6 flat network.

IPv4 Basic Deployment

IPv4, also known as the Internet Protocol version 4, with a 32-bit long address, is the most widely used version of the inter-networking protocol today. ZStack Cloud VPC network supports IPv4 protocol and this chapter will introduce the basic deployment of IPv4 VPC network in detail.

Assume that the customer environment is as follows:
  1. Public Network
    Public Network Configuration
    NIC em1
    VLAN ID No VLAN
    IP Range 10.108.10.100~10.108.10.200
    Netmask 255.0.0.0
    Gateway 10.0.0.1
    DHCP IP 10.108.10.101
  2. Management Network
    Management Network Configuration
    NIC em2
    VLAN ID No VLAN
    IP Range 192.168.29.10~192.168.29.20
    Netmask 255.255.255.0
    Gateway 192.168.29.1
    Note:
    • For security and stability reasons, we recommend that you deploy an independent management network and separate it from the public networks.
    • The management network we mentioned here is the same as that in ZStack Cloud. That is, the management network is the network used to manage hosts, primary storage, and image storage. If a management network was created before, you can use it directly.
  3. VPC Network-1
    Private Network Configuration
    NIC em1
    VLAN ID 2800
    IP CIDR 192.168.10.0/24
    Gateway 192.168.10.1
    DHCP IP 192.168.10.2
  4. VPC Network-2
    Private Network Configuration
    NIC em1
    VLAN ID 2900
    IP CIDR 192.168.11.0/24
    Gateway 192.168.11.1
    DHCP IP 192.168.11.2
To deploy a VPC Network in the Cloud, follow these steps:
  1. Create an L2 public network and attach it to the corresponding cluster.
  2. Create an L3 public network.
  3. Create an L2 management network and attach it to the corresponding cluster.
  4. Create an L3 management network.
  5. Add a vRouter image.
  6. Create a vRouter offering.
  7. Create a VPC vRouter from the vRouter offering you created in the preceding step.
  8. Create an L2 private network and attach it to the corresponding cluster. This L2 private network is used to create an L3 VPC network (VPC Network-1).
  9. Create an L3 VPC network (VPC Network-1).
  10. Create an L2 private network and attach it to the corresponding cluster. This L2 private network is used to create an L3 VPC network (VPC Network-2).
  11. Create an L3 VPC network (VPC Network-2).
  12. Use VPC Network-1 and VPC Network-2 to create VM-1 and VM-2, respectively.
  13. Test the connectivity between VPC Network-1 and VPC Network-2.
  1. Create an L2 public network and attach it to the corresponding cluster.

    For network configuration information, see Public Network configuration.

    On the main menu of ZStack Cloud, choose Resource Center > Network Resource > L2 Network Resources > L2 Network. On the L2 Network page, click Create L2 Network. Then, the Create L2 Network page is displayed. On the displayed page, set the following parameters:
    • Zone: By default, the current zone is displayed.
    • Name: Set the name as L2-Public Network.
    • Description: Optional. Enter a description for the L2 network.
    • Switch Type: Select Linux Bridge.
    • Network Type: Select L2NoVlanNetwork.
    • Cluster: Select a cluster to be attached, for example, Cluster-1.
    • NIC Name: Enter a NIC name for the L2 network. For example, em1.
    Figure 29. Create L2-Public Network


  2. Create an L3 public network.

    For network configuration information, see Public Network configuration.

    On the main menu of ZStack Cloud, choose Resource Center > Network Resource > L3 Network Resources > Public Network. On the Public Network page, click Create Public Network. The Create Public Network page is displayed. On the displayed page, set the following parameters:
    • Name: Set the name as L3-Public Network.
    • Description: Optional. Enter a description for the public network.
    • L2 Network: Select the existing L2-Public Network.
    • Network Address Type: Select IPv4.
    • Network Range Method: Select IP Range.
    • Start IP: Set a start IP address for the network range, for example, 10.108.10.100.
    • End IP: Set an end IP address for the network range, for example, 10.108.10.200.
    • Netmask: Set a netmask for the network range, for example, 255.0.0.0.
    • Gateway: Set a gateway for the network range, for example, 10.0.0.1.
    • IP Allocation Policy: Optional. After the DHCP service is enabled, IP addresses can be assigned according to the following three allocation policies:
      • Random: The system randomly assigns IP addresses from the network range.
      • Allocate in Order:
        • The system assigns all available IP addresses from the network range in ascending order. Released IP addresses are assigned in the next allocation.
        • Example: Assume that the network range is 192.168.0.101~192.168.0.120, within which 192.168.0.101~192.168.0.108 are allocated. If 192.168.0.106 is released, it will be assigned first in the next allocation.
      • Allocate in Cycle:
        • The system assigns available IP addresses to VM instances from the network range in ascending order. Released IP addresses are assigned when currently available IP addresses are used up.
        • Example: Assume that the network range is 192.168.0.101~192.168.0.120, within which 192.168.0.101~192.168.0.108 are allocated. If 192.168.0.106 is released, it will be assigned after 192.168.0.120 is used.
    • DHCP Service: Choose whether to enable the DHCP service.
      Note:
      • The DHCP service is a built-in distributed service of the Cloud, which assigns IP addresses only to resources in the Cloud and does not conflict with your existing DHCP server.
      • By default, the DHCP service is enabled so that IP addresses are automatically assigned to resources in the Cloud. You can customize a DHCP IP or use the DHCP IP that the system assigned according to the IP allocation policy.
      • If you disable this option, IP addresses are not automatically assigned to resources that use this network. Therefore, you need to manually assign IP addresses to these resources. In addition, you cannot specify a DHCP IP. Neither can the system allocate one.
      • DHCP IP: Optional. Set an IP address for the DHCP server, for example, 10.108.10.101.
        Note:
        • A DHCP IP is an IP address used by the DHCP service to assign IP addresses to resources that use this L3 network.
        • If you create an L3 network for the first time with the DHCP service enabled, or if you add the first network range to an L3 network with the DHCP service enabled, you can customize the DHCP IP.
        • If the L3 network has a DHCP IP, you cannot customize the DHCP IP when you add a network range.
        • The DHCP IP can be in or outside the added IP range, but it must be an unoccupied IP address in the CIDR block of the added IP range
        • The IP range determined by the start IP and end IP cannot contain the link-local address 169.254.0.0/16.
        • If you select random as the IP allocation policy and this field is left blank, the system randomly assigns IP addresses from the added network range.
        • If you select allocate in order/allocate in cycle as the IP allocation policy and this field is left blank, the system uses the start IP address in the network range as the DHCP IP.
    • DNS: Optional. Add a DNS server to provide domain name resolution services for the public network, for example, 114.114.114.114.
    Figure 30. Create L3-Public Network


  3. Create an L2 management network and attach it to the corresponding cluster.

    For network configuration information, see Management Network Configuration.

    On the main menu of ZStack Cloud, choose Resource Center > Network Resource > L2 Network Resources > L2 Network. On the L2 Network page, click Create L2 Network. Then, the Create L2 Network page is displayed. On the displayed page, set the following parameters:
    • Zone: By default, the current zone is displayed.
    • Name: Set the name as L2-Management Network.
    • Description: Optional. Enter a description for the L2 network.
    • Switch Type: Select Linux Bridge.
    • Network Type: Select L2NoVlanNetwork.
    • Cluster: Select a cluster to be attached, for example, Cluster-1.
    • NIC Name: Enter a NIC name for the L2 network. For example, em2.
    Figure 31. Create L2-Management Network


  4. Create an L3 management network.

    For network configuration information, see Management Network Configuration.

    On the main menu of ZStack Cloud, choose Resource Center > Network Resource > Dedicated Network > Management Network. On the Management Network page, click Create Management Network. Then, the Create Management Network page is displayed. On the displayed page, set the following parameters:
    • Name: Set the name as L3-Management Network.
    • Description: Optional. Enter a description for the management network.
    • L2 Network: Select the existing L2-Management Network.
    • Network Range Method: Select IP Range.
    • Start IP: Set a start IP address for the network range, for example, 192.168.29.10.
    • End IP: Set an end IP address for the network range, for example, 192.168.29.20.
    • Netmask: Set a netmask for the network range, for example, 255.255.255.0.
    • Gateway: Set a gateway for the network range, for example, 192.168.29.1.
    Figure 32. Create L3-Management Network


  5. Add a vRouter image.

    Log in to ZCF, switch to the corresponding region, and then on the main menu, choose Resource Center > Network Resource > vRouter > vRouter Image. On the vRouter Image page, click Add vRouter Image. Then, the Add vRouter Image page is displayed.

    Set the following parameters:
    • Name: Enter a name for the vRouter image.
    • Description: Optional. Enter a description for the vRouter image.
    • Image Usage: Display VPC vRouter.
    • CPU Architecture: Select a CPU architecture for the vRouter image. VPC vRouters created from the vRouter image inherit this CPU architecture.
    • OS: Select a OS for the vRouter image. Supported OS types differ depending on the CPU architecture.
    • Image Storage: Select an image storage to store the vRouter image.
    • Image Path: Enter a URL or upload a local file.
      • URL: Enter the download URL of the vRouter image.
      • Local File: Upload a vRouter image file that can directly be accessed by the current browser.
        Note:
        • You can upload the vRouter image to an ImageStore or Ceph image storage.
        • A local browser will serve as a transmission relay used for uploading the vRouter image. Do not refresh or stop the current browser, nor stop your management node. Otherwise, you will fail to add the vRouter image.
  6. Create a vRouter offering.
    On the displayed page, set the following parameters:
    • Zone: By default, the current zone is displayed.
    • Name: Enter a name for the vRouter offering.
    • Description: Optional. Enter a description for the vRouter offering.
    • CPU: Set the number of CPU cores for a vRouter.
      Note: Currently, a vRouter can have up to 240 CPU cores. In an actual production environment, we recommend that you set more than 8 CPU cores for a vRouter.
    • Memory: Set the memory size for a vRouter. Unit: MB, GB, and TB. In an actual production environment, we recommend that the memory size greater than 8 GB.
    • Image: Select a vRouter image you added before.
      Note: If the L3 public network in the vRouter offering has a network range of the IPv6 type, when you create a VPC vRouter, you must use the vRouter image of version 3.10.0 or later.
    • Management Network: Select an L3 management network you created before.
      • A management network is used by the management node to deploy and configure resources such as hosts and VPC vRouters.
      • If a system network is used to manage physical resources, select the system network as the management network.
      • If you use a public network to manage physical resources, select the public network as the management network.
    • Public Network: Select a public network you created before.
      • vRouters created from this vRouter offering can provide VPC network services.
    Figure 33. Create vRouter Offering


  7. Create a VPC vRouter from the vRouter offering you created in the preceding step.

    Log in to ZCF, switch to the corresponding region, and then on the main menu, choose Resource Center > Network Resource > vRouter > VPC vRouter. On the VPC vRouter page, click Create VPC vRouter. Then, the Create VPC vRouter page is displayed. On the displayed page, set the following parameters:

    On the displayed page, set the following parameters:
    • Name: Enter a name for the VPC vRouter.
    • Description: Optional. Enter a description for the VPC vRouter.
    • vRouter Offering: Select a vRouter offering you created before.
      Note: A VPC vRouter created from a vRouter offering has a public network and a management network.
      • Enable SR-IOV: Optional. Choose whether to use SR-IOV to pass through a VF NIC to the VPC vRouter as a default public network NIC.
        Note:
        • By default, SR-IOV is disabled and a vNIC is attached to the VPC vRouter as a public network NIC.
        • If the hardware requirements are satisfied, you can enable SR-IOV to attach a VF NIC to the VPC vRouter as a public network NIC.
        • To enable SR-IOV, ensure the following points:
          • The public network and the management network of the VPC vRouter are deployed separately.
          • The vRouter offering uses an openEuler image.
          • There are available VF NICs based on the physical NICs corresponding to the public network.
    • Cluster: Optional. Specify a cluster for the host on which the VPC vRouter is to be started.
    • Storage Allocation Policy: Specify how the Cloud allocates a primary storage. The following two policies are supported:
      • System Allocation: The Cloud allocates a primary storage according to the preconfigured policy.
      • Custom: Select a primary storage as needed.
        • Primary Storage: Select a primary storage for the VPC vRouter.
    • Host: Optional. Select a host on which the VPC vRouter is started.
    • Default IPv4/IPv6 Address: Optional. Specify a default IP address for the VPC vRouter. If not specified, the Cloud allocates one automatically.
    • Assign Management Network IP: Optional. Assign a management network IP to the VPC vRouter.
      Note: To assign a management network IP, make sure that the management network used by the VPC vRouter is separated from the public network the VPC vRouter uses. If the VPC vRouter uses a same network both as its management network and public network, you cannot assign a management network IP.
    • DNS: Optional. Set the DNS service for the VPC vRouter. If not specified, 223.5.5.5 will be used.
      Note:
      • You can set an IPv4 DNS or IPv6 DNS as needed. For example, you can set the IPv4 DNS to 223.5.5.5 or IPv6 DNS to 240C::6644.
      • Services in the VPC vRouter can access the public network services via DNS. You can also specify the other DNS address if necessary.
      • For VM instances created by using a VPC network, the DNS is the gateway of the VPC network. The VM traffics are forwarded by a VPC vRouter.
    • CPU Pinning: Associate the virtual CPUs (vCPUs) of a VPC vRouter with host pCPUs stringently and allow you to allocate specific pCPUs for the VPC vRouter, thus improving VPC vRouter performances.
      Note:
      • Pinning Format
        • In the left input box, set a vCPU range. In the right input box, set a pCPU range. Range format: integer, hyphen(-), and caret (^). Use commas to separate them.
        • The vCPU range depends on the vRouter offering attached to the VPC vRouter.
        • The pCPU range depends on the pCPU quantity of the selected cluster or host.
      • Example: In the left input box, enter 1. In the right input box, enter 0-3,^2. This example indicates that vCPU 1 is stringently associated with pCPU 0, pCPU 1, and pCPU 3, while ^ represents that vCPU 2 is excluded.
    Figure 34. Create VPC vRouter


  8. Create an L2 private network and attach it to the corresponding cluster. This L2 private network is used to create an L3 VPC network (VPC Network-1).

    For network configuration information, see VPC Network-1 Configuration.

    Log in to ZCF, switch to the corresponding region, and then on the main menu, choose Resource Center > Network Resource > L2 Network Resources > L2 Network. On the L2 Network page, click Create L2 Network. Then, the Create L2 Network page is displayed. On the displayed page, set the following parameters:
    • Zone: By default, the current zone is displayed.
    • Name: Set the name as L2-Private Network.
    • Description: Optional. Enter a description for the L2 network.
    • Switch Type: Select Linux Bridge.
    • Network Type: Select L2VlanNetwork.
    • Cluster: Select a cluster to be attached, for example, Cluster-1.
    • VLAN ID: Enter 2800.
    • NIC Name: Enter a NIC name for the L2 network. For example, em1.
    • PVLAN (Isolated): Disable the switch.
    Figure 35. Create L2-Private Network


  9. Create an L3 VPC network (VPC Network-1).

    For network configuration information, see VPC Network-1 Configuration.

    Log in to ZCF, switch to the corresponding region, and then on the main menu, choose Resource Center > Network Resource > L3 Network Resources > VPC Network. On the VPC Network page, click Create VPC Network. The Create VPC Network page is displayed. On the displayed page, set the following parameters:
    • Name: Set the name as VPC Network-1.
    • Description: Optional. Enter a description for the VPC network.
    • L2 Network: Select the existing L2-Private Network.
    • VPC vRouter: Optional. Select the existing VPC vRouter.
    • Network Address Type: Select IPv4.
    • Network Range Method: Select CIDR.
    • CIDR: Set a CIDR block for the VPC network, for example, 192.168.10.0/24.
    • Gateway: Set a gateway for the VPC network, for example, 192.168.10.1.
    • IP Allocation Policy: Optional. After the DHCP service is enabled, IP addresses can be assigned according to the following three allocation policies:
      • Random: The system randomly assigns IP addresses from the network range.
      • Allocate in Order:
        • The system assigns all available IP addresses from the network range in ascending order. Released IP addresses are assigned in the next allocation.
        • Example: Assume that the network range is 192.168.0.101~192.168.0.120, within which 192.168.0.101~192.168.0.108 are allocated. If 192.168.0.106 is released, it will be assigned first in the next allocation.
      • Allocate in Cycle:
        • The system assigns available IP addresses to VM instances from the network range in ascending order. Released IP addresses are assigned when currently available IP addresses are used up.
        • Example: Assume that the network range is 192.168.0.101~192.168.0.120, within which 192.168.0.101~192.168.0.108 are allocated. If 192.168.0.106 is released, it will be assigned after 192.168.0.120 is used.
    • DHCP Service: Choose whether to enable the DHCP service.
      Note:
      • The DHCP service is a built-in distributed service of the Cloud, which assigns IP addresses only to resources in the Cloud and does not conflict with your existing DHCP server.
      • By default, the DHCP service is enabled so that IP addresses are automatically assigned to resources in the Cloud. You can customize a DHCP IP or use the DHCP IP that the system assigned according to the IP allocation policy.
      • If you disable this option, IP addresses are not automatically assigned to resources that use this network. Therefore, you need to manually assign IP addresses to these resources. In addition, you cannot specify a DHCP IP. Neither can the system allocate one.
      • DHCP IP: Optional. Set an IP address for the DHCP server, for example, 192.168.10.2.
        Note:
        • A DHCP IP is an IP address used by the DHCP service to assign IP addresses to resources that use this L3 network.
        • If you create an L3 network for the first time with the DHCP service enabled, or if you add the first network range to an L3 network with the DHCP service enabled, you can customize the DHCP IP.
        • If the L3 network has a DHCP IP, you cannot customize the DHCP IP when you add a network range.
        • The DHCP IP can be in or outside the added IP range, but it must be an unoccupied IP address in the CIDR block of the added IP range
        • The IP range determined by the start IP and end IP cannot contain the link-local address 169.254.0.0/16.
        • If you select random as the IP allocation policy and this field is left blank, the system randomly assigns IP addresses from the added network range.
        • If you select allocate in order/allocate in cycle as the IP allocation policy and this field is left blank, the system uses the start IP address in the network range as the DHCP IP.
    • DNS: Optional.
    Figure 36. Create VPC Network-1


  10. Create an L2 private network and attach it to the corresponding cluster. This L2 private network is used to create an L3 VPC network (VPC Network-2).
  11. Create an L3 VPC network (VPC Network-2).
  12. Use VPC Network-1 and VPC Network-2 to create VM-1 and VM-2, respectively.

    Log in to ZCF, switch to the corresponding region, and then on the main menu, choose Resource Center > Resource Pool > Virtual Resource > VM Instance. Click Create VM Instance. Use the existing VPC Network-1 and VPC Network-2 to create VM-1 and VM-2, respectively.

  13. Test the connectivity between VPC Network-1 and VPC Network-2.

    Expected result: VPC Netowrk-1 and VPC Network-2 can communicate with each other.

    To test the connectivity, follow these steps:
    • Log in to VM-1, use the ping command to ping VM-2.
      Figure 37. VM-1 Ping VM-2


    • Log in to VM-2, use the ping command to ping VM-1.
      Figure 38. VM-2 ping VM-1


So far, we have introduced the basic deployment of IPv4 VPC network.

IPv6 Basic Deployment

IPv6, also known as Internet Protocol version 6, with an address length of 128 bits, not only solves the problem of insufficient IPv4 address, but it also clears the barrier for multiple access devices to connect to the Internet. ZStack Cloud VPC network supports IPv6 protocol and this chapter will introduce the basic deployment of IPv6 VPC network in detail.

Assume that the customer environment is as follows:
  1. Public Network
    Public Network Configuration
    NIC em1
    VLAN ID No VLAN
    IP Range 10.108.10.100~10.108.10.200
    Netmask 255.0.0.0
    Gateway 10.0.0.1
    DHCP IP 10.108.10.101
    Note: The public network used to create the VPC vRouter supports both IPv4 and IPv6 networks. In this scenario, we use IPv4 as an example.
  2. Management Network
    Management Network Configuration
    NIC em2
    VLAN ID No VLAN
    IP Range 192.168.29.10~192.168.29.20
    Netmask 255.255.255.0
    Gateway 192.168.29.1
    Note:
    • The management network used to create the VPC vRouter supports IPv4 network only.
    • For security and stability reasons, we recommend that you deploy an independent management network and separate it from the public networks.
    • The management network we mentioned here is the same as that in ZStack Cloud. That is, the management network is the network used to manage hosts, primary storage, and image storage. If a management network was created before, you can use it directly.
  3. VPC Network-1
    VPC Network Configuration
    NIC em1
    VLAN ID 2800
    IP CIDR 234e:0:4569::/64
    DHCP IP 234e:0:4569::2
  4. VPC Network-2
    VPC Network Configuration
    NIC em1
    VLAN ID 2900
    IP CIDR 234e:0:456a::/64
    DHCP IP 234e:0:456a::2
To deploy a VPC network in the Cloud, follow these steps:
  1. Create an L2 public network and attach it to the corresponding cluster.
  2. Create an L3 public network.
  3. Create an L2 management network and attach it to the corresponding cluster.
  4. Create an L3 management network.
  5. Add a vRouter image.
  6. Create a vRouter offering.
  7. Create a VPC vRouter from the vRouter offering you created in the preceding step.
  8. Create an L2 private network and attach it to the corresponding cluster. This L2 private network is used to create an L3 VPC network.
  9. Create L3 VPC networks and attach it to the VPC vRouter.
  10. Use two VPC networks to create VM instances respectively.
  11. Obtain the IPv6 address of the VM instances.
  12. Test the connectivity between two VPC networks.
  1. Create an L2 public network and attach it to the corresponding cluster.

    For network configuration information, see Public Network Configuration.

    On the main menu of ZStack Cloud, choose Resource Center > Network Resource > L2 Network Resources > L2 Network. On the L2 Network page, click Create L2 Network. Then, the Create L2 Network page is displayed. On the displayed page, set the following parameters:
    • Zone: By default, the current zone is displayed.
    • Name: Set the name as L2-Public Network.
    • Description: Optional. Enter a description for the L2 network.
    • Switch Type: Select Linux Bridge.
    • Network Type: Select L2NoVlanNetwork.
    • Cluster: Select a cluster to be attached, for example, Cluster-1.
    • NIC Name: Enter a NIC name for the L2 network. For example, em1.
    Figure 39. Create L2-Public Network


  2. Create an L3 public network.

    For network configuration information, see Public Network Configuration.

    On the main menu of ZStack Cloud, choose Resource Center > Network Resource > L3 Network Resources > Public Network. On the Public Network page, click Create Public Network. The Create Public Network page is displayed. On the displayed page, set the following parameters:
    • Name: Set the name as L3-Public Network.
    • Description: Optional. Enter a description for the public network.
    • L2 Network: Select the existing L2-Public Network.
    • Network Address Type: Select IPv4.
    • Network Range Method: Select IP Range.
    • Start IP: Set a start IP address for the network range, for example, 10.108.10.100.
    • End IP: Set an end IP address for the network range, for example, 10.108.10.200.
    • Netmask: Set a netmask for the network range, for example, 255.0.0.0.
    • Gateway: Set a gateway for the network range, for example, 10.0.0.1.
    • IP Allocation Policy: Optional. After the DHCP service is enabled, IP addresses can be assigned according to the following three allocation policies:
      • Random: The system randomly assigns IP addresses from the network range.
      • Allocate in Order:
        • The system assigns all available IP addresses from the network range in ascending order. Released IP addresses are assigned in the next allocation.
        • Example: Assume that the network range is 192.168.0.101~192.168.0.120, within which 192.168.0.101~192.168.0.108 are allocated. If 192.168.0.106 is released, it will be assigned first in the next allocation.
      • Allocate in Cycle:
        • The system assigns available IP addresses to VM instances from the network range in ascending order. Released IP addresses are assigned when currently available IP addresses are used up.
        • Example: Assume that the network range is 192.168.0.101~192.168.0.120, within which 192.168.0.101~192.168.0.108 are allocated. If 192.168.0.106 is released, it will be assigned after 192.168.0.120 is used.
    • DHCP Service: Choose whether to enable the DHCP service.
      Note:
      • The DHCP service is a built-in distributed service of the Cloud, which assigns IP addresses only to resources in the Cloud and does not conflict with your existing DHCP server.
      • By default, the DHCP service is enabled so that IP addresses are automatically assigned to resources in the Cloud. You can customize a DHCP IP or use the DHCP IP that the system assigned according to the IP allocation policy.
      • If you disable this option, IP addresses are not automatically assigned to resources that use this network. Therefore, you need to manually assign IP addresses to these resources. In addition, you cannot specify a DHCP IP. Neither can the system allocate one.
      • DHCP IP: Optional. Set an IP address for the DHCP server, for example, 10.108.10.101.
        Note:
        • A DHCP IP is an IP address used by the DHCP service to assign IP addresses to resources that use this L3 network.
        • If you create an L3 network for the first time with the DHCP service enabled, or if you add the first network range to an L3 network with the DHCP service enabled, you can customize the DHCP IP.
        • If the L3 network has a DHCP IP, you cannot customize the DHCP IP when you add a network range.
        • The DHCP IP can be in or outside the added IP range, but it must be an unoccupied IP address in the CIDR block of the added IP range
        • The IP range determined by the start IP and end IP cannot contain the link-local address 169.254.0.0/16.
        • If you select random as the IP allocation policy and this field is left blank, the system randomly assigns IP addresses from the added network range.
        • If you select allocate in order/allocate in cycle as the IP allocation policy and this field is left blank, the system uses the start IP address in the network range as the DHCP IP.
    • DNS: Optional. Add a DNS server to provide domain name resolution services for the public network, for example, 114.114.114.114.
  3. Create an L2 management network and attach it to the corresponding cluster.

    For network configuration information, see Management Network Configuration.

    On the main menu of ZStack Cloud, choose Resource Center > Network Resource > L2 Network Resources > L2 Network. On the L2 Network page, click Create L2 Network. Then, the Create L2 Network page is displayed. On the displayed page, set the following parameters:
    • Zone: By default, the current zone is displayed.
    • Name: Set the name as L2-Management Network.
    • Description: Optional. Enter a description for the L2 network.
    • Switch Type: Select Linux Bridge.
    • Network Type: Select L2NoVlanNetwork.
    • Cluster: Select a cluster to be attached, for example, Cluster-1.
    • NIC Name: Enter a NIC name for the L2 network. For example, em2.
  4. Create an L3 management network.

    For network configuration information, see Management Network Configuration.

    On the main menu of ZStack Cloud, choose Resource Center > Network Resource > Dedicated Network > Management Network. On the Management Network page, click Create Management Network. Then, the Create Management Network page is displayed. On the displayed page, set the following parameters:
    • Name: Set the name as L3-Management Network.
    • Description: Optional. Enter a description for the management network.
    • L2 Network: Select the existing L2-Management Network.
    • Network Range Method: Select IP Range.
    • Start IP: Set a start IP address for the network range, for example, 192.168.29.10.
    • End IP: Set an end IP address for the network range, for example, 192.168.29.20.
    • Netmask: Set a netmask for the network range, for example, 255.255.255.0.
    • Gateway: Set a gateway for the network range, for example, 192.168.29.1.
  5. Add a vRouter image.

    Log in to ZCF, switch to the corresponding region, and then on the main menu, choose Resource Center > Network Resource > vRouter > vRouter Image. On the vRouter Image page, click Add vRouter Image. Then, the Add vRouter Image page is displayed.

    Set the following parameters:
    • Name: Enter a name for the vRouter image.
    • Description: Optional. Enter a description for the vRouter image.
    • Image Usage: Display VPC vRouter.
    • CPU Architecture: Select a CPU architecture for the vRouter image. VPC vRouters created from the vRouter image inherit this CPU architecture.
    • OS: Select a OS for the vRouter image. Supported OS types differ depending on the CPU architecture.
    • Image Storage: Select an image storage to store the vRouter image.
    • Image Path: Enter a URL or upload a local file.
      • URL: Enter the download URL of the vRouter image.
      • Local File: Upload a vRouter image file that can directly be accessed by the current browser.
        Note:
        • You can upload the vRouter image to an ImageStore or Ceph image storage.
        • A local browser will serve as a transmission relay used for uploading the vRouter image. Do not refresh or stop the current browser, nor stop your management node. Otherwise, you will fail to add the vRouter image.
  6. Create a vRouter offering.
    On the displayed page, set the following parameters:
    • Zone: By default, the current zone is displayed.
    • Name: Enter a name for the vRouter offering.
    • Description: Optional. Enter a description for the vRouter offering.
    • CPU: Set the number of CPU cores for a vRouter.
      Note: Currently, a vRouter can have up to 240 CPU cores. In an actual production environment, we recommend that you set more than 8 CPU cores for a vRouter.
    • Memory: Set the memory size for a vRouter. Unit: MB, GB, and TB. In an actual production environment, we recommend that the memory size greater than 8 GB.
    • Image: Select a vRouter image you added before.
      Note: If the L3 public network in the vRouter offering has a network range of the IPv6 type, when you create a VPC vRouter, you must use the vRouter image of version 3.10.0 or later.
    • Management Network: Select an L3 management network you created before.
      • A management network is used by the management node to deploy and configure resources such as hosts and VPC vRouters.
      • If a system network is used to manage physical resources, select the system network as the management network.
      • If you use a public network to manage physical resources, select the public network as the management network.
    • Public Network: Select a public network you created before.
      • vRouters created from this vRouter offering can provide VPC network services.
    Figure 40. Create vRouter Offering


  7. Create a VPC vRouter from the vRouter offering you created in the preceding step.
    Log in to ZCF, switch to the corresponding region, and then on the main menu, choose Resource Center > Network Resource > vRouter > VPC vRouter. On the VPC vRouter page, click Create VPC vRouter. Then, the Create VPC vRouter page is displayed. On the displayed page, set the following parameters:
    • Name: Enter a name for the VPC vRouter.
    • Description: Optional. Enter a description for the VPC vRouter.
    • vRouter Offering: Select a vRouter offering you created before.
    • Cluster: Optional. Specify a cluster for the host on which the VPC vRouter is to be started.
    • Storage Allocation Policy: Specify how the Cloud allocates a primary storage. The following two policies are supported:
      • System Allocation: The Cloud allocates a primary storage according to the preconfigured policy.
      • Custom: Select a primary storage as needed.
        • Primary Storage: Select a primary storage for the VPC vRouter.
    • Host: Optional. Select a host on which the VPC vRouter is started.
    • Default IPv6 Address: Optional. Specify a default IP address for the VPC vRouter. If not specified, the Cloud allocates one automatically.
    • Assign Management Network IP: Optional. Assign a management network IP to the VPC vRouter.
      Note: To assign a management network IP, make sure that the management network used by the VPC vRouter is separated from the public network the VPC vRouter uses. If the VPC vRouter uses a same network both as its management network and public network, you cannot assign a management network IP.
    • DNS: Optional. Set the DNS service for the VPC vRouter. In this scenario, specify 240C::6644.
      Note:
      • You can set an IPv4 DNS or IPv6 DNS as needed. For example, you can set the IPv4 DNS to 223.5.5.5 or IPv6 DNS to 240C::6644.
      • Services in the VPC vRouter can access the public network services via DNS. You can also specify the other DNS address if necessary.
      • For VM instances created by using a VPC network, the DNS is the gateway of the VPC network. The VM traffics are forwarded by a VPC vRouter.
    • CPU Pinning: Associate the virtual CPUs (vCPUs) of a VPC vRouter with host pCPUs stringently and allow you to allocate specific pCPUs for the VPC vRouter, thus improving VPC vRouter performances.
      Note:
      • Pinning Format
        • In the left input box, set a vCPU range. In the right input box, set a pCPU range. Range format: integer, hyphen(-), and caret (^). Use commas to separate them.
        • The vCPU range depends on the vRouter offering attached to the VPC vRouter.
        • The pCPU range depends on the pCPU quantity of the selected cluster or host.
      • Example: In the left input box, enter 1. In the right input box, enter 0-3,^2. This example indicates that vCPU 1 is stringently associated with pCPU 0, pCPU 1, and pCPU 3, while ^ represents that vCPU 2 is excluded.
    Figure 41. Create VPC vRouter


  8. Create an L2 private network and attach it to the corresponding cluster. This L2 private network is used to create an L3 VPC network.

    For network configuration information, see VPC Network-1 Configuration.

    Log in to ZCF, switch to the corresponding region, and then on the main menu, choose Resource Center > Network Resource > L2 Network Resources > L2 Network. On the L2 Network page, click Create L2 Network. Then, the Create L2 Network page is displayed. On the displayed page, set the following parameters:
    • Zone: By default, the current zone is displayed.
    • Name: Set the name as L2-VPC-1.
    • Description: Optional. Enter a description for the L2 network.
    • Switch Type: Select Linux Bridge.
    • Network Type: Select L2VlanNetwork.
    • Cluster: Select a cluster to be attached, for example, Cluster-1.
    • VLAN ID: Enter 2800.
    • NIC Name: Enter a NIC name for the L2 network. For example, em1.
    • PVLAN (Isolated): Disable the switch.
    Figure 42. Create L2-VPC-1


    Similarly, Create L2-VPC-2 and attach it to the corresponding cluster.

  9. Create L3 VPC networks and attach it to the VPC vRouter.

    For network configuration information, see VPC Network-1 Configuration.

    Log in to ZCF, switch to the corresponding region, and then on the main menu, choose Resource Center > Network Resource > L3 Network Resources > VPC Network. On the VPC Network page, click Create VPC Network. The Create VPC Network page is displayed. On the displayed page, set the following parameters:
    • Name: Set the name as L3-VPC-1.
    • Description: Optional. Enter a description for the VPC network.
    • L2 Network: Select the existing L2-VPC-1.
    • VPC vRouter: Optional. Select the existing VPC vRouter.
    • Network Address Type: Select IPv6.
    • Network Range Method: Select CIDR.
    • IP Configuration Mode: Select Stateful-DHCP.
      • Stateful-DHCP: The interface address and other parameters are all configured through DHCP. The IP range method supports stateful DHCP.
      • Stateless-DHCP: The interface address is automatically derived from the route advertisement prefix and the interface Mac address. Other parameters are configured through DHCP.
      • SLAAC: The interface address is automatically derived from the prefix of the route advertisement that also contains other parameters.
    • CIDR: Set a CIDR block for the VPC network, for example, 234e:0:4569::/64.
    • DHCP Service: Choose whether to enable the DHCP service.
      Note:
      • The DHCP service is enabled by default. This service automatically assigns an IP address to a VM instance. You can specify an IP address for the DHCP server. If you do not specify, the system assigns a random IP address for the DHCP server.
      • If you disable the DHCP service, no IP address is automatically assigned to VM instances in the public network. You need to manually configure IP addresses for the VM instances.
      • DHCP IP: Optional. Set an IP address for the DHCP server, for example, 234e:0:4569::2.
        Note:
        • When you create an L3 network and enable the DHCP service for the first time, or when you add the first network range for an L3 network that has the DHCP service enabled, you can specify an IP address for the DHCP server.
        • If a DHCP IP is specified for an L3 network, you cannot specify another DHCP IP when you add a network range for the network.
        • The DHCP IP must be within the CIDR block and must not be in use.
        • If not specified, the system would randomly specify a DHCP IP within the added IP range for the DHCP server.
        • The first IP address in the CIDR block is predefined as the default gateway and cannot be used as a DHCP server IP.
    • DNS: Provide DNS services for an L3 network. Here, you can specify a DNS address such as 240C::6666.
    Figure 43. Create L3-VPC-1


    Similarly, create L3-VPC-2 and attach it to the VPC vRouter.

  10. Use two VPC networks to create VM instances respectively.

    Log in to ZCF, switch to the corresponding region, and then on the main menu, choose Resource Center > Resource Pool > Virtual Resource > VM Instance. Click Create VM Instance. Use the existing L3-VPC-1 and L3-VPC-2 to create VM-1 and VM-2, respectively.

  11. Obtain the IPv6 address of the VM instances.
    You need to manually obtain the IP address of the IPv6 VM instance. Launch the console of the two VM instances and run the following command to obtain the IP address:
    [root@localhost~]# dhclient -6 eth0  //eth0 indicates the NIC name
    [root@localhost~]# ifconfig
    Note: FE80-started address is the link-local address.
    Figure 44. Obtain IP Address


    In this scenario, the obtained IP addresses are as follows:
    • VM-1 IP address: 234e:0:4569::42:e4a6
    • VM-2 IP address: 234e:0:456a::1a:ebe9
  12. Test the connectivity between two VPC networks.

    Expected result: L3-VPC-1 and L3-VPC-2 can communicate with each other.

    To test the connectivity, follow these steps:
    • Log in to VM-1, use the ping command to ping VM-2.
      Figure 45. VM-1 ping VM-2


    • Log in to VM-2, use the ping command to ping VM-1.
      Figure 46. VM-2 ping VM-1


So far, we have introduced the basic deployment of IPv6 VPC network.

IPv4+IPv6 Dual Stack

An IPv4+IPv6 dual stack is one NIC with two types of IP addresses: IPv4 and IPv6, and takes full advantage of both IPv4 and IPv6. With the IPv4+IPv6 dual stack, you can meet the needs of different business scenarios.

The following tables list the assumed environment configurations.
  1. IPv4 Network Range
    Flat Network Configurations
    NIC em1
    VLAN ID 2002
    IP Range 192.168.2.2-192.168.2.254
    Netmask 255.255.255.0
    Gateway 192.168.2.1
    DHCP IP 192.168.2.3
    DNS 223.5.5.5
  2. IPv6 Network Range
    Flat Network Configurations
    IP Range 234e:0:4568::2-234e:0:4568:0:ffff:ffff:ffff:ffff
    Prefix Length 64
    Gateway 234e:0:4568::1
    DHCP IP 234e:0:4567::3
    DNS 240c::6644
To create an IPv4+IPv6 dual stack, follow these steps:
  1. Create an IPv4 networking environment.
  2. Add an IPv6 range.
  3. Add an IPv6 DNS address.
  4. Create VM instances by using the dual-stack network.
  5. Obtain IPv6 addresses of the VM instances.
  6. Validate the network connectivity.
  1. Create an IPv4 networking environment.
    Create a flat network with an IPv4 address, for example, L3-Flat Network. At this time, this network is an IPv4 network. For network configuration information, see IPv4 Network Configuration and IPv6 Network Configuration.
    Note: You can also create an IPv6 flat network first, and then add an IPv4 range to a flat network.
  2. Add an IPv6 range.

    Add an IPv6 range to the existing IPv4 network to form an IPv4+IPv6 dual-stack network.

    On the Flat Network page, locate the IPv4 network and click Actions > Add IPv6 Range. On the displayed Add Network Range page, set the following parameters:
    • Network Range Method: Select a method to add a network range for the VPC network. You can select IP Range or CIDR. Here, select IP Range.
    • IP Configuration Mode: Select Stateful-DHCP.
      Note:
      • Stateful-DHCP: The interface address and other parameters are all configured through DHCP. The IP range method supports stateful DHCP.
      • Stateless-DHCP: The interface address is automatically derived from the route advertisement prefix and the interface Mac address. Other parameters are configured through DHCP.
      • SLAAC: The interface address is automatically derived from the prefix of the route advertisement that also contains other parameters.
    • Start IP: Set a start IP address for the network range, for example, 234e:0:4568::2.
    • End IP: Set an end IP address for the network range, for example, 234e:0:4568:0:ffff:ffff:ffff:ffff.
    • Prefix Length: Set a prefix length for the network range, for example, 64. Range: 64-126.
    • Gateway: Set a gateway for the network range, for example, 234e:0:4568::1.
    • DHCP IP: Optional. Set an IP address for the DHCP server, for example, 234e:0:4568::3.
      Note:
      • When you create an L3 network and enable the DHCP service for the first time, or when you add the first network range for an L3 network that has the DHCP service enabled, you can specify an IP address for the DHCP server.
      • If a DHCP IP is specified for an L3 network, you cannot specify another DHCP IP when you add a network range for the network.
      • The DHCP IP can be within or out of the added IP range. However, the IP address must be within the CIDR block to which the added IP range belongs and must not be in use.
      • The IP range determined by the start IP and end IP cannot contain the link-local address fe80::/10.
      • If not specified, the system would randomly specify a DHCP IP within the added IP range for the DHCP server.
    Figure 47. Add IPv6 Range


  3. Add an IPv6 DNS address.
    On the DNS tab page of the flat network, click Add DNS. On the Add DNS dialogue box, set the following parameters:
    • Network Address Type: Select IPv6.
    • DNS: Specify a DNS address, for example, 240c::6644.
    Figure 48. Add IPv6 DNS Address


  4. Create VM instances by using the dual-stack network.

    Log in to ZCF, switch to the corresponding region, and then on the main menu, choose Resource Center > Resource Pool > Virtual Resource > VM Instance. On the VM Instance page, click Create VM Instance. Then, the Create VM Instance page is displayed. On the displayed page, create two VM instances by using the IPv4 flat network, for example, VM-Dual Stack-1 and VM-Dual Stack-2.

  5. Obtain IPv6 addresses of the VM instances.
    By default, ZStack Cloud can automatically obtain IP addresses for the IPv4 network, while you must manually configure IP addresses for VM instances that use the IPv6 network. Launch the consoles of these two VM instances respectively, and run the following commands to obtain IPv6 addresses:
    [root@loaclhost~]# dhclient -6 eth0  //eth0 indicates the NIC name.
    Note: The address that begins with FE80 is the link-local address instead of the expected address.
    Figure 49. Obtain IP Address


    In this scenario, after running ifconfig, you will obtain the following addresses:
    • VM-Dual Stack-1 IPv4 address: 192.168.2.248
    • VM-Dual Stack-1 IPv6 address: 234e:0:4568::69:9fdc
    • VM-Dual Stack-2 IPv4 address: 192.168.2.183
    • VM-Dual Stack-2 IPv6 address: 234e:0:4568::23:c59b
  6. Validate the network connectivity.
    Expected result:
    • Log in to the VM-Dual Stack-1. Use the IPv4 address and the IPv6 address respectively to validate whether these two IP addresses can ping VM-Dual Stack-2.
    • Log in to the VM-Dual Stack-2. Use the IPv4 address and the IPv6 address respectively to validate whether these two IP addresses can ping VM-Dual Stack-1.
    Figure 50. Validate Network Connectivity


    Similarly, log in to the VM-Dual Stack-2. Use the IPv4 address and the IPv6 address to validate whether these two IP addresses ping VM-Dual Stack-1.

    So far, we have introduced how to use a Dual stack (IPv4+IPv6) flat network.

Multi-Tenant Isolation

You can use VLAN or VXLAN to provide isolation for multiple tenants on layer 2 network.
VLAN VXLAN
  • VLAN supports a maximum of 4096 VLAN IDs, that is a maximum of 4096 isolated tenant networks are provided in a single VLAN network, which is difficult to meet the needs of large-scale cloud computing data centers.
  • The VLAN configuration methods of each switch vendors vary differently.
  • VXLAN can support a maximum of 16 million logical networks for multi-tenant isolation, based on the existing network typology of client's IDC.
  • VXLAN is an overlay technology that allows for the creation of overlaying L2 networks. The overlay virtualization process can be realized by software or by a VXLAN-enabled switch. You can choose the method as needs.
  • Compared to VLAN, VXLAN has higher performance loss and higher network latency.

This chapter mainly introduces the practice of multi-tenant isolation provided by the VXLAN VPC network.

To set up a VXLAN VPC network for multi-tenant isolation, follow these steps:
  1. Admin creates two sub-accounts (Sub-Account-A and Sub-Account-B).
  2. Admin creates an L2 public network and attaches it to the corresponding cluster.
  3. Admin creates an L3 public network.
  4. Admin creates an L2 management network and attaches it to the corresponding cluster.
  5. Admin creates an L3 management network that is used to communicate with physical resources, such as hosts, primary storage, and image storage.
  6. Admin adds a vRouter image.
  7. Admin creates a vRouter offering and shares it to Sub-Account-A and Sub-Account-B.
  8. Admin creates a VXLAN pool, attaches it to the corresponding cluster, and shares it to Sub-Account-A and Sub-Account-B.
  9. Create VPC vRouters from the vRouter offering using Sub-Account-A and Sub-Account-B respectively, for example, VPC vRouter-A and VPC vRouter-B.
  10. Create two VXLAN networks from the VXLAN pool using Sub-Account-A and Sub-Account-B respectively, for example, L2-VXLAN-A1, L2-VXLAN-A2, L2-VXLAN-B1, and L2-VXLAN-B2.
  11. Create VPC networks using the four VXLAN networks in Sub-Account-A and Sub-Account-B respectively, for example, VPC-A1, VPC-A2, VPC-B1, and VPC-B2.
  12. Create a VM instance in each sub-account using the corresponding VPC networks, for example, VM-A1, VM-A2, VM-B1, and VM-B2.
  13. Test the connectivity among VM instances.
  14. Admin shares the L3 public network to Sub-Account-A and Sub-Account-B.
  15. Create a route table to enable VM-A1 and VM-B1 that are isolated in layer 2 can communicate with each other.
  16. Test the connectivity between VM-A1 and VM-B1.
Note:
  • VXLAN pool and VXLAN network together provide configuration for the VXLAN network type.
  • If you create an L2 network of the VxlanNetwork type, you must specify a software SDN-based VXLAN pool. The L2 network must correspond to a VNI in the pool.
  • A VXLAN pool is only a collection of VXLAN networks and cannot be used to create L3 networks. You can L3 networks from L2 VxlanNetworks.
Assume the customer environment is as follows:
  1. Public Network
    Public Network Configuration
    NIC em01
    VLAN ID No VLAN
    IP Range 10.151.10.100~10.151.10.200
    Netmask 255.0.0.0
    Gateway 10.0.0.1
    DHCP IP 10.151.10.101
  2. Management Network
    Management Network Configuration
    NIC em02
    VLAN ID No VLAN
    IP Range 192.168.28.100~192.168.28.200
    Netmask 255.255.255.0
    Gateway 192.168.28.1
    Note:
    • For security and stability reasons, we recommend that you deploy an independent management network and separate it from the public networks.
    • The management network we mentioned here is the same as that in ZStack Private Cloud. That is, the management network is the network used to manage hosts, primary storages, and backup storages. If a management network was created before, you can use it directly.
  3. VXLAN Pool
    VXLAN Pool Configuration
    VNI Range 20-1200
    VTEP CIDR 192.168.28.1/24
  4. VPC-A1
    VPC Network Configuration
    NIC em01
    IP CIDR 192.168.21.0/24
    Gateway 192.168.21.1
    DHCP IP 192.168.21.2
  5. VPC-A2
    VPC Network Configuration
    NIC em01
    IP CIDR 192.168.22.0/24
    Gateway 192.168.22.1
    DHCP IP 192.168.22.2
  6. VPC-B1
    VPC Network Configuration
    NIC em01
    IP CIDR 192.168.23.0/24
    Gateway 192.168.23.1
    DHCP IP 192.168.23.2
  7. VPC-B2
    VPC Network Configuration
    NIC em01
    IP CIDR 192.168.24.0/24
    Gateway 192.168.24.1
    DHCP IP 192.168.24.2

To create a VXLAN-VPC network, follow these steps:

  1. Admin creates two sub-accounts (Sub-Account-A and Sub-Account-B).
    Log in to ZCF, switch to the corresponding region, and then on the main menu, choose Settings > Sub-Account Setting > Sub-Account Management. On the Sub-Account page, click Create Sub-Account. Then, the Create Sub-Account page is displayed. On the displayed page, set the following parameters:
    • Name: Enter a name for the sub-account, for example, Sub-Account-A.
    • Description: Optional. Enter a description for the sub-account.
    • Password: Enter a password for the sub-account.
    • Confirm Password: Confirm the sub-account password.
    • Pricing List: Optional. Select a pricing list. If left blank, the default pricing list is used.
    Figure 51. Create Sub-Account


    Similarly, create another sub-account named as Sub-Account-B.
    Figure 52. Create Sub-Account


  2. Admin creates an L2 public network and attaches it to the corresponding cluster.

    For network configuration information, see Public Network Configuration.

    Log in to ZCF, switch to the corresponding region, and then on the main menu, choose Resource Center > Network Resource > L2 Network Resources > L2 Network. On the L2 Network page, click Create L2 Network. Then, the Create L2 Network page is displayed. On the displayed page, set the following parameters:
    • Zone: By default, the current zone is displayed.
    • Name: Set the name as L2-Public Network.
    • Description: Optional. Enter a description for the L2 network.
    • Switch Type: Select Linux Bridge.
    • Network Type: Select L2NoVlanNetwork.
    • Cluster: Select a cluster to be attached, for example, Cluster-1.
    • NIC Name: Enter a NIC name for the L2 network. For example, em01.
    Figure 53. Create L2-Public Network


  3. Admin creates an L3 public network.

    For network configuration information, see Public Network Configuration.

    Log in to ZCF, switch to the corresponding region, and then on the main menu, choose Resource Center > Network Resource > L3 Network Resources > Public Network. On the Public Network page, click Create Public Network. The Create Public Network page is displayed. On the displayed page, set the following parameters:
    • Name: Set the name as L3-Public Network.
    • Description: Optional. Enter a description for the public network.
    • L2 Network: Select the existing L2-Public Network.
      Note: ZStack Cloud allows you to use an L2 network to create multiple L3 networks. However, we recommend that you do not use an L2 network to create multiple L3 networks if not for specific business needs.
      On the Select L2 Network page, two tabs are displayed:
      • Recommended: lists L2 networks in the current zone that are not attached to an L3 network.
      • All: lists all L2 networks in the current zone.
    • Network Address Type: Select IPv4.
    • Network Range Method: Select IP Range.
    • Start IP: Set a start IP address for the network range, for example, 10.151.10.100.
    • End IP: Set an end IP address for the network range, for example, 10.151.10.200.
    • Netmask: Set a netmask for the network range, for example, 255.0.0.0.
    • Gateway: Set a gateway for the network range, for example, 10.0.0.1.
    • DHCP Service: Choose whether to enable the DHCP service.
      Note:
      • The DHCP service is a built-in distributed service of the Cloud, which assigns IP addresses only to resources in the Cloud and does not conflict with your existing DHCP server.
      • By default, the DHCP service is enabled so that IP addresses are automatically assigned to resources in the Cloud. You can customize a DHCP IP or use the DHCP IP that the system assigned according to the IP allocation policy.
      • If you disable this option, IP addresses are not automatically assigned to resources that use this network. Therefore, you need to manually assign IP addresses to these resources. In addition, you cannot specify a DHCP IP. Neither can the system allocate one.
      • IP Allocation Policy: Optional. IP addresses can be assigned according to the following three allocation policies:
        • Random: The system randomly assigns IP addresses from the network range.
        • Allocate in Order:
          • The system assigns all available IP addresses from the network range in ascending order. Released IP addresses are assigned in the next allocation.
          • Example: Assume that the network range is 192.168.0.101~192.168.0.120, within which 192.168.0.101~192.168.0.108 are allocated. If 192.168.0.106 is released, it will be assigned first in the next allocation.
        • Allocate in Cycle:
          • The system assigns available IP addresses to VM instances from the network range in ascending order. Released IP addresses are assigned when currently available IP addresses are used up.
          • Example: Assume that the network range is 192.168.0.101~192.168.0.120, within which 192.168.0.101~192.168.0.108 are allocated. If 192.168.0.106 is released, it will be assigned after 192.168.0.120 is used.
      • DHCP IP: Optional. Set an IP address for the DHCP server.
        Note:
        • A DHCP IP is an IP address used by the DHCP service to assign IP addresses to resources that use this L3 network.
        • If you create an L3 network for the first time with the DHCP service enabled, or if you add the first network range to an L3 network with the DHCP service enabled, you can customize the DHCP IP.
        • If the L3 network has a DHCP IP, you cannot customize the DHCP IP when you add a network range.
        • The DHCP IP can be in or outside the added IP range, but it must be an unoccupied IP address in the CIDR block of the added IP range
        • The IP range determined by the start IP and end IP cannot contain the link-local address 169.254.0.0/16.
        • If you select random as the IP allocation policy and this field is left blank, the system randomly assigns IP addresses from the added network range.
        • If you select allocate in order/allocate in cycle as the IP allocation policy and this field is left blank, the system uses the start IP address in the network range as the DHCP IP.
    • DNS: Optional. Add a DNS server to provide domain name resolution services for the public network, for example, 223.5.5.5.
      Note: When you add an IP range for an IPv4 L3 network, note that:
      • The IP range cannot contain gateway IP addresses in the format of xxx.xxx.xxx.1, broadcast addresses in the format of xxx.xxx.xxx.255, or network addresses in the format of xxx.xxx.xxx.0.
      • The IP range of a private network cannot overlap with the IP range of a public network used to create a vRouter offering or of a management network.
    Figure 54. Create L3-Public Network


  4. Admin creates an L2 management network and attaches it to the corresponding cluster.

    For network configuration information, see Management Network Configuration.

    Log in to ZCF, switch to the corresponding region, and then on the main menu, choose Resource Center > Network Resource > L2 Network Resources > L2 Network. On the L2 Network page, click Create L2 Network. Then, the Create L2 Network page is displayed. On the displayed page, set the following parameters:
    • Zone: By default, the current zone is displayed.
    • Name: Set the name as L2-Management Network.
    • Description: Optional. Enter a description for the L2 network.
    • Switch Type: Select Linux Bridge.
    • Network Type: Select L2NoVlanNetwork.
    • Cluster: Select a cluster to be attached, for example, Cluster-1.
    • NIC Name: Enter a NIC name for the L2 network. For example, em02.
    Figure 55. Create L2-Management Network


  5. Admin creates an L3 management network that is used to communicate with physical resources, such as hosts, primary storage, and image storage.

    For network configuration information, see Management Network Configuration.

    Log in to ZCF, switch to the corresponding region, and then on the main menu, choose Resource Center > Network Resource > Dedicated Network > Management Network. On the Management Network page, click Create Management Network. Then, the Create Management Network page is displayed. On the displayed page, set the following parameters:
    • Name: Set the name as L3-Management Network.
    • Description: Optional. Enter a description for the management network.
    • L2 Network: Select the existing L2-Management Network.
      Note: ZStack Cloud allows you to use an L2 network to create multiple L3 networks. However, we recommend that you do not use an L2 network to create multiple L3 networks if not for specific business needs.
      On the Select L2 Network page, two tabs are displayed:
      • Recommended: lists L2 networks in the current zone that are not attached to an L3 network.
      • All: lists all L2 networks in the current zone.
    • Network Range Method: Select IP Range.
    • Start IP:Set a start IP address for the network range, for example, 192.168.28.100.
    • End IP: Set an end IP address for the network range, for example, 192.168.28.200.
    • Netmask: Set a netmask for the network range, for example, 255.255.255.0.
    • Gateway: Set a gateway for the network range, for example, 192.168.28.1.
    • Note: When you add an IP range for an IPv4 L3 network, note that:
      • The IP range cannot contain gateway IP addresses in the format of xxx.xxx.xxx.1, broadcast addresses in the format of xxx.xxx.xxx.255, or network addresses in the format of xxx.xxx.xxx.0.
      • The IP range of a private network cannot overlap with the IP range of a public network used to create a vRouter offering or of a management network.
    Figure 56. Create L3-Management Network


  6. Admin adds a vRouter image.

    Log in to ZCF, switch to the corresponding region, and then on the main menu, choose Resource Center > Network Resource > vRouter > vRouter Image. On the vRouter Image page, click Add vRouter Image. Then, the Add vRouter Image page is displayed.

    Set the following parameters:
    • Name: Enter a name for the vRouter image.
    • Description: Optional. Enter a description for the vRouter image.
    • Image Usage: Display VPC vRouter.
    • CPU Architecture: Select a CPU architecture for the vRouter image. VPC vRouters created from the vRouter image inherit this CPU architecture.
    • OS: Select a OS for the vRouter image. Supported OS types differ depending on the CPU architecture.
    • Image Storage: Select an image storage to store the vRouter image.
    • Image Path: Enter a URL or upload a local file.
      • URL: Enter the download URL of the vRouter image.
      • Local File: Upload a vRouter image file that can directly be accessed by the current browser.
        Note:
        • You can upload the vRouter image to an ImageStore or Ceph image storage.
        • A local browser will serve as a transmission relay used for uploading the vRouter image. Do not refresh or stop the current browser, nor stop your management node. Otherwise, you will fail to add the vRouter image.
  7. Admin creates a vRouter offering and shares it to Sub-Account-A and Sub-Account-B.
    1. Create a vRouter offering.
      On the displayed page, set the following parameters:
      • Zone: By default, the current zone is displayed.
      • Name: Enter a name for the vRouter offering.
      • Description: Optional. Enter a description for the vRouter offering.
      • CPU: Set the number of CPU cores for a vRouter.
        Note: Currently, a vRouter can have up to 240 CPU cores. In an actual production environment, we recommend that you set more than 8 CPU cores for a vRouter.
      • Memory: Set the memory size for a vRouter. Unit: MB, GB, and TB. In an actual production environment, we recommend that the memory size greater than 8 GB.
      • Image: Select a vRouter image you added before.
        Note: If the L3 public network in the vRouter offering has a network range of the IPv6 type, when you create a VPC vRouter, you must use the vRouter image of version 3.10.0 or later.
      • Management Network: Select an L3 management network you created before.
        • A management network is used by the management node to deploy and configure resources such as hosts and VPC vRouters.
        • If a system network is used to manage physical resources, select the system network as the management network.
        • If you use a public network to manage physical resources, select the public network as the management network.
      • Public Network: Select a public network you created before.
        • vRouters created from this vRouter offering can provide VPC network services.
      Figure 57. Create vRouter Offering


    2. Share the vRouter offering to Sub-Account-A and Sub-Account-B.
      Log in to ZCF, switch to the corresponding region, and then on the main menu, choose Resource Center > Network Resource > vRouter > vRouter Offering. On the vRouter Offering page, locate the vRouter offering and click Actions > Set Sharing Mode. On the Set Sharing Mode dialogue box, select Share to specified projects/accounts and select Sub-Account-A and Sub-Account-B in Specify Account.
      Figure 58. Set Sharing Mode


  8. Admin creates a VXLAN pool, attaches it to the corresponding cluster, and shares it to Sub-Account-A and Sub-Account-B.
    1. Create a VXLAN pool.

      For VXLAN pool configuration information, see VXLAN Pool Configuration.

      Log in to ZCF, switch to the corresponding region, and then on the main menu, choose Resource Center > Network Resource > L2 Network Resources > VXLAN Pool. On the VXLAN Pool page, click Create VXLAN Pool. Then, the Create VXLAN Pool page is displayed. On the displayed page, set the following parameters:
      • Zone: By default, the current zone is displayed.
      • Name: Enter a name for the VXLAN pool.
      • Description: Optional. Enter a description for the VXLAN pool.
      • SDN Type: Select Software.
      • VNI Range: Enter the start ID and end ID of VXLAN networks.
        Note:
        • You can enter an ID that ranges from 1 to 16777214.
        • The end ID must be equal to or greater than the start ID.
        • The two VNI IDs 16777215 and 16777216 are reserved by the system of this cloud platform.
      • Cluster: Optional. Attach the VXLAN pool to a cluster.
        Note:
        • You can attach a VXLAN pool to a cluster when you create the VXLAN pool or after the VXLAN pool is created.
        • When you attach the VXLAN pool to a cluster, IP addresses of the compute nodes must be available in the cluster that correspond to the VTEP CIDR block.
      • VTEP CIDR: Enter the corresponding VTEP CIDR block.
      Figure 59. Create VXLAN Pool


    2. Share the VXLAN pool to Sub-Account-A and Sub-Account-B.

      Log in to ZCF, switch to the corresponding region, and then on the main menu, choose Resource Center > Network Resource > L2 Network Resources > VXLAN Pool. On the VXLAN Pool page, locate the VXLAN pool and click Actions > Set Sharing Mode. On the Set Sharing Mode dialogue box, select Share to specified projects/accounts and select Sub-Account-A and Sub-Account-B in Specify Account.

      Figure 60. Set Sharing Mode


  9. Create VPC vRouters from the vRouter offering using Sub-Account-A and Sub-Account-B respectively, for example, VPC vRouter-A and VPC vRouter-B.
    Log in to ZCF using Sub-Account-A, switch to the corresponding region, and then on the main menu, choose Resource Center > Network Resource > vRouter > VPC vRouter. On the VPC vRouter page, click Create VPC vRouter. Then, the Create VPC vRouter page is displayed. On the displayed page, set the following parameters:
    • Name: Enter a name for the VPC vRouter.
    • Description: Optional. Enter a description for the VPC vRouter.
    • vRouter Offering: Select a vRouter offering you created before.
    • Cluster: Optional. Specify a cluster for the host on which the VPC vRouter is to be started.
    • Storage Allocation Policy: Specify how the Cloud allocates a primary storage. The following two policies are supported:
      • System Allocation: The Cloud allocates a primary storage according to the preconfigured policy.
      • Custom: Select a primary storage as needed.
        • Primary Storage: Select a primary storage for the VPC vRouter.
    • Host: Optional. Select a host on which the VPC vRouter is started.
    • Default IPv4/IPv6 Address: Optional. Specify a default IP address for the VPC vRouter. If not specified, the Cloud allocates one automatically.
    • Assign Management Network IP: Optional. Assign a management network IP to the VPC vRouter.
      Note: To assign a management network IP, make sure that the management network used by the VPC vRouter is separated from the public network the VPC vRouter uses. If the VPC vRouter uses a same network both as its management network and public network, you cannot assign a management network IP.
    • DNS: Optional. Set the DNS service for the VPC vRouter. If not specified, 223.5.5.5 will be used.
      Note:
      • You can set an IPv4 DNS or IPv6 DNS as needed. For example, you can set the IPv4 DNS to 223.5.5.5 or IPv6 DNS to 240C::6644.
      • Services in the VPC vRouter can access the public network services via DNS. You can also specify the other DNS address if necessary.
      • For VM instances created by using a VPC network, the DNS is the gateway of the VPC network. The VM traffics are forwarded by a VPC vRouter.
    • CPU Pinning: Associate the virtual CPUs (vCPUs) of a VPC vRouter with host pCPUs stringently and allow you to allocate specific pCPUs for the VPC vRouter, thus improving VPC vRouter performances.
      Note:
      • Pinning Format
        • In the left input box, set a vCPU range. In the right input box, set a pCPU range. Range format: integer, hyphen(-), and caret (^). Use commas to separate them.
        • The vCPU range depends on the vRouter offering attached to the VPC vRouter.
        • The pCPU range depends on the pCPU quantity of the selected cluster or host.
      • Example: In the left input box, enter 1. In the right input box, enter 0-3,^2. This example indicates that vCPU 1 is stringently associated with pCPU 0, pCPU 1, and pCPU 3, while ^ represents that vCPU 2 is excluded.
    Figure 61. Create VPC vRouter-A


    Similarly, log in to the Cloud using Sub-Account-B and create another VPC vRouter.
  10. Create two VXLAN networks from the VXLAN pool using Sub-Account-A and Sub-Account-B respectively, for example, L2-VXLAN-A1, L2-VXLAN-A2, L2-VXLAN-B1, and L2-VXLAN-B2.
    Log in to ZCF, switch to the corresponding region, and then on the main menu, choose Resource Center > Network Resource > L2 Network Resources > L2 Network. On the L2 Network page, click Create L2 Network. Then, the Create L2 Network page is displayed. On the displayed page, set the following parameters:
    • Zone: By default, the current zone is displayed.
    • Name: Set the name as L2-VXLAN-A1.
    • Description: Optional. Enter a description for the L2 network.
    • Switch Type: Select Linux Bridge.
    • Network Type: Select VxlanNetwork.
    • VXLAN Pool: Select a VXLAN pool of the software SDN type.
    • VNI: Optional. Select a specified VNI in the VXLAN pool.

      If not specified, the Cloud allocates a VNI randomly.

    Figure 62. Create L2-VXLAN-A1


    Similarly, create L2-VXLAN-A2, L2-VXLAN-B1, and L2-VXLAN-B2 respectively.
  11. Create VPC networks using the four VXLAN networks in Sub-Account-A and Sub-Account-B respectively, for example, VPC-A1, VPC-A2, VPC-B1, and VPC-B2.

    For VPC network configuration information, see VPC-A1 Configuration.

    Log in to ZCF, switch to the corresponding region, and then on the main menu, choose Resource Center > Network Resource > L3 Network Resources > VPC Network. On the VPC Network page, click Create VPC Network. The Create VPC Network page is displayed. On the displayed page, set the following parameters:
    • Name: Set the name as VPC-A1.
    • Description: Optional. Enter a description for the VPC network.
    • L2 Network: Select the existing L2-VXLAN-A1.
      On the Select L2 Network page, two tabs are displayed:
      • Recommended: lists L2 networks in the current zone that are not attached to an L3 network.
      • All: lists all L2 networks in the current zone.
    • VPC vRouter: Optional. You can specify a VPC vRouter when you create a VPC network or attach a VPC vRouter after you create the VPC network.
    • Network Address Type: Select IPv4.
    • Network Range Method: Select CIDR.
    • CIDR: Set a CIDR block for the VPC network, for example, 192.168.108.1/24.
    • Gateway: Set a gateway for the VPC network, for example, 192.168.108.1.
      Note:
      • You can use the first or last IP address in the specified CIDR block as the gateway.
      • If left blank, the first IP address in the specified CIDR block is used as the gateway.
    • DHCP Service: Choose whether to enable the DHCP service.
      Note:
      • The DHCP service is a built-in distributed service of the Cloud, which assigns IP addresses only to resources in the Cloud and does not conflict with your existing DHCP server.
      • By default, the DHCP service is enabled so that IP addresses are automatically assigned to resources in the Cloud. You can customize a DHCP IP or use the DHCP IP that the system assigned according to the IP allocation policy.
      • If you disable this option, IP addresses are not automatically assigned to resources that use this network. Therefore, you need to manually assign IP addresses to these resources. In addition, you cannot specify a DHCP IP. Neither can the system allocate one.
      • IP Allocation Policy: Optional. After the DHCP service is enabled, IP addresses can be assigned according to the following three allocation policies:
        • Random: The system randomly assigns IP addresses from the network range.
        • Allocate in Order:
          • The system assigns all available IP addresses from the network range in ascending order. Released IP addresses are assigned in the next allocation.
          • Example: Assume that the network range is 192.168.0.101~192.168.0.120, within which 192.168.0.101~192.168.0.108 are allocated. If 192.168.0.106 is released, it will be assigned first in the next allocation.
        • Allocate in Cycle:
          • The system assigns available IP addresses to VM instances from the network range in ascending order. Released IP addresses are assigned when currently available IP addresses are used up.
          • Example: Assume that the network range is 192.168.0.101~192.168.0.120, within which 192.168.0.101~192.168.0.108 are allocated. If 192.168.0.106 is released, it will be assigned after 192.168.0.120 is used.
      • DHCP IP: Optional. Set an IP address for the DHCP server, for example, 192.168.21.2.
        Note:
        • A DHCP IP is an IP address used by the DHCP service to assign IP addresses to resources that use this L3 network.
        • If you create an L3 network for the first time with the DHCP service enabled, or if you add the first network range to an L3 network with the DHCP service enabled, you can customize the DHCP IP.
        • If the L3 network has a DHCP IP, you cannot customize the DHCP IP when you add a network range.
        • The DHCP IP can be in or outside the added IP range, but it must be an unoccupied IP address in the CIDR block of the added IP range
        • The IP range determined by the start IP and end IP cannot contain the link-local address 169.254.0.0/16.
        • If you select random as the IP allocation policy and this field is left blank, the system randomly assigns IP addresses from the added network range.
        • If you select allocate in order/allocate in cycle as the IP allocation policy and this field is left blank, the system uses the start IP address in the network range as the DHCP IP.
    • DNS: Optional.
    Figure 63. Create VPC-A1


    Similarly, create VPC-A2, VPC-B1, and VPC-B2 respectively.
  12. Create a VM instance in each sub-account using the corresponding VPC networks, for example, VM-A1, VM-A2, VM-B1, and VM-B2.

    As for how to create a VM instance, you can refer to the Create VM Instance chapter of the User Guide.

  13. Test the connectivity among VM instances.
    1. Log in to VM-A1 and use the ping command to test the network connectivity:
      Expected result:
      • ping baidu.com: Successful
      • ping VM-A2: Successful
      • ping VM-B1: Failed (Two VXLAN-VPC network are isolated in layer 2)
      • ping VM-B2: Failed (Two VXLAN-VPC network are isolated in layer 2)
      Note:
      In VM-A1 system, you need to manually add the IP addresses of other VM instances to the /etc/hosts directory.
      [root@Localhost~]# vim /etc/hosts
      ...
      192.168.22.156 VM-A2
      192.168.23.177 VM-B1
      192.168.24.193 VM-B2
      ...
      Figure 64. Test VM-A1 Network Connectivity


    2. Similarly, the network connectivity of VM-A2 is expected the be the same as that of VM-A1.
    3. Log in to VM-B1 and use the ping command to test the network connectivity.
      Expected result:
      • ping baidu.com: Successful
      • ping VM-A1: Failed (Two VXLAN-VPC network are isolated in layer 2)
      • ping VM-A2: Failed (Two VXLAN-VPC network are isolated in layer 2)
      • ping VM-B2: Successful
      Note:
      In VM-B1 system, you need to manually add the IP addresses of other VM instances to the /etc/hosts directory.
      [root@Localhost~]# vim /etc/hosts
      ...
      192.168.21.250 VM-A1
      192.168.22.156 VM-A2
      192.168.24.193 VM-B2
      ...
      Figure 65. Test VM-B2 Network Connectivity


    4. Similarly, the network connectivity of VM-B2 is expected the be the same as that of VM-B1.
  14. Admin shares the L3 public network to Sub-Account-A and Sub-Account-B.

    Log in to ZCF, switch to the corresponding region, and then on the main menu, choose Resource Center > Network Resource > L3 Network Resources > Public Network. On the Public Network page, locate the L3-Public Network and click Actions > Set Sharing Mode. On the Set Sharing Mode dialogue box, select Share to specified projects/accounts and select Sub-Account-A and Sub-Account-B in Specify Account.

    Figure 66. Set Sharing Mode


  15. Create a route table to enable VM-A1 and VM-B1 that are isolated in layer 2 can communicate with each other.
    1. Create a route table.

      Log in to ZCF, switch to the corresponding region, and then on the main menu, choose Resource Center > Network Service > Advanced Network Service > Route Table. On the Route Table page, click Create Route Table. Then, the Create Route Table page is displayed.

      On the displayed page, set the following parameters:
      • Name: Enter a name for the route table.
      • Description: Optional. Enter a description for the route table.
      • VPC vRouter: Optional. Select a VPC vRouter to which the route table is attached.
      Figure 67. Create Route Table


    2. Add two route entries to the route table.
      Destination Network Next Hop
      Route Entry-1 The VPC network CIDR of VM-A1 The public IP of the VPC vRouter of VM-A1
      Route Entry-2 The VPC network CIDR of VM-B1 The public IP of the VPC vRouter of VM-B1

      On the Route Table page, locate the created route table and enter its details page. On the Route Entry tab of the details page, click Add Route Entry to add two route entries respectively.

      Figure 68. Add Route Entry


  16. Test the connectivity between VM-A1 and VM-B1.
    Expected result:
    • Log in to VM-A1, ping VM-B1: Successful
    • Log in to VM-B1, ping VM-A2: Successful
    Figure 69. Test Connectivity Between VM-A1 and VM-B1




So far, we have introduced the deployment practice of multi-tenant isolation in VPC network.

Multi-Web Server

To deploy a multi-web server of VPC network, follow these steps:
  1. Create three VPC subnets from the same VPC vRouter, for example, VPC-Web, VPC-app, and VPC-database.
    Note: The network range of the three VPC subnets cannot overlap with one another.
  2. Create three VM instances using the three VPC subnets respectively, for example, VM-web, VM-app, and VM-database.
  3. Test the network connectivity among three VM instances.
Assume the customer environment is as follows:
  1. Public Network
    Public Network Configuration
    NIC em01
    VLAN ID No VLAN
    IP Range 10.151.10.100~10.151.10.200
    Netmask 255.0.0.0
    Gateway 10.0.0.1
  2. Management Network
    Management Network Configuration
    NIC em02
    VLAN ID No VLAN
    IP Range 192.168.28.100~192.168.28.200
    Netmask 255.255.255.0
    Gateway 192.168.28.1
    Note:
    • For security and stability reasons, we recommend that you deploy an independent management network and separate it from the public networks.
    • The management network we mentioned here is the same as that in ZStack Cloud. That is, the management network is the network used to manage hosts, primary storage, and image storage. If a management network was created before, you can use it directly.
  3. VPC-web
    Private Network Configuration
    NIC em01
    VLAN ID 2017
    IP CIDR 192.168.10.0/24
  4. VPC-app
    Private Network Configuration
    NIC em01
    VLAN ID 2020
    IP CIDR 192.168.20.0/24
  5. VPC-database
    Private Network Configuration
    NIC em01
    VLAN ID 2050
    IP CIDR 192.168.50.0/24

The following part describes the practice of deploying a multi-web server of VPC network in detail.

  1. Create three VPC subnets from the same VPC vRouter, for example, VPC-Web, VPC-app, and VPC-database. For detailed information, you can refer to the Create VPC Network chapter of User Guide.
    Note: The network range of the three VPC subnets cannot overlap with one another.
    Figure 70. Three VPC Subnets


  2. Create three VM instances using the three VPC subnets respectively, for example, VM-web, VM-app, and VM-database.
    Figure 71. Three VM Instances


  3. Test the network connectivity among three VM instances.
    1. Log in to VM-web and use the ping command to test network connectivity.
      Expected result:
      • ping baidu.com: Successful
      • ping VM-app: Successful
      • ping VM-database: Successful
      Note:
      In VM-web system, you need to manually add the IP addresses of VM-app and VM-database to the /etc/hosts directory.
      [root@VM-web ~]# vim /etc/hosts
      ...
      192.168.20.187 VM-app
      192.168.50.141 VM-database
      ...
      Figure 72. Test VM-web Network Connectivity


    2. Log in to VM-app and use the ping command to test network connectivity.
      Expected result:
      • ping baidu.com: Successful
      • ping VM-web: Successful
      • ping VM-database: Successful
      Note:
      In VM-app system, you need to manually add the IP addresses of VM-web and VM-database to the /etc/hosts directory.
      [root@VM-app ~]# vim /etc/hosts
      ...
      192.168.10.79 VM-web
      192.168.50.141 VM-database
      ...
      Figure 73. Test VM-app Network Connectivity


    3. Log in to VM-database and use the ping command to test network connectivity.
      Expected result:
      • ping baidu.com: Successful
      • ping VM-app: Successful
      • ping VM-web: Successful
      Note:
      In VM-database system, you need to manually add the IP addresses of VM-app and VM-web to the /etc/hosts directory.
      [root@VM-database ~]# vim /etc/hosts
      ...
      192.168.20.187 VM-app
      192.168.10.79 VM-web
      ...
      Figure 74. Test VM-database Network Connectivity


So far, we have introduced the practice of deploying a multi-web server.

STS

STS: If a VPC vRouter is connected with multiple public networks, egress traffic is sent to a public network in the same route as the ingress traffic sent from the public network.
  • Make sure that all planned public networks are able to connecting to the Internet.
  • Effectiveness: This policy takes effect on all public networks that are connected with the VPC vRouter except the default public network.

To use the STS feature of a VPC vRouter, follow these steps:

  1. Set up a basic VPC environment.
  2. Attach multiple public networks to the VPC vRouter.
  3. Enable the STS feature of VPC vRouter.
  4. Functional verification.
Assume the customer environment configuration is as follows:
  1. Public Network-Unicom (Default Public Network)
    Public Network Configuration
    NIC eth1
    VLAN ID No VLAN
    CIDR 172.31.5.0/24
  2. Public Network-Mobile
    Public Network Configuration
    NIC eth3
    VLAN ID No VLAN
    CIDR 172.31.4.0/24
  3. Management Network
    Management Network Configuration
    NIC eth2
    VLAN ID No VLAN
    CIDR 10.5.117.0/24
    Note:
    • For security and stability reasons, we recommend that you deploy an independent management network and separate it from the public networks.
    • The management network we mentioned here is the same as that in ZStack Cloud. That is, the management network is the network used to manage hosts, primary storage, and image storage. If a management network was created before, you can use it directly.
  4. VPC-1
    VPC-1 Configuration
    NIC eth1
    VLAN ID 1982
    IP CIDR 192.168.3.0/24
  5. VPC-2
    VPC-2 Configuration
    NIC eth3
    VLAN ID 1983
    IP CIDR 192.168.4.0/24

The following part describes the practice of deploying a multiple public networks of VPC vRouter.

  1. Set up a basic VPC environment.
    Set up a basic VPC environment according to the assumed customer environment configuration.
    Note: The basic environment supports adding one public network to the VPC vRouter. In this scenario, we use Public Network-Unicom as the default public network. You can create Public Network-Mobile in advance for later use.
    Figure 75. Set up Basic VPC Environment


  2. Attach multiple public networks to the VPC vRouter.

    On the Network tab of the details page, click Public Network. Then, click Attach to attach a public network (Public Network-Mobile) to the VPC vRouter.

    Figure 76. Attach Public Network to VPC vRouter


  3. Enable the STS feature of VPC vRouter.
    On the details page of the VPC vRouter, turn on the STS switch to enable the STS feature.
    Note: Modifications on the policy take effect immediately. You do not need to restart the VPC vRouter.
    Figure 77. Enable STS


    At this point, the STS configuration of the VPC vRouter is completed. And all external traffic accesses to the resources of the VPC vRouter will support STS.

  4. Functional verification.

    Create a VM instance using the VPC network and associate EIPs created from the two public network. Use external network to ping the EIP created from non-default public network (Public Network-Mobile).

    Expected result: Monitor the two NICs (eth1 and eth3) of the VPC vRouter and only the NIC (eth3) of the non-default public network can receive the requested return data.

    1. Create a VM instance for test.

      On the VM Instance page, create a VM instance using VPC-1 or VPC-2.

    2. Create EIPs and associate them with the VM instance.

      Create EIPs using Public Network-Unicom and Public Network-Mobile respectively and associate them with the VM instance.

      Figure 78. Create and Associate EIPs


    3. Monitor data flow direction.

      Use external network to ping the EIP of the VM instance, for example, 172.31.4.18. The requested data goes through the eth3 NIC of the VPC vRouter.

      Figure 79. External Excess to VM Instance


      Log in to the VPC vRouter, use the tcpdump command to monitor the data traffic of the two public network NICs. The returned data only goes through the eth3, which is the same NIC that gives the request.

      Figure 80. Monitor Returned Data


Address Pool

An address pool network range must co-exist with a normal network range. An address pool network range can be only used to create VIPs to provide network services based on VPC vRouters.

To add an address pool, follow these steps:

  1. Plan your network.
  2. Create a public network.
  3. Add an address pool.
  4. Create a VIP using the address pool.
  5. Test whether the VIP works properly.
The following tables list the user's assumed environment configuration.
  1. Public Network (Normal Network Range)
    Public Network Configuration
    NIC em01
    VLAN ID No VLAN
    CIDR 10.151.0.0~10.151.0.255
    Netmask 255.0.0.0
    Gateway 10.151.0.1
  2. Public Network (Address Pool)
    Address Pool Configuration
    IP Range 172.20.0.1~172.20.0.254
    Netmask 255.255.0.0

The following section describes the detailed steps of how to use an address pool.

  1. Plan your network.
    IPv4 public networks support address pool. Make sure that the address pool network range is planned and configured as a public network. Otherwise, the network is unreachable.
    Note: We recommend that you plan your network according to the actual scenarios and make relevant configurations in key switches.
  2. Create a public network.
    1. Create an L2 network.
      Log in to ZCF, switch to the corresponding region, and then on the main menu, choose Resource Center > Network Resource > L2 Network Resources > L2 Network. On the L2 Network page, click Create L2 Network. Then, the Create L2 Network page is displayed. On the displayed page, set the following parameters:
      • Zone: By default, the current zone is displayed.
      • Name: Set the name as L2- Public Network.
      • Description: Optional. Enter a description for the L2 network.
      • Switch Type: Select Linux Bridge.
      • Network Type: Select L2NoVlanNetwork.
      • Cluster: Optional. Select the cluster to be attached, for example, Cluster-1.
      • NIC Name: Enter a NIC name for the L2 network. For example, em01.
      Figure 81. Create L2-Public Network


    2. Create an L3 public network.
      Log in to ZCF, switch to the corresponding region, and then on the main menu, choose Resource Center > Network Resource > L3 Network Resources > Public Network. On the Public Network page, click Create Public Network. The Create Public Network page is displayed. On the displayed page, set the following parameters:
      • Name: Enter a name for the public network.
      • Description: Optional. Enter a description for the public network.
      • L2 Network: Select an L2 network for the public network.
        Note: ZStack Cloud allows you to use an L2 network to create multiple L3 networks. However, we recommend that you do not use an L2 network to create multiple L3 networks if not for specific business needs.
        On the Select L2 Network page, two tabs are displayed:
        • Recommended: lists L2 networks in the current zone that are not attached to an L3 network.
        • All: lists all L2 networks in the current zone.
      • Network Address Type: Select IPv4.
      • Network Range Method: Select IP Range.
      • Start IP: Set a start IP address for the network range, for example, 10.151.0.2.
      • End IP: Set an end IP address for the network range, for example, 10.151.0.254.
      • Netmask: Set a netmask for the network range, for example, 255.0.0.0.
      • Gateway: Set a gateway for the network range, for example, 10.0.0.1.
      • DHCP Service: Choose whether to enable the DHCP service.
        Note:
        • The DHCP service is a built-in distributed service of the Cloud, which assigns IP addresses only to resources in the Cloud and does not conflict with your existing DHCP server.
        • By default, the DHCP service is enabled so that IP addresses are automatically assigned to resources in the Cloud. You can customize a DHCP IP or use the DHCP IP that the system assigned according to the IP allocation policy.
        • If you disable this option, IP addresses are not automatically assigned to resources that use this network. Therefore, you need to manually assign IP addresses to these resources. In addition, you cannot specify a DHCP IP. Neither can the system allocate one.
        • IP Allocation Policy: Optional. IP addresses can be assigned according to the following three allocation policies:
          • Random: The system randomly assigns IP addresses from the network range.
          • Allocate in Order:
            • The system assigns all available IP addresses from the network range in ascending order. Released IP addresses are assigned in the next allocation.
            • Example: Assume that the network range is 192.168.0.101~192.168.0.120, within which 192.168.0.101~192.168.0.108 are allocated. If 192.168.0.106 is released, it will be assigned first in the next allocation.
          • Allocate in Cycle:
            • The system assigns available IP addresses to VM instances from the network range in ascending order. Released IP addresses are assigned when currently available IP addresses are used up.
            • Example: Assume that the network range is 192.168.0.101~192.168.0.120, within which 192.168.0.101~192.168.0.108 are allocated. If 192.168.0.106 is released, it will be assigned after 192.168.0.120 is used.
        • DHCP IP: Optional. Set an IP address for the DHCP server, for example, 172.20.108.10.
          Note:
          • A DHCP IP is an IP address used by the DHCP service to assign IP addresses to resources that use this L3 network.
          • If you create an L3 network for the first time with the DHCP service enabled, or if you add the first network range to an L3 network with the DHCP service enabled, you can customize the DHCP IP.
          • If the L3 network has a DHCP IP, you cannot customize the DHCP IP when you add a network range.
          • The DHCP IP can be in or outside the added IP range, but it must be an unoccupied IP address in the CIDR block of the added IP range
          • The IP range determined by the start IP and end IP cannot contain the link-local address 169.254.0.0/16.
          • If you select random as the IP allocation policy and this field is left blank, the system randomly assigns IP addresses from the added network range.
          • If you select allocate in order/allocate in cycle as the IP allocation policy and this field is left blank, the system uses the start IP address in the network range as the DHCP IP.
      • DNS: Optional. You can specify 114.114.114.114.
      • Note: When you add an IP range for an IPv4 L3 network, note that:
        • The IP range cannot contain gateway IP addresses in the format of xxx.xxx.xxx.1, broadcast addresses in the format of xxx.xxx.xxx.255, or network addresses in the format of xxx.xxx.xxx.0.
        • The IP range of a private network cannot overlap with the IP range of a public network used to create a vRouter offering or of a management network.
      Figure 82. Create L3-Public Network


  3. Add an address pool.
    An address pool network range must co-exist with a normal network range. You cannot add an address pool network range if no normal network range is available. On the Network Range tab of the details page of the L3-Public Network, click Add Network Range. On the displayed Add Network Range page, set the following parameters:
    • IP Address Type: By default, the IPv4 type is displayed.
    • Network Range Method: By default, the IP range method is displayed.
    • Network Range Type: Select Address Pool.
    • Start IP: Set a start IP address for the address pool, for example, 172.20.0.1.
    • End IP: Set a end IP address for the address pool, for example, 172.20.0.254.
      Note: The address pool cannot contain broadcast addresses in the format of xxx.xxx.xxx.255, or network addresses in the format of xxx.xxx.xxx.0.
    • Netmask: Set a netmask for the address pool, for example, 255.255.0.0.
    Figure 83. Add Address Pool


  4. Create a VIP using the address pool.
    Log in to ZCF, switch to the corresponding region, and then on the main menu, choose Resource Center > Network Service > Basic Network Service > VIP. On the VIP page, click Create VIP. Then, the Create VIP page is displayed. On the displayed page, set the following parameters:
    • Name: Enter a name for the virtual IP address (VIP).
    • Description: Optional. Enter a description for the VIP.
    • Network: Select an L3 network that has an address pool.
    • Network Range: Select an address pool.
    • Assign IP: Optional. You can assign a virtual IP address.
    • VIP QoS: You can limit the network bandwidth of public VIPs and flat network VIPs. You can set the QoS for a custom VIP when you create the VIP or after the VIP is created.
    Figure 84. Create VIP


  5. Test whether the VIP works properly.

    The VIP works properly if the VIP are used to provide EIP, port forwarding, load balancing, IPsec tunnel, and other network services. In this scenario, we use the VIP to create an EIP for verification.

    Log in to ZCF, switch to the corresponding region, and then on the main menu, choose Resource Center > Network Service > Basic Network Service > EIP. On the EIP page, click Create EIP. Then, the Create EIP page is displayed. On the displayed page, select Use Existing VIP.

    Figure 85. Create EIP


    The successful creation of EIP indicates that the VIP created from the VPC address pool can work properly.

So far, we have introduced how to use an address pool.
ZStack Cloud | ZStack Cloud · ZCF | ZStack Resource Center