From a43d72d802c984501448b7deadb009bcdf87c4f6 Mon Sep 17 00:00:00 2001 From: George T Kramer Date: Wed, 8 Mar 2017 15:02:26 -0800 Subject: [PATCH] Focusing network booting article on NAT Some of the instructions provided code that was not clear or did not work on the latest version of Clear Linux. The documentation is being updated to close these gaps. --- source/_static/images/pxe.png | Bin 0 -> 24006 bytes source/_static/images/pxe.svg | 156 ++++++++ source/network_boot.rst | 649 ++++++++++++++-------------------- 3 files changed, 412 insertions(+), 393 deletions(-) create mode 100644 source/_static/images/pxe.png create mode 100644 source/_static/images/pxe.svg diff --git a/source/_static/images/pxe.png b/source/_static/images/pxe.png new file mode 100644 index 0000000000000000000000000000000000000000..6f2eb8495bcaa682b1f63cdb07b4fc49d995979e GIT binary patch literal 24006 zcmdVCXIN8f6E+$^KqDGOBPa@rC>jgckgbGfK@=%MsL~V#E7*Y$LNTDCqM%~KfGA)> zQ&4)hA<_gX3WTQ8drcrYvsM7nckl1~{LZ^y+M2#R7b0t3?p;V&I$J~hIB1kN4M(!|6RE^dJj)9f|&YhW-h{b!Ea3d83a zPJ7JGVK56;ApaN8J|NeP!B|>o@6<4Iw(6+i#L5j(eh!TixoQhUF3wfICM;(<^6KMH z-zHHZtNg)->WA`fzWz2~d9O+MUcd@@&s#Pt%+mIl$2=d{tMo3vTlPT1-sM(DeVUv) z&;6`s*ZPhaQBs)OA7i_zxv+crQ$AZ3)YRWU@@@% zR-DcgncSJOvS;IB)VOUf_|sHQUt$KgYr&ACM75dAoQ6&xU+E#j5>L*6^bzUH+X_{t zURr)j;iibt-S#&g%fBzU{%ODF^%FY8l_f_X96K!0XEyU(!t}(* z#Hd%-oeZ9rP@3IVZQtP1&DB#I(NiH!*ULGI6Fa(e$HI>`I5A<&L0z2K&5RFDt~O3> zJDw38?oT6Vh*Z!GFc_tfD?c;JIL`e7R?7};-_njI9>rmV^i1_k;(Ei#&aUttToP35p&D z^@V6mS>_>=2`yGv{9Z2T29_&=ELU;W6GD5WXt;*>A{ANC{7vizW%eQVdj-{9sn$n8S(4s5R`St}~KbX3Z=6DsOedh}JEAf3|Dge1>{z zm#2lyp_xR*B<^*=EHK=MoH?-54nM*+cY20mFelaLcDUnDsvC^H5Y06)5N`F1kIBh& zjdNY=e1upnlRU8UZPxs7HPQi^rnt^Xd=A@p4H$@28_!oJ`Qd2Kx#i@;DFfN0J>>3D z`G8B@0smT8(M9?RRYLJ49S)BG=uqUusz4eS_fEb1ufTf^JO zI7gP@VIdQF2KV`>$i^h@b8vJi{hjBm_YtRiF8sK8+X`EMFww6b0ff;wQ`$gSZlj*f zj4z2zBR0-LqbM<2GQGz`K2x$W&O)iHz zS_5NKORS^M^+Y^zB~o4NNnSE6_IdU_1!B4t)j7Ykq9Rjepv0o$mH6n}^j`xKCe((# z9wg_U#G2T2?jerc;`jS@=c3yFjB5Kcs%^6TGi)119UoxtC10L96e}&K=C&mgD>rk8 z3qB)>p_zAS%SrYcrcE2qh@Ci8V&Qm~WIM1qE>9%=DV7!?YC=2NPi=D`(Y{*5WICm} z)hAXfOf#XgwO?ZYiOJbEBbL(gy;b8@#tH!mmcJk-PGDC8hXnsZRBB&M#rH}puSk8I z!rf7Uam2r(zFk$671(BLNl{zKjN>xYC=VRQ3R`fe#Kx30HtwwL74aqe9o$T!!8Dk^wbF*95{c^#_sE+McV#9xV zcga`ss0;p#mrO^ZqB2|h&yd;vnnAF^J$^-~G|VAjLP@Je1H;>J!?!IQPa7|zC|5@2 zw7w4WuXa7LNoZHgj;x>T)DJYh#o6DtT5l($a8-=5i3{)FkhoIqWj%KOKyZUaK+ydd zN;ajtO(99{nQ_5zb95VxFrO~;iVzhYz&9VUyII*S3cJvd_>g1XsxkeudU(m|8JzXu zSS^~#txuUu9a80}$($st-`A~@O3XOdyk^^-_%G7R-FpoNlj7Vtr8Mf>D?Ra=#sdH~!4*W52fe_#*o>tGyiBL-++#_zTEB95t z9(4U8OQJpg8vYTYr}RjK%+vib|WyyoDO0HA6*pPvOgBr{69hc(fHg=asEa zvojjC*C`c?ayOlCMAMRD?J_0Rm#}|??0?f3gB?*jbZ1XS?qi?OVWzRaAkA@mEN^aD zU@z{8PTEX$3jSW$0B4l#D06C>$Eo_c0uh<>`D*DrvE(#P41y-&#w~N}my(P;UF&wU zOlSj{ckijmB-smAT-C%!3A`K13-G{+8VLuEp3`cxzVBvfeMKW&pEkRZXeOZ95YEdog!Nw&&lN3HJq)9uTax zzG>pbV${Mgil5beeyYB`Nw!%u1gHXmI~OytN+GMbppFFxgs~V4`DGN#RXXedgL3bu zQ36*4>t1sc@3cklyLCoj)$N-ZtkxCF1Gj|CK25o@Y%r@BvTc{vw5j<(w8&Z*aL#w> zX)BhcA*Lzv|CS8jTEKIY9!pC?GOY)gQ|(*%XHr{q5dm#BBB*tVfOYv#e`Rb=Q+to` z5Fsk!$8pQ$p{(;2LYn|E9Hj0RumLzyK)F&*R7~hKC=>d}p@-yf>+&^e$q+Lh? zH6h{S!R`pTJ=b3mMx&X69T{5xfg<^^3Pq7idl�te-c`<*%mXDT?hdaU$AT(YXIZ ze7F^EZWM}MoLw?BQ!giU;Q#EcLdQZ4@QY9ojDT>!jW0xx&h($IJT{rZ+nfNRK>Xob z$QN@rJRtzqms2tXIJXLR9Bg(S+=0Cbi^&zUbAWuFdG1$DTZLi86*Ady>$jwrySiN4 zn``saL~Ao$&SfNU>m1#0AJ{;OL?N+L|JXwmlh4PLFP)Jzu*|1Y$a@yXuchhJnpo<{ zb_MF-Rg-7*Clv0xz8+;4b_k0nyEY0NRO%ff2gV5?9^;DO_LynUgA}Z!~cxDgSqdBv#pKOX>JEQbA zseTJ7v?zmDeOFZeS6J1ToVen)JqIG5VkfbDDdH_Y<@7DiJ7F_lLKTFT5cQp$bt@aI z>{J%ruyQsdHE&_&)M)*(A6)oIA+X}MgYeF4Dx}JzIIn;?wNP1Lg38bwwYRRWKjKDUNig$aHV=O} z0bAO_z_K$mV<|je6IEyDiz-&vYvR2aORct$`1K2@`m(&IU{;wBKiILYb>ijhNX}M8 z*s*&g+s%gfXHR0WXtlyplAh}@X6CIm4WMRfD*|l+Y(XTrfUC|tn`S0VT+{!MRR7bv zR4Xi*v2@udCKNSbPnEmTD)IpC^MU}6QtN9dQrbN9T8SJ&5WC4(YH*0*ftH2wphD!< zt~*2cu{Xom47ZqMt8OHGRoqw@0^S0&JQDWUvPW<{q&8GAbiEAlB0EX9R$U-v{f~E` z9{Z!iGmId11s;`#Trx$V-!=l3tg-sU(+(IQPXmM>JeUO$ukw$Cu+wz%GGm&fk4Y#$ zJPO#%Lcq?UD?~+DoR`epjf@EOe;i!J1 z)lPI@K}0b@%0zx;`L%OycJlqAwKEtw`XJPbXV_eqyy=Om`cUc;JiVuE%eK}DWsQ<5 zOZM%CD2-IM0I-7x)k%_zNg7X$NTFzWg-RG*bAzI*&6``(#&x`x*&UIst&c0`mvl!_ zlHj6iT_jfMDPhl@YlJ#>d^h49NzbJ3ualda_D{u&-ef2)Wq9p8W=tE`{nzD!!XCB= zRq*-^OGt|(IR_+oJ5d*p$IcCJr6tWr&4cbv2$92dazKmUDH^vt1REzn=^Adx&6{T( zmN?`ATGd3f%6GhYn%1vxC-N+zU`$ox$o=N`VI{v z;VOyOq~;jWm2X5v0C+C|RgEnimlh#5vZ_VRO>D~p2}v56z3Dl)*z};WlS@e&Z=D$k zNdQTV9ly_Y=Xge4LX@?;7oXg+A77h#hK^v#6K%NHF`De2;EbJ`;9*~p zs9}J)Kaqb8#RCY>Tn%YkRk^QIx0>*R*RSWccF-L0&#bu;90NCBO?>YqAA4FqmU6tOm1Mj^H0(kShNk zoUtH*{ji2|j6Qm1EIx0hs#HO@u>f5Kd+ov*l`gkr#EVP;UpW*{01|{AalyG-(=LS{inYR2vOVhg3*?~1hz80i8Ga|u2`4K4>Cn)$Qx(>(&%(~P= z3o8f;5PwZt<&yu9v6So{7piURCNpLr=Q%h6s;B`>L>+;U#8hhhHRz5Os3^Qgoh})iHNj zpt0?SM+KY%!Y{(XZ<Rb}=Y(J~D2a(hz=XelXuAFcUun=toQ^JDLq1ngfX zOlk83td@njW6HqpK;qso{8sdMHOh63;}V2D73j|zPhYo5;|~V<4?)htn5c;i>BWR_ zjzrmu^veYZ^v7W_mF)JVgeDE-Z)@dGb#Y5KUu9Nu+?;&jksk1=di z@f2)?$PhZX^sbx+NfL|1b`xYL|Fj1_MSBcnM+;ENI zT6sLfYT%~^57>1SKO9|-dEQIVA@R5FBpxZ^{s8jNrOUJ#aR&<*Fmf?KNAcz58f;8a-<$JEKAX=d+X|a|+m`}2`0n2NM&6!G2XCmD7gMyMF3whA! z0?;VLdYarMoP&S___7M%g(mK?CVl}RIwb!yu%g`oB|vIVl$s9b`iV-1Z)tZOdIJ_T zhU_q8&T`)nF+1>rXti8mryGF1MWPLqP-qd9@DE%1(Zb3ESBY_}B;ltZXkfm-bs-=% zJZ|{45-^C{hO8JlOA&}dL9Y9gNWP!bz&W)U)AXy>gd{l)mXYv6@a|IYwxU%SG2o+< zaV06DKE|qh`Bb^ceEb5I<8ln9XzW@P)|y+GPp3589qWFPIriC+GDcvY zQ%e|5Dpv5&r)Kz7LJOh#Y%Ai2zu7}`L*s_sr35fPez^xTa|%*%?t|q6Tix9|KA6O& zyAOOjVZw4*H`1s-)}_boV-2$vR5^h`bsanG=r?6}qij8vdskszdx`UgH@v|r`9f9d z=4rAIL`Wgx%70RqFM&8^C0lQMBu`S7F6erq!=frDyHnjdxXm5pUydv(TtydgY>hF^ zgq11aDD(JIr~GM^`_*on(=Tn?E?xBD9C6K_^hkpK44_1>PrzB98h-wI%2!+&o#HWa z=$|L+ba(fO+Q)zY5I7{Wzm}rxK2+cIUPvk|l%4Llf;8MyAk{sX{Zj9;3(w&!$8NCB z&3&7h&H{-(KU`3PpzJPB5`V*m`4DKlTT<00on)~-$e7mR=Asm=wy2HC zr2+W8hf9Mq+Z9wS*2?$2t2*zp(M)C0I_W1x{=3g{8l5Pu-?j0z$<%qZs>*{`l^0dX zA93Gk^|p0^i;8;zAn0=c=MovB6hbLq<;g)k2fve$HU)#YRe27eA}9HCLR9B3qxz9^_{xf69dxHBQ z6>T!7B7G#_PyX;B=wcmNj#?pHp$VFRK zW3Sic8B9Tbc?!Nb;aol!S<7*lD{8F*rqTXmd0EMX>g}1c9Ay~&eS-A0bNy2Ye}#h3 znpm%etFC3H$hFTip>cjC)_2H?=2!^-=4GNGCH>t>SaJZctj6qv(ER$ZXn^$N5K6?i z0;26LAroU-#BnBoBz}3psX_54+D5z4xfDs0XX_6A{{C+^eM#$b&E0St2`j)yC?PN& zho4F>mPI51n;3gUrS!g6n?HIuo%gfn}boe`&0eBBpxj<}jI)8eGmiqclmU3;ks zgfz~3s!yWd;w!!iloMgt2sLU?M-lg1;ph>0E^W`@%pu;GAv1?b9az(S@pkT+wmh|b zW=QFh;bfCr(vMkIW2O4_^q~exp_+)vO;idZv`4j*@-gXH-1wDozC;#8PRf^B0#`H%f?){B#nVh;nJ?=G9 zeWuk2I75;Zwb9=1M{mQSfsrpQf_kLlE&n`P^gURO``v{4iy7PH%VJYA*;jePtDPG| z#&XY@>~8F#)wBkNmkNVU{8TL#a>UCRHl=+%A6U2C+1ck5g8kq7`Qg^h#CoqEH4?V0 zuF9zVwDulDlVyg#S+qO;-Nsqo(hJXrg8CW?-@FS@v_6;?N$CGRL{IJQZgNwxC=8Mq zJQ=a784>1PaDgAmcAIs^@HIy931b@BzpyA`CdaNSLWfi=`~(C@YQncR{RqQ#tSOc- zqPfQts$HEgZhJ$JTUJr(wZ0n!c$-Z493;We>H7zGP4RWGn9R}2w8pm+;x zy~G(5BBUHe?x%~^juq|5V_zV}X!AovOUfw2U>OfKFc-4@6-LO3i}0)lBbtB#{(Qmz z7jAyKjWk^Qa=%H*-L6yIve!esmz1ni$??Oxhjw5xZzmZ2%7Leo{!j7nY1?%8zd3`#z#mzCJ ztWjD*d{kWD0e_7ZRO|NbqdP&Wx&QFdSi>XKfzjAkBeSb4jJxJ=N>akcw=HQO6sAX% z6@Ip^X$x4fpE|N~(O7ls)nx|Lb=VR$!=yZm@~*mzZeap6`byCS~mmKtIIoley&QSkxQ=WQ^EVyT* zzO&acc1cRe#NvaEvx$rC6j<`u*wJT#%sBJz2HeaGp_Ovq)48?-H|2>*XHWGlf8-+* zEj0NATl^P+=Z`w`Qb@N7eh%xKXq(@agZ3gwb9JYxe6*E*Zk~gv-U4(t@nWja}THAC6;nfR!Dea0~R@8tKHI zG5h+C+=1#o1qhb_ts=20kw|bdiOTUV?YUurtIZgxYb6i44|b;0Ym>G+@IDyI@NUHN z8vGo&Tb(&|qwVk0=`~55zM)Rb%(3R$mUd?q`ey~$%3<T99mS8`V3f#g!zxY<2-W z`YruT1J`4$HqreZqx&0YYh6d~IY+lKZc~kDpoM=puJC6>;Jckg*p&Mq#u@v@L-RHT zTUS=AC_k$C=K-bLfz8d$Bje-;Kh(4B%z+GYmH=qjIj<+Xq^UEnz1huO$xKJ0B|fKh zUS#Q4$hUsmr6eBRuWC4SM`itInI}bE^uo?3I;Xrl7wh@vlj?t6s`XC9-K5C2FDz7D zJ^13Eg#cXN*rz@xHbtv?ZnG?aMI^^tiij zL|kl+KSfMmmq_R4M{|r1)4!)XR^;T>zQJX19jWX*>MH}`?>+CvzBd(q@?Lc*pBQx^ z_PxOi&Rl6c(V-!!d6`A|wttSd8gy>{bmnTjx%}KhKix-?!LKhqk@_&=?Z^YHRGWK( zw)N(5ou}8A>zvsC?IC{u_VXL)7miyUDyfvsc~$-@w261`jdj}^F6&1=S3%x&zjT_l z1?>W^AwV6OJ6Z@O{fxznDE@;)#ad}eF-&eK?wNGi@k$|IhWacF%%efK54h}-w;vWk zTY5HS=^_da(D@FT=@s6BW`CoJ~=NtDr=6XxjnYczH#Fs4fZbS}x?h!pWhZ z*ektxzh

uN>4Y2S=O=q~{_?HoijE;UC22jWaekuQQmjcrjajGg}&JXdl%%F={6$ zO9rxDL<)9hh`!_Z9kZbCI7Cco*KiRBbZ6pt;+ki6C{7FNA7KAaQKlcHmb15Yc$S7^=Ywq4*A|Vdq1HQGyLrc? z9o)$HU^SGLO{n`CV7(uaCAs33CFh>PHh%KVm1qn?-g4;i5oTW14eY()@_LtoLIFuteTn7<@wJY zbexZGK9!xzHII^LVQnzl1^<)8?B+C&JFA~rm6$3^@*LK{Wb2){~%Kc$Jb=u3{^ zJ_W+ihEsFyg$iVYK(Vu5i0azm!NT~qXbU4CVqo6Nz*sMZS=SQ(BB?nT%#8LP#$*6t^=B-QPB$dT@_RSBXxe zq>w4@=6)AkcYB*>^5>}vgCT(M7`W4fuCg(K9y?@i!UzZ0aVYL`Tah{I`B2si#)RT? z#g*Y|%fS$p8A)6*6V-#z3kKr^b32A}?|rXFXN7TcBe>6@JX7V=eD(LGDx^6d*(SX% zJc&bcD7JVCB8@olA2{xQspvqVS`HFc!Z1_R_iZSvu2|H3C?pVZYt&|t!Ok-mQ(b$<-nCNu8dZ-R=@|5qW1D=W) zzA;q=Ee*l)nJLuUK?9D+L<_{V1Ye@l+8KT6%pC4Z!eeRr=auvHBoWcYm6iKF`KB<7 zvJ`Qci#0+Y_$&lJq-g~aSLq3&cd4+%iHUf?wCJ%4p~KpykLd-4y4G&|=5|R*kDZDc z&C_b{)BPYISbHuqRths9s7hXExc4JYj?UNoVNFSL$N&;`cWPHjjOf*pszZ0=Y|kqA6X$w(!m_<}gZ>A$lDG^1w3A|$fN#woVui`p9a zG%Vf{r^IjyCy04KE4?NxEU>R+m5cC;Qg9p8H>V_u^)azTCqX9UC^Qr;@6srh>kkz@ zqm2@t*LSm)!^AR-B2)=Qn9_b(AHcg7FuJ+Hz8@kQb(!iL6q9=E`H2V#k-P)Zu`Hq! z$`Ji`Wa~h?6>o`aRJJX=U?hCa6Eu8<@9yQIIRo}+W?0sV*TYZA2tV~*kx>(fXrbcs zq455442eyXDP`Ohom}gTNS=%IF9RvpNj_i2Pk4*jPBpM65Jf2d5Q?Bx@+@pZ6;s2M z#z5B9SiyT)p(R5f$;F#zP?|O5wIP2&esRHx!2->B1fT*EVi0Hl5>y4Ol_SF?PPp%L`#^eeu`?FRX)$5R&lZTN-#<=|%i|dE7pnrq@x{2uU z@G?X_5VM@vEC&H=a=$fp$gGIY8R>6_`()ln!tG?9eWN-@!~aInPQM7QUXW|76-hDkQ&{R5ZY$`QK-d zXw^$qK1ZURBiUjEL3SAM zVqknx+<|5zVuxpAEb_zuMleT%FZc6yX28zjAxZoWYo{nn#V{u*U=5uu?%hV77c=)x z4U83_%g$LR`;id`hGwGw^gob^D70o_2>m+v=bwpGzy{nny*2x&xDm~^Dk>-H85UhF z5pW7%fEcy5hS_1Fx_$(7!&Lj1uAhO7fzSZ~G{G3zz%oFFk?qLD#m5wEV~N8xQr2CZ z)_A%DG#GT8;#(#ZVSt~s%7-xf1*V|}CfvLWcRd!Jm^g-)zH1~f=~95wAiE(Mw>0^K zEVDR6^tTUY1IYV1cNsi!k2d~q7H;-;2BABe^C*~fHo9UNqru>l|J30%#QX~BQGF{2_7Q!t-ym#*NSuoW+8eDI-j6!c0 z`pL>NjW{%BxZdayb<_5SXc(LP?cB-(OHES=|EPl`UO)l5 zrj}NC8C%DvDs%*@#ZZ-8vhBkb))MLhwKQI?zxgXzL4p+eJ?OeaGm1eYq&I(w1dE@F zsnJm2TOwpnqLqw{9AhzVIVp6;4iYVY^%n)&$ZZNvd$-Q{6=%drW+(pVTv8U)hJ5H^ zhj#lPS7;8nEC@!AHY4{#YiMoRuA>JEL(WV!ewi9o<#t?pf4-)Q@a^{WmwNz zm_6X4!G`*xJP2@QlXi3+p==<_1|vC}5^@xVz)-;7PjoF2Dg}(KgxSxwqV#0 zWUHJctd+mHtzKe!ETlpt6l7_iKH{bf@9Wcr5CQFlOQZj`8QCgaxHv-R{r z?GM2j@977VjfW+kl+Mj;vC{ukJBz8`oBm_7B5mlUb%W|rwt%lC(#+zQ%c=t*+b@tl z{*gIQ(03+_*nAj&eNFbFQ$4K~#lwp++i#Lg*OA#9>hp5bOX@OXoPK#umXNC0cuqTZ1Ncl4}er?-4L%e zzL7)3GVhHv!ebcG@Fkg+8GDYWgfj1rHPJcrooEqoyj*Ap^2^Bt4ly(92Xc;W?{ku* zp4M_wC=ccsj`k&IViSI&e7i59Y-D|W6za{XRrf{4{nSglY_;|AKC&-z(zW~xp-|%E zE4r&wvKz8SNKfO;1jXNKAmou8Ot#<1sHlYTJaK(tzDW+e5KYy$f?e}jBNJ1#eA3hT zPzoX~yB3+dNh5_I3Ei3j*KY@Z05I}rcKW;m{0+%;PS8vN)IV-kuou;9tKNJh0M<@v zno_e#zDJsjl5-edRvX3Xb@07!TZ|}_u>kcWMYkx5EQDSS91d|f0J0(BcWjQnFaW5a z(JPQvZcmUHHn-3Rnwi*cdsrE!X$Ka~M|oO%*PB@)NsrG>go2*GupC6IK$vi( zTQz1?Q|QM6rjcw{H87w?PEj5R`H;fMNf8Z}6ZkXtSJKfbmYqfdca`+GPgM9;(sz2k}7lKZB<4Z;{^#?d#92#Nz z_c-n%*~S8DWJxun2NPl38-&ppy1xRMBZ|s73&$T3QD1cv;G6;AX%r@DY}F3IU=F&e z0mXpDJdlLl1j}BB0W-~<@IdyWtqmDMGy}`n5D`!rj+`_s_ z{NOC!xVpU2YUBrM05c*r+wwukBX*_?hEpCow$FEBrz`%`5nDq5+<1z$eC!(M&tSrkvew^z>fss(#<0f>&rjX5-o_~11N;-38Pl6R zThJK8R}Xlrm^w_1Atsz)v5p*Xh#Rzggd%Pe!oc)8#=Xc-h)k9^~?d82fw`z=gt zl^(7)CutCs#Q;G;Jp$}uhOetWf3+}Uj%Rka>bVb&O4m428#B>nz$P{4Lj#S(B#D@6 z_s!d+3oMYIOU^<7`TqtR{%(VS2S?|;BPP*7*_rHE=<2x4zr&D?T?3&U<$6&eBi35efrMkg)Q!R2x z^)jpsK}QAUE*kkl=gpWJDOQpix6a{g*ZGSZpZFi96B3Ilnj%l!$98x z$0+8jT7GETll|`-ONNL0M{C3SEO14vOzL1~O{vr+y$=6VX_va941cZYG&xIh=61kb z(TT7cvi^yawflL_ef7hIJ^l4n?Vq=GKEWFYb`b~aJiZ!xA~TIpn!>1x2ntVgDgH|P z)*hY5^cthu+c#>-hjBiHrE2|3lzCF)?(E){ZMJFf#P%)6vq<&NPblPmZ(RI!(bk^G za=F7BlE@p=F9pbDOV2Ni@N02PHWe9VVq3Fq`%FCl29yu>wIjoYlML-M?LADJO`C%E zuWY|CB1U{}7h^&k}i- z{TsPw3Np`mYrc^X=wSNMGjf~{15OI5FFR+QM+c8l8k|q1ov86HD>Ie+X-GbFUq?Q$ z#NlLN(LDRxg<64~I{7ztBooqlvi-lv6w2xxFOYgzZjQDFtJ9c77#$t- zU+XgW=<5ahKc86PSM<}*&q&;Rq*vCZe$}cO%5%}tOz6ct z3#b<+`DLM2jX3Wv&qf$Sn##;Co0E4LAz{NLh>A-9M+jkVX2`&4I^cLV_q-&yc0=2c zJGeEF_gcBi(VEhtXS1luM%Z|~B8Gt5e`U^EIC7Qk#*w%79J!U=FUlGr-52@C^nZk` zl~#_y4r)24%B24+6;HRa>!yV`^{3nt%}{^a{5oXLaO<45h8!z}6so%g>6WY>Qo2A; z7^jP&n*v86`E?z|F(gJ*_aq+WQU9%K=ROf-czJvwj4p(+ukkIxAo+VrXCYGC3)r<; zuKS?Io-Bs>_{UlY8JJRs0t0*paO_!`xlxlfy|-r$kxJ_F5pzyc; zdnnO{a46t!(BK)cw>&6;iYM?}yb$SWZIPn7FR@5h24$TlYEr=p=z1U`4V{BA0yxGz zUO{ZZ)HQQZS{G>$L4yB4s^6|QBK56bX_d%t!U&35q(c^i43`NK7(hczx2-lf&(bC!?UvVqs( zx2gD|cb?^6X9U-I=0lrfN#UU7* z{7qVptF|KsQSH(UEa>%M=W@aI5Ean+o8tdE7@V^IZ1%q`$gu)l`vwxU2N4B>X$hbS z9qo1eEniNw?`#`syt~cVzg!m<^L}|D=xxSO*29?3p-${K(0G!j3iNL8SurK=tz0j zuE++{1P-T(Ui$U}zaE^#YTt&+!bFGsJ0sflWL27r!+dLof3D$WuWWo2tHN!r&lT4y zSiH;GXwAIbCC8@g^C4xY%~z%#lvsslXnYCnH1MgY~b93PokAbzarY^zK?2*m6#xy(nV% zg^UX4s^e(99&scy>$`8;1FGA|I}_Z%pO(XDOB)?A6Wp>+36d zLb5G_Q)&w&W-`5U=EPF)6Nz#>D#K)Vo_CJjMk)W;^e{sIL(0Y4WcR}x9~J#v;Ipe& z_=q~Lx{6b!piIKEp*N8$VJ%&7FaF0a_S@nQj=e)>j|k0kmj$V=(g_di+0M|+tg`Q@Z)SUB!H;-nRK6xC>#8U1V)zgCXR{Hh0{bSvFW|?_BAyV`s!v=?K z>?`^1$b^wWdN4in+?d^FsiG)sy@3-Bn_qRv<-99*>{m>d?_I7F$$7KYW4(^P3oqk} zmdv6%Z;s627qEOQuBK$ZvpZRYJ%+C}z_UNAZZ~0NxT`$$5BIB5d7)_|`Gs(>QUMN< zKpUuirUFrgPTwzKI8-CNNVVq*Lldpeks5+er`>d4$Mhnuxn8K{nEu?JW(C_+RGZ>{ zUUeVimg<_F$Xun05om=}pFJ{K=5D=GLAJ$gnXU~U=>C;6pvN`Q^>*qM`avpQvuCXQ z4c6~R?mSXx#X)>0y#QWiz;X(&pXdJ#^q>(y(0Lzrn^AlTc)i%AyGZr9Fq-)c>uTJb zcme-2qVzeV*dr4=ffo2VIrplg%?1+QCsZ5%g*PMY0)D*_?TI1YoWbytp6m6T$Gq4^ zxK5%y@ndS%Q!5Ma9XZnz3S}Zgb06xVFlr3odpzk8jq9mxn@8jgL<4l-h9maoq*vj91pXq46$I*GmQx zigy@T2|FTG^(rIUy=^bxP#3)4XEJ`JLFl1{X2JU*T+L630|A6QtOJ>s{yiX)@!=D> zZXX;+^^uLuIk{nk9zPi=K!*?mznIv25 z7ua>XNQf$s!W`*FpsHw=gPMC446^Iv2k(RGZN_Dq=-3}eX2szgkZl+I9_kzZw93SU zzn=TlkYGeYG>l|cI0B^zXx0UnqV08tB6$*))OC~fYo-^e4|AH~+Bo4JK?mU&peYMEJ~ zRO>Pj^!@R5q(^{r%wUIeY>NicvF!PY;e>?wKrEp=1+bIIq(%0EK&L!XBs={fckqcy z&+CEheHKbomsyDlT9;(S9+;-IC$}fg?ZafcJ9(B>wl}wOR0@LWwFQ@-@p2_Iw&axI~6%X z;dfXq)sK**(9o-Zuca`P#2I;lHMWLcFq-vygY4C#$I%#CN zQeaV5JB1B={LHK`tgoS&U-N&4Pgm8=^WD!=DpztRxcq8bE@4$@H8z%-z9zCZYJrcH zFy$I_GuOR-F;3O%Lcv2G(2s_?RK7Lsg>Q zT|Q=8zfMuF#oD|GQECVwp)3kJ5f93B$#s?6t=;j}6^AwpFclj1hTD#Pe;v}#e3!yX zjGMcHY9b}0FmjzQ^szm`=hoM%1)gidqfZ!K<2L1(7li46;@oKuzTbGn0Du zO-5bD*=py|g_$M`RTr+L{3>9L=2^>*q|cHOb>DL?(9P`On4*h)kzLt3-4i=vz&te| zzCnu#z$kDfT`zm3`!~#ZuWDpYYl&gp%2;}9?7hXgOmaNSv(qea{gW--SaNvIl z=OEE9XT^&ao>hHR1gtUyvM2Bqb)=$(c_Hr(jYFXXF(3Z*aNHj_dUQ}KNE-^SW1EB? zyt{@(*qmAVYYG;IrC{D8UJ=c5XoyWEEIy8d z&a?qvOA=7@p(KQFejup)3SUd#fEYAIlN2h@ItC&Qv=t+TxC=~+GW2qr4LDc%R#n$QZm#IjE| z1w3IpzJHdG=0SaMZ}6&nYksdF1q(z7ykq92t`~B`16?Xaw^BL@cYOZTe58kWD*cY^ zas0G}{DBAPo9ol0ki&?`G}Uu@dwgjIme*bF*KPY;&7G&l-9vH+V_=orP8EkICYT|V z!D8?)f<{RSw$I{{j0&%}tth?!Tl~+xl0${BF2p{P$>?VfSm18%?h7ZGKDmBWA(LDB z%Su<(2)b0UvfGc+gJj0~gE{u`rFn-oS~IXO-vD2O7UBFsh9j7@68C8DoHr)sC0$Z+ z;bk|oYx)wq9%o+Qv`2p*{D2*ty=C{3q(=*7;!3^`y|3u>XOWeY&uyfX^_yk8=T)5_ z>2`DHI3Jg34dyf^4$x0IRz?g5lN+UQD`iw3n&aCyJtu6AizXC@B<`FTTG7W`84Ei7 zz{vJx0y6dFUD^^ImX|sdsF-%{*JyC+uZq1jOgM(;Zt&`=X#P(Q+dD567nq)eoOF~Y z-B$>dduvpGC?!dmzP`htv9qOpEbPUsTb#OgnfKZ+bJiZDD!QX57mw4I1D^eEmQSLs zsxk2tNnbI+R2)9c-nW8iO0rE(u&1@0JfrkPCU}3BwBA~=!M8TGse0`J3K zx}@Y0hvPWx;9Ym_x14vvqxT{Y5W%^ zWLLW+9Hm+v{#LGCqO+LurS@I}x2ih8=FyWhw}dMkRXetk?YzFwA5Cs=5+Y{J%uSDP zS}rx5pZDV&{R-Ls94Ad>ugv_Fora4?l~?K7^O>B5%*`~o>t*dJ7s(5hJI9usoJYtdmv}voi(HZY2{UI$uw>l-h$<+7;sP0wUUS*F}^*+FK z!8?>9Q;#SG0^G1qTi5NhI|(UGyH>=mU(Y)s&r-hY+A>pP-G@W3mGkJuAA*9<(HF6! zv_n=-Q5sT`!`T3zFy6g;$0#xj>VJ`TK6{Y#*P4+&E;23qLR9wEmbrgXb-x?8JMHql z80u4bxhZY-opzk#<6r(Jc-n+)F{VIrg~(m`c#&j0)p8M>&SxIcRT5nALra#bbn!5I!+e<2U|I4J6>VW!A z*O0ymhGWX)A27^U_BftL`W=7LN-!?e>UpJKTOJ6SKS)%ho8K$FYKH6=2`E~Sk*q(b zJ7OaXJ;?n`k*Q~79PKY+5OlUj?;UU}f6SrsTj)FOmOlMAg6~3^cUbIb z4)S{2Sjx|RhuN#=-kvRtyhO6+lKbka@cmn@Xvtby*1D{|P5%BSj-mV#f{ksof0a4% z;U=~;b5V7yn*w{cr!f43`!PF=1gV!~JT*m07cVZ`9`v&c+Q^z{zuFa5vfz_HJ zi&-aHTQ_yt39Mow9l>G^DB$2{xrVeG$OL_5Ms5S|OUENKk>Xaf`h3!ErPK3DAP zpf0%zW5#xvgcq6_T3na3d@Y}+}~1kk4KCW`F5`cUS;FQ zt1M|%`|;JncxHz5d8dH~Ct9}09==siu#;Iaf2do>ROqXCl+p7^kDFktRz2*n zaM*trIQKeuLgI0z{#p%q@j?b+zSYi@*QeEcdkyOAG0qHqcCSHBAG}fWxx=W=#_BoRT$!_fB|Zkx%C7}Y+@A#Uf7upFi~v&6dV!dSd!?>;4|tPm{o1Fgud#m=_H_nthswr1$Ysr7wS-qMk?8N<0d&l(92-SfA!jE*C7S|3fzVHQ#S;%(%R5Men^CeUg`KsSqi4`or7`J_Z`n2W^ljqEBQGY~eO3hqgN^Ac<<6WY} zN@+V%rJHZRRL(oz508P9#A zTT$}b85dWOR&8F&^S#+#M=o>`KR`<^$~3pm+lDhgyz<^qiI%Tz`Lbij`tJI>Ev_=VV>cPCV`(d3-im5%~5qmbfxvH|nh zb*Zdx^qcWYcyc6nuh*5u>(K_;)ZXCS+wij1;;94lNLH{jget(d6wbHM$GbYnO*J1H zBhw`?h&_>5=2p$Io;rJ_zVq#xSJ>Z!n-JUg1jCpOG9@)<{E)^9jh%1h(enc!8geQJ zxkwD{g-&)X=iYW+L2~BAXCAe!yysZKPP=lY{gbFQFHwqgU)5QrcE`@0vp + + + + + + + + + + + + + + + + + + + + + + + + + + + + + Page-1 + + + + Rectangle.15 + Public Network + + + + + + + Public Network + + Rectangle.14 + Private Network + + + + + + + Private Network + + Rectangle.6 + Switch + + + + + + + + + + Switch + + Rectangle + PXE Server + + + + + + + + + + PXE Server + + Rectangle.13 + Switch + + + + + + + + + + Switch + + Sheet.16 + + Rectangle.2 + PXE Client + + + + + + + + + + PXE Client + + Rectangle.3 + PXE Client + + + + + + + + + + PXE Client + + + Dynamic connector + + + + Dynamic connector.18 + + + + Dynamic connector.19 + + + + Dynamic connector.21 + + + + diff --git a/source/network_boot.rst b/source/network_boot.rst index 053a1881..2b4a4932 100644 --- a/source/network_boot.rst +++ b/source/network_boot.rst @@ -1,285 +1,310 @@ .. _network_boot: -Network booting +Network Booting ################ -Network booting is an important feature that every data center should have; -it can be used, among other things, to install an operating system. To do this, -a :abbr:`Pre-boot eXecution Environment (PXE)` is defined upon a foundation of -industry-standard Internet protocols and services, namely TCP/IP, DHCP, and -`TFTP`_. +Clear Linux* Project for Intel® Architecture is bootable from a pre-boot execution +environment (PXE) using UEFI. PXE is an industry standard for describing the +client-server interaction to network boot software using DHCP and TFTP protocols. +One use of this environment is to automatically install an operating system. -Clear Linux* Project for Intel® Architecture uses UEFI to boot, so your target -machine should be UEFI-capable. At present, the UEFI binary is not signed, so -be sure to disable secure boot. +Using an extension of PXE known as iPXE adds support for additional protocols such +as HTTP, iSCIS, ATA over Ethernet (AoE), and Fiber Channel over Ethernet (FCoE). +iPXE can also be used to enable network booting computers that lack built-in PXE +support. This guide covers how to perform an iPXE boot using: UEFI, a private network, +and network address translation (NAT). Figure 1 illustrates the assumed network topology. +.. figure:: _static/images/pxe.png + :align: center + :alt: Figure 1: PXE network topology -Network Setup Options -===================== + Figure 1: PXE network topology -There are two basic network configurations: +Preparations +============ -* Place all of your nodes behind a :abbr:`Network Address Traversal (NAT)`, or -* Connect one node to your regular network and the other to a switch - connecting all your machines. This option requires at least two network - interfaces (dual NIC). +Before performing an iPXE boot, verify the following: -Note that lack of (or incorrectly-configured) NAT can expose your cluster to external -networks. NAT allows you to control the traffic that goes to the external network. +* Your PXE server has at least two network adapters +* Your PXE server and PXE clients are connected to a switch +* Your PXE server is connected to a network +* If applicable, your PXE server has secure boot disabled -A script for NAT setup can be found on this `gist`_. Be sure -to export the DOMAIN and DNS variables to be the domain name of your internal -network (example.com) and whatever DNS servers you want to use (8.8.8.8 and -8.8.4.4 DNS can work for some situations). +.. note:: + A switch sets up a private network. Using a private network allows for greater control of which + traffic is exposed to PXE clients by isolating them on their own network. -Network Topologies -================== +.. note:: -Dual NIC --------- + Secure boot needs disabled because the UEFI binaries for booting the Clear Linux* Project for + Intel® Architecture are not signed. -.. code-block:: console - - +----------+ - | External | - | Network | - +----------+-----------+----------------+----------------+ - | | | | - | | | | - +----------+ +----------+ +----------+ +----------+ - | Network | | PXE | | PXE | | PXE | - | Boot | | Boot | | Boot | | Boot | - | Server | | Client | | Client | | Client | - +----------+ +----------+ +----------+ +----------+ - | | | | - | | | | - +----------+-----------+----------------+----------------+ - | Internal | - | Network | - +----------+ - -NAT ---- - -.. code-block:: console - - +----------+ - | External | - | Network | - +----------+ - | - | - +----------+ +----------+ +----------+ +----------+ - | Network | | PXE | | PXE | | PXE | - | Boot | | Boot | | Boot | | Boot | - | Server | | Client | | Client | | Client | - +----------+ +----------+ +----------+ +----------+ - | | | | - | | | | - +----------+-----------+----------------+----------------+ - | Internal | - | Network | - +----------+ - -Dual-NIC setup information will be added in the future. This guide currently -only covers NAT setup. - - -PXE + iPXE -=========== - -To retrieve data through other protocols such as HTTP, iSCSI, :abbr:`ATA over Ethernet -(AoE)`, or :abbr:`Fiber Channel over Ethernet (FCoE)`, an open source network boot -firmware called **iPXE** was created. iPXE provides a full PXE implementation, -enhanced with additional features. It can be used to enable network booting from -computers that lack built-in PXE support. - -Clear Linux* Project for Intel Architecture can be configured to do network -booting via HTTP, with the help of iPXE. The following sets up an iPXE -environment using Clear Linux OS for Intel Architecture; these configuration -options can also be applied elsewhere. +Configuration +============= +The below steps have been automated during the installation of the `Ister Cloud Init Service`_ to quickly enable a bulk +provisioning setup. Before running the installation scripts, modify ``parameters.conf`` with your specific configurations. Step 1 ------ -Add the ``pxe-server`` bundle to your system; this has all the bits to run a PXE -server. +Define variables that are used to parameterize the rest of the configuration of an iPXE boot. .. code-block:: console - # swupd bundle-add pxe-server + web_root=/var/www + ipxe_root=$web_root/ipxe + tftp_root=/srv/tftp + + external_iface=eno1 + internal_iface=eno2 + pxe_subnet=192.168.1 + pxe_internal_ip=$pxe_subnet.1 + pxe_subnet_mask_ip=255.255.255.0 + pxe_subnet_bitmask=24 + Step 2 ------ -Configure the ``tftpd`` service using ``dnsmasq``. To do this, populate the -:file:`/etc/dnsmasq.conf` file with the following entries: +Add the ``pxe-server`` bundle to your system. This has all of the software needed run a PXE +server. .. code-block:: console - # cat << EOF > /etc/dnsmasq.conf - enable-tftp - tftp-root=/srv/tftp/ - EOF + swupd bundle-add pxe-server + + Step 3 -------- +------ -Copy the :file:`/usr/share/ipxe/undionly.kpxe` (legacy) and -:file:`/usr/share/ipxe/ipxe-x86_64.efi` files, and place them in your TFTP -directory. - -You can also download the ``undionly.kpxe`` (legacy) and ``ipxe.efi`` (EFI) -files from the `iPXE website`_. +Download the latest network-bootable release of the Clear Linux* Project for Intel® Architecture and create an iPXE boot script. The iPXE boot script tells the PXE client which files to use for network booting the latest release. .. code-block:: console - # mkdir /srv/tftp/ - # cp /usr/share/ipxe/undionly.kpxe /srv/tftp/undionly.kpxe - # cp /usr/share/ipxe/ipxe-x86_64.efi /srv/tftp/ipxe.efi - -**Note**: If booting with a 32-bit UEFI, copy the -:file:`/usr/share/ipxe/ipxe-i386.efi` file instead. + rm -rf $ipxe_root + mkdir -p $ipxe_root + curl -o /tmp/clear-pxe.tar.xz https://download.clearlinux.org/current/clear-$(curl https://download.clearlinux.org/latest)-pxe.tar.xz + tar -xJf /tmp/clear-pxe.tar.xz -C $ipxe_root + ln -sf $(ls $ipxe_root | grep 'org.clearlinux.*') $ipxe_root/linux + cat > $ipxe_root/ipxe_boot_script.txt << EOF + #!ipxe + kernel linux quiet init=/usr/lib/systemd/systemd-bootchart initcall_debug tsc=reliable no_timer_check noreplace-smp rw initrd=initrd + initrd initrd + boot + EOF Step 4 ------- -Start the dnsmasq service with: +The ``pxe-server`` bundle comes with a lightweight nginx web server. Create a configuration file for +the web server which will serve iPXE content to PXE clients. .. code-block:: console - # systemctl start dnsmasq.service + mkdir -p /etc/nginx + cat > /etc/nginx/nginx.conf << EOF + server { + listen 80; + server_name localhost; + location / { + root $ipxe_root; + autoindex on; + } + } + EOF + Step 5 ------- -The kernel (linux), initramfs (initrd) and the iPXE scripts are transported via -HTTP. Download the Linux kernel and initrd files, and put them in the http -server root ``/var/www/pxe/``. +Start the nginx web server and enable startup on boot .. code-block:: console - # mkdir -p /var/www/pxe/ - # version=$(curl https://download.clearlinux.org/latest) - # curl -o /var/www/pxe/clear-${version}-pxe.tar.xz https://download.clearlinux.org/current/clear-${version}-pxe.tar.xz - # tar -xJf /var/www/pxe/clear-${version}-pxe.tar.xz -C /var/www/pxe/ && rm /var/www/pxe/clear-${version}-pxe.tar.xz - # unset version + systemctl start nginx + systemctl enable nginx + + Step 6 -------- +------ -Create an iPXE script named ``ipxe_boot_script.txt`` under the http server root -:file:`/var/www/pxe/`. +Enable chainloading by placing a copy of iPXE firmware on a TFTP server. Chainloading allows +machines with both BIOS and UEFI implementations to boot using iPXE. .. code-block:: console - # cat << EOF > /var/www/pxe/ipxe_boot_script.txt - #!ipxe - - kernel linux quiet rdinit=/usr/lib/systemd/systemd-bootchart initcall_debug tsc=reliable no_timer_check noreplace-smp rw initrd=initrd - initrd initrd - boot - EOF + rm -rf $tftp_root + mkdir -p $tftp_root + ln -sf /usr/share/ipxe/ipxe-x86_64.efi $tftp_root/ipxe-x86_64.efi + ln -sf /usr/share/ipxe/undionly.kpxe $tftp_root/undionly.kpxe + cat > /etc/dnsmasq.conf << EOF + enable-tftp + tftp-root=$tftp_root + EOF -If your kernel is not already named ``linux``, either rename the kernel or create a symlink. + systemctl enable dnsmasq -.. code-block:: console +.. note:: - # kernel=$(find /var/www/pxe/ -name 'org.clearlinux.*') - # ln -s ${kernel} /var/www/pxe/linux - # unset kernel + ``dnsmasq`` is a lightweight implementation of a DNS server, a DHCP server, and a TFTP server. It + is only being enabled now to start automatically on boot and not started because it's DNS server + conflicts with the DNS stub listener offered by systemd-resolved. Step 7 ------- -Create a configuration file for the http service (nginx in this example) to -serve the kernel, initramfs, and ipxe_boot_script in -:file:`/etc/nginx/nginx.conf` with the following: +Configure a DNS server for PXE clients on the private network. Set the DNS server to listen on a +dedicated IP address. PXE clients on the private network can then use this IP address for DNS resolution. Disable the +DNS stub listener included with systemd-resolved to avoid a conflict with the DNS server offered by +``dnsmasq``. .. code-block:: console - # mkdir /etc/nginx/ - # cat << EOF > /etc/nginx/nginx.conf - server { - listen 80; - server_name hostname; - server_name_in_redirect off; - location / { - root /var/www/pxe; - autoindex on; - index index.html index.htm; - } - } - EOF + mkdir -p /etc/systemd + cat > /etc/systemd/resolved.conf << EOF + [Resolve] + DNSStubListener=no + EOF + + cat >> /etc/dnsmasq.conf << EOF + listen-address=$pxe_internal_ip + EOF + + systemctl stop systemd-resolved + systemctl restart dnsmasq + systemctl start systemd-resolved + +.. note:: + + Using the DNS server provided by ``dnsmasq`` so that the list of DNS servers identified by systemd-resolved + for the network connection can be dyanmically updated for the PXE clients on the private network. In effect, this creates a proxy DNS server. Step 8 -------- +------ -Start the nginx service: +Assign a static IP address to the network adapter for the private network. systemd-networkd will try to always +use DHCP for all network adapters, so this functionality nees disabled prior to assinging a static +IP address. .. code-block:: console - # systemctl start nginx.service + mkdir -p /etc/systemd/network + + ln -sf /dev/null /etc/systemd/network/80-dhcp.network + + cat > /etc/systemd/network/80-external-dynamic.network << EOF + [Match] + Name=$external_iface + [Network] + DHCP=yes + EOF + + cat > /etc/systemd/network/80-internal-static.network << EOF + [Match] + Name=$internal_iface + [Network] + DHCP=no + Address=$pxe_internal_ip/$pxe_subnet_bitmask + EOF + + systemctl restart systemd-networkd + Step 9 ------- -To use PXE chainloading, set up ISC DHCPD to first assign ``undionly.kpxe`` to any -legacy PXE clients, and to then assign boot configuration to iPXE clients. Do this -by telling ISC DHCPD to make the assignments based on the DHCP user class. Here’s -one way to do this using the :file:`/etc/dhcpd.conf` file: +Configure a DHCP server to dyanmically allocate IP addresses to PXE clients on the private network. +Create a file where the DHCP server can maintain the leased IP addresses. .. code-block:: console - allow booting; - allow bootp; - DHCPDARGS="interface"; - - # Set up a class to assign an "IP only" to devices attempting network boot. - class "pxeclients" { - match if substring(option vendor-class-identifier, 0, 9) = "PXEClient"; - next-server 192.168.1.1; - if exists user-class and option user-class = "iPXE" { - filename "http://my.web.server/ipxe_boot_script.txt"; - } elsif exists client-arch and option client-arch = 9 { - # client-arch = 9 (64-bit EFI) - filename "ipxe.efi"; - } else { - # client-arch = 0 (Standard PC BIOS) - filename "undionly.kpxe"; - } - } - - # Private subnet, in case you aren't able to run your own network wide DHCP service. - # Works when the machine you are network booting has two network interfaces, - # one connected to the private PXE boot network and the other connected to an external - # network. - subnet 192.168.0.0 netmask 255.255.0.0 { - pool { - # These IPs will only be asigned to PXE clients - allow members of "pxeclients"; - range 192.168.1.150 192.168.1.254; - } - - # If you are not doing the NAT setup do not add the following to this - # section. These IPs will be assigned to the hosts when they boot and - # after they have been installed - range 192.168.1.2 192.168.1.149; - default-lease-time 600; - max-lease-time 7200; - option subnet-mask 255.255.0.0; - option broadcast-address 192.168.255.255; - option routers 192.168.1.1; - # If your external network runs its own DNS servers then replace the - # following with those - option domain-name-servers 8.8.8.8, 8.8.4.4; - # You can leave this change this or remove it. It changes the FQDNs - # of your hosts. So host bob can be accessed (from this machine) at - # bob.example.com - option domain-name "example.com"; - } + cat > /etc/dhcpd.conf << EOF + option space ipxe; + option ipxe-encap-opts code 175 = encapsulate ipxe; + option ipxe.priority code 1 = signed integer 8; + option ipxe.keep-san code 8 = unsigned integer 8; + option ipxe.skip-san-boot code 9 = unsigned integer 8; + option ipxe.syslogs code 85 = string; + option ipxe.cert code 91 = string; + option ipxe.privkey code 92 = string; + option ipxe.crosscert code 93 = string; + option ipxe.no-pxedhcp code 176 = unsigned integer 8; + option ipxe.bus-id code 177 = string; + option ipxe.bios-drive code 189 = unsigned integer 8; + option ipxe.username code 190 = string; + option ipxe.password code 191 = string; + option ipxe.reverse-username code 192 = string; + option ipxe.reverse-password code 193 = string; + option ipxe.version code 235 = string; + option iscsi-initiator-iqn code 203 = string; + option ipxe.pxeext code 16 = unsigned integer 8; + option ipxe.iscsi code 17 = unsigned integer 8; + option ipxe.aoe code 18 = unsigned integer 8; + option ipxe.http code 19 = unsigned integer 8; + option ipxe.https code 20 = unsigned integer 8; + option ipxe.tftp code 21 = unsigned integer 8; + option ipxe.ftp code 22 = unsigned integer 8; + option ipxe.dns code 23 = unsigned integer 8; + option ipxe.bzimage code 24 = unsigned integer 8; + option ipxe.multiboot code 25 = unsigned integer 8; + option ipxe.slam code 26 = unsigned integer 8; + option ipxe.srp code 27 = unsigned integer 8; + option ipxe.nbi code 32 = unsigned integer 8; + option ipxe.pxe code 33 = unsigned integer 8; + option ipxe.elf code 34 = unsigned integer 8; + option ipxe.comboot code 35 = unsigned integer 8; + option ipxe.efi code 36 = unsigned integer 8; + option ipxe.fcoe code 37 = unsigned integer 8; + option ipxe.vlan code 38 = unsigned integer 8; + option ipxe.menu code 39 = unsigned integer 8; + option ipxe.sdi code 40 = unsigned integer 8; + option ipxe.nfs code 41 = unsigned integer 8; + + class "PXE-Chainload" { + match if substring(option vendor-class-identifier, 0, 9) = "PXEClient"; + + next-server $pxe_internal_ip; + if exists user-class and option user-class = "iPXE" { + filename "http://$pxe_internal_ip/ipxe_boot_script.txt"; + } + elsif substring(option vendor-class-identifier, 0, 20) = "PXEClient:Arch:00007" or substring(option vendor-class-identifier, 0, 20) = "PXEClient:Arch:00008" or substring(option vendor-class-identifier, 0, 20) = "PXEClient:Arch:00009" { + filename "ipxe-x86_64.efi"; + } + elsif substring(option vendor-class-identifier, 0, 20) = "PXEClient:Arch:00000" { + filename "undionly.kpxe"; + } + } + + subnet $pxe_subnet.0 netmask $pxe_subnet_mask_ip { + authoritative; + option routers $pxe_internal_ip; + option domain-name-servers $pxe_internal_ip; + + pool { + allow members of "PXE-Chainload"; + range $pxe_subnet.128 $pxe_subnet.253; + default-lease-time 600; + max-lease-time 3600; + } + + pool { + deny members of "PXE-Chainload"; + range $pxe_subnet.2 $pxe_subnet.127; + default-lease-time 3600; + max-lease-time 21600; + } + } + EOF + + mkdir -p /var/db + touch /var/db/dhcpd.leases + + systemctl enable dhcp4 + systemctl restart dhcp4 This ensures that either iPXE image (``undionly.kpxe`` for BIOS or ``ipxe.efi`` for EFI) is handed out only when the DHCP request comes from a legacy PXE client @@ -287,185 +312,49 @@ or from a UEFI client, respectfully. Once iPXE loads, the DHCP server will direc boot from options configured in your ``http://my.web.server/real_boot_script.txt`` file. -Note. +.. note:: -``192.168.1.1`` is set to the address your TFTP server is using. + There are three places in which a DHCP server can be used: systemd-networkd, dnsmasq, and dhcpd. + Using dhcpd because it's part of ISC and is more flexible for iPXE booting. -``my.web.server`` is set to the address your web server is using. +.. note:: -``DHCPDARGS`` is set to the interface you are using. + Include iPXE-specific options from http://www.ipxe.org/howto/dhcpd in your DHCPD -If you are doing a NAT setup then you need to set ``interface`` to the interface -connected to the internal network. +.. note:: + + By defining only one subnet with the correct range, the DHCP server will be bound only to the interface + and service requests for the private network. Step 10 ------- -There are several DHCP options specific to `iPXE`_ which are -not recognized by the standard ISC DHCPD installation. To add suport for these -options, add the following to the top of your :file:`/etc/dhcpd.conf`: +Configure NAT so that traffic from the private network can be routed externally. This effectively +turns the PXE server into a router. .. code-block:: console - ################################################### - # iPXE-specific options # - # Source: http://www.ipxe.org/howto/dhcpd # - ################################################### - option space ipxe; - option client-arch code 93 = unsigned integer 16; - option ipxe-encap-opts code 175 = encapsulate ipxe; - option ipxe.priority code 1 = signed integer 8; - option ipxe.keep-san code 8 = unsigned integer 8; - option ipxe.skip-san-boot code 9 = unsigned integer 8; - option ipxe.syslogs code 85 = string; - option ipxe.cert code 91 = string; - option ipxe.privkey code 92 = string; - option ipxe.crosscert code 93 = string; - option ipxe.no-pxedhcp code 176 = unsigned integer 8; - option ipxe.bus-id code 177 = string; - option ipxe.bios-drive code 189 = unsigned integer 8; - option ipxe.username code 190 = string; - option ipxe.password code 191 = string; - option ipxe.reverse-username code 192 = string; - option ipxe.reverse-password code 193 = string; - option ipxe.version code 235 = string; - option iscsi-initiator-iqn code 203 = string; - # Feature indicators - option ipxe.pxeext code 16 = unsigned integer 8; - option ipxe.iscsi code 17 = unsigned integer 8; - option ipxe.aoe code 18 = unsigned integer 8; - option ipxe.http code 19 = unsigned integer 8; - option ipxe.https code 20 = unsigned integer 8; - option ipxe.tftp code 21 = unsigned integer 8; - option ipxe.ftp code 22 = unsigned integer 8; - option ipxe.dns code 23 = unsigned integer 8; - option ipxe.bzimage code 24 = unsigned integer 8; - option ipxe.multiboot code 25 = unsigned integer 8; - option ipxe.slam code 26 = unsigned integer 8; - option ipxe.srp code 27 = unsigned integer 8; - option ipxe.nbi code 32 = unsigned integer 8; - option ipxe.pxe code 33 = unsigned integer 8; - option ipxe.elf code 34 = unsigned integer 8; - option ipxe.comboot code 35 = unsigned integer 8; - option ipxe.efi code 36 = unsigned integer 8; - option ipxe.fcoe code 37 = unsigned integer 8; - option ipxe.vlan code 38 = unsigned integer 8; - option ipxe.menu code 39 = unsigned integer 8; - option ipxe.sdi code 40 = unsigned integer 8; - option ipxe.nfs code 41 = unsigned integer 8; + iptables -t nat -F POSTROUTING + iptables -t nat -A POSTROUTING -o $external_iface -j MASQUERADE + systemctl enable iptables-save.service + systemctl restart iptables-save.service + systemctl enable iptables-restore.service + systemctl restart iptables-restore.service -Step 11 -------- + mkdir -p /etc/sysctl.d + echo net.ipv4.ip_forward=1 > /etc/sysctl.d/80-nat-forwarding.conf + echo 1 > /proc/sys/net/ipv4/ip_forward -Create an empty :file:`/var/db/dhcpd.leases` file. -.. code-block:: console +.. note:: - # mkdir /var/db/ - # touch /var/db/dhcpd.leases + The firewall MASQUERADEs, or translates packets to make them appear as if they are coming + from the PXE server. This hides the PXE clients from the network. -Step 12 -------- - -If you are doing the NAT setup skip this we will do it at the end. - -Start the dhcp service: - -.. code-block:: console - - # systemctl start dhcp4.service - -Step 13 -------- - -From here on out we are doing NAT specific steps. Set your external and -internal network interface names to variables for convenience. - -.. code-block:: console - - # export external_iface=eno0 - # export internal_iface=eno1 - -Disable auto-starting dhcp for all interfaces - -.. code-block:: console - - # mkdir -p /etc/systemd/network/ - # cd /etc/systemd/network/ - # ln -s /dev/null 80-dhcp.network - -Set your external and internal network interfaces to behave accordingly. You -may need to change the external.network if the external network is not going to -assign this machine an IP via dhcp. The internal network address corresponds to -the settings in dhcpd.conf - -.. code-block:: console - - # cat << EOF > 80-external-dynamic.network - [Match] - Name=$external_iface - [Network] - DHCP=yes - EOF - # cat << EOF > 80-internal-static.network - [Match] - Name=$internal_iface - [Network] - Address=192.168.1.1/16 - EOF - -Step 14 -------- - -Configure iptables to forward all traffic coming from inside the NAT to the -external network. Without this swupd will not be able to connect to the -internet. - -.. code-block:: console - - # cat << EOF > ~/natrules - *nat - :PREROUTING ACCEPT [5077:516379] - :INPUT ACCEPT [5054:514369] - :OUTPUT ACCEPT [147:7526] - :POSTROUTING ACCEPT [114:5508] - :PROXY - [0:0] - -A POSTROUTING -o $external_iface -j MASQUERADE - COMMIT - *filter - :INPUT ACCEPT [338542:30287508] - :FORWARD ACCEPT [168279:154877988] - :OUTPUT ACCEPT [49875:536021461] - -A FORWARD -i $external_iface -o $internal_iface -m state --state RELATED,ESTABLISHED -j ACCEPT - -A FORWARD -i $internal_iface -o $external_iface -j ACCEPT - -A FORWARD -j REJECT --reject-with icmp-host-prohibited - COMMIT - EOF - # iptables-restore ~/natrules - # for unitfile in $(cd /usr/lib/systemd/system/; ls ip*) - do - systemctl enable ${unitfile} - systemctl start ${unitfile} - done - -Tell the kernel to forward packets. Without this the above rules do nothing. - -.. code-block:: console - - # echo 1 > /proc/sys/net/ipv4/ip_forward - # echo net.ipv4.ip_forward=1 > /etc/sysctl.conf - -Step 15 -------- - -Restart all your networking. If you did something wrong then you may loose -connection if you are working over ssh. - -.. code-block:: console - - # systemctl restart systemd-networkd - # systemctl restart dhcp4.service +.. note:: + Tell the Linux kernel to forward network packets on to different interfaces. Otherwise + NAT will not work. PXE + GRUB ========== @@ -501,7 +390,7 @@ Add the following content to your :file:`/etc/dhcpd.conf` file: grubx64. } - # Private subnet, in case you are able to run your own network wide DHCP service. + # private network, in case you are able to run your own network wide DHCP service. # Works when the machine you are network booting has two network interfaces, # one connected to the private PXE boot network and the other connected to an external # network. @@ -605,33 +494,7 @@ following content: Where the Linux kernel is named ``linux`` and the initrd ``initrd``. -TFTP configuration ------------------- - -Clear Linux OS for Intel Archiecture uses ``dnsmasq`` to provide the tftpd -service. It requires the following entries exist in :file:`/etc/dnsmasq.conf`: - -.. code-block:: console - - enable-tftp - tftp-root=/srv/tftp/ - -The Linux kernel and initrd files can be downloaded from - https://download.clearlinux.org/current/ (with a name like - ``clear-$version-pxe.tar.xz``) as a compressed tar file containing two - clearly-labeled files that should be moved to the tftp root (``/srv/tftp/``, - per the tftp server configuration), as ``linux`` and ``initrd`` respectively. - The bootloader :file:`grubx64.efi` and its configuration file -:file:`grub.cfg` should also be placed in the tftp root ``/srv/tftp/``. - -Now start the tftp service with this command: - -.. code-block:: console - - systemctl start dnsmasq.service - - .. _TFTP: http://download.intel.com/design/archives/wfm/downloads/pxespec.pdf -.. _gist: https://gist.github.com/pdxjohnny/d6945910bf7bed962438bf64e70a6a40 .. _iPXE website: http://boot.ipxe.org/ .. _iPXE: http://ipxe.org/ +.. _Ister Cloud Init Service: https://github.com/gtkramer/ister-cloud-init-svc \ No newline at end of file