Piszki Lab | EN

My case study in the clouds…

2014/04/11
by Piotr Pisz
3 Comments

VMware Lab, Part 2: SSL Certificates in vCenter (with an emphasis on vCSA)

Now that we have in our LAB nested ESXi servers, it’s time to install vCenter. Installing the “big” vCenter is not difficult , but in LAB, easier and faster is to install vCenter Server Appliance (vCSA). It is difficult to even talk about installing, just deploy the appliance. It is so simple that it will not be the subject of this entry (same as the initial setup). There is one topic that makes the vSphere huge problems, they are SSL certificates. The whole environment is based on SSL, and there is absolutely no sense to use vSphere with the default, self-signed certificates. Fortunately, as I have sometimes written, there are people on the Internet that make life easier. One of these people is Derek Seaman, who created the script, which is an extension of the functionality offered by the VMware SSL Automation Tool. With this script, generating and installing SSL certificates in vCenter, it takes just a few minutes (especially if you have enabled OCSP in Microsoft CA). However, as you can guess, this script in PowerShell fully automates the installation of certificates only in vCenter installed on Windows Server. The same applies to VMware SSL Automation Tool, as now, there is no version supporting vCSA. Is there a solution?

VMware-vSphere-Lab-Virtual-Edition-–-Part-6-Installing-vCenter-35

Continue Reading →

2014/04/11
by Piotr Pisz
0 comments

TCP/IP Exhaustion, a problem in your network.

Traditionally, much of the virtual environment is based on Microsoft Windows Server (as the basis for many machines, including MsSQL and vCenter). It is usually highly engaged environment, dozens of services and servers to each other non-stop “talking”. When it comes to such a large number of web servers, may be quite busy phenomenon, what is the depletion of the fields of dynamic ports on yours servers. This phenomenon is very difficult to detect unless involving persistent overload condition (the operating system itself does not indicate a problem, but reports other “problems” that are only effect). In our case, we have experienced very strange behavior of Tomcat and JBoss servers that repelled strange waves of correct motion. On the solution led us messages that served us some time Trend Micro Deep Sucurity : TCP / IP and UDP Port Limit, appearing occasionally in the course of communication between random machines.

tcpipexschaustion

Continue Reading →

2014/03/31
by Piotr Pisz
2 Comments

Horizon View: Adding a virtual workstation to manual pool.

VMware products can be divided evenly into two categories, those refined (such as vSphere), and those that uh, pose problems (with respect to the employees of the company that I know I will not be named these products). However, even these refined, such as Horizon View, are sometimes so strange gaps that your hands fall off. In the case of View, we have to deal with two serious limitations, one is that you cannot migrate pools between vCenter servers and second, the lack of ability to add machines to the manual pool. While the first I can somehow understand, the latter is not. When creating a manual pool, choose the machine that we add, we can then remove from the pool, but to add new, absolutely not. Does adding a small plus in the GUI is up such a challenge?

Fortunately we have the Internet, and in it a few witted people. Procedure of virtual workstation migration between different vCenter follows (Horizon View can be hooked to both vCenter or they may be two different systems Horizon View) that:

On source, if the pool is automatic, switching mode to “Disable Provisioning”. Virtual machine switch to “maintenance” and remove from Horizon View Manager:

m-view-2

 

Continue Reading →

2014/03/25
by Piotr Pisz
3 Comments

Deep Security: Removing orphaned Agent

Motto: When Agent loses contact with the Base, it should be eliminated Smile

In view of recent updates of the Trend Micro Deep Security, I had to carry out mass action raising agents to the new version. During this operation, the amazement I found that one of the virtual machines operating in a strange mode of suspension. Lost the protection afforded by DSVA and Agent “hangs” with the message “Activation delayed” (infinity). Migrating to another host did not gave, as to reinstall VMware Tools. Very disturbing is the fact that the state did not generate any alerts!

agent3

Continue Reading →