Wednesday, December 16, 2009

Exclusive IP configuration for non-global Solaris zones

Configured using this statement in zone configuration:

set ip-type=exclusive

… this mode implies that a given non-global zone will have exclusive access to one of the NICs on your system.

While for me the most important aspect of such exclusivity was the possibility to configure zone-specific routing, there’s obviously much more offered by this mode:

* DHCPv4 and IPv6 stateless address autoconfiguration
* IP Filter, including network address translation (NAT) functionality
* IP Network Multipathing (IPMP)
* IP routing
* ndd for setting TCP/UDP/SCTP as well as IP/ARP-level knobs
* IP security (IPsec) and IKE, which automates the provision of authenticated keying material for IPsec security association

So here it is – another design lesson for you – make sure you know what kind of networking your zones will need.
See also:

1 comment:

  1. there are many ways of fix broken pdf links, try this application if you’d like to get better results

    ReplyDelete