All of lore.kernel.org
 help / color / mirror / Atom feed
From: Whit Blauvelt <whit-M6G8SDWvnhfby3iVrkZq2A@public.gmane.org>
To: Daniel Lezcano <daniel.lezcano-GANU6spQydw@public.gmane.org>
Cc: containers-cunTk1MwBs9QetFLy7KEm3xJsTq8ys+cHZ5vskTnxNA@public.gmane.org
Subject: Re: How do containers tie to multiple IP's on a NIC?
Date: Sun, 4 Jul 2010 19:08:27 -0400	[thread overview]
Message-ID: <20100704230827.GA1066@transpect.com> (raw)
In-Reply-To: <4C30E5CB.1080902-GANU6spQydw@public.gmane.org>

On Sun, Jul 04, 2010 at 09:49:31PM +0200, Daniel Lezcano wrote:

> Well  ... please don't consider what I will suggest as "preaching
> for its parish" ;)

In English, "Preaching to the choir."

> I would recommend to use the lxc tools, preferably the 0.7.1
> version. 

Will do.

> These tools allow to do what you are expecting that is assign several Ip
> addresses to the same virtual nic.

Ah, then what I need to understand is the relationship of the virtual NIC to
the real NIC. That is, some of what I set up is multi-purpose boxes, where
the single machine functions as an iptables firewall, perhaps multi-homed to
two ISPs, with 3 real NICs, one for the IP block assigned by each ISP, and
one for the LAN - which might also have more than on IP on it. But these
aren't just firewalls. They tend to serve a website or two, perhaps ftp,
smtp, dns - spread over serveral of the IPs. They're also doing SNAT and
DNAT for systems behind them.

It would make all sorts of sense to be adding containers to these systems,
in terms of security, isolation, and the flexibility to easily migrate
services to other servers. But unlike the more usual virtualization
instance, where someone has a dozen different boxes and wants to consolidate
them, I'm already fully consolidated. What I need to do is split things
apart more, so they can go into containers, but still consolidated on boxes
which continue to be multi-purpose, and where each single NIC may have over
a dozen IPs assigned to it, but as a rule from within a single block per
NIC.

I've seen discussions elsewhere (using Google to try to find hints for this)
where people have given a machine two IPs on the same LAN by actually using
two physical NICs (and then need to play STP tricks). My attitude is "Why
use two pieces of hardware where one can do the job?"

Time for some trial-and-error with lxc tools.

Regards,
Whit

  parent reply	other threads:[~2010-07-04 23:08 UTC|newest]

Thread overview: 13+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2010-07-04  3:40 How do containers tie to multiple IP's on a NIC? Whit Blauvelt
     [not found] ` <20100704034023.GA29753-M6G8SDWvnhfby3iVrkZq2A@public.gmane.org>
2010-07-04 16:51   ` Daniel Lezcano
     [not found]     ` <4C30BC16.9090802-GANU6spQydw@public.gmane.org>
2010-07-04 19:18       ` Whit Blauvelt
     [not found]         ` <20100704191841.GA31425-M6G8SDWvnhfby3iVrkZq2A@public.gmane.org>
2010-07-04 19:49           ` Daniel Lezcano
     [not found]             ` <4C30E5CB.1080902-GANU6spQydw@public.gmane.org>
2010-07-04 23:08               ` Whit Blauvelt [this message]
     [not found]                 ` <20100704230827.GA1066-M6G8SDWvnhfby3iVrkZq2A@public.gmane.org>
2010-07-05  9:50                   ` Pavel Labushev
     [not found]                     ` <4C31AAEE.5010201-Re5JQEeQqe8AvxtiuMwx3w@public.gmane.org>
2010-07-05 14:07                       ` Whit Blauvelt
     [not found]                         ` <20100705140750.GA3113-M6G8SDWvnhfby3iVrkZq2A@public.gmane.org>
2010-07-05 21:13                           ` Daniel Lezcano
     [not found]                             ` <4C324AFE.8000801-GANU6spQydw@public.gmane.org>
2010-07-05 22:04                               ` Whit Blauvelt
2010-07-06 15:00                           ` Pavel Labushev
     [not found]                             ` <4C334523.2080503-Re5JQEeQqe8AvxtiuMwx3w@public.gmane.org>
2010-07-06 15:04                               ` Pavel Labushev
2010-07-07 12:55                           ` Eric W. Biederman
     [not found]                             ` <m1sk3vjvt1.fsf-+imSwln9KH6u2/kzUuoCbdi2O/JbrIOy@public.gmane.org>
2010-07-07 13:22                               ` Whit Blauvelt

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20100704230827.GA1066@transpect.com \
    --to=whit-m6g8sdwvnhfby3ivrkzq2a@public.gmane.org \
    --cc=containers-cunTk1MwBs9QetFLy7KEm3xJsTq8ys+cHZ5vskTnxNA@public.gmane.org \
    --cc=daniel.lezcano-GANU6spQydw@public.gmane.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.