![]() | Oracle System Handbook - ISO 7.0 May 2018 Internal/Partner Edition | ||
|
|
![]() |
||||||||||||||||||||||||||
Solution Type Troubleshooting Sure Solution 1395461.1 : Sun Storage 7000 Unified Storage System: Best Practice Recommendations for Network Configuration
In this Document
Applies to:Sun Storage 7210 Unified Storage System - Version All Versions and laterOracle ZFS Storage ZS3-4 - Version All Versions and later Oracle ZFS Storage ZS4-4 - Version All Versions and later Oracle ZFS Storage ZS3-BA - Version All Versions and later Sun Storage 7410 Unified Storage System - Version All Versions and later 7000 Appliance OS (Fishworks) PurposeThis document will explain the best practice recommendations for setting up various network related configurations on the Sun Storage 7000 Unified Storage System. To discuss this information further with Oracle experts and industry peers, we encourage you to review, join or start a discussion in the My Oracle Support Community - Disk Storage ZFS Storage Appliance Community
Troubleshooting StepsThe appliance uses a 4 layer model for network configuration.
Datalink layerLink Aggregation or LACP is used primarily as a means of increasing performance (example configuration). It works by associating two or more devices with a single datalink to increase the throughput available to that datalink. It can be seen then that for Link Aggregation to work correctly the devices that are to be used in the aggregation must be cabled to the same switch before attempting to configure the datalink. As of 2013.1 code, VNICs can be used similarly to VLANs to create multiple interfaces on the same physical datalink/device. Interface LayerIPMP is used primarily as a way of increasing redundancy so that network connectivity is unaffected by the failure of a single component be it a physical network port, a cable or a switch. To provide this redundancy, an IPMP group is created where the IPMP interface sits above two or more interfaces that are associated with datalinks. For the maximum redundancy the lower level interfaces associated with datalinks must have those datalinks associated with devices connected physically to different switches so that if one switch fails, other datalinks are still active.
The best practice recommendation is to use link-based failure detection on the appliance. This removes the dependence on other networking components external to the appliance to provide a stable network interface. To enable link-based failure detection you need to make sure that the test interfaces in an IPMP group do not have a traditional IP addresses configured. Instead they should be configured with the address and netmask of 0.0.0.0/8. Only the IPMP interface itself should be configured with a valid IP address and netmask for the appropriate subnet. RoutingIf routing is administered manually and RIP and RIPng routing protocols are not allowed to automatically configure dynamic routes, then follow these best practices:
This will ensure that requests made by clients on the data networks are not routed back through the admin interface. The interfaces and datalinks that connect to the client data networks should use the higher throughput devices if any are installed. e.g. the 10 Gbps Ethernet devices rather than the 1 Gbps onboard devices. These onboard devices can be used for the admin interface as this will not require a high throughput.
ServicesPLEASE NOTE: For all appliances running 2013.1.x releases, 'DNS-less' operation is NOT supported and could cause undesirable results.
The Appliance DNS service must be configured with a working DNS server which contains the appropriate A and PTR records for all names and IP addresses used by the appliance. DNS - The appliance works best when the DNS service is correctly configured and able to resolve all hostnames and client IP addresses successfully. Although it is possible to specify the loopback IP address of 127.0.0.1 during initial configuration for DNS servers this is not recommended in a production environment, and is only suitable for testing purposes. The appliance will not be able to resolve hostnames of itself or other servers in this situation and critical services may not work. This is especially true if Active Directory is used as a directory service. In this case at least one of the DNS servers must be able to resolve hostname and server records in the Active Directory portion of the domain namespace. The DNS server(s) should contain both forward and reverse lookup entries for the appliance. Please ensure that at least one of your configured DNS servers is a physical machine that does NOT reside on the ZFSSA ( as a VM )." NTP - It is recommended that NTP be used to synchronize the time on the appliance and on any other severs that may be required to provide client access to shares. For example if Active Directory is used to authenticate users of an SMB share then the time on the Active Directory Server and the appliance must agree. NTP is the best way to achieve this. In order to have NTP synchronize the times there must be less than 5 minutes difference between the time on the appliance and the time provided by the NTP server when NTP is configured. Dynrouting - It is recommended that dynrouting be disabled unless the production network is specifically using RIP to dynamically advertise routes. Clustering ConsiderationsWhen configuring a cluster, it is recommended that each cluster head have it's own dedicated admin interface that is private and locked out of the cluster resources that will not move during takeover and failback operations. The reason for this is so that each head will always have access to DNS and still be accessible via the BUI when the head is stripped (passive). This will enable faster troubleshooting to find the root cause of unexpected takeovers or reboots. It will also allow a support bundle to be collected from a cluster head in a stripped state. Usually two of the built-in interfaces are used for management, e.g. nge0 on headA and nge1 on headB, which will make nge0 unusable on headB and nge1 unusable on headA. If the system is running at least 2013.1 code, management can be done via VNICs which are both in the same physical NIC, such as ixgbe0, thus only using a single physical network port for management. Back to Document 1392086.1 (Sun Storage 7000 Unified Storage System: How to Troubleshoot Network Problems).
Oracle ZFS Storage Appliance services and associated IP port numbers If a firewall is present between the clients and the Oracle ZFS Storage Appliance, make
Check for relevancy - 11-May-2018 Referenceshttp://www.oracle.com/technetwork/server-storage/sun-unified-storage/documentation/networking-bestprac-zfssa-2215767.pdf<NOTE:1396100.1> - Sun Storage 7000 Unified Storage System: Causes and Solutions for Well Known General Networking Problems <NOTE:1542826.2> - Information Center: Disk Storage <NOTE:1400154.1> - Sun Storage 7000 Unified Storage System: An Example of How to Configure Link Aggregation on a Switch <NOTE:1392086.1> - Sun Storage 7000 Unified Storage System: How to Troubleshoot Network Problems Attachments This solution has no attachment |
||||||||||||||||||||||||||
|