VMware vNetwork Distributed Switch Benefits



 VMware vNetwork Distributed Switch Benefits

In summary, network configuration at the datacenter level offers several advantages.

·         First, it simplifies datacenter setup and administration by centralizing network configuration. For example, adding a new host to a cluster and making it vMotion compatible is much easier.
·         Also, distributed ports migrate with their clients. So, when you migrate a virtual machine with vMotion, the distributed port statistics and policies move with the virtual machine, thus simplifying debugging and troubleshooting.
·         And, enterprise networking vendors can provide proprietary networking interfaces to monitor, control and manage virtual networks.

Tuesday, September 11, 2012
Tag :

Standard vSwitch vs. Distributed Switch

Standard vSwitch vs. Distributed Switch

Similarities in vNetwork Standard Switch & vNetwork Distributed Switch 
·         Both work on Layer 2
·         Both Supports VLAN’s
·         Both understand 802.1q VLAN encapsulation
·         Both Supports NIC Teaming
·         Both can do traffic shaping for the outbound (TX) traffic
Features only available in Distributed Switch 
·         Supports traffic shaping for inbound (RX) Traffic
·         Centralized management interface through vCenter
·         Supports Private VLAN’s (PVLAN’s)

VMware vNetwork standard switches and distributed switches Maximums


                     This table summarizes the recommended maximum number of various virtual networking devices for vNetwork standard switches and distributed switches
Sunday, September 9, 2012
Tag :

Step by step Create a vNetwork Distributed Virtual Switch

Create a vNetwork Distributed Virtual Switch

In vCenter, click Home > Inventory > Networking.



Right Click on Data Center and Select New vNetwork Distributed Switch.


Choose vNetwork Distribute Switch version


Specify the Name of the vNetwork Distributed Switch & the number of dvUplink ports 


Select the hosts will be using this vNetwork Distributed Switch. In case the host you are planning is not listed than select Add later and click on NEXT.


Click on Finish to create a new vNetwork Distributed Switch



Boot Bank Partitions in ESXi 3.X & ESXi 4.X


                      In case of ESXi upgrade, ESXi implements a dual-image architecture. Dual-Image architecture in boot disk maintains two partitions these partitions are referred as boot banks.  One boot bank will be carrying active image of ESXi and referred to as the primary boot bank. Other boot bank referred as alternate boot bank will be carrying the previous ESXi image. Boot bank partition can be viewed using VI Client connected to ESX Host.

ESXi Host -> Configuration -> Storage.  From the list of datastores select the boot disk, and then from the Datastore Details section select properties. In ESXi 3.X boot bank partition was of 48 MB & in case of ESXi 4.X size of boot bank partition is 250 MB.


During ESXi upgrade process the current active image will be copied to the alternate boot bank from primary boot bank and new image will get installed to the primary book bank. This dual-image approach helps quick failing back to previous image in-case of any issue arise after patch deployment or up-gradation.


To fallback to previous image, one simply need to reboot the host and press Shift + R at the beginning of boot process to instruct the boot loader to boot from the alternate boot bank.


After Fallback


Default Partition created by ESX4


    VMcore  –> 110 MB
    SWAP      –> 600 MB
    Ext3 (/)  –> 5 GB
    /Boot      –> 1.10 GB
    /var/log –> 2 GB

    Port used by vSphere 4



    1. Vmotion : 8000
    2. HA traffic : 2050–2250 and 8042–8045
    3. Traffic between ESX hosts for VMware Fault Tolerance : 8100, 8200
    4. Transactions to iSCSI storage devices : 3260
    5. Transactions from NFS storage devices : 2049
    6. vSphere Client uses ports 80 to communicate with vCenter Server and Port 443 to communicate with ESX server
    7. Port 902 : vCenter Server uses this port to send data to vCenter Server managed hosts. 

    Port 902 is the port that vCenter Server assumes is available when sending data to an    ESX host. VMware does not support configuring a different port for this connection.
    1. Port 443 : The vSphere Client, vSphere Web Access Client, and SDK use this port to send data to     vCenter Server managed hosts. Also, the vSphere Client, vSphere Web Access Client, and SDK, when connected directly to an ESX host, use this port to support any management functions related to the server and its virtual machines. Port 443 is the port that clients assume is available when sending data to the ESX host. VMware does not support configuring a different port for these connections.
    2. Port 903: The vSphere Client and vSphere Web Access use this port to provide a

    connection for guest operating system MKS activities on virtual machines. It isthrough this port that users interact with the guest operating systems andapplications of the virtual machine.

    VMware does not support configuring a different port for this function.

    Private VLANs Architecture in VMware vNetwork Distributed Switch




    Private VLANs allow you to isolate traffic between virtual machines in the same isolated VLAN. They provide additional security between virtual machines on the same subnet without exhausting VLAN number space.

     PVLANs are useful on a DMZ where the server needs to be available to external connections and possibly internal connections, but rarely needs to communicate with the other servers on the DMZ. A PVLAN can be configured to allow the servers to only communicate with the default gateway on the DMZ, denying communication between the servers. If one of the servers was compromised by a hacker, or infected with a virus, the other servers on the DMZ would be safe.

     The basic concept behind Private VLANs is to divide an existing VLAN, referred to as the primary VLAN, into one or more separated VLANs, called secondary VLANs.

     There are three types of secondary VLANs: Promiscuous, Isolated, and Community.
    Virtual machines in a Promiscuous PVLAN are reachable by and can reach any machine in the same primary VLAN. In this example, virtual machines E and F are in promiscuous PVLAN 5, so all virtual machines in PVLAN 5 can communicate with them. When you configure a private VLAN, the vSphere Client automatically creates a promiscuous secondary PVLAN with the same ID as the primary PVLAN ID.

    Virtual machines in an Isolated PVLAN can talk to no virtual machines except those in the promiscuous PVLAN. In this example, virtual machines C and D are in isolated PVLAN 155, so they can communicate only with E and F.

    Virtual machines in a Community PVLAN can talk to each other and to the virtual machines in the promiscuous PVLAN, but not to any other virtual machine. In this example, virtual machines A and B can talk to each other and to E and F because they are in the promiscuous VLAN. However, they cannot communicate with C or D because they are not in the community.

     Traffic in both community and isolated PVLANs travels tagged as the associated secondary PVLAN.
     There are a couple of things to note about how vNetwork implements private VLANs.

     First, vNetwork does not encapsulate traffic inside private VLANs . In other words, there is no secondary PVLAN encapsulated inside a primary private VLAN packet.

     Also, traffic between virtual machines on the same private VLAN but on different ESX or ESXi hosts moves through the physical switch. Therefore, the physical switch must be PVLAN-aware and configured appropriately so that traffic in the secondary PVLANs can reach its destination.
    Saturday, September 8, 2012
    Tag :

    Oracle Secure Global Desktop

    Introduction : 
    Oracle Secure Global Desktop provides secure access to centralized, server-hosted Windows, UNIX, mainframe, and midrange applications from a wide variety of popular client devices, including Windows PCs, Mac OS X systems, Oracle Solaris workstations, Linux PCs, thin clients, and more. Additionally, Oracle Secure Global Desktop provides access to full-screen desktop environments, allowing administrators the freedom to use a single solution to provide access to both server-based applications and server-hosted desktop environments such as Microsoft Remote Desktop Services.
    In the Oracle Secure Global Desktop architecture, applications are deployed on introduce new applications or upgrade existing ones. Users can then begin using the new software immediately—without modifying their client devices.Centrally managed application servers and can be accessed via a Web browser. By simply modifying a few central application servers, administrators can instantly
    Designed to meet stringent security requirements, Oracle Secure Global Desktopleverages open standards and provides industrial-strength security and encryption. It helps administrators ensure that only authorized users can access applications and data, establishing identity by integrating with corporate standards such as the Light-weight Directory Access Protocol (LDAP), UNIX passwords, Pluggable Authen- tication Modules (PAMs), Novell eDirectory, and Microsoft Active Directory.


    ORACLE SECURE GLOBAL DESKTOP DELIVERS
    • Complete server-hosted application and server-hosted desktop access
    • Secure access to corporate data and applications
    • Easier IT management of centralized resources and applications
    • Remote access to applications and desktops for mobile workforce
    • Flexibility to deploy Windows, Linux, and Solaris applications or desktops to nearly any modern PC or thin client
    Oracle Secure Global Desktop Specifications
    Installation Platforms
    • Oracle Solaris 10 and Oracle Solaris 10 Trusted Extensions (SPARC platform)
    • Oracle Solaris 10 and Oracle Solaris 10 Trusted Extensions (x86 platform)
    • OpenSolaris 2008.11+ (x86 platform)
    • Red Hat Enterprise Linux 5 (x86 32-bit and 64-bit platforms)
    • SUSE Linux Enterprise Server 10 (x86 32-bit and 64-bit platforms)
    Supported Application Types
    • Windows desktops and applications
    • Character applications running on Oracle Solaris, Linux, HP-UX, and AIX
    • X applications running on Oracle Solaris, Linux, HP-UX, and AIX
    • IBM mainframe and AS/400 applications
    • Web applications (using HTML and Java technology)
    Supported Protocols
    • Microsoft Remote Desktop Protocol version 5.2
    • HTTP
    • HTTPS
    • Secure shell version 2 or later
    • Telnet VT, ANSI
    • TN3270E
    • TN5250
    Supported Client Operating Systems
    • Windows Vista
    • Windows XP Professional
    • Oracle Solaris 10 and Oracle Solaris 10 Trusted Extensions (SPARC platform)
    • Oracle Solaris 10 and Oracle Solaris 10 Trusted Extensions (x86 platform)
    • OpenSolaris 2008.11+ (x86)
    • Mac OS X 10.5+
    • Red Hat Enterprise Linux Desktop 5.1+ (x86)
    • Ubuntu 8+ (x86)
     Server Requirements
    • Supported operating system
    • 1.5 GB of disk space, plus an additional 300 MB during installation
    • 1 GB RAM
    • 20 MB of memory (in addition to RAM) per active user on the Oracle Secure Global    Desktop server (typical usage)
    • 1 GHz processor
    • Network interface card
     Supported Authentication Mechanisms
    • RSA SecurID
    • Windows Domains
    • eDirectory
    • PAM for UNIX user authentication
    • Active Directory
    • Network Information Service
    • LDAP v3
    • HTTP, HTTPS including public key infrastructure−based client certificates

    Ports used by Red Hat Enterprise Virtualization Manager

    Port 22 for SSH,
    Ports 5634 to 6166 for guest console connections,
    Port 16514 for libvirt virtual machine migration traffic,
    Ports 49152 to 49216 for VDSM virtual machine migration traffic, and
    Port 54321 for the Red Hat Enterprise Virtualization Manager.
    Port 8080 for no SSL access the Red Hat Enterprise Virtualization Manager
    Port 8443 for SSL access the Red Hat Enterprise Virtualization Manager

        Pageviews

        Followers

        Powered by Blogger.

        - Copyright © 2013 Selva Sharing -Selvasharing- Powered by Blogger - Designed by @ Access -