Professional Documents
Culture Documents
01-02 Vs Configuration
01-02 Vs Configuration
2 VS Configuration
Virtual systems (VSs) are managed by administrators that are granted with corresponding
authority. A physical system (PS) administrator can manage all VSs which belong to the PS; a
VS administrator can perform operations only on the managed VS, including starting and
stopping the allocated services.
Background
As the demand on various types of network services is growing, network management
becomes more complex. Requirements for service isolation, system security, and reliability
are steadily increasing. The virtual private network (VPN) technique can be used to isolate
services on a PS. If a module failure occurs on the PS, all services configured on the PS will
be interrupted.
To prevent service interruptions, the VS technique is used to partition a PS into several VSs.
Each VS functions as an independent network element and uses separate physical resources to
isolate services.
Further development of the distributed routing and switching systems allows VS technique to
fully utilize the service processing capability of a single PS. The VS technique helps simplify
network deployment and management, and strengthen system security and reliability.
The PS administrator has the authority to manage all VSs. The VS administrator has the authority to
query VSs but cannot manage them.
Basic Concepts
Figure 2-2 shows VS concepts.
PS Physical system
Concept Description
If the memory of the master If the memory of the master VS configurations may be
main control board is main control board is lost.
inconsistent with that of the inconsistent with that of the
slave main control board, a slave main control board,
master/slave main control increase the memory of the
board switchover or device master or slave main control
restart occurs, which may board to achieve memory
cause VS configurations to consistency.
be lost.
Multicast NAT does not Plan services properly. Multicast NAT does not
support multiple VSs. support multiple VSs.
When an interface and its Deploy an interface and its If an interface and its sub-
sub-interfaces are deployed sub-interfaces in the same interfaces are deployed in
in different VSs, ESI route VS. different VSs and an ESI is
negotiation is not supported. configured on the interface,
the sub-interfaces fail to
forward packets.
Different names and IDs Configure different names NAT instances, service-
must be configured for NAT and IDs for NAT instances, locations, service instance
instances, service-locations, service-locations, service groups on different Vses
service instance groups on instance groups on different cannot have the same name
different VSes. VSes. or ID.
Different names and IDs Configure different names DS-Lite instances, NAT64
must be configured for DS- and IDs for DS-Lite instances, service-locations,
Lite instances, NAT64 instances, NAT64 instances, service instance groups on
instances, service-locations, service-locations, service different Vses cannot have
service instance groups on instance groups on different the same name or ID.
different VSes. VSes.
After a device is upgraded Before the upgrade, save the The configuration
from the unified VS mode to configuration file of a non- information of the non-
the independent VS mode Admin-VS VS. After the Admin VS is lost.
with existing configurations, upgrade, save the
data in all VSs except configuration file to the non-
Admin-VS is lost. Admin VS directory for
configuration restoration.
The function of filtering Configure the whitelist Hardware does not support
DHCP packets based on the function only in Admin-VS. this feature.
whitelist does not support
multiple VSs.
Usage Scenario
To fully utilize hardware resources and share board resources, a PS can be divided into
multiple VSs. Each VS can bear a new type of service independently.
Pre-configuration Tasks
Before configuring VSs, complete the following tasks:
l Install the PS and power it on properly.
l Ensure that the PS administrator has the authority to create VSs.
2.3.1 Creating a VS
A Physical System (PS) administrator can create Virtual Systems (VSs) on the PS, but cannot
create, or delete the Admin-VS. The Admin-VS is the default VS on a PS and manages the
entire PS. The Admin-VS is automatically created when a PS is being started. All the
unassigned resources on a PS belong to the Admin-VS by default. A VS is started as soon as
it is created.
Procedure
Step 1 Run system-view
You cannot delete the port mode that has been configured for a VS.
The network administrator can configure a description for the VS to describe the service type
or usage.
In the VS creation process, the NetStream function becomes unavailable in two minutes.
----End
Context
The Admin-VS is the default VS in a PS and manages the PS. All unallocated resources in the
PS belong to the Admin-VS by default.
The Admin-VS has all board and interface resources of a PS, and the board and interface
resources of the Admin-VS cannot be added to or deleted.
Only in the virtual cluster scenario, hardware resources can be configured for the VS.
Procedure
Step 1 Run system-view
You cannot delete the port mode that has been configured for a VS.
You can run this command to change the default CPU weight value.
In the VS creation process, the NetStream function becomes unavailable in two minutes.
----End
Context
PS administrator can assign a logical resource to a VS each time, or use a resource template to
assign multiple logical resources to a VS in a batch.
Procedure
l Assign a logical resource to a VS each time.
a. Run system-view
The system view is displayed.
b. Run admin
The admin view is displayed.
c. Run virtual-system vs-name
A VS is created and started.
d. Run port-mode port [ resource-template template-name ]
A port mode is configured for the VS.
You cannot delete the port mode that has been configured for a VS.
e. In virtual system view, run resource { m4route | m6route | u4route | u6route |
vpn-instance } upper-limit resource-limit
Logical resources are assigned to the VS.
f. Run commit
The configuration is committed.
l Assign multiple logical resources to a VS in a batch.
a. Run system-view
The system view is displayed.
b. Run admin
The admin view is displayed.
c. Run virtual-system vs-name
You cannot delete the port mode that has been configured for a VS.
e. Run resource-template template-name
A resources template is created.
f. In resource template view, run resource { m4route | m6route | u4route | u6route |
vpn-instance } upper-limit resource-limit
Resource items are added to the resource template.
g. Run assign resource-template template-name
The resource template is assigned to the VS.
h. Run commit
The configuration is committed.
----End
Context
Procedure
l Run switch virtual-system vs-name
The administrator is switched to a target VS.
The VS name is displayed in the Name field in the display virtual-system command
output.
----End
Prerequisites
All VS configurations are complete.
Procedure
l Run the display virtual-system [ name vs-name ] [ verbose ] command to check basic
VS information.
l Run the display virtual-system [ name vs-name ] resource command to check resource
information about a specified VS or all VSs of a PS.
----End
2.4.1 Resetting a VS
When updating VS configurations or diagnosing faults, you can reset the VS.
Context
When a VS is being reset, all interfaces of the VS switch to the Down state, and all services are interrupted.
Exercise caution when running reset command. For details on precautions of this command, see reset
virtual-system.
This configuration process is supported only on the Admin-VS.
Procedure
l Run the reset virtual-system to reset a VS.
----End
Networking Requirements
On the network shown in Figure 2-3, the main control board of a PS processes all services
offered by an SP. If a service failure on the PS causes a PS failure, other services running on
the PS cannot be properly forwarded. To prevent this problem, configure different VSs on the
PS to independently carry services to improve network security.
As shown in Figure 2-3, different VSs can be created on a PS. The VSs carry their own
services that are mutually isolated. Services can be quickly differentiated by VS, and physical
interfaces can be shared between the VSs, saving physical links and reducing networking
costs.
Precautions
When creating VSs, note the following points:
l A VS starts after it is created.
l The VS slot resources can be allocated only by the PS administrator.
l The same slot resources can be allocated to multiple VSs.
l An interface can be allocated only to a single VS.
l The slot resources deleted from a VS are automatically allocated to the Admin-VS, and
the Admin-VS takes over services carried using these slot resources.
Configuration Roadmap
The configuration roadmap is as follows:
1. Create VSs and configure PVMBs for each VS so that the VSs can start.
2. Allocate interfaces to VSs to allow the VSs to forward services.
Data Preparation
To complete the configuration, you need the following data:
l Names of the VSs to be created: vs1, vs2, and vs3
l Interface number allocated to each VS
Procedure
Step 1 Create and start VSs.
<HUAWEI> system-view
[~HUAWEI] admin
[~HUAWEI-admin] virtual-system vs1
[*HUAWEI-admin-vs:vs1] port-mode port
Run the display virtual-system [ name vs-name ] [ verbose ] command on the PS. The
following example uses vs1 configurations.
[~HUAWEI-admin] display virtual-system name vs1 verbose
Name : vs1
Status : running
Description :
Create time : 2017-03-13 21:24:27+09:30 DST
Port mode : port
System MAC : 00-e0-fc-12-34-56
Assigned slot(s)
pvmb : 6
pvmb : 7
CPU(s)
slot 6 : 4%
slot 7 : 4%
fcard:/VS_huawei: 0%, 16/41943040 (Used Kbytes/Max Kbytes)
Assigned interface(s)
GE3/0/0, slot 3
Assigned resource(s)
u4route : 10000(Max)
m4route : 1000(Max)
u6route : 1000(Max)
m6route : 1000(Max)
vpn-instance : 256(Max)
cpu : 5(weight)
Run the display virtual-system configuration state command on the PS to check whether
VS configurations have been saved.
[~HUAWEI-admin] display virtual-system configuration state
-----------------------------------------------------------------
Name Saved-configuration
-----------------------------------------------------------------
Admin-VS not saved
vs1 not saved
vs2 not saved
vs3 not saved
-----------------------------------------------------------------
----End
Configuration Files
PS configuration files
#
admin
virtual-system vs1
assign interface GigabitEthernet3/0/2
virtual-system vs2
assign interface GigabitEthernet3/0/3
virtual-system vs3
assign interface GigabitEthernet3/0/4