NSX for vSphere 622 Release Notes.docx
- 文档编号:13696796
- 上传时间:2023-06-16
- 格式:DOCX
- 页数:59
- 大小:50.33KB
NSX for vSphere 622 Release Notes.docx
《NSX for vSphere 622 Release Notes.docx》由会员分享,可在线阅读,更多相关《NSX for vSphere 622 Release Notes.docx(59页珍藏版)》请在冰点文库上搜索。
NSXforvSphere622ReleaseNotes
NSXforvSphere6.2.2ReleaseNotes
Documentupdated4March2016
NSXforvSphere6.2.2 | Released3March2016 | Build3604087
What'sintheReleaseNotes
Thereleasenotescoverthefollowingtopics:
∙What'sNew
∙RecommendedVersions,SystemRequirementsandInstallation
∙UpgradeNotes
∙KnownIssues
∙ResolvedIssues
∙DocumentRevisionHistory
What'sNew
Seewhat'snewandchangedinNSX6.2.2and6.2.1and6.2.0.
Newin6.2.2
The6.2.2releasedeliversasecuritypatchtoaddresstheglibcvulnerabilityandincludesanumberofbugfixesdocumentedintheResolvedIssuessection.Thisreleaseincludesthesamecriticalbugfixesthatwereprovidedinallthe6.1.4-basedand6.1.5-basedpatches.ForNSX6.1.xusers,thissamesetofpatchfixesisavailableintheNSX6.1.6release.
Themainfeaturesofthisreleaseare:
∙CVE-2015-7547(glibc)securitypatch:
ThispatchaddressesCVE-2015-7547,alsoknownastheglibcvulnerability.
∙RemovalofconstraintvalidationsonDHCPdomainnameconfigurationsNSX6.2.2re-enablessupportforDHCPpoolswith".local"domains.SeeVMwareknowledgebasearticle2144097.
∙DFWUIEnhancementsforbetteruserexperience.
Newin6.2.1
The6.2.1releasedeliversanumberofbugfixesthathavebeendocumentedintheResolvedIssuessection.
∙6.1.5fixes:
ReleaseincludesthesamecriticalfixesasNSX-vSphere6.1.5content.
∙Introducednew'showcontrol-clusternetworkipsecstatus'commandthatallowsusestoinspecttheInternetProtocolSecurity(IPsec)state.
∙Connectivitystatus:
NSXManageruserinterfacenowshowstheconnectivitystatusoftheNSXControllercluster.
∙SupportforvRealizeOrchestratorPlug-inforNSX1.0.3:
WithNSX6.2.1release,NSX-vROpluginversion1.0.3isintroducedforusewithvRealizeAutomation7.0.0.ThispluginincludesfixesthatimproveperformancewhenvRealizeAutomation7.0usesNSXforvSphere6.2.1asanetworkingandsecurityendpoint.
∙Startingin6.2.1,NSXManagerquerieseachControllernodeintheclustertogettheconnectioninformationbetweenthatcontrollerandtheothercontrollersinthecluster.
ThisisprovidedintheoutputoftheNSXRESTAPI("GEThttps:
//[NSX-MANAGER-IP-ADDRESS]/api/2.0/vdn/controller"command),whichnowshowsthepeerconnectionstatusamongthecontrollernodes.IfNSXManagerfindstheconnectionbetweenanytwocontrollernodesisbroken,asystemeventisgeneratedtoalerttheuser.
∙ServiceComposernowexposesanAPIthatenablesuserstoconfigureautocreationofFirewalldraftsforServiceComposerworkflows.
Thissettingcanbeturnedon/offusingRESTAPIandthechangescanbesavedacrossreboot.Whendisabled,nodraftiscreatedintheDistributedFirewall(DFW)forpolicyworkflows.Thislimitsthenumberofdraftsthatareauto-createdinthesystemandprovidesbetterperformance.
Newin6.2.0
NSXvSphere6.2.0includedthefollowingnewandchangedfeatures:
∙CrossvCenterNetworkingandSecurity
oNSX6.2withvSphere6.0supportsCrossvCenterNSXwherelogicalswitches(LS),distributedlogicalrouters(DLR)anddistributedfirewalls(DFW)canbedeployedacrossmultiplevCenters,therebyenablinglogicalnetworkingandsecurityforapplicationswithworkloads(VMs)thatspanmultiplevCentersormultiplephysicallocations.
oConsistentfirewallpolicyacrossmultiplevCenters:
FirewallRuleSectionsinNSXcannowbemarkedas"Universal"wherebytherulesdefinedinthesesectionsgetreplicatedacrossmultipleNSXmanagers.ThissimplifiestheworkflowsinvolvingdefiningconsistentfirewallpolicyspanningmultipleNSXinstallations
oCrossvCentervMotionwithDFW:
VirtualMachinesthathavepoliciesdefinedinthe"Universal"sectionscanbemovedacrosshoststhatbelongtodifferentvCenterswithconsistentsecuritypolicyenforcement.
oUniversalSecurityGroups:
SecurityGroupsinNSX6.2thatarebasedonIPAddress,IPSet,MACAddressandMACSetcannowbeusedinUniversalrules,wherebythegroupsandgroupmembershipsaresyncedupacrossmultipleNSXmanagers.ThisimprovestheconsistencyinobjectgroupdefinitionsacrossmultipleNSXmanagers,andenablesconsistentpolicyenforcement
oUniversalLogicalSwitch(ULS):
ThisnewfunctionalityintroducedinNSX6.2asapartofCrossvCenterNSXallowscreationoflogicalswitchesthatcanspanmultiplevCenters,allowingthenetworkadministratortocreateacontiguousL2domainforanapplicationortenant.
oUniversalDistributedLogicalRouter(UDLR):
ThisnewfunctionalityintroducedinNSX6.2asapartofCrossvCenterNSXallowscreationofdistributedlogicalroutersthatcanspanmultiplevCenters.Theuniversaldistributedlogicalroutersenableroutingacrosstheuniversallogicalswitchesdescribedearlier.Inaddition,NSXUDLRiscapableoflocalizednorth-southroutingbasedonthephysicallocationoftheworkloads.
∙OperationsandTroubleshootingEnhancements
oNewtraceflowtroubleshootingtool:
Traceflowisatroubleshootingtoolthathelpsidentifyiftheproblemisinthevirtualorphysicalnetwork.Itprovidestheabilitytotraceapacketfromsourcetodestinationandhelpsobservehowthatpacketpassesthroughthevariousnetworkfunctionsinthevirtualnetwork.
oFlowmonitoringandIPFIXseparation:
InNSX6.1.x,NSXsupportedIPFIXreporting,butIPFIXreportingcouldbeenabledonlyifflowreportingtoNSXManagerwasalsoenabled.StartinginNSX6.2.0,thesefeaturesaredecoupled.InNSX6.2.0andlater,youcanenableIPFIXindependentofflowmonitoringonNSXManager.
oNewCLImonitoringandtroubleshootingcommandsin6.2:
Seeknowledgebasearticle2129062formoreinformation.
oCentralCLI:
CentralCLIreducestroubleshootingtimefordistributednetworkfunctions.CommandsarerunfromthecommandlineonNSXManagerandretrieveinformationfromcontrollers,hosts,andtheNSXManager.Thisallowsyoutoquicklyaccessandcompareinformationfrommultiplesources.ThecentralCLIprovidesinformationaboutlogicalswitches,logicalrouters,distributedfirewallandedges.
oCLIpingcommandaddsconfigurablepacketsizeanddo-not-fragmentflag:
StartinginNSX6.2.0,theNSXCLI'ping'commandoffersoptionstospecifythedatapacketsize(notincludingtheICMPheader)andtosetthedo-not-fragmentflag.SeetheNSXCLIReferencefordetails.
oShowhealthofthecommunicationchannels:
NSX6.2.0addstheabilitytomonitorcommunicationchannelhealth.ThechannelhealthstatusbetweenNSXManagerandthefirewallagent,betweenNSXManagerandthecontrolplaneagent,andbetweenhostandtheNSXControllercanbeseenfromtheNSXManagerUI.Inaddition,thehostcommandchanneloffersgreaterfaulttolerance.
oStandaloneEdgeL2VPNclientCLI:
PriortoNSX6.2,astandaloneNSXEdgeL2VPNclientcouldbeconfiguredonlyby'deployOVF'settingsprovidedtothevirtualcenter.CommandsspecifictostandaloneNSXEdgehavebeenaddedtoallowconfigurationusingthecommandlineinterface.
∙LogicalNetworkingandRouting
oL2BridgingInteroperabilitywithDistributedLogicalRouter:
WithVMwareNSXforvSphere6.2,L2bridgingcannowparticipateindistributedlogicalrouting.TheVXLANnetworktowhichthebridgeinstanceisconnected,willbeusedtoconnecttheroutinginstanceandthebridgeinstancetogether.
oSupportof/31prefixesonESGandDLRinterfacesperRFC3021.
oEnhancedsupportofrelayedDHCPrequestontheESGDHCPserver.
oAbilitytopreserveVLANIDs/headersinsideNSXvirtualnetworks.
oExactMatchforredistributionfilters:
TheredistributionfilterhassamematchingalgorithmasACL,soexactprefixmatchbydefault(exceptifleorgeoptionsareused).
oSupportofadministrativedistanceforstaticroute.
oAbilitytoenable,relax,ordisablecheckperinterfaceonEdge.
oDisplayASpathinCLIcommandshowipbgp
oHAinterfaceexclusionfromredistributionintoroutingprotocolsontheDLRcontrolVM.
oDistributedlogicalrouter(DLR)force-syncavoidsdatalossforeast-westroutingtrafficacrosstheDLR.North-southroutingandbridgingmaycontinueexperienceaninterruption.
oViewactiveedgeinHApair:
IntheNSX6.2webclient,youcanfindoutifanNSXEdgeapplianceistheactiveorbackupinanHApair.
oRESTAPIsupportsreversepathfilter(rp_filter)onEdge:
UsingthesystemcontrolRESTAPI,rp_filtersysctlcanbeconfiguredthroughUI,andisalsoexposedthroughRESTAPIforvNICinterfacesandsub-interfaces.SeetheNSXAPIdocumentationformoreinformation.
oBehavioroftheIPprefixGEandIPprefixLEBGProutefilters:
InNSX6.2,thefollowingenhancementshavebeenmadetoBGProutefilters:
▪LE/GEkeywordsnotallowed:
Forthenullroutenetworkaddress(definedasANYorinCIDRformat0.0.0.0/0),less-than-or-equal-to(LE)andgreater-than-or-equal-to(GE)keywordsarenolongerallowed.Inpreviousreleases,thesekeywordswereallowed.
▪LEandGEvaluesintherange0-7arenowtreatedasvalid.Inpreviousreleases,thisrangewasnotvalid.
▪Foragivenrouteprefix,youcannolongerspecifyaGEvaluethatisgreaterthanthespecifiedLEvalue.
∙NetworkingandEdgeServices
oThemanagementinterfaceoftheDLRhasbeenrenamedtoHAinterface.ThishasbeendonetohighlightthefactthattheHAkeepalivestravelthroughthisinterfaceandthatinterruptionsintrafficonthisinterfacecanresultinasplit-braincondition.
oLoadbalancerhealthmonitoringimprovements:
Deliversgranularhealthmonitoringthatreportsinformationonfailures,keepstrackoflasthealthcheckandstatuschange,andreportsfailurereasons.
oSupportVIPandpoolportrange:
Enablesloadbalancersupportforapplicationsthatrequirea
- 配套讲稿:
如PPT文件的首页显示word图标,表示该PPT已包含配套word讲稿。双击word图标可打开word文档。
- 特殊限制:
部分文档作品中含有的国旗、国徽等图片,仅作为作品整体效果示例展示,禁止商用。设计者仅对作品中独创性部分享有著作权。
- 关 键 词:
- NSX for vSphere 622 Release Notes