Solved

single VM in promiscuous mode on AHV


Badge +8
how to enable promiscuous mode on AHV ?
icon

Best answer by EladRosen 18 January 2018, 17:09

Hi
i was able to make it work with this commands

$ ovs-vsctl add-br br0$ ovs-vsctl add-port br0 eth0$ ovs-vsctl add-port br0 tap0$ ovs-vsctl add-port br0 tap1 -- --id=@p get port tap1 -- --id=@m create mirror name=m0 select-all=true output-port=@p -- set bridge br0 mirrors=@m

View original

12 replies

Userlevel 3
Badge +12
Are you looking to sniff only packets destined/originating from vm's running on AHV? or do you want to sniff packets from physical devices outside the host?
Badge +8
Sniff packets from physical devices outside the host
Badge +8
any news?
Userlevel 3
Badge +12
As of now it is not possible to sniff packets from physical devices external to Nutanis. There is a feature request logged for this capability. You can only sniff packets that are originating or destined to AHV vm's by using the network chain functionality.
Badge +8
Hi
i was able to make it work with this commands

$ ovs-vsctl add-br br0$ ovs-vsctl add-port br0 eth0$ ovs-vsctl add-port br0 tap0$ ovs-vsctl add-port br0 tap1 -- --id=@p get port tap1 -- --id=@m create mirror name=m0 select-all=true output-port=@p -- set bridge br0 mirrors=@m
Userlevel 3
Badge +12
EladRosen We don't recommend doing it directly from OVS for the following reason,

1. Acropolis service doesn't have any control on the config done directly on OVS so a host reboot will lose the config
2. When the vm gets shutdown and started the config is lost.
3. When the vm is moved to another host the config is lost.

The feature request logged is to support this as a acropolis feature as OVS supports it already.
Badge +8
I know all this ( a lot of testing )Thank you for making it clear.But still, until you'll release the support of this it's a valid work around for my customer,Instead off not working at all.We will use affinity rule for that VM or the agent vm feature.While AHV upgrades will be Handled carefully.Hope this RFE will be available ASAP.
Userlevel 3
Badge +12
Thanks EladRosen just wanted to clarify the limitations of the config if any one else refers to this post in the future.
when creating a new scenario for planning future resource requirements, what is the maximum runway duration?
Hello guys,

My scenario little bit same.
I have cluster setup with 1 gig switch( hybrid 1 gig and 10 gig switch) where only one 10 gig port available.
10 gig cable connected to the 2nd server where VM is created with 2 nic's
For second nic need to configure the dedicated 10 gig port ( which is already mirror on switch level).. Anyone can suggest step by step commands for this to setup? Since the passthrough physical NIC and Promiscuous mode not supported by AHV / Nutanix?

Any help would be highly appreciated..

Anand-
Userlevel 7
Badge +35
Thanks for sharing @Anant5515

Anything you can add here @Chandru - Thanks 👍
Badge +4
Trying to deploy an IPS sensor appliance, which obviously would require a NIC in promiscuous mode in order to monitor network traffic.

Reply