Slide 14
Slide 14 text
Catalyst 8000V (AWS版)の冗長化スクリプトの動作
C8000V#1 (AWS版)
guestshell
csr_ha.service
【IAM Policy】
{
"Version": "2012-10-17",
"Statement": [
{
"Sid": "VisualEditor0",
"Effect": "Allow",
"Action": [
"logs:CreateLogStream",
"cloudwatch:",
"s3:",
"ec2:AssociateRouteTable",
"ec2:CreateRoute",
"ec2:CreateRouteTable",
"ec2:DeleteRoute",
"ec2:DeleteRouteTable",
"ec2:DescribeRouteTables",
"ec2:DescribeVpcs",
"ec2:ReplaceRoute",
"ec2:DescribeRegions",
"ec2:DescribeNetworkInterfaces",
"ec2:DisassociateRouteTable",
"ec2:ReplaceRouteTableAssociation",
"logs:CreateLogGroup",
"logs:PutLogEvents"
],
"Resource": "*"
}
]
}
Destination Target
192.168.0.0/16 eni-**01 (C8000V#1)
⇒ eni-**02 (C8000V#2)
172.31.0/16 local
C8000V#2 (AWS版)
guestshell
csr_ha.service
インスタンス
障害
【Route table: rt-private】
Tunnel Interface上で
BFDと動的ルーティングを動作させて障害を検知
障害検知時に
Route tableのTargetを書き換え
必要な権限 (IAM Policy)