Pages

Showing posts with label ovs. Show all posts
Showing posts with label ovs. Show all posts

Tuesday, March 31, 2015

Open vSwitch flows for L2 Switching

All the SDN controllers have pre-written code for L2 switching. However, for this you need to connect the controller to OVS. If the topology is complicated and all you want to achieve is simple L2 forwarding through OVS, we can just install the flows and forget the controller.

Let's understand what flows are required for a simply topology shown below.

 (10.0.0.1)Host----------(port_no=1) OVS (port_no=2)-------Host(10.0.0.2)

Whenever a host tries to ping another machine, it search for a mac-address of the destination in its mac-address cache. If it does not find it, it sends an arp request to the gateway, which may be a router or a switch. In our topology, the first device that is connected to the host is the OVS. So, flows for arp are required which sends the arp request to the correct destination.
For the topology shown above, the arp flows are as follows:

cookie=0x0, duration=7.096s, table=0, n_packets=0, n_bytes=0, idle_age=7, arp,arp_tpa=10.0.0.2 actions=output:2
cookie=0x0, duration=12.818s, table=0, n_packets=0, n_bytes=0, idle_age=12, arp,arp_tpa=10.0.0.1 actions=output:1

The commands to add them are as follows:

ovs-ofctl add-flow s1 arp,nw_dst=10.0.0.1,actions:output=1
ovs-ofctl add-flow s1 arp,nw_dst=10.0.0.2,actions:output=2

After the host gets an arp reply, it saves the mac-address in its arp cache. When we ping to the same destination next time, icmp packets need to be forwarded to the correct destination.

For the topology shown above, the icmp flows are as follows:

cookie=0x0, duration=84.809s, table=0, n_packets=0, n_bytes=0, idle_age=84, in_port=2,dl_dst=00:00:00:00:00:01 actions=output:1
cookie=0x0, duration=93.627s, table=0, n_packets=0, n_bytes=0, idle_age=93, in_port=1,dl_dst=00:00:00:00:00:02 actions=output:2

The commands to add them are as follows:

ovs-ofctl add-flow s1 in_port=1,dl_dst=00:00:00:00:00:02,actions:output=2
ovs-ofctl add-flow s1 in_port=2,dl_dst=00:00:00:00:00:01,actions:output=1

With these four flows you will be able to establish L2 switching between the hosts without the use of controller.

Monday, December 8, 2014

Connecting Mininet Hosts to Internet

While working on my project on open vswitch I had to connect mininet hosts to internet to enable some functionalities in mininet hosts. After working on it for two days, I came to realise that its just 4 easy steps. If you are struggling with the same here is the solution.

Step 1: Make sure that your guest OS ie mininet OS is connected to the internet.

In virtualbox network setting make sure that you have a NAT interface enabled that allows you to connect to internet. It will have an ip address like this : 10.0.3.15 ie a class A address
Test by pinging www.google.com to make sure you are connected to internet from the guest OS ie Mininet OS.




Step 2: Start the network

Start a mininet netowrk with a switch and a host or any topology you prefer.

sudo mn  --switch ovsk --mac --topo single,2

The above command creates a network with single switch and two hosts.
This will create a switch s1 and two hosts h1 and h2.

Step 3: Connect the guest interface(that connects to the internet) to the ovs bridge

The command used to achieve this is an ovs-vsctl command which is used for quering and configuring openvswitchd(this is a process of openvswitch).

Open an xterm window for s1 as this command does not run directly on mininet.For this you need to ssh the guest OS from the host OS. If you don't know how to do this, you can refer to my earlier post titled "Error: Cannot Connect to Display"

Check the openvswitch configuration using the command: ovs-vsctl show
My switch had the following configuration.

root@mininet-vm:~# ovs-vsctl show
d27a9060-3edf-4ee7-a4cf-09e705c93f56
    Bridge "s1"
        Controller "ptcp:6634"
        Controller "tcp:127.0.0.1:6633"
            is_connected: true
        fail_mode: secure
        Port "s1-eth1"
            Interface "s1-eth1"
        Port "s1-eth2"
            Interface "s1-eth2"
        Port "s1"
            Interface "s1"
                type: internal
    ovs_version: "2.0.1"

Now, run the following command to connect eth1 to s1: ovs-vsctl add-port s1 eth1

Check the configuration again using ovs-vsctl show. The new interface that is added has been highlighted in red.

root@mininet-vm:~# ovs-vsctl show
d27a9060-3edf-4ee7-a4cf-09e705c93f56
    Bridge "s1"
        Controller "ptcp:6634"
        Controller "tcp:127.0.0.1:6633"
            is_connected: true
        fail_mode: secure
        Port "eth1"
            Interface "eth1"
        Port "s1-eth1"
            Interface "s1-eth1"
        Port "s1-eth2"
            Interface "s1-eth2"
        Port "s1"
            Interface "s1"
                type: internal
    ovs_version: "2.0.1"

Step 4: Run dhclient on hosts.

Open  xterm windows for h1 and h2 and run the following commands. The first command removes the ip from h1-eth0,the second command gets the ip address for h1-eth0 from dhcp server. The second command shows the interface description.

root@mininet-vm:~# ifconfig h1-eth0 0
root@mininet-vm:~# dhclient h1-eth0
root@mininet-vm:~# ifconfig
h1-eth0   Link encap:Ethernet  HWaddr 00:00:00:00:00:01
          inet addr:10.0.3.16  Bcast:10.0.3.255  Mask:255.255.255.0
          inet6 addr: fe80::200:ff:fe00:1/64 Scope:Link
          UP BROADCAST RUNNING MULTICAST  MTU:1500  Metric:1
          RX packets:24 errors:0 dropped:0 overruns:0 frame:0
          TX packets:12 errors:0 dropped:0 overruns:0 carrier:0
          collisions:0 txqueuelen:1000
          RX bytes:3304 (3.3 KB)  TX bytes:1764 (1.7 KB)

lo        Link encap:Local Loopback
          inet addr:127.0.0.1  Mask:255.0.0.0
          inet6 addr: ::1/128 Scope:Host
          UP LOOPBACK RUNNING  MTU:65536  Metric:1
          RX packets:1252 errors:0 dropped:0 overruns:0 frame:0
          TX packets:1252 errors:0 dropped:0 overruns:0 carrier:0
          collisions:0 txqueuelen:0
          RX bytes:151432 (151.4 KB)  TX bytes:151432 (151.4 KB)

Now check the internet connectivity using ping.

root@mininet-vm:~# ping www.google.com
PING www.google.com (216.58.216.164) 56(84) bytes of data.
64 bytes from sea15s02-in-f4.1e100.net (216.58.216.164): icmp_seq=14 ttl=54 time=61.9 ms
64 bytes from sea15s02-in-f4.1e100.net (216.58.216.164): icmp_seq=15 ttl=54 time=60.7 ms
^C
--- www.google.com ping statistics ---
15 packets transmitted, 2 received, 86% packet loss, time 14065ms
rtt min/avg/max/mdev = 60.707/61.336/61.965/0.629 ms

Summary:

The command that we have used to achieve internet connectivity to hosts are:

ovs-vsctl add-port s1 eth1
ifconfig h1-eth0 0
dhclient h1-eth0