Create a subnet for setting up VSP One SDS Block.
If you already created a subnet satisfying the following conditions, no more subnets need to be created because you can use the subnet for setting up VSP One SDS Block.
-
If you use an existing subnet, the number of characters must be from 1 to 63.
-
Each subnet for control network, internode network, and compute network is set with the required IP address range.
-
For the IP address range for the control network subnet, set a range of IPv4 addresses sufficient to create storage nodes (or tiebreaker node), controller nodes, and load balancers.
-
For the IP address range for the internode network subnet, set a range of IPv4 addresses sufficient to create storage nodes (or tiebreaker node).
-
For the IP address range for the compute network subnet, set a range of IPv4 addresses sufficient to create storage nodes and a compute node.
To use a combination of IPv4 and IPv6 addresses (dual stack), also set a range of IPv6 addresses sufficient to create storage nodes and a compute node.
-
-
Communication between the control network subnet and its outside is allowed.
-
Communication between the internode network subnet and its outside is not allowed.
-
To mitigate security risks, each subnet for control network, internode network, and compute network is a private subnet.
-
Private Google Access is set as enabled.
-
When placing a compute node in the VPC or subnet different from the VPC or subnet for compute network, communication between the compute network subnet and the VPC and subnet in which a compute node is to be placed must be allowed.
-
To perform remote copy (by using the Universal Replicator function) with a storage system placed in a network different from that for the subnet of VSP One SDS Block compute network, communication between the network for the compute network subnet and the network in which the storage system is installed must be allowed.
-
In the case of Multi-Zone configuration, the following subnets are created in each Zone.
-
For Zone in which storage nodes are to be installed: Control network subnet, internode network subnet, compute network subnet
-
For Zone in which tiebreaker node is to be installed: Control network subnet, internode network subnet
-
-
In the case of Multi-Zone configuration, communication between subnets of the same type in each Zone is allowed.
-
Various communications are allowed in each virtual network firewall conforming to TCP/UDP port numbers required for communication and Setting Cloud Next Generation Firewall.