Answer the question
In order to leave comments, you need to log in
What is the correct way to set up networking for libvirt to avoid unicast-flood?
Hello!
My colleagues asked a similar question toster.ru/q/173735, but they wanted to solve it using active network equipment, but as it turns out, from this side, you can only reduce the amount of mac address-table aging-time, which will lead to an increase in the amount of ARP traffic, which can also bring problems and in general this parameter does not solve the problem.
Question for libvirt specialists and its settings for KVM virtualization. We have several subnets of white addresses and several servers for virtualization combined into VLANs, each VDS is given the same address as done in Digital Ocean, on servers there are approximately 200 VDS. Here, at the moments when one of the physical servers is restarted, the network port twitches and the traffic that was intended for the virtual machines of this physical server immediately starts going to all physical servers in this VLAN, and multiplies to all virtual servers, that is, the same traffic goes in each VDS , the load at such moments becomes colossal because each VDS takes on this "left" traffic. This also happens when there is a DDoS on some VDS, the user turns off the server, the IP becomes unavailable and the traffic spreads to all VDS within the server.
Who faced similar? Perhaps there are some options with https://libvirt.org/formatnwfilter.html to prevent traffic from multiplying to all VDS?
Thank you!
Answer the question
In order to leave comments, you need to log in
Didn't find what you were looking for?
Ask your questionAsk a Question
731 491 924 answers to any question