VMware Networking Community
MinaMF
Enthusiast
Enthusiast
Jump to solution

ssh to DLR

Hello ,

how to ssh to any DLR if its uplink interface connected to EDGE , i can ssh to EDGE normally , but i can't do it with DLR .

thanks ,

1 Solution

Accepted Solutions
yantothen
Enthusiast
Enthusiast
Jump to solution

Hi,

You can SSH to DLR Control VM by SSH to its Protocol Address.

The Protocol Address is in the same IP subnet as your uplink segment (the segment that you connect DLR to Edge), you will configure this Protocol Address when you are configuring dynamic routing (OSPF/BGP) on your DLR.

Also make sure that:

- SSH access is enabled when you deploy the DLR.

- The firewalls on DLR and other intermediate device (e.g. ESG) are allowing the SSH traffic.

Regards,

yantothen

blog.ipcraft.net

View solution in original post

4 Replies
yantothen
Enthusiast
Enthusiast
Jump to solution

Hi,

You can SSH to DLR Control VM by SSH to its Protocol Address.

The Protocol Address is in the same IP subnet as your uplink segment (the segment that you connect DLR to Edge), you will configure this Protocol Address when you are configuring dynamic routing (OSPF/BGP) on your DLR.

Also make sure that:

- SSH access is enabled when you deploy the DLR.

- The firewalls on DLR and other intermediate device (e.g. ESG) are allowing the SSH traffic.

Regards,

yantothen

blog.ipcraft.net

MinaMF
Enthusiast
Enthusiast
Jump to solution

Thanks yantothen , it works Smiley Happy

Reply
0 Kudos
wreedMH
Hot Shot
Hot Shot
Jump to solution

Wonder why you can only SSH to it on the protocol address...???

Reply
0 Kudos
mdac
Enthusiast
Enthusiast
Jump to solution

Hi wreedMH,

This is because the protocol address is always tied to the DLR control VM for dynamic routing purposes. The interface and forwarding addresses are distributed LIF address that exist on every ESXi host in the transport zone. Although you configure these addresses on the control VM, they do not exist on the appliance itself. If you try to SSH to the gateway addresses or forwarding address, you won't be reaching the control VM, but rather a net-vdr module on an ESXi host somewhere.

Regards,

Mike

My blog: https://vswitchzero.com Follow me on Twitter: @vswitchzero
Reply
0 Kudos