Sangfor HCI and aSV provide a unified infrastructure combining compute, storage, networking, and built-in security to simplify deployment, operations, and services.
It is recommended to make dual switch link aggregation and adopt a 2 * 10GE interface.
1. Must use the 10 Gigabit interface to build the storage private network.
2. Linkless aggregation is prohibited.
Management network
It is recommended to stack and deploy, use 2 * Ge interfaces for aggregation, and use the IP address for a load. The corresponding interface of the switch needs to be configured with static interface aggregation. The networking switch of the cluster management interface and Overlay Network Interface needs to support multicast function. Otherwise, the cluster cannot be established.
IGMP snooping is prohibited.
Service network
It is recommended to stack and deploy, use 2 * Ge interfaces for aggregation, and use the IP address for a load. Static interface aggregation needs to be configured for the corresponding interface of the switch.
-
VXLAN network
It is recommended that the 2 * Ge network interface be aggregated, loaded in the IP address mode, and turned on the high-performance mode. The connected switch needs to turn on the jumbo frame, which is set to more than 1600 (the Xinrui switch is set to 2000). At the same time, the corresponding interface of the switch needs to be configured with static network interface aggregation. (it is allowed to reuse the VXLAN and service network when the equipment network interface is insufficient).
1. A high-performance mode must be enabled for the VXLAN network settings of the HCI platform.
2. IGMP snooping is prohibited.
Switch
The STP function must be turned off at the networking port on the switch. Except for the storage switch, other switches adopt stacked deployment.
Single switch deployment without redundancy is prohibited.
IP address planning
It is recommended that the management network segment, VXLAN network segment, and service network segment be divided into different network segments to avoid IP address conflict.
-
Network cable specification
1. It is recommended to use multimode optical fiber within 50m and single-mode optical fiber over 50m.
2. It is recommended to use category 5 and above twisted pair.
1. It is forbidden to connect a single-mode optical fiber to the multi-mode module.
2. It is forbidden to connect a multimode optical fiber to the single-mode module.
3. Class 1 to 4 twisted pair is prohibited.
Dual active networking
1. The bandwidth between the witness node and the active and secondary fault domain is recommended to be more than 100Mbps, and the delay is < = 1ms (fluctuation within 5ms is allowed).
2. The primary fault domain and the secondary fault domain of the stretched cluster volume must be connected with 10 Gigabit bare optical fiber, with a delay of < = 1ms.
-
Table 1:Precautions for HCI platform installation networking
The networking switch of the Overlay Network Interface shall confirm whether it supports the jumbo frame. If yes, it is recommended to turn on the high-performance mode of the Overlay Network Interface and change the MTU of the VXLAN port to 1600. If it is not supported, it is forbidden to turn on the high-performance mode of the Overlay Network Interface. Otherwise, the data of the virtual machine will be blocked.
The connectivity detection of Health Check is only Ping detection. Even if multicast fails, the detection result is normal as long as Ping is enabled.
The four communication interface types (management communication port, VXLAN Overlay Network Interface, VS Storage interface, and physical interface) are not allowed to be multiplexed. However, in the case of an insufficient network interface, and you have to reuse the network interface, please reuse the physical interface and VXLAN interface. It is suggested that the network interface should be planned as two management interfaces, two storage interfaces, and two aggregation interfaces for VXLAN and physical export reuse.
Do not hot-plug the NIC, whether a third-party server or an HCI aServer. Otherwise, the network interface may be out of order.