Hi All,
The more I work with Cloudmin the more i love it but I feel like I set everything up wrong. Recently I have been having problems with my Ubuntu VMs where they cannot apt-get update (Cannot connect) and other such networking troubles (this is related to virtualization and networking as opposed to inaccesible hosts at ubuntu) . My systems are unorthodox so I recognize there are lots of potential things wrong, now I just need to figure out how to rebuild my infrastructure correctly in situ. with three hosts I should be able to fix one at a time and move my vms around until I have all three set up correctly.
So, generally speaking, I have 3 Host systems, each with 2 nics, This was originally done to have two separate but secure networks that can access each system (and the VMs they host) from two separate networks but never have the networks talk to each other. This was done to satisfy the security folks here. (we are a govt operation so making them happy comes before practicality or functionality) So on the internet side, I have a DSL modem that connects to the public side of a firewall (IPcop). IPcop acts as the primary internet firewall and provides DHCP for a private network 192.168.80.0 (255.255.255.0)
So each of my 3 host systems (HP Proliant DL 360 G6 running 64 bit Ubuntu 12.04.1 LTS) has a nic on the local lan, 216.xxx.xxx.0 (255.255.255.128) - inward facing - Intranet if you will, and one on the private network to the internet
Now on each host I have configured the network as such:
The loopback network interface
auto lo
iface lo inet loopback
The CORP network interface
auto eth0
iface eth0 inet manual
CORP Bridge for VMs on this host
auto br0
iface br0 inet static
address 216.xxx.xxx.10
netmask 255.255.255.128
bridge_ports eth0
bridge_stp off
bridge_fd 0
bridge_maxwait 0
dns-nameservers 192.168.80.1 192.235.200.134
The INTERNET network interface
auto eth1
iface eth1 inet manual
INTERNAT Bridge for VMs on this host
auto br1
iface br1 inet dhcp
bridge_ports eth1
bridge_stp off
bridge_fd 0
bridge_maxwait 0
gateway 192.168.80.1
I have installed, Cloudmin on one of these servers, and added the other two as KVM hosts.
Further, I have set up logical groups and volumes on each host as such:
groups: lg_storage (130gb) lg_system (68 gb)
volumes on lg_storage: lv_backups(50GB)
volumes on lg_system lv_root (18gb) lv_swap (9gb)
The Host OS is installed on lv_root and uses lv_swap as swap.
Cloudmin uses free space on lv_storage on each host to create logical volumes for each VM.
automated cloudmin backups use lv_snapshots and save to lv_backups on each server
most virtual machines have two nics so they can be accessed from the internet and the local lan both. but I have been systematically trying to move away from this and simply have intranet users access the internet version but some systems need direct access to secure systems on the govt lan, so it cant be nixed entirely.
an example of this networking inside the vm (/etc/network/interfaces)looks like this:
The loopback network interface
auto lo eth0 eth1
iface lo inet loopback
The primary network interface CORP network
iface eth0 inet static
address 216.xxx.xxx.59
netmask 255.255.255.128
up ip route add 216.xxx.xxx.0/25 via 216.xxx.xxx.1
Secondary is INTERNET
iface eth1 inet static
address 192.168.80.245
netmask 255.255.255.0
broadcast 192.168.80.255
network 192.168.80.0
gateway 192.168.80.1
while this works for most things including access to this VM over the internet and this VM connecting to private secure servers on the Corp lan, it cannot seem to
sudo apt-get update
It seems my older VMs (ubuntu 10.10) which were migrated from virtmanager and converted into cloudmin VMs seem to have strange hangovers and the result is mostly:
Err http://security.ubuntu.com maverick-security/restricted Sources
404 Not Found [IP: 91.189.92.190 80]
or they hang like this:
0% [Connecting to ca.archive.ubuntu.com] [Connecting to security.ubuntu.com]…
I have read as much and as fast I can to understand the nuances of Cloudmin and for the most part I love it, I just dont understand it enough to troubleshoot these strange networking issues I have.
My VMs have to talk to each other, and servers on the local lan, and to websites on the internet, and this system needs to be mission critical before the spring.
So if you can see something that I have done wrong, or even if I have done it the “less than desirable” way, I would love to hear your thoughts and make this work better.
Thanks For any and all advice/discussion
Franco Nogarin