Nevermind, I thought again about it and it's a bad idea™, because it would not handle a single connection loss. I would need two more network ports per node.
Hi everyone,
I'm designing a new 3-node cluster. It's not the first cluster I make but it's the first with a full-mesh Ceph network (no dedicated switch) . Each node has a double 10G NIC and they're already physically connected each other. So I've been reading the docs and I think the best...
Maybe that's just my impression, but I feel that it happens more often in case you have multiple backup tasks running over the same node. Can anyone confirm?
No need to apologize! :) Yes I attached /dev/urandom to a virtio-RNG device for my VM, but noticed no significant improvements (all virtIO drivers installed ofc).
Unfortunately I need to use the most generic CPU type because I have a cluster with (sligthly) different nodes, I can't risk not...
Hi, please ignore this thread. I found the root cause was that my benchmark tool wrote random data instead of plain zeroes, and it seems the guest OS is very slow in generating random numbers.
I'm going to find a clue about the slow random data generation and open a new thread in case I need...
Hi,
PVE 7.4 here. There's something wrong with my Windows guests. No matter the underlying hardware, I have very poor performance in I/O for write operations. Like, 1.3GB/s in read and about 100MB/s in write. I tested using both my Ceph storage and local SSDs.
I have latest VirtIO drivers...
I can't. Customers would see the firewall rules. That's the whole point.
The Security Group described by aaron is the right solution for me (I need it for a specific VM, therefore the API part is actually not relevant for my purpose)
@gurubert thanks for your input, the problem is that my customers can see/edit the firewall rules at VM-level. aaron's solution is what I was looking for: setting policies without customers to even know.
cheers! ;)
@aaron thanks again, it worked perfectly! in fact, I'd had a good hunch in creating the security group, but for some reason I didn't apply it to the VM :D what a genius
Hi @gurubert , sorry for the late reply. I understand.
So there's no other way to drop a given type of VM-level traffic without using the VM firewall? I'd like to block this protocol without my users ever noticing.
Thank you very much!
Hi,
PVE 7.4-16 here. It looks like I can't drop this type of traffic at datacenter/node level. Only VM level works.
As per Anydesk documentation (and further traffic sniffing) this is the traffic I need to drop:
- protocol: UDP
- destination IP: 239.255.102.18 (multicast)
- destination ports...
Thanks @fiona ! Oops. Sorry about that, I got the two things confused. Updated and will reboot soon.
No anomalies on the load/network.
Anyway, I start to see a pattern. It looks like all the VMs where the problem occurs have Acronis cloud backup agent installed and running. Although PVE seems...
Hi @fiona, However it's happening more and more often. I really don't know what to do.
I'm attaching a log of another failed backup on another VM, where the hardware changes were already applied and the disk went read-only nonetheless.
Hi,
some guests become readonly after the snapshot backup (performed overnight by PBS) fails. Curiously, I happen to see the very same backup logs on different guests, even with the same guest OS, but they don't go readonly. The backup task fails, and they go on like it was nothing.
Can you...
Hi,
I see from the QEMU 7.2 changelog that it is going to use 'max' CPU model instead of 'qemu32' / 'qemu64'. Is PVE going to be affected by this? I guess not, can you confirm?
Thanks!
This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
By continuing to use this site, you are consenting to our use of cookies.