]>
Commit | Line | Data |
---|---|---|
7d9809ef BP |
1 | .\" -*- nroff -*- |
2 | .de IQ | |
3 | . br | |
4 | . ns | |
5 | . IP "\\$1" | |
6 | .. | |
d2cb6c95 | 7 | .TH ovs\-vswitchd 8 "@VERSION@" "Open vSwitch" "Open vSwitch Manual" |
812560d7 | 8 | .\" This program's name: |
064af421 BP |
9 | .ds PN ovs\-vswitchd |
10 | . | |
11 | .SH NAME | |
f30f26be | 12 | ovs\-vswitchd \- Open vSwitch daemon |
064af421 BP |
13 | . |
14 | .SH SYNOPSIS | |
80df177a | 15 | \fBovs\-vswitchd \fR[\fIdatabase\fR] |
064af421 BP |
16 | . |
17 | .SH DESCRIPTION | |
299a244b | 18 | A daemon that manages and controls any number of Open vSwitch switches |
f30f26be | 19 | on the local machine. |
064af421 | 20 | .PP |
80df177a BP |
21 | The \fIdatabase\fR argument specifies how \fBovs\-vswitchd\fR connects |
22 | to \fBovsdb\-server\fR. The default is \fBunix:@RUNDIR@/db.sock\fR. | |
23 | The following forms are accepted: | |
6f61c75b | 24 | .so ovsdb/remote-active.man |
c9f3f37a | 25 | .so ovsdb/remote-passive.man |
064af421 | 26 | .PP |
76343538 BP |
27 | \fBovs\-vswitchd\fR retrieves its configuration from \fIdatabase\fR at |
28 | startup. It sets up Open vSwitch datapaths and then operates | |
29 | switching across each bridge described in its configuration files. As | |
30 | the database changes, \fBovs\-vswitchd\fR automatically updates its | |
31 | configuration to match. | |
32 | .PP | |
299a244b | 33 | \fBovs\-vswitchd\fR switches may be configured with any of the following |
f30f26be | 34 | features: |
064af421 BP |
35 | . |
36 | .IP \(bu | |
37 | L2 switching with MAC learning. | |
38 | . | |
39 | .IP \(bu | |
40 | NIC bonding with automatic fail-over and source MAC-based TX load | |
41 | balancing ("SLB"). | |
42 | . | |
43 | .IP \(bu | |
44 | 802.1Q VLAN support. | |
45 | . | |
46 | .IP \(bu | |
47 | Port mirroring, with optional VLAN tagging. | |
48 | . | |
49 | .IP \(bu | |
50 | NetFlow v5 flow logging. | |
51 | . | |
52 | .IP \(bu | |
d1ae8299 | 53 | sFlow(R) monitoring. |
72b06300 BP |
54 | . |
55 | .IP \(bu | |
064af421 BP |
56 | Connectivity to an external OpenFlow controller, such as NOX. |
57 | . | |
58 | .PP | |
59 | Only a single instance of \fBovs\-vswitchd\fR is intended to run at a time. | |
f30f26be | 60 | A single \fBovs\-vswitchd\fR can manage any number of switch instances, up |
064af421 BP |
61 | to the maximum number of supported Open vSwitch datapaths. |
62 | .PP | |
f30f26be | 63 | \fBovs\-vswitchd\fR does all the necessary management of Open vSwitch datapaths |
064af421 BP |
64 | itself. Thus, external tools, such \fBovs\-dpctl\fR(8), are not needed for |
65 | managing datapaths in conjunction with \fBovs\-vswitchd\fR, and their use | |
66 | to modify datapaths when \fBovs\-vswitchd\fR is running can interfere with | |
67 | its operation. (\fBovs\-dpctl\fR may still be useful for diagnostics.) | |
68 | .PP | |
69 | An Open vSwitch datapath kernel module must be loaded for \fBovs\-vswitchd\fR | |
5fca1acd | 70 | to be useful. Please refer to the \fBINSTALL.Linux\fR file included in the |
064af421 BP |
71 | Open vSwitch distribution for instructions on how to build and load |
72 | the Open vSwitch kernel module. | |
73 | .PP | |
74 | .SH OPTIONS | |
4e312e69 | 75 | .IP "\fB\-\-mlockall\fR" |
86a06318 BP |
76 | Causes \fBovs\-vswitchd\fR to call the \fBmlockall()\fR function, to |
77 | attempt to lock all of its process memory into physical RAM, | |
78 | preventing the kernel from paging any of its memory to disk. This | |
79 | helps to avoid networking interruptions due to system memory pressure. | |
80 | .IP | |
81 | Some systems do not support \fBmlockall()\fR at all, and other systems | |
82 | only allow privileged users, such as the superuser, to use it. | |
83 | \fBovs\-vswitchd\fR emits a log message if \fBmlockall()\fR is | |
84 | unavailable or unsuccessful. | |
85 | . | |
42dd41ef | 86 | .SS "Daemon Options" |
a7ff9bd7 BP |
87 | .ds DD \ |
88 | \fBovs\-vswitchd\fR detaches only after it has connected to the \ | |
89 | database, retrieved the initial configuration, and set up that \ | |
90 | configuration. | |
064af421 | 91 | .so lib/daemon.man |
42dd41ef GS |
92 | .SS "Service Options" |
93 | .so lib/service.man | |
ac300505 | 94 | .SS "Public Key Infrastructure Options" |
6f61c75b BP |
95 | .so lib/ssl.man |
96 | .so lib/ssl-bootstrap.man | |
064af421 BP |
97 | .so lib/vlog.man |
98 | .so lib/common.man | |
064af421 | 99 | . |
b16fdafe BP |
100 | .SH "RUNTIME MANAGEMENT COMMANDS" |
101 | \fBovs\-appctl\fR(8) can send commands to a running | |
102 | \fBovs\-vswitchd\fR process. The currently supported commands are | |
103 | described below. The command descriptions assume an understanding of | |
76343538 | 104 | how to configure Open vSwitch. |
9e15c889 BP |
105 | .SS "GENERAL COMMANDS" |
106 | .IP "\fBexit\fR" | |
107 | Causes \fBovs\-vswitchd\fR to gracefully terminate. | |
e8fe3026 EJ |
108 | .IP "\fBqos/show\fR \fIinterface\fR" |
109 | Queries the kernel for Quality of Service configuration and statistics | |
110 | associated with the given \fIinterface\fR. | |
6d13e6dd PR |
111 | .IP "\fBbfd/show\fR [\fIinterface\fR]" |
112 | Displays detailed information about Bidirectional Forwarding Detection | |
113 | configured on \fIinterface\fR. If \fIinterface\fR is not specified, | |
114 | then displays detailed information about all interfaces with BFD | |
115 | enabled. | |
116 | .IP "\fBbfd/set-forwarding\fR [\fIinterface\fR] \fIstatus\fR" | |
117 | Force the fault status of the BFD module on \fIinterface\fR (or all | |
118 | interfaces if none is given) to be \fIstatus\fR. \fIstatus\fR can be | |
119 | "true", "false", or "normal" which reverts to the standard behavior. | |
ae75dae3 | 120 | .IP "\fBcfm/show\fR [\fIinterface\fR]" |
20c8e971 | 121 | Displays detailed information about Connectivity Fault Management |
ae75dae3 JP |
122 | configured on \fIinterface\fR. If \fIinterface\fR is not specified, |
123 | then displays detailed information about all interfaces with CFM | |
124 | enabled. | |
d7243b93 EJ |
125 | .IP "\fBcfm/set-fault\fR [\fIinterface\fR] \fIstatus\fR" |
126 | Force the fault status of the CFM module on \fIinterface\fR (or all | |
127 | interfaces if none is given) to be \fIstatus\fR. \fIstatus\fR can be | |
128 | "true", "false", or "normal" which reverts to the standard behavior. | |
fe4a02e4 EJ |
129 | .IP "\fBstp/tcn\fR [\fIbridge\fR]" |
130 | Forces a topology change event on \fIbridge\fR if it's running STP. This | |
131 | may cause it to send Topology Change Notifications to its peers and flush | |
132 | its MAC table.. If no \fIbridge\fR is given, forces a topology change | |
133 | event on all bridges. | |
b16fdafe BP |
134 | .SS "BRIDGE COMMANDS" |
135 | These commands manage bridges. | |
96e466a3 EJ |
136 | .IP "\fBfdb/flush\fR [\fIbridge\fR]" |
137 | Flushes \fIbridge\fR MAC address learning table, or all learning tables | |
138 | if no \fIbridge\fR is given. | |
b16fdafe BP |
139 | .IP "\fBfdb/show\fR \fIbridge\fR" |
140 | Lists each MAC address/VLAN pair learned by the specified \fIbridge\fR, | |
141 | along with the port on which it was learned and the age of the entry, | |
142 | in seconds. | |
fa05809b BP |
143 | .IP "\fBbridge/reconnect\fR [\fIbridge\fR]" |
144 | Makes \fIbridge\fR drop all of its OpenFlow controller connections and | |
145 | reconnect. If \fIbridge\fR is not specified, then all bridges drop | |
146 | their controller connections and reconnect. | |
147 | .IP | |
148 | This command might be useful for debugging OpenFlow controller issues. | |
cdd35cff | 149 | . |
4e312e69 | 150 | .IP "\fBbridge/dump\-flows\fR \fIbridge\fR" |
cdd35cff | 151 | Lists all flows in \fIbridge\fR, including those normally hidden to |
4e312e69 | 152 | commands such as \fBovs\-ofctl dump\-flows\fR. Flows set up by mechanisms |
cdd35cff JP |
153 | such as in-band control and fail-open are hidden from the controller |
154 | since it is not allowed to modify or override them. | |
b16fdafe BP |
155 | .SS "BOND COMMANDS" |
156 | These commands manage bonded ports on an Open vSwitch's bridges. To | |
157 | understand some of these commands, it is important to understand a | |
be02e7c3 EJ |
158 | detail of the bonding implementation called ``source load balancing'' |
159 | (SLB). Instead of directly assigning Ethernet source addresses to | |
160 | slaves, the bonding implementation computes a function that maps an | |
161 | 48-bit Ethernet source addresses into an 8-bit value (a ``MAC hash'' | |
162 | value). All of the Ethernet addresses that map to a single 8-bit | |
163 | value are then assigned to a single slave. | |
b16fdafe BP |
164 | .IP "\fBbond/list\fR" |
165 | Lists all of the bonds, and their slaves, on each bridge. | |
064af421 | 166 | . |
c33a8a25 EJ |
167 | .IP "\fBbond/show\fR [\fIport\fR]" |
168 | Lists all of the bond-specific information (updelay, downdelay, time | |
169 | until the next rebalance) about the given bonded \fIport\fR, or all | |
170 | bonded ports if no \fIport\fR is given. Also lists information about | |
171 | each slave: whether it is enabled or disabled, the time to completion | |
172 | of an updelay or downdelay if one is in progress, whether it is the | |
173 | active slave, the hashes assigned to the slave. Any LACP information | |
174 | related to this bond may be found using the \fBlacp/show\fR command. | |
175 | . | |
b16fdafe | 176 | .IP "\fBbond/migrate\fR \fIport\fR \fIhash\fR \fIslave\fR" |
be02e7c3 EJ |
177 | Only valid for SLB bonds. Assigns a given MAC hash to a new slave. |
178 | \fIport\fR specifies the bond port, \fIhash\fR the MAC hash to be | |
179 | migrated (as a decimal number between 0 and 255), and \fIslave\fR the | |
180 | new slave to be assigned. | |
b16fdafe BP |
181 | .IP |
182 | The reassignment is not permanent: rebalancing or fail-over will | |
183 | cause the MAC hash to be shifted to a new slave in the usual | |
184 | manner. | |
185 | .IP | |
186 | A MAC hash cannot be migrated to a disabled slave. | |
4e312e69 | 187 | .IP "\fBbond/set\-active\-slave\fR \fIport\fR \fIslave\fR" |
b16fdafe BP |
188 | Sets \fIslave\fR as the active slave on \fIport\fR. \fIslave\fR must |
189 | currently be enabled. | |
190 | .IP | |
191 | The setting is not permanent: a new active slave will be selected | |
192 | if \fIslave\fR becomes disabled. | |
4e312e69 BP |
193 | .IP "\fBbond/enable\-slave\fR \fIport\fR \fIslave\fR" |
194 | .IQ "\fBbond/disable\-slave\fR \fIport\fR \fIslave\fR" | |
b16fdafe BP |
195 | Enables (or disables) \fIslave\fR on the given bond \fIport\fR, skipping any |
196 | updelay (or downdelay). | |
197 | .IP | |
198 | This setting is not permanent: it persists only until the carrier | |
199 | status of \fIslave\fR changes. | |
672d18b2 | 200 | .IP "\fBbond/hash\fR \fImac\fR [\fIvlan\fR] [\fIbasis\fR]" |
e58de0e3 | 201 | Returns the hash value which would be used for \fImac\fR with \fIvlan\fR |
672d18b2 | 202 | and \fIbasis\fR if specified. |
064af421 | 203 | . |
5dab8ece | 204 | .IP "\fBlacp/show\fR [\fIport\fR]" |
6aa74308 EJ |
205 | Lists all of the LACP related information about the given \fIport\fR: |
206 | active or passive, aggregation key, system id, and system priority. Also | |
207 | lists information about each slave: whether it is enabled or disabled, | |
208 | whether it is attached or detached, port id and priority, actor | |
5dab8ece JP |
209 | information, and partner information. If \fIport\fR is not specified, |
210 | then displays detailed information about all interfaces with CFM | |
211 | enabled. | |
6aa74308 | 212 | . |
27022416 | 213 | .so ofproto/ofproto-dpif-unixctl.man |
7aa697dd | 214 | .so ofproto/ofproto-unixctl.man |
b16fdafe | 215 | .so lib/vlog-unixctl.man |
149ff68a | 216 | .so lib/memory-unixctl.man |
6901e5e2 | 217 | .so lib/coverage-unixctl.man |
7a7708a0 | 218 | . |
42ed0063 BP |
219 | .SH "OPENFLOW IMPLEMENTATION" |
220 | . | |
221 | .PP | |
222 | This section documents aspects of OpenFlow for which the OpenFlow | |
223 | specification requires documentation. | |
224 | . | |
225 | .SS "Packet buffering." | |
226 | The OpenFlow specification, version 1.2, says: | |
227 | . | |
228 | .IP | |
229 | Switches that implement buffering are expected to expose, through | |
230 | documentation, both the amount of available buffering, and the length | |
231 | of time before buffers may be reused. | |
232 | . | |
233 | .PP | |
fb405080 | 234 | Open vSwitch maintains a separate set of 256 packet buffers for each |
42ed0063 BP |
235 | OpenFlow connection. Any given packet buffer is preserved until it is |
236 | referenced by an \fBOFPT_FLOW_MOD\fR or \fBOFPT_PACKET_OUT\fR request | |
237 | or for 5 seconds, whichever comes first. | |
238 | . | |
7a7708a0 BP |
239 | .SH "LIMITS" |
240 | . | |
241 | .PP | |
242 | We believe these limits to be accurate as of this writing. These | |
243 | limits assume the use of the Linux kernel datapath. | |
244 | . | |
245 | .IP \(bu | |
991d922c | 246 | \fBovs\-vswitchd\fR started through \fBovs\-ctl\fR(8) provides a limit of 7500 |
8ed70321 GS |
247 | file descriptors. The limits on the number of bridges and ports is decided by |
248 | the availability of file descriptors. With the Linux kernel datapath, creation | |
249 | of a single bridge consumes 3 file descriptors and adding a port consumes | |
250 | 1 file descriptor. Performance will degrade beyond 1,024 ports per bridge due | |
251 | to fixed hash table sizing. Other platforms may have different limitations. | |
7a7708a0 BP |
252 | . |
253 | .IP \(bu | |
2be9d4f0 BP |
254 | 2,048 MAC learning entries per bridge, by default. (This is |
255 | configurable via \fBother\-config:mac\-table\-size\fR in the | |
256 | \fBBridge\fR table. See \fBovs\-vswitchd.conf.db\fR(5) for details.) | |
7a7708a0 BP |
257 | . |
258 | .IP \(bu | |
259 | Kernel flows are limited only by memory available to the kernel. | |
260 | Performance will degrade beyond 1,048,576 kernel flows per bridge with | |
261 | a 32-bit kernel, beyond 262,144 with a 64-bit kernel. | |
262 | (\fBovs\-vswitchd\fR should never install anywhere near that many | |
263 | flows.) | |
264 | . | |
265 | .IP \(bu | |
266 | OpenFlow flows are limited only by available memory. Performance is | |
267 | linear in the number of unique wildcard patterns. That is, an | |
268 | OpenFlow table that contains many flows that all match on the same | |
269 | fields in the same way has a constant-time lookup, but a table that | |
270 | contains many flows that match on different fields requires lookup | |
271 | time linear in the number of flows. | |
272 | . | |
273 | .IP \(bu | |
274 | 255 ports per bridge participating in 802.1D Spanning Tree Protocol. | |
275 | . | |
276 | .IP \(bu | |
277 | 32 mirrors per bridge. | |
278 | . | |
279 | .IP \(bu | |
280 | 15 bytes for the name of a port. (This is a Linux kernel limitation.) | |
281 | . | |
064af421 BP |
282 | .SH "SEE ALSO" |
283 | .BR ovs\-appctl (8), | |
76343538 | 284 | .BR ovsdb\-server (1), |
5fca1acd | 285 | \fBINSTALL.Linux\fR in the Open vSwitch distribution. |