Files
infix/doc/networking.md
T
2023-11-08 11:18:23 +01:00

17 KiB

Linux Networking

Interface LEGO®

Linux Networking Blocks

Type Yang Model Description
bridge infix-if-bridge SW implementation of an IEEE 802.1Q bridge
ip ietf-ip, infix-ip IP address to the subordinate interface
vlan infix-if-vlan Capture all traffic belonging to a specific 802.1Q VID
lag1 infix-if-lag Bonds multiple interfaces into one, creating a link aggregate
lo ietf-interfaces Software loopback interface
eth ietf-interfaces Physical Ethernet device/port
veth infix-if-veth Virtual Ethernet pair, typically one end is in a container

Data Plane

The blocks you ctose, and how you connect them, defines your data plane. Here we see an example of how to bridge a virtual port with a physical LAN.

Example of a 4-port switch with a link aggregate and a VETH pair to a container

Depending on the (optional) VLAN filtering of the bridge, the container may have full or limited connectivity with outside ports, as well as the internal CPU.

In fact the virtual port connected to the bridge can be member of several VLANs, with each VLAN being an interface with an IP address inside the container.

Thanks to Linux, and technologies like switchdev, that allow you to split a switching fabric into unique (isolated) ports, the full separation and virtualization of all Ethernet layer properties are possible to share with a container. Meaning, all the building blocks used on the left hand side can also be used freely on the right hand side as well.

Bridging

This is the most central part of the system. A bridge is a switch, and a switch is a bridge. In Linux, setting up a bridge with ports connected to physical switch fabric, means you manage the actual switch fabric!

In Infix ports are by default not switch ports, unless the customer specific factory config sets it up this way. To enable switching between ports you create a bridge and then add ports to that bridge. That's it.

admin@example:/> configure
admin@example:/config/> edit interfaces interface br0
admin@example:/config/interfaces/interface/br0/> up
admin@example:/config/interfaces/> set interface eth0 bridge-port bridge br0
admin@example:/config/interfaces/> set interface eth1 bridge-port bridge br0
admin@example:/config/interfaces/> leave

Here we add two ports to bridge br0: eth0 and eth1.

Note: Infix has many built-in helpers controlled by convention. E.g., if you name your bridge brN, where N is a number, Infix will set the interface type automatically for you, and unlock all bridge features for you.

VLAN Filtering Bridge

By default bridges in Linux do not filter based on VLAN tags. It can be enabled in Infix when creating a bridge by adding a port to a VLAN as a tagged or untagged member. Use the port default VID (PVID) setting to control VLAN association for traffic ingressing a port untagged (default PVID: 1).

admin@example:/config/> edit interfaces interface br0 
admin@example:/config/interfaces/interface/br0/> up
admin@example:/config/interfaces/> set interface eth0 bridge-port bridge br0
admin@example:/config/interfaces/> set interface eth0 bridge-port pvid 10
admin@example:/config/interfaces/> set interface eth1 bridge-port bridge br0
admin@example:/config/interfaces/> set interface eth1 bridge-port pvid 20
admin@example:/config/interfaces/> edit interface br0
admin@example:/config/interfaces/interface/br0/> set bridge vlans vlan 10 untagged eth0
admin@example:/config/interfaces/interface/br0/> set bridge vlans vlan 20 untagged eth1

This sets eth0 as an untagged member of VLAN 10 and eth1 as an untagged member of VLAN 20. Switching between these ports is thus prohibited.

To terminate a VLAN in the switch itself, either for switch management or for routing, the bridge must become a (tagged) member of the VLAN.

admin@example:/config/interfaces/interface/br0/> set bridge vlans vlan 10 tagged br0
admin@example:/config/interfaces/interface/br0/> set bridge vlans vlan 20 tagged br0

To route or to manage via a VLAN, a VLAN interface also needs to be created on top of the bridge, see section VLAN Interfaces below.

VLAN Interfaces

Creating a VLAN can be done in many ways. This section assumes VLAN interfaces created atop another Linux interface. E.g., the VLAN interfaces created on top of the Ethernet interface or bridge in the picture below.

VLAN interface on top of Ethernet or Bridge interfaces

A VLAN interface is basically a filtering abstraction. When you run tcpdump on a VLAN interface you will only see the frames matching the VLAN ID of the interface, compared to all the VLAN IDs if you run tcpdump on the lower-layer interface.

admin@example:/> configure 
admin@example:/config/> edit interfaces interface eth0.20
admin@example:/config/interfaces/interface/eth0.20/> set vlan id 20
admin@example:/config/interfaces/interface/eth0.20/> set vlan lower-layer-if eth0
admin@example:/config/interfaces/interface/eth0.20/> leave

The example below assumes bridge br0 is already created, see VLAN Filtering Bridge.

admin@example:/> configure 
admin@example:/config/> edit interfaces interface vlan10
admin@example:/config/interfaces/interface/vlan10/> set vlan id 10
admin@example:/config/interfaces/interface/vlan10/> set vlan lower-layer-if br0
admin@example:/config/interfaces/interface/vlan10/> leave

As conventions, a VLAN interface for VID 20 on top of an Ethernet interface eth0 is named eth0.20, and a VLAN interface for VID 10 on top of a bridge interface br0 is named vlan10.

Note: If you name your VLAN interface foo0.N or vlanN, where N is a number, Infix will set the interface type automatically for you.

Management Plane

This section details IP Addresses And Other Per-Interface IP settings.

Infix support several network interface types, each can be assigned one or more IP addresses, both IPv4 and IPv6 are supported.

IP on top of network interface examples

IPv4 Address Assignment

Multiple address assignment methods are available:

Type Yang Model Description
static ietf-ip Static assignment of IPv4 address, e.g., 10.0.1.1/24
link-local infix-ip Auto-assignment of IPv4 address in 169.254.x.x/16 range
dhcp infix-dhcp-client Assignment of IPv4 address by DHCP server, e.g., 10.0.1.1/24

DHCP address method is only available for LAN interfaces (ethernet, virtual ethernet (veth), bridge, etc.)

IPv6 Address Assignment

Multiple address assignment methods are available:

Type Yang Model Description
static ietf-ip Static assignment of IPv6 address, e.g., 2001:db8:0:1::1/64
link-local ietf-ip2 (RFC4862) Auto-configured link-local IPv6 address (fe80::0 prefix + interface identifier, e.g., fe80::ccd2:82ff:fe52:728b/64)
global auto-conf ietf-ip (RFC4862) Auto-configured (stateless) global IPv6 address (prefix from router + interface identifier, e.g., 2001:db8:0:1:ccd2:82ff:fe52:728b/64

Both for link-local and global auto-configuration, it is possible to auto-configure using a random suffix instead of the interface identifier.

Examples

Switch example (eth0 and lo)

admin@example:/> show interfaces 
INTERFACE       PROTOCOL   STATE       DATA                                     
eth0            ethernet   UP          02:00:00:00:00:00                        
                ipv6                   fe80::ff:fe00:0/64 (link-layer)
lo              ethernet   UP          00:00:00:00:00:00                        
                ipv4                   127.0.0.1/8 (static)
                ipv6                   ::1/128 (static)
admin@example:/>

To illustrate IP address configuration, the examples below uses a switch with a single Ethernet interface (eth0) and a loopback interface (lo). As shown above, these examples assume eth0 has an IPv6 link-local address and lo has static IPv4 and IPv6 addresses by default.

Setting static IPv4 (and link-local IPv4)

admin@example:/> configure
admin@example:/config/> edit interfaces interface eth0 ipv4
admin@example:/config/interfaces/interface/eth0/ipv4/> set address 10.0.1.1 prefix-length 24
admin@example:/config/interfaces/interface/eth0/ipv4/> set autoconf enabled true 
admin@example:/config/interfaces/interface/eth0/ipv4/> diff
+interfaces {
+  interface eth0 {
+    ipv4 {
+      address 10.0.1.1 {
+        prefix-length 24;
+      }
+      autoconf {
+        enabled true;
+      }
+    }
+  }
+}
admin@example:/config/interfaces/interface/eth0/ipv4/> leave
admin@example:/> show interfaces 
INTERFACE       PROTOCOL   STATE       DATA                                     
eth0            ethernet   UP          02:00:00:00:00:00                        
                ipv4                   169.254.1.3/16 (random)
                ipv4                   10.0.1.1/24 (static)
                ipv6                   fe80::ff:fe00:0/64 (link-layer)
lo              ethernet   UP          00:00:00:00:00:00                        
                ipv4                   127.0.0.1/8 (static)
                ipv6                   ::1/128 (static)
admin@example:/>

As shown, the link-local IPv4 address is configured with set autconf enabled true. The resulting address (169.254.1.3/16) is of type random (IETF ip-yang).

Use of DHCP for IPv4 address assignment

Using DHCP for IPv4 address assignment

admin@example:/> configure 
admin@example:/config/> edit dhcp-client 
admin@example:/config/dhcp-client/> set client-if eth0
admin@example:/config/dhcp-client/> set enabled true 
admin@example:/config/dhcp-client/> leave
admin@example:/> show interfaces 
INTERFACE       PROTOCOL   STATE       DATA                                     
eth0            ethernet   UP          02:00:00:00:00:00                        
                ipv4                   10.1.2.100/24 (dhcp)
                ipv6                   fe80::ff:fe00:0/64 (link-layer)
lo              ethernet   UP          00:00:00:00:00:00                        
                ipv4                   127.0.0.1/8 (static)
                ipv6                   ::1/128 (static)
admin@example:/>

The resulting address (10.1.2.100/24) is of type dhcp.

The (only) way to disable IPv6 link-local addresses is by disabling IPv6 on the interface.

admin@example:/> configure 
admin@example:/config/> edit interfaces interface eth0 ipv6
admin@example:/config/interfaces/interface/eth0/ipv6/> set enabled false
admin@example:/config/interfaces/interface/eth0/ipv6/> leave
admin@example:/> show interfaces 
INTERFACE       PROTOCOL   STATE       DATA                                     
eth0            ethernet   UP          02:00:00:00:00:00                        
lo              ethernet   UP          00:00:00:00:00:00                        
                ipv4                   127.0.0.1/8 (static)
                ipv6                   ::1/128 (static)
admin@example:/>

Static IPv6 address

Setting static IPv6

admin@example:/> configure 
admin@example:/config/> edit interfaces interface eth0 ipv6
admin@example:/config/interfaces/interface/eth0/ipv6/> set address 2001:db8::1 prefix-length 64
admin@example:/config/interfaces/interface/eth0/ipv6/> leave
admin@example:/> show interfaces 
INTERFACE       PROTOCOL   STATE       DATA                                     
eth0            ethernet   UP          02:00:00:00:00:00                        
                ipv6                   2001:db8::1/64 (static)
                ipv6                   fe80::ff:fe00:0/64 (link-layer)
lo              ethernet   UP          00:00:00:00:00:00                        
                ipv4                   127.0.0.1/8 (static)
                ipv6                   ::1/128 (static)
admin@example:/>

Stateless Auto-configuration of Global IPv6 Address

Auto-configuration of global IPv6

Stateless address auto-configuration of global addresses is enabled by default. The address is formed by concatenating the network prefix advertised by the router (here 2001:db8:0:1::0/64) and the interface identifier. The resulting address is of type link-layer, as it is formed based on the interface identifier (IETF ip-yang).

admin@example:/> show interfaces 
INTERFACE       PROTOCOL   STATE       DATA                                     
eth0            ethernet   UP          02:00:00:00:00:00                        
                ipv6                   2001:db8:0:1:0:ff:fe00:0/64 (link-layer)
                ipv6                   fe80::ff:fe00:0/64 (link-layer)
lo              ethernet   UP          00:00:00:00:00:00                        
                ipv4                   127.0.0.1/8 (static)
                ipv6                   ::1/128 (static)
admin@example:/>

Disabling auto-configuration of global IPv6 addresses can be done as shown below.

admin@example:/> configure
admin@example:/config/> edit interfaces interface eth0 ipv6
admin@example:/config/interfaces/interface/eth0/ipv6/> set autoconf create-global-addresses false 
admin@example:/config/interfaces/interface/eth0/ipv6/> leave
admin@example:/> show interfaces 
INTERFACE       PROTOCOL   STATE       DATA                                     
eth0            ethernet   UP          02:00:00:00:00:00                        
                ipv6                   fe80::ff:fe00:0/64 (link-layer)
lo              ethernet   UP          00:00:00:00:00:00                        
                ipv4                   127.0.0.1/8 (static)
                ipv6                   ::1/128 (static)
admin@example:/>

Auto-configuration of global IPv6

By default, the auto-configured link-local and global IPv6 addresses are formed from a link-identifier based on the MAC address.

admin@example:/> show interfaces 
INTERFACE       PROTOCOL   STATE       DATA                                     
eth0            ethernet   UP          02:00:00:00:00:00                        
                ipv6                   2001:db8:0:1:0:ff:fe00:0/64 (link-layer)
                ipv6                   fe80::ff:fe00:0/64 (link-layer)
lo              ethernet   UP          00:00:00:00:00:00                        
                ipv4                   127.0.0.1/8 (static)
                ipv6                   ::1/128 (static)
admin@example:/>

To avoid revealing identity information in the IPv6 address, it is possible to specify use of a random identifier (ietf-ip YANG and RFC8981).

admin@example:/> configure 
admin@example:/config/> edit interfaces interface eth0 ipv6
admin@example:/config/interfaces/interface/eth0/ipv6/> set autoconf create-temporary-addresses true 
admin@example:/config/interfaces/interface/eth0/ipv6/> leave
admin@example:/> show interfaces 
INTERFACE       PROTOCOL   STATE       DATA                                     
eth0            ethernet   UP          02:00:00:00:00:00                        
                ipv6                   2001:db8:0:1:b705:8374:638e:74a8/64 (random)
                ipv6                   fe80::ad3d:b274:885a:9ffb/64 (random)
lo              ethernet   UP          00:00:00:00:00:00                        
                ipv4                   127.0.0.1/8 (static)
                ipv6                   ::1/128 (static)
admin@example:/>

Both the link-local address (fe80::) and the global address (2001:) have changed type to random.


  1. Please note, link aggregates are not yet supported in Infix. ↩︎

  2. Link-local IPv6 addresses are implicitly enabled when enabling IPv6. IPv6 can be enabled/disabled per interface in ietf-ip YANG model. ↩︎