vSwitch and vRouter Configuration Overview


A virtual switch (vSwitch) is a logical partition of the Sun Secure Application Swtich physical platform. A vSwitch is a software construction that allows the Sun Secure Application Swtich to operate as a number of independent switches. Different vSwitches can be created to support different user organizations, data partitions, etc. Each vSwitch contains one or more virtual router (vRouter), a set of virtual services (such as SSL termination), and independent policies.

vRouters are independent IP routers. Each vRouter has its own set of IP interfaces (including Ethernet, LAG, and VLAN interfaces), route table, and access control lists (ACLs). vRouters isolate networks from each other since one vRouter will only exchange data with another if it is explicitly configured to do so.

There are two types of vSwitches-the system vSwitch and operator-defined vSwitches. The system vSwitch contains the resources used for overall management of the switch, and those resources that are shared by all vSwitches, including:

The management vRouter is resident on the system vSwitch, and isolates management traffic from data traffic in the system. The system software automatically creates the management vRouter. The software also automatically creates one shared vRouter (named shared). The system supports up to three additional vRouters, each one providing an Internet interface for the operator-defined vSwitches (and the Web servers connected to them). Each operator-defined vSwitch functions as a separate entity, serving a backend Web server group or distinct customer site. When you work with the configuration commands, you can create, modify, delete, and display vSwitch and vRouter configurations. You cannot delete the system vSwitch or its resident management vRouter. As you create a vSwitch, the system automatically creates an associated vRouter, which it names default.