SDLab

SDLab
SDLab.org::Adminな脳み
ラベル XenServer の投稿を表示しています。 すべての投稿を表示
ラベル XenServer の投稿を表示しています。 すべての投稿を表示

2016年7月27日水曜日

New Windows PV Drivers


新しいWindows PVドライバがリリースされました。

Windows PV Drivers
http://www.xenproject.org/developers/teams/windows-pv-drivers.html

しかもちゃんとReleased Sign。

みんなが待ち望んでいたので、MLでは賞賛の嵐です。Thank you Paul!

プレゼンの説明
http://wiki.xenproject.org/wiki/Windows_PV_Drivers_Presentation


2015年6月4日木曜日

Hotfix XS62ESP1024 - for XenServer 6.2.0 Service Pack 1

Hotfix XS62ESP1024 - for XenServer 6.2.0 Service Pack 1
http://support.citrix.com/article/CTX142496

Kernelを含むアップデート。
Hotfix XS62ESP1009 の件もあるからちょっと様子見したいところ。


2015年5月14日木曜日

VENOM

VENOM(Virtualized Environment Neglected Operations Manipulation)の件

◆詳細

Crowdstrike.com
Q+A: Learn More About VENOMhttp://venom.crowdstrike.com/

◆Xen

[Xen-users] Xen Security Advisory 133 (CVE-2015-3456) - Privilege escalation via emulated floppy disk drive
http://lists.xen.org/archives/html/xen-users/2015-05/msg00109.html


ISSUE DESCRIPTION
=================
The code in qemu which emulates a floppy disk controller did not
correctly bounds check accesses to an array and therefore was
vulnerable to a buffer overflow attack.

◆XenServer

Citrix Security Advisory for CVE-2015-3456
http://support.citrix.com/article/CTX201078

Description of Problem
Citrix is aware of the recent vulnerability that has been reported against the Xen hypervisor. This issue is known as the 'VENOM' vulnerability and has been assigned the following CVE number:
CVE-2015-3456: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-3456
The following sections will provide guidance to customers on the potential impact of this issue. Citrix is actively analysing the impact of this vulnerability on supported versions of Citrix XenServer. Additional details and guidance will be added to this document as soon as they are available.
<追記 2015/5/19>

https://securityblog.redhat.com/2015/05/13/venom-dont-get-bitten/

VENOMでは、VM上で特定コマンドを実施することで、ハイパーバイザ上で任意のコマンドを実施できるというもの。
ただし、Redhatとしては、特定コマンドは実施できるが、ハイパーバイザ上での実効は確認できていないとのこと。
We believe that code execution is possible but we have not yet seen any working reproducers that would allow this.
なお、既存のExploitは、QEMUをCrashさせるので、Segfault LOGをみてれば、その攻撃を判定できそうとのこと。

ちなみに、影響をうけるのは、HVM(完全仮想化)なVMだけだよ。XenTools入った準仮想化VMは影響受けないらしいよ。
まぁ、RootとられてXenTools抜かれたらやられちゃうけど。

2015年5月1日金曜日

Docker with XenServer6.5

Preview of XenServer support for Docker and Container Management
http://xenserver.org/blog/entry/preview-of-xenserver-support-for-docker-and-container-management.html

3月10日に公開されてた・・・

PRE-RELEASE COMPONENTS - DOCKER INTEGRATION
http://xenserver.org/overview-xenserver-open-source-virtualization/prerelease.html

XenServer6.5用のDocker。
Supplemental Packとして提供されている。
PRE-RELEASE版なので、遊ぶにはちょうどいいけど、それ以外にはちょっと怖い。
Dundeeまで待ちたいね。

XenServer Dundee

Introducing XenServer Dundee

CentOS7ベースの次期XenServer 「Dundee」
Versionとかは見てないけど、多分XenServer 7?


DOWNLOAD - PRE-RELEASE XENSERVER
XenServer Dundee Alpha1 がDownloadできます。

2014年12月22日月曜日

Hotfix XS62ESP1012 - For XenServer 6.2.0 Service Pack 1

Hotfix XS62ESP1012 - For XenServer 6.2.0 Service Pack 1
http://support.citrix.com/article/CTX141845

XenToolsのUpdateです。
パッチ番号は滅茶苦茶ですが、XenToolsだけの更新なので、適当な順番であてれば問題無いと思います。
修正内容は主にWindows系のPVドライバ関係です。

下記も更新しました。

XenServer6.2 SP1 のパッチリスト (2014/12/3時点)
http://mada0833.blogspot.jp/2014/04/XenServer62SP1PatchList.html


2014年12月3日水曜日

Hotfix XS62ESP1015 - For XenServer 6.2.0 Service Pack 1

Hotfix XS62ESP1015 - For XenServer 6.2.0 Service Pack 1
https://support.citrix.com/article/CTX141717

含まれるFix
This hotfix also includes the following previously released hotfixes:
CTX140052 -  Hotfix XS62E014 - For XenServer 6.2.0
CTX140051 -  Hotfix XS62ESP1002 - For XenServer 6.2.0 Service Pack 1
CTX140417 -  Hotfix XS62ESP1004 - For XenServer 6.2.0 Service Pack 1
CTX141036 -  Hotfix XS62ESP1008 - For XenServer 6.2.0 Service Pack 1
CTX141472 -  Hotfix XS62ESP1011 - For XenServer 6.2.0 Service Pack 1
CTX141480 -  Hotfix XS62ESP1013 - For XenServer 6.2.0 Service Pack 1

あて方は、XS62ESP015には、Kernelが含まれていないため、
Recommended Updates for XenServer 6.x Hotfixes
のXS62ESP1013の置き換えと考えてよさそうだ。

XS62ESP1009は最後かぁ・・・

2014年11月26日水曜日

What are the top Citrix XenServer Issues/Workarounds/Best Practices for NFSv3

NetAppに情報があったので。

What are the top Citrix XenServer Issues/Workarounds/Best Practices for NFSv3
https://kb.netapp.com/support/index?id=3014326&page=content

あと、折角のリンクが壊れてたので、ここに書いておきます。
XenServer and NetApp Storage Best Prictices
https://www.netapp.com/us/media/tr-3732.pdf

2014年11月12日水曜日

Windows10 on XenServer6.2 SP1

今更ながら Win10 Techical Preview を XenServer 6.2 SP1 (PatchはXS62ESP1014まで) にINSTALLしてみた。

Win10は基本的にWin8.1らしいのでやってみた。
(内部の仕組みは、今度詳しい人が来日したタイミングで聞いてみる)

Win8.1と同じならテンプレートからNew VMできんじゃね? と思って
NewVM でWindows 8 64bitのテンプレートを選択。
何の問題なくインストール完了

ちょっと物足らない・・・
xentoolsも入れた。
問題なく動作。

ちょっとDom0のログでも見てみるかな。



2014年10月2日木曜日

XenServer Shellshock と XSA-108

Citrix Security Advisory for GNU Bash Shellshock Vulnerabilities
http://support.citrix.com/article/CTX200217

XenServerは影響を継続調査中とのこと。


XSA-108
http://xenbits.xen.org/xsa/advisory-108.html
http://xenbits.xen.org/xsa/

公表をもったいつけてた?XSA-108の件、
XSA-100の延長って印象。HVMで運用してなきゃ、まぁ影響はなさそう。

2014年10月1日水曜日

Hotfix XS62ESP1011 - For XenServer 6.2.0 Service Pack 1

Hotfix XS62ESP1011 - For XenServer 6.2.0 Service Pack 1



私的にはこの辺かな。
The option Restore Virtual Machine Metadata in xsconsole fails to restore VDIs on the storage repositories (SRs). VDIs are restored if the SRs contain the backup of the pool metadata.
When Linux bridge is used as the network stack, generic receive offload (GRO) does not always work on VLANs.

なお、XS62ESP1002 / XS62ESP1004 / XS62ESP1008 が含まれる。

最近Blogの更新ができません。
だれかうちでXenServerの技術者しませんか?

2014年7月23日水曜日

Memory usage alert mail など

xapi


Add Dom0 mem_usage alert
https://github.com/xapi-project/xen-api/pull/1836

+def get_percent_mem_usage(ignored):
+    "Get the percent usage of Dom0 memory/swap. Input list is ignored and should be empty"

Swapの状況もDom0でとれて、Alertメールも出せるようになる。


CP-9019: Automatically log the Xen console
https://github.com/andyhhp/xen-api/commit/9c5c623df0fbe477d3aa1e0c5cdf5054bd9ebe33

/usr/sbin/xenconsoled --log=hv --timestamp=hv --log-dir=/var/log/xen


CP-8987: Use Sexp for Xenops header serialisation
https://github.com/simonjbeaumont/xenopsd/commit/42b0c6061408e08ff8b2c9880344e294c5865a2a
We want to be able to extend the Xenops record in the suspend image in future
versions

sexp_lib

2014年7月16日水曜日

XenServer関連の修正メモ

あまり目に着く情報がなかったので、Blog自体を更新してなかったが、
この辺で更新しておきます。

XenServer


CA-139739: encode NFS shares

self.remotepath = self.dconf['serverpath'].encode('utf-8')

え?encode? そういう書き方もできるのか。

CP-8636: Change gpumon build to use new NVIDIA GDK

 -Source1: tdk_5.319.43.tar.gz
 +Source1: gdk_331_62_release.tgz
 -tar zxvf /obj/SOURCES/tdk_5.319.43.tar.gz
 -cp $RPM_BUILD_DIR/tdk_5.319.43/nvml/include/nvml.h /usr/include
 +tar zxvf /obj/SOURCES/gdk_331_62_release.tgz
 +cp $RPM_BUILD_DIR/gdk_linux_amd64_release/nvml/include/nvml.h /usr/include

GDKのVersion情報が必要になった時のMEMO

CP-8285: Remove maxcpus=1 workaround (only SLES 11 SP0 needs this)
linux-guest-loaderのeliloader.py

2014年7月9日水曜日

XenServer Tech Preview Releas / Alpha4

XenServer Tech Preview Release Date: Jul 8, 2014
https://www.citrix.com/downloads/xenserver/product-software/xenserver-tech-preview
Citrix XenServer 6.4.93

XenServer Creedence Alpha 4
http://xenserver.org/open-source-virtualization-download/11-product/142-download-pre-release.html
2014-07-02 nightly build

多分 TechPreviewはAlpha4と同じと思われる。
なお、最新Nightly Buildは 2014-07-07 だ。次は07-12?

2014年6月17日火曜日

xapi daemon のRRDの説明、 MPP-RDAC 他

RE: [xs-devel] Gluster FS with libgfapi
https://lists.xenserver.org/sympa/arc/xs-devel/2014-06/msg00052.html

Creedenceでは、libgfapiはサポートしてない模様。


The problem with xapi daemon metrics in monitoring XenServer performance
http://discussions.citrix.com/topic/346909-the-problem-with-xapi-daemon-metrics-in-monitoring-xenserver-performance/

xapi DaemonのRRD関連の
xapi_allocation_kib
xapi_free_memory_kib
xapi_live_memory_kib
xapi_memory_usage_kib
の説明。


MultiPath XenServer MPP-RDAC - IBM DS3512/24 - 1746
http://discussions.citrix.com/topic/352656-multipath-xenserver-mpp-rdac-ibm-ds351224-1746/

iSCSIで組む人は、MPP-RDACがおすすめらしいけど。使ったことない。
LSIのチップ積んだストレージなら可能とManualで読んだ記憶が。
また、MPP-RDACで使えば、XenMotionでPacket Loss無しにSeemlessにMigration可能だという話もどこかで見た記憶がある。

2014年5月30日金曜日

XenServer 6.2 で ftp コマンド を利用する方法

通常、ftpは過去の遺物なので使う機会が少ないのだが、
運用で全く使わないということではないのが現実。

XenServer6.2では、telnetとかtcpdumpとか基本的なツールが入っているが、ftp client だけない。
そこで、ftp をどうしても使いたい時のTIPS。

XenServer6.2 は CentOS 5.7 ベースなので、そのパッケージを利用すればいい。

[root@cw01 ~]# rpm -qif /etc/redhat-release
Name        : centos-release               Relocations: (not relocatable)
Version     : 5                                 Vendor: CentOS
Release     : 7.el5.centos                  Build Date: Mon 29 Aug 2011 08:00:09 PM JST

なお、XenServer6.2 は 32bit だよ。

[root@cw01 ~]# uname -a
Linux cw01 2.6.32.43-0.4.1.xs1.8.0.853.170791xen #1 SMP Mon Mar 3 06:36:39 EST 2014 i686 i686 i386 GNU/Linux

なので、まぁこんな感じで ftp client のRPMを取得すればいい。
ダウンロードは例としてMazのところの公開サーバを利用させてもらう
http://ftp.iij.ad.jp/pub/linux/centos/5.10/os/i386/CentOS/ftp-0.17-38.el5.i386.rpm

取得

[root@cw01 ~]# wget http://ftp.iij.ad.jp/pub/linux/centos/5.10/os/i386/CentOS/ftp-0.17-38.el5.i386.rpm
--2014-05-30 08:41:39--  http://ftp.iij.ad.jp/pub/linux/centos/5.10/os/i386/CentOS/ftp-0.17-38.el5.i386.rpm
Resolving ftp.iij.ad.jp... 202.232.140.170, 2001:240:bb8f:200::1:170
Connecting to ftp.iij.ad.jp|202.232.140.170|:80... connected.
HTTP request sent, awaiting response... 200 OK
Length: 56209 (55K) [application/x-rpm]
Saving to: `ftp-0.17-38.el5.i386.rpm'
100%[==========================================================>] 56,209      --.-K/s   in 0.04s
2014-05-30 08:41:39 (1.43 MB/s) - `ftp-0.17-38.el5.i386.rpm' saved [56209/56209]

インストール

[root@cw01 ~]# rpm -Uvh ftp-0.17-38.el5.i386.rpm
Preparing...                ########################################### [100%]
   1:ftp                    ########################################### [100%]

テスト

[root@cw01 ~]# ftp ftp.iij.ad.jp
Trying 202.232.140.170...
Connected to ftp.iij.ad.jp (202.232.140.170).
220 IIJ FTP server ready (IPv4 client).
Name (ftp.iij.ad.jp:root): anonymous
230 Login successful.
Remote system type is UNIX.
Using binary mode to transfer files.
ftp> quit
221 Goodbye.


なお、この方法で他のRPMの多少いけるが、
ftp client くらいの単純なRPMならいいけど、
それ以外は、ちゃんとDDKでコンパイルして適用することをお勧めする。


2014年5月21日水曜日

2014/05/21 のMEMO

NIC driver for Windows PE
http://discussions.citrix.com/topic/284196-nic-driver-for-windows-pe/
2011年3月から続くThread。
Clearwaterで認識させる基本的なStepや、下記のような強引にNICを認識させるPatchなどで紹介されている。
  qemu_args[i] = qemu_args[i].replace('rtl8139', 'e1000')


CA-99235: Keep trying to remove the tag forever
https://github.com/xapi-project/sm/commit/7ca2d42adc17cfde8ec7f37c07a24293741af274
In the error handling path of VDI.activate, if the connection with the
master is lost, the slave cannot remove the tag from sm-config. When the
connection is restored, the VDI is left in undefined state. To avoid
this we keep trying to remove the tag until we succeed (the connection
with the host has been restored).

これってClearwaterでも発生するんだよね、多分。

2014年5月20日火曜日

XenServer.next Alpha Available for Download

http://www.xenserver.org/discuss-virtualization/virtualization-blog/entry/xenserver-next-alpha-available-for-download.html

The XenServer engineering team is pleased to announce the availability an alpha of the next release of XenServer, code named “Creedence”. 


ちなみに、
Creedence versionってなに?っと検索すると、http://ja.wikipedia.org/wiki/%E3%82%AF%E3%83%AA%E3%83%BC%E3%83%87%E3%83%B3%E3%82%B9%E3%83%BB%E3%82%AF%E3%83%AA%E3%82%A2%E3%82%A6%E3%82%A9%E3%83%BC%E3%82%BF%E3%83%BC%E3%83%BB%E3%83%AA%E3%83%90%E3%82%A4%E3%83%90%E3%83%AB
そうきたかw。最適な名前ですね。
これは、完全に別のものだと思ってた。
絶対sarasotaだと思ってた。だってSourceに・・・
https://github.com/Zhengchai/xenadmin/blob/4100f506ca2b832ff0c207bbaaeca93a68b7e0af/XenAdminTests/XenModelTests/TestAPICallVersions.cs
って、このSource、2013年6月のものだった・・・orz
古かったのね。

Creedence Clearwater Revival (CCR)からますます目が離せないですねぇ。(意外とどっちでもよくなってる)

ちなみにVersionも、
XenServer 6.2.50 
と表示されてたんだよ。4月のBuildまでは。5月は見てない。
5/19以降のBuildでどう表示されるか試してみるか。


2014年5月16日金曜日

XenServer6.2) VIFのLocking-modeで遊んでみた

VIFのLocking-modeで遊んでみた。

VIFのlocking-modeに関してはマニュアルに書いてある通り。
端的にいうと、VIF側で利用できるIPアドレスを制限しちゃおうという機能。

試験環境

Dom0:XS62SP1(patch:-5)
PM:CentOS6.4からVM:CentOSのApache上の1MBファイルをabで取得する。

VIF状態
[root@txs01 ~]# xe vif-param-list uuid=61694e93-42d6-465e-3fc0-2f214b973884
uuid ( RO)                        : 61694e93-42d6-465e-3fc0-2f214b973884
                     vm-uuid ( RO): 7aa322f7-b272-c936-f4e4-55b522c7eec1
               vm-name-label ( RO): CentOS-130-Apache
          allowed-operations (SRO): attach; unplug
          current-operations (SRO):
                      device ( RO): 1
                         MAC ( RO): 06:06:3e:45:cb:70
           MAC-autogenerated ( RO): true
                         MTU ( RO): 1500
          currently-attached ( RO): true
          qos_algorithm_type ( RW):
        qos_algorithm_params (MRW): kbps: 1000
    qos_supported_algorithms (SRO):
                other-config (MRW):
                network-uuid ( RO): 1deba6e0-7167-8287-b428-0f142baa8a85
          network-name-label ( RO): VLAN901
                 io_read_kbs ( RO): 0.000
                io_write_kbs ( RO): 0.000
                locking-mode ( RW): network_default
                ipv4-allowed (SRW):
                ipv6-allowed (SRW):
abの結果(設定前)
Server Software:        Apache/2.2.3
Server Hostname:        10.0.1.130
Server Port:            80
Document Path:          /index.html
Document Length:        1024000 bytes
Concurrency Level:      100
Time taken for tests:   8.759 seconds
Complete requests:      1000
Failed requests:        0
Write errors:           0
Total transferred:      1026769248 bytes
HTML transferred:       1026498438 bytes
Requests per second:    114.16 [#/sec] (mean)
Time per request:       875.935 [ms] (mean)
Time per request:       8.759 [ms] (mean, across all concurrent requests)
Transfer rate:          114472.43 [Kbytes/sec] received
<SNAP>
Total transferred:      1026800112 bytes
HTML transferred:       1026529302 bytes
Requests per second:    113.86 [#/sec] (mean)
Time per request:       878.284 [ms] (mean)
Time per request:       8.783 [ms] (mean, across all concurrent requests)
Transfer rate:          114169.77 [Kbytes/sec] received
<SNAP>
Total transferred:      1024270000 bytes
HTML transferred:       1024000000 bytes
Requests per second:    114.43 [#/sec] (mean)
Time per request:       873.907 [ms] (mean)
Time per request:       8.739 [ms] (mean, across all concurrent requests)
Transfer rate:          114458.81 [Kbytes/sec] received

DEVTYPE=bridge: Rx=0.948 Gbit/s, Tx=0.006 Gbit/s
|- netback/0: Rx=0.000 Gbit/s, Tx=0.000 Gbit/s
|  |- vif3.0: Rx=0.000 Gbit/s, Tx=0.000 Gbit/s
|- netback/1: Rx=0.000 Gbit/s, Tx=0.000 Gbit/s
|  |- vif3.1: Rx=0.000 Gbit/s, Tx=0.000 Gbit/s
|- netback/2: Rx=0.000 Gbit/s, Tx=0.000 Gbit/s
|  |- vif12.0: Rx=0.000 Gbit/s, Tx=0.000 Gbit/s
|- netback/3: Rx=0.948 Gbit/s, Tx=0.006 Gbit/s
|  |- vif12.1: Rx=0.948 Gbit/s, Tx=0.006 Gbit/s
DEVTYPE=bridge: Rx=0.949 Gbit/s, Tx=0.006 Gbit/s
|- netback/0: Rx=0.000 Gbit/s, Tx=0.000 Gbit/s
|  |- vif3.0: Rx=0.000 Gbit/s, Tx=0.000 Gbit/s
|- netback/1: Rx=0.000 Gbit/s, Tx=0.000 Gbit/s
|  |- vif3.1: Rx=0.000 Gbit/s, Tx=0.000 Gbit/s
|- netback/2: Rx=0.000 Gbit/s, Tx=0.000 Gbit/s
|  |- vif12.0: Rx=0.000 Gbit/s, Tx=0.000 Gbit/s
|- netback/3: Rx=0.949 Gbit/s, Tx=0.006 Gbit/s
|  |- vif12.1: Rx=0.949 Gbit/s, Tx=0.006 Gbit/s
DEVTYPE=bridge: Rx=0.947 Gbit/s, Tx=0.006 Gbit/s
|- netback/0: Rx=0.000 Gbit/s, Tx=0.000 Gbit/s
|  |- vif3.0: Rx=0.000 Gbit/s, Tx=0.000 Gbit/s
|- netback/1: Rx=0.000 Gbit/s, Tx=0.000 Gbit/s
|  |- vif3.1: Rx=0.000 Gbit/s, Tx=0.000 Gbit/s
|- netback/2: Rx=0.000 Gbit/s, Tx=0.000 Gbit/s
|  |- vif12.0: Rx=0.000 Gbit/s, Tx=0.000 Gbit/s
|- netback/3: Rx=0.947 Gbit/s, Tx=0.006 Gbit/s
|  |- vif12.1: Rx=0.947 Gbit/s, Tx=0.006 Gbit/s

1GbpsNIC環境ならこんなもんですね。

設定変更

まず、ipvX-allowedを指定せずに locking-mode を locked に変更
[root@xs01 ~]# xe vif-param-set uuid=61694e93-42d6-465e-3fc0-2f214b973884 locking-mode=locked
[root@xs01 ~]# xe vif-param-list uuid=61694e93-42d6-465e-3fc0-2f214b973884
uuid ( RO)                        : 61694e93-42d6-465e-3fc0-2f214b973884
                     vm-uuid ( RO): 7aa322f7-b272-c936-f4e4-55b522c7eec1
               vm-name-label ( RO): CentOS
          allowed-operations (SRO): attach; unplug
          current-operations (SRO):
                      device ( RO): 1
                         MAC ( RO): 06:06:3e:45:cb:70
           MAC-autogenerated ( RO): true
                         MTU ( RO): 1500
          currently-attached ( RO): true
          qos_algorithm_type ( RW):
        qos_algorithm_params (MRW): kbps: 1000
    qos_supported_algorithms (SRO):
                other-config (MRW):
                network-uuid ( RO): 1deba6e0-7167-8287-b428-0f142baa8a85
          network-name-label ( RO): VLAN01
                 io_read_kbs ( RO): 0.000
                io_write_kbs ( RO): 0.000
                locking-mode ( RW): locked
                ipv4-allowed (SRW):
                ipv6-allowed (SRW):

外部(PM)からPINGが飛ばなくなった。
次に、IPを設定してやる。

[root@xs01 ~]# xe vif-param-set uuid=61694e93-42d6-465e-3fc0-2f214b973884 ipv4-allowed=10.0.1.130 ipv6-allowed=fe80::406:3eff:fe45:cb70
[root@xs01 ~]# xe vif-param-list uuid=61694e93-42d6-465e-3fc0-2f214b973884
uuid ( RO)                        : 61694e93-42d6-465e-3fc0-2f214b973884
                     vm-uuid ( RO): 7aa322f7-b272-c936-f4e4-55b522c7eec1
               vm-name-label ( RO): CentOS
          allowed-operations (SRO): attach; unplug
          current-operations (SRO):
                      device ( RO): 1
                         MAC ( RO): 06:06:3e:45:cb:70
           MAC-autogenerated ( RO): true
                         MTU ( RO): 1500
          currently-attached ( RO): true
          qos_algorithm_type ( RW):
        qos_algorithm_params (MRW): kbps: 1000
    qos_supported_algorithms (SRO):
                other-config (MRW):
                network-uuid ( RO): 1deba6e0-7167-8287-b428-0f142baa8a85
          network-name-label ( RO): VLAN01
                 io_read_kbs ( RO): 0.084
                io_write_kbs ( RO): 0.056
                locking-mode ( RW): locked
                ipv4-allowed (SRW): 10.0.1.130
                ipv6-allowed (SRW): fe80::406:3eff:fe45:cb70

PINGが飛ぶようになった。

レスポンスは

DEVTYPE=bridge: Rx=0.947 Gbit/s, Tx=0.006 Gbit/s
|- netback/0: Rx=0.000 Gbit/s, Tx=0.000 Gbit/s
|  |- vif3.0: Rx=0.000 Gbit/s, Tx=0.000 Gbit/s
|- netback/1: Rx=0.000 Gbit/s, Tx=0.000 Gbit/s
|  |- vif3.1: Rx=0.000 Gbit/s, Tx=0.000 Gbit/s
|- netback/2: Rx=0.000 Gbit/s, Tx=0.000 Gbit/s
|  |- vif16.0: Rx=0.000 Gbit/s, Tx=0.000 Gbit/s
|- netback/3: Rx=0.947 Gbit/s, Tx=0.006 Gbit/s
|  |- vif16.1: Rx=0.947 Gbit/s, Tx=0.006 Gbit/s
DEVTYPE=bridge: Rx=0.947 Gbit/s, Tx=0.006 Gbit/s
|- netback/0: Rx=0.000 Gbit/s, Tx=0.000 Gbit/s
|  |- vif3.0: Rx=0.000 Gbit/s, Tx=0.000 Gbit/s
|- netback/1: Rx=0.000 Gbit/s, Tx=0.000 Gbit/s
|  |- vif3.1: Rx=0.000 Gbit/s, Tx=0.000 Gbit/s
|- netback/2: Rx=0.000 Gbit/s, Tx=0.000 Gbit/s
|  |- vif16.0: Rx=0.000 Gbit/s, Tx=0.000 Gbit/s
|- netback/3: Rx=0.947 Gbit/s, Tx=0.006 Gbit/s
|  |- vif16.1: Rx=0.947 Gbit/s, Tx=0.006 Gbit/s

Total transferred:      1026134032 bytes
HTML transferred:       1025863492 bytes
Requests per second:    114.22 [#/sec] (mean)
Time per request:       875.518 [ms] (mean)
Time per request:       8.755 [ms] (mean, across all concurrent requests)
Transfer rate:          114456.18 [Kbytes/sec] received

locking-modeを利用しても、1GbpsNICの環境では特に劣化は見られなかった。

なお、複数IPを許可したい場合には、単純に複数記述してやればよい。
参考)
vif-param-add
http://discussions.citrix.com/topic/351462-vif-param-add/

2014年5月15日木曜日

XenServer6.2 ) interface-rename COMMAND

How to Change Order of NICs in XenServer 6.x

http://support.citrix.com/article/CTX135809


interface-renameってコマンドを使ってみた。

[root@xs01 ~]# interface-rename --help
usage: interface-rename --rename|--list|--update <args>|--reset-to-install [-v] [-d]
Utility for managing the naming of physical network interfaces.  It is used to
undo the damage of race condition for device drivers grabbing eth names on
boot, taking into account naming policies provided at install time.  In
addition, it implements sensible policies when network hardware changes, and
the ability for manual alteration of the policies after install.
options:
  --version             show program's version number and exit
  -h, --help            show this help message and exit
  -v, --verbose         increase logging
  -d, --dry-run         dry run - don't write any state back to disk
  Actions:
    Exactly one action is expected
    -r, --rename        rename physical interfaces.  It is not safe to rename
                        interfaces which have traffic passing, or higher level
                        networking constructs on them (bonds/bridges/etc).
                        Use at your own risk after boot
    -l, --list          list current physical device information in a concise
                        manner as a reference for --update
    -u, --update        manually update the order of devices.  <args> should
                        be one or more <target eth name>=MAC|PCI|Phys|"SMBios"
    --reset-to-install  reset configuration to install state

renameとupdateはCLIから利用することはないだろうね・・・
listはNICのドライバ一覧を取得するのに便利だね。

[root@xs01 ~]# interface-rename --list
ERROR    [2014-05-13 19:17:46] Can't generate current state for interface '{'Driver': '802.1Q VLAN Support', 'Bus Info': '', 'BIOS device': {'all_ethN': 'eth6', 'physical': ''}, 'Assigned MAC': '00:1B:21:79:BB:9B', 'Firmware version': 'N/A', 'Driver version': '1.8', 'Kernel name': 'bond1.901'}' - Unrecognised PCI address ''
ERROR    [2014-05-13 19:17:46] Can't generate current state for interface '{'Driver': '802.1Q VLAN Support', 'Bus Info': '', 'BIOS device': {'all_ethN': 'eth7', 'physical': ''}, 'Assigned MAC': '00:1B:21:79:BB:9B', 'Firmware version': 'N/A', 'Driver version': '1.8', 'Kernel name': 'bond1.902'}' - Unrecognised PCI address ''
ERROR    [2014-05-13 19:17:46] Can't generate current state for interface '{'Driver': '802.1Q VLAN Support', 'Bus Info': '', 'BIOS device': {'all_ethN': 'eth8', 'physical': ''}, 'Assigned MAC': '00:1B:21:79:BB:9B', 'Firmware version': 'N/A', 'Driver version': '1.8', 'Kernel name': 'bond1.903'}' - Unrecognised PCI address ''
Name  MAC                PCI           ethN  Phys  SMBios  Driver  Version     Firmware
eth0  00:26:2d:08:12:78  0000:01:00.0  eth0  em1           igb     4.1.2       2.5, 0xf1300000
eth1  00:26:2d:08:12:79  0000:01:00.1  eth1  em2           igb     4.1.2       2.5, 0xf1300000
eth2  00:1b:21:79:bb:9a  0000:03:00.0  eth2  p2p1          e1000e  2.3.2-NAPI  5.11-2
eth3  00:1b:21:79:bb:9b  0000:03:00.1  eth3  p2p2          e1000e  2.3.2-NAPI  5.11-2
eth4  00:1b:21:79:ba:94  0000:04:00.0  eth4  p1p1          e1000e  2.3.2-NAPI  5.11-2
eth5  00:1b:21:79:ba:95  0000:04:00.1  eth5  p1p2          e1000e  2.3.2-NAPI  5.11-2


インストール時の状態にリセットも可能っぽい(今回は、Dry-Run)
[root@xs01 ~]# interface-rename --dry-run --reset-to-install
INFO     [2014-05-13 19:20:31] Dry Run - logging to stdout instead of '/var/log/interface-rename.log'
INFO     [2014-05-13 19:20:31] Would copy '/etc/sysconfig/network-scripts/interface-rename-data/.from_install/static-rules.conf' to '/etc/sysconfig/network-scripts/interface-rename-data/static-rules.conf' if not dry run
INFO     [2014-05-13 19:20:31] Would copy '/etc/sysconfig/network-scripts/interface-rename-data/.from_install/dynamic-rules.json' to '/etc/sysconfig/network-scripts/interface-rename-data/dynamic-rules.json' if not dry run
INFO     [2014-05-13 19:20:31] Would write:
# Automatically generated file from /etc/sysconfig/network-scripts/interface-rename.py
ACTION!="add" GOTO="network-done"
# Rules generated from static configuration and last boot data

# Rename unrecognised devices sideways to deal with them later
SUBSYSTEM=="net" KERNEL=="eth*" PROGRAM="/etc/udev/scripts/net-rename-sideways.sh %k" NAME="%c"
LABEL="network-done"
to '/etc/udev/rules.d/60-net.rules' if not dry run
INFO     [2014-05-13 19:20:31] All Done

こんなところにInstall時の設定が退避されるんだね。
見てみよう
[root@xs01 ~]# cd /etc/sysconfig/network-scripts/interface-rename-data/.from_install/
[root@xs01 .from_install]# ls
dynamic-rules.json  static-rules.conf
JSONだって。
MACとPCI BUSとETHで構成されるだけだった。
なお、ファイルの見方は static-rules.confに書いてある。
[root@xs01 .from_install]# more dynamic-rules.json
# Automatically adjusted file.  Do not edit unless you are certain you know how to
{
    "lastboot": [
        [
            "00:1B:21:79:BB:9B",
            "0000:03:00.1",
            "eth3"
        ],
        [
            "00:1B:21:79:BA:95",
            "0000:04:00.1",
            "eth5"
        ],
        [
            "00:26:2D:08:12:78",
            "0000:01:00.0",
            "eth0"
        ],
        [
            "00:1B:21:79:BA:94",
            "0000:04:00.0",
            "eth4"
        ],
        [
            "00:26:2D:08:12:79",
            "0000:01:00.1",
            "eth1"
        ],
        [
            "00:1B:21:79:BB:9A",
            "0000:03:00.0",
            "eth2"
        ]
    ],
    "old": []
}
listくらいしか用途を見いだせなかった。