|
|
|
|
|
|
|
|
|
|
xen-users
Re: [Xen-users] DomU Bridged vs. Routed Networking?
Ian Pratt wrote:
Seems like most users opt for the bridged approach. Perhaps it's
because it is easier to setup and it is the default setting. For
route, I spent several days to learn that
/proc/sys/net/ipv4/conf/eth0/proxy_arp needs to be set to 0. It is
not (Debian Sarge). It should probably be added to
/etc/xen/scripts/network-route.
I also modified scripts/vif-route (using iptables) to forward only
packets belonging to each domU's IP address, thereby
preventing domU's
from using IP addresses not assigned to them.
Please can you post diffs and we'll update the example scripts.
There are network-nat and vif-nat scripts, but they need
a little tweaking. Would be good to merge Andy's changes.
With bridge, I'd need
to install etables - one extra program to install and learn.
That's not actually true -- you can use iptables to do packet filtering
in bridge mode. You only need ebtables if you want to do matches on MAC
addrs.
There is one other factor which some people have noticed and
pointed out on this list: the interface is in promiscuous
mode in the bridging scenario, which deteriorates performance.
Your mileage may vary.
All modern Ethernet networks are switched rather than shared media.
Putting the interface in promiscous mode will make NO difference to
performance unless you have lots of *multicast* traffic on your network
that this host isn't interested in.
Yep, mostly multicast traffic, since that's the only additional bucket
(unless you turn off icmp broadcast echo replies when not promiscuous)
but I measured this earlier this morning with a tcp netperf stream
and it was about 4% difference. Admittedly, today was an exception,
the network was getting hammered due to a misconfigured router,
congestion on the net due to the worm and some heavy multicast
traffic. I didn't see this till now but it was logging a bunch
of those, which exacerbated the load on the system.
thanks,
Nivedita
_______________________________________________
Xen-users mailing list
Xen-users@xxxxxxxxxxxxxxxxxxx
http://lists.xensource.com/xen-users
|
|
|
|
|