Series

Neutron internals and gotchas

Standalone deep dives into the parts of Neutron that bite you in production: VNI ranges, port security, external networks and SR-IOV passthrough.

Part 1 — VNI Ranges: What do they do ?

· 1 min read

Deployment tools for Openstack have become very popular, including the very well known Openstack-Ansible. It makes deploying a Cloud an easy task, at the expense of losing access to the insights of “Behind the Scenes”…

Part 2 — Port security in Openstack

· 1 min read

Openstack Neutron provides by default some protections for your VMs’ communications, those protections verify that VMs can not impersonate other VMs. You can easily see how it does that by checking the flow rules in an…

Part 3 — Private External Networks in Neutron

· 3 min read

You might find yourself in a position where you need to restrict access by tenants to specific external networks. In Openstack there’s the notion that external networks are accessible by all tenants and anyone can…

Part 4 — PCI passthrough: Type-PF, Type-VF and Type-PCI

· 3 min read

Passthrough has became more and more popular with time. It started initially for simple PCI device assignment to VMs and then grew to be part of high performance network realm in the Cloud such as SR-IOV, Host-level…

Part 5 — How NICs work ? a quick dive !

· 3 min read

I’ve written this post as a draft sometime ago, but forgot to post it. The reason I looked into it was to find out how DPDK physically works as the OS/Device level and how it bypasses the network stack. So, when you…