Azure Stack Hub 耐用網路設定生命週期管理Azure Stack Hub ruggedized network configuration lifecycle management

本主題涵蓋網路設定的生命週期管理。This topic covers lifecycle management for network configuration.

更新設定Update configuration

在欄位中更新切換設定的方法。A methodology for updating switch configurations in the field. 這適用于所有和任何類型的設定更新。This applies to all and any type of configuration updates. 由於我們的控制項之外有許多未知的變數,例如客戶或 OEM 所套用的手動設定,因此將會是多步驟的手動程式。Due to many unknown variables outside of our control, like manual configurations applied by customers or by the OEM this will be a multi-step manual process. 目前無法保證在維護期間執行的執行時間和更新。At this time there is no guarantee of uptime and updates should be performed during a maintenance window.

# 1- 製作 tor1、tor2 和 BMC 交換器之目前設定檔的備份。#1 - Make a backup of the current configuration files for tor1, tor2 and BMC switches. 從交換器複製這些檔案。Copy these files off the switch.

# 2- 記下現有設定的工具組組建編號。#2 - Make a note of the toolkit build number of the existing configuration. 所有設定在 motd 橫幅中都應該有這項功能。All configurations should have this in the motd banner. 搜尋 "BUILDNUMBER"Do a search for "BUILDNUMBER"

# 3- 使用步驟 # 中的相同工具組版本重新產生初始設定二級.#3 - Regenerate the initial configurations using the same toolkit version from step #2.

# 4- 將步驟3中的設定載入 # 至各自的參數。#4 - Load the configurations from step #3 onto their respective switches. 這點 是為了讓我們的工具 透過切換參數所產生的設定,以取得基準。The point of this is to wash the config generated by our tools through a switch to get a baseline. 這可能是由 OEM 在不同的硬體上執行,例如在 OEM 的實驗室中,或與客戶的現場。This could be performed by the OEM on separate hardware, like in the OEM’s lab, or onsite with the customer.

# 5- 建立步驟4中的配置檔案備份 # ,然後將它複製到遠端位置#5 - Make a backup of the config file from step #4 and copy it to a remote location

# 6- 使用至您選擇的差異工具,將步驟1中目前設定的備份與 # 步驟5中基準設定的備份進行比較 # 。#6 - Using to the diff tool of your choice compare the backup of the current config from step #1 to the backup of the baseline configuration from step #5. 針對每個裝置所升級的交換器設定,記下所有差異的附注/複本。Make a note/copy of all the differences that should be carried over to the upgraded switch configuration per device.

# 7- 執行將會產生更新交換器設定的新工具組。#7 - Run the new toolkit that will generate the updated switch configurations.

# 8- 將步驟6的差異合併至新的交換器設定。#8 - Merge the differences from step 6 into the new switch configurations.

# 9- 將新的設定載入至個別的交換器,並從我們的工具執行輸出目錄中提供的 post 驗證命令。#9 - Load the new configurations onto the respective switches and run the post validation commands provided in the output directory from our tooling.

# 10- 儲存設定。#10 - Save the configurations.

NTPNTP

您可以使用具特殊權限的端點 (PEP) 來更新 Azure Stack 中的時間伺服器。You can use the privileged endpoint (PEP) to update the time server in Azure Stack. 請使用可解析為兩個或更多 NTP 伺服器 IP 位址的主機名稱。Use a host name that resolves to two or more NTP server IP addresses.

Azure Stack 會使用網路時間通訊協定 (NTP) 連線至網際網路上的時間伺服器。Azure Stack uses the Network Time Protocol (NTP) to connect to time servers on the Internet. NTP 伺服器會提供精確的系統時間。NTP servers provide accurate system time. 在 Azure Stack 的實體網路交換器、硬體生命週期主機、基礎結構服務和虛擬機器上,都會使用時間。Time is used across Azure Stack's physical network switches, hardware lifecycle host, infrastructure service, and virtual machines. 如果時鐘不同步,Azure Stack 可能會發生嚴重的網路和驗證問題。If the clock isn't synchronized, Azure Stack may experience severe issues with the network and authentication. 記錄檔、文件和其他檔案可能會以不正確的時間戳記建立。Log files, documents, and other files may be created with incorrect timestamps.

需提供一部時間伺服器 (NTP) 讓 Azure Stack 同步處理時間。Providing one time server (NTP) is required for Azure Stack to synchronize time. 在部署 Azure Stack 時,您應提供 NTP 伺服器的位址。When you deploy Azure Stack, you provide the address of an NTP server. 時間是重要的資料中心基礎結構服務。Time is a critical datacenter infrastructure service. 如果服務有所變更,您就需要更新時間。If the service changes, you will need to update the time.

Azure Stack 支援將時間與一部時間伺服器 (NTP) 進行同步處理。Azure Stack supports synchronizing time with only one time server (NTP). 您無法為 Azure Stack 提供多個 NTP 來同步處理時間。You cannot provide multiple NTPs for Azure Stack to synchronize time with. 建議您設定可解析為多部 NTP 伺服器的 DNS 專案。It is recommended to setup DNS entry that resolves to multiple NTP servers.

更新 NTP 部署後Update NTP post deployment

  1. 連接到具有特殊許可權的端點 (PEP) 。Connect to the privileged endpoint (PEP). 您不需要開啟支援票證來解除鎖定具特殊許可權的端點。You don't need to open a support ticket to unlock the privileged endpoint. |

  2. 執行下列命令以檢閱目前設定的 NTP 伺服器:Run the following command to review the current configured NTP server:

    Get-AzsTimeSource
    
  3. 執行下列命令來更新 Azure Stack,以使用新的 NTP 伺服器並立即同步處理時間:Run the following command to update Azure Stack to use the new NTP Server and to immediately synchronize the time:

    Set-AzsTimeSource -Timeserver NEWTIMESERVER -resync
    

    注意

    此程式不會更新實體交換器上的時間伺服器。This procedure doesn’t update the time server on the physical switches.

DNSDNS

更新 Azure Stack 中的 DNS 轉寄站Update the DNS forwarder in Azure Stack

Azure Stack 基礎結構必須至少有一個可連線的 DNS 轉寄站,才能解析外部名稱。At least one reachable DNS forwarder is necessary for the Azure Stack infrastructure to resolve external names. 部署 Azure Stack 時必須提供 DNS 轉寄站。A DNS forwarder must be provided for the deployment of Azure Stack. 該輸入會用來作為 Azure Stack 內部 DNS 伺服器的轉寄站,並針對驗證、市集管理或使用情況等服務啟用外部名稱解析。That input is used for the Azure Stack internal DNS servers as forwarder, and enables external name resolution for services like authentication, marketplace management, or usage.

DNS 是可變更的重要資料中心基礎結構服務,若真的有變更,則必須更新 Azure Stack。DNS is a critical datacenter infrastructure service that can change, and if it does, Azure Stack must be updated.

本文將說明如何使用具特殊權限的端點 (PEP) 來更新 Azure Stack 中的 DNS 轉寄站。This article describes using the privileged endpoint (PEP) to update the DNS forwarder in Azure Stack. 建議您使用兩個可靠的 DNS 轉寄站 IP 位址。It is recommended that you use two reliable DNS forwarder IP addresses.

  1. 連接到具有特殊許可權的端點 (PEP) 。Connect to the privileged endpoint (PEP). 您不需要開啟支援票證來解除鎖定具特殊許可權的端點。You don't need to open a support ticket to unlock the privileged endpoint.

  2. 執行下列命令以檢閱目前設定的 DNS 轉寄站。Run the following command to review the current configured DNS forwarder. 或者,您也可以使用系統管理員入口網站區域屬性:As an alternative, you can also use the admin portal region properties:

    Get-AzsDnsForwarder
    
  3. 執行下列命令,可將 Azure Stack 更新為使用新的 DNS 轉寄站:Run the following command to update Azure Stack to use the new DNS forwarder:

    Set-AzsDnsForwarder -IPAddress "IPAddress 1", "IPAddress 2" 
    
  4. 檢查命令的輸出中是否有任何錯誤。Review the output of the command for any errors.