[SOLVED] Vlans in a PVE cluster

yswery

Well-Known Member
May 6, 2018
83
5
48
54
Hi Guys and Gals

Sorry this might seem like a silly question but here goes.

I have a node cluster all connected to a cisco switch (where all three ethernet ports are configured as trunks for all vlans on the switch)

When I create two VMs in the same PVE node on VLAN 123 (for example - via the web UI) they can talk to each other and its all good, but when I migrate one of those VMs to a different node they no longer able to talk to each other.

Is there something i am missing here to get them to talk to one another?

Thanks!
 
1. Both nodes need to have vmbr0 as VLAN aware
2. VLAN ID needs to be set on the VMs' NIC
3. The switch needs to put the VLAN as tagged on the trunk

That's the whole magic.
 
1. Both nodes need to have vmbr0 as VLAN aware
2. VLAN ID needs to be set on the VMs' NIC
3. The switch needs to put the VLAN as tagged on the trunk

That's the whole magic.
Thanks for the reply @ph0x

1) Yes both are on vmbr0 and are vlan aware
2) The VLAN ID is set on both VMs via the webui
3) the switch (Catalyst 2960s) is set up as trunk

Where did I go wrong? my first assumption is the switch config for the ports that both nodes are on, but it seems to be all set up, no?
 

Attachments

  • Screen Shot 2021-06-23 at 2.22.18 PM.png
    Screen Shot 2021-06-23 at 2.22.18 PM.png
    176.7 KB · Views: 92
  • Screen Shot 2021-06-23 at 2.21.44 PM.png
    Screen Shot 2021-06-23 at 2.21.44 PM.png
    84.5 KB · Views: 93
  • Screen Shot 2021-06-23 at 2.21.59 PM.png
    Screen Shot 2021-06-23 at 2.21.59 PM.png
    244.4 KB · Views: 94
All VLAN IDs are allowed yes, but is this sufficient? I don't know Cisco enough to be sure.
But are you sure about the IP address and the gateway address? They are not on the same /24 subnet, is this on purpose?
 
All VLAN IDs are allowed yes, but is this sufficient? I don't know Cisco enough to be sure.
But are you sure about the IP address and the gateway address? They are not on the same /24 subnet, is this on purpose?
Yeah it’s done on purpose with the addressing.
In theory I should be able to see arp and regular non ip traffic between the vm machines.
If they are both on the same node then it’s working great hence why I tend to point my finger at the switch
 

About

The Proxmox community has been around for many years and offers help and support for Proxmox VE, Proxmox Backup Server, and Proxmox Mail Gateway.
We think our community is one of the best thanks to people like you!

Get your subscription!

The Proxmox team works very hard to make sure you are running the best software and getting stable updates and security enhancements, as well as quick enterprise support. Tens of thousands of happy customers have a Proxmox subscription. Get yours easily in our online shop.

Buy now!