I have been experimenting with Proxmox and Openvswitch, and I think it is worth a second look from the dev team. The biggest tripping point at the moment, is that there is no persistant name for the vif that gets activated. Without persistence, it makes it a little bit more cumbersome to spin up prebuilt bridges for vlans. That being said, by utilizing openvswitch, proxmox could achieve vlan network isolation without ever needed to touch/sync a switch configuration. The vlans can easily be synced across devices, and it would also be possible to build pseudo distributed switches spanning multiple devices.
We have been using proxmox for a couple of years now, and of all the solutions available, nothing comes close to being a easy to deploy and maintain as Proxmox. The one thing we find ourselves lacking is a consistent method of network isolation. Blind bridges are OK, but only allow traffic within a single device. Traffic on a single device is OK until you have a failure or heavy load, and everything goes down. We want to be able to manage the isolation from the proxmox servers themselves, versus needing to manage the switch side and do the vlan tango. Openvswitch and so some degree +ebtables would be a nice way to tackle network isolation within proxmox.
It would be nice to hear what the dev team has in mind, and if they have considered this type of configuration. It would really be a special feather in the Proxmox cap to hand these types of configurations.
We have been using proxmox for a couple of years now, and of all the solutions available, nothing comes close to being a easy to deploy and maintain as Proxmox. The one thing we find ourselves lacking is a consistent method of network isolation. Blind bridges are OK, but only allow traffic within a single device. Traffic on a single device is OK until you have a failure or heavy load, and everything goes down. We want to be able to manage the isolation from the proxmox servers themselves, versus needing to manage the switch side and do the vlan tango. Openvswitch and so some degree +ebtables would be a nice way to tackle network isolation within proxmox.
It would be nice to hear what the dev team has in mind, and if they have considered this type of configuration. It would really be a special feather in the Proxmox cap to hand these types of configurations.