Академический Документы
Профессиональный Документы
Культура Документы
Table of Contents
Lab Overview - HOL-SDC-1602 - vSphere with Operations Management 6 Advanced
Topics ................................................................................................................................ 2
Lab Guidance .......................................................................................................... 3
Module 1: What's new in vSphere with Operations Manager (vSOM) - (60 Minutes)......... 7
Content Library ....................................................................................................... 8
ESXi Security Enhancements ................................................................................ 10
Network I/O Control Enhancements (NIOC) ........................................................... 12
Migrating a Virtual Machine between Two vCenters .............................................. 29
vSphere Web Client Enhancements ...................................................................... 31
vSphere SSL Certificates ....................................................................................... 41
vRealize Operations 6.1 - Custom Profiles for Capacity Planning .......................... 43
vRealize Operations 6.1 - Automation Action Framework...................................... 57
vRealize Operations 6.1 - Custom Data Center for Capacity ................................. 62
vRealize Operations 6.1 - Workload Balancing ...................................................... 72
Module 2: Build and Manage Your Infrastructure - Networking - (30 Minutes) ................ 78
Migrating to the vSphere Distributed Switch - Overview....................................... 79
Implementing Quality of Service (QoS) Tagging .................................................. 106
Monitoring the vSphere Distributed Switch with Encapsulated Remote
Mirroring.............................................................................................................. 142
Implementing LACP on the vSphere Distributed Switch ...................................... 167
Managing NSX..................................................................................................... 213
Module 3: Build and Manage Your Infrastructure - Storage - (30 Minutes) .................... 214
VVOL Management ............................................................................................. 215
VSAN Management ............................................................................................. 216
Module 4: Build and Manage Your Infrastructure - Scale Out - (60 Minutes) ................. 217
Build a Resilient Management Platform .............................................................. 218
Configuring Auto Deploy ..................................................................................... 251
Centralized Management of VM Content............................................................. 291
vCloud Air Management ...................................................................................... 331
Module 5: Optimize Workload Performance While Maintaining Business Priorities - (60
Minutes) ........................................................................................................................ 340
Enable Controlled Usage Of Resources Based On Business Priorities.................. 341
vRealize Operations Custom Alerting .................................................................. 383
Module 6: Ensure Business Continuity and Availability - (30 Minutes) .......................... 395
Demonstrate transparent failover for virtual machines ...................................... 396
Demonstrate automatic restart of virtual machines after a storage failure ....... 399
Module 7: Simplified Security and Compliance - (30 Minutes) ...................................... 417
Integrate your environment into your enterprise certificate infrastructure......... 418
Show fine-grained control of local user access on ESXi ...................................... 465
HOL-SDC-1602
Page 1
HOL-SDC-1602
HOL-SDC-1602
Page 2
HOL-SDC-1602
Lab Guidance
You are about to embark on a hands-on journey to learn about Advanced Topics in
vSphere with Operations Management. This lab will walk you through step-by-step, so
basic vSOM experience is not necessary, but it is helpful. If you would like to learn the
basics, VMware recommends also taking our lab titled "HOL-SDC-1610 - vSphere with
Operations Management - The Basics."
VMware vSphere with Operations Management delivers vSphere optimized for efficient
server virtualization management by adding critical capacity management and
performance monitoring capabilities. It is designed for businesses of all sizes to run
applications at high service levels and maximize hardware savings through higher
capacity utilization and consolidation ratios. Create an easy-to-manage virtual
environment with the most trusted virtualization platform, vSphere.
This Hands-On Lab uses a beta version of vRealize Operations Manager, which is still
undergoing development before final release. Product features that are included in this
lab are subject to change and there is no commitment from VMware to deliver them in
any generally available product.
The following is a list of the different modules contained in this lab:
Module 1 - What's New in vSphere with Operations Manager (vSOM) (60 minutes)
Module 2 - Build and Manage Your Infrastructure - Networking (30 minutes)
Module 3 - Build and Manage Your Infrastructure - Storage (30 minutes)
Module 4 - Build and Manage Your Infrastructure - Scale Out (60 minutes)
Module 5 - Optimize Workload Performance While Maintaining Business Priorities
(60 minutes)
Module 6 - Ensure Business Continuity and Availability (30 minutes)
Module 7 - Simplified Security and Compliance (30 minutes)
Module 8 - PowerCLI for vR Ops: Automate Your Virtual Infrastructure
Remediation (45 minutes)
Lab Captains:John Dias (Modules 1, 2, 3, 4, 6 and 7), Yuval Tenenbaum (Modules 1 and
5), Tom Bonanno (Module 4), and Pavel Dimitrov (Module 8)
This lab manual can be downloaded from the Hands-on Labs Document site found here:
http://docs.hol.pub/HOL-2016/hol-sdc-1602_pdf_en.pdf
This lab may be available in other languages. To set your language preference and have
a localized manual deployed with your lab, you may utilize this document to help guide
you through the process:
http://docs.hol.vmware.com/announcements/nee-default-language.pdf
HOL-SDC-1602
Page 3
HOL-SDC-1602
Login Credentials
In the Hands-On-Lab environments, VMware has established a convention of default
login credentials. You will be the administrator/root user on most systems throughout
the lab. Unless otherwise noted, the default login credentials for this lab are as follows:
HOL-SDC-1602
Page 4
HOL-SDC-1602
Username: administrator@vsphere.local
administrator@corp.local
Password: VMware1!
VMware1!
-or sometimes-
Username:
Password:
This information is also available in the README file, in the Lab Guidance section near
the top. You will learn more about the README file next.
README File
On the ControlCenter desktop, you will find a file named README.txt. This file will
assist you throughout the lab. It has all of the login credentials, commands, and
information you will need for this lab. Feel free to open this file and copy/paste from it.
It is especially helpful if you are on an international keyboard, as you will have to type
very little, if at all.
Now that you know your way around the lab a little, it's time to begin Module 1.
Disclaimer
This session may contain product features that are currently under
development.
HOL-SDC-1602
Page 5
HOL-SDC-1602
HOL-SDC-1602
Page 6
HOL-SDC-1602
HOL-SDC-1602
Page 7
HOL-SDC-1602
Content Library
A new feature introduced in vSphere 6 is the Content Library.
Many organizations have several vCenters servers across diverse geographic locations,
and on these vCenters there is most likely a collection of templates and ISOs. Currently
there is function within vCenter to centrally manage the templates and distribute them
to all locations. The Content Catalog provides the ability to centrally manage content
and ensure its distributed across the infrastructure.
Conclusion
If you would like more details, Content Libraries are covered in depth in Module 4 Build
and Manage Your Infrastructure - Scale Out
HOL-SDC-1602
Page 8
HOL-SDC-1602
HOL-SDC-1602
Page 9
HOL-SDC-1602
HOL-SDC-1602
Page 10
HOL-SDC-1602
The first mode is normal lockdown mode. The DCUI access is not stopped, and users
on the DCUI.Access list can access DCUI. The second mode is strict lockdown mode.
In this mode, DCUI is stopped.
There is also a new functionality called Exception Users. These are local accounts or
Microsoft Active Directory accounts with permissions defined locally on the host where
these users have host access. These Exception Users are not recommended for general
user accounts but are recommended for use by third-party applicationsService
Accounts, for examplethat need host access when either normal or strict lockdown
mode is enabled. Permissions on these accounts should be set to the bare minimum
required for the application to do its task and with an account that needs only read-only
permissions to the ESXi host
Smart Card Authentication to DCUI
This functionality is for U.S. federal customers only. It enables DCUI login access using a
Common Access Card (CAC) and Personal Identity Verification (PIV). An ESXi host must
be part of an Active Directory domain.
In this lesson, we will take a close look at the improved auditing feature in ESXi.
Conclusion
In this lab Module 7 Simplified Security and Compliance takes you through a deeper dive
into some of the ESXi security enhancements.
HOL-SDC-1602
Page 11
HOL-SDC-1602
HOL-SDC-1602
Page 12
HOL-SDC-1602
In this lesson, we will walk through the steps needed to configure Network I/O Control at
the vNIC level.
Select Networking
First, let's verify the vDS we want to use is running NIOC version 3 and is enabled.
Start by clicking the Networking icon.
HOL-SDC-1602
Page 13
HOL-SDC-1602
Expand vcsa-01a.corp.local
Expand vcsa-01a.corp.local until you can see the distributed switch vds-site-a.
HOL-SDC-1602
Page 14
HOL-SDC-1602
Edit Settings
1. Click on vds-site-a,
2. Click on Manage tab.
3. Then click on the Settings.
4. Finally make sure you are on the Properties tab.
5. We can see that Network I/O Control is enabled on the distributed switch.
Note: If it were not enabled, you would just need to click the Edit button, select Enable
in the Network I/O Control drop-down box and click OK.
HOL-SDC-1602
Page 15
HOL-SDC-1602
HOL-SDC-1602
Page 16
HOL-SDC-1602
HOL-SDC-1602
Page 17
HOL-SDC-1602
Reservation
In the Reservation box, type '2000' to reserve 2,000Mbs bandwidth for Virtual Machine
traffic. Leave all other settings to their defaults.
Click OK to continue.
Reservation Set
Once you click OK, you will notice even though we have set a reservation of 2,000Mbs
for virtual machine traffic, it is not showing up under the Reservation Column. This is
because we have just set the Reservation and not actually reserved it for a virtual
machine.
HOL-SDC-1602
Page 18
HOL-SDC-1602
HOL-SDC-1602
Page 19
HOL-SDC-1602
Clone linux-micro-01a
So we don't interfere with other lessons you may want to take, let's clone linuxmicro-01a. Expand the Cluster till you can see the VM 'linux-micro-01a'
1. Right-click on 'linux-micro-01a'
2. Select Clone -->
3. Clone to Virtual Machine...
HOL-SDC-1602
Page 20
HOL-SDC-1602
Name your VM
1. Name your VM linux-nioc-01a
2. Accept the default location of Datacenter Site A for the location.
Click Next to continue.
HOL-SDC-1602
Page 21
HOL-SDC-1602
HOL-SDC-1602
Page 22
HOL-SDC-1602
HOL-SDC-1602
Page 23
HOL-SDC-1602
Ready to Complete
Verify the settings look correct and click Finish to clone the VM.
It should only take a minute to perform the clone operation. You can track the progress
by clicking on the Recent Tasks link in the bottom left corner of the vSphere Web Client.
HOL-SDC-1602
Page 24
HOL-SDC-1602
HOL-SDC-1602
Page 25
HOL-SDC-1602
HOL-SDC-1602
Page 26
HOL-SDC-1602
Viewing Reservation
1. View the reservation by clicking on the summary tab for the Virtual Machine and
2. Expanding the VM hardware section, you can now see the reservation is set so that
this virtual machine's network adapter will have a reserved 2,000Mbs of bandwidth.
HOL-SDC-1602
Page 27
HOL-SDC-1602
Lesson Clean Up
Feel free to explore other options with NIOC. When you are finished with this lesson,
please delete the linux-nioc-01a virtual machine to avoid confusion in other lessons.
Just go back to the Hosts and Clusters view and right-click on the virtual machine linuxnioc-01a and select Delete from Disk.
HOL-SDC-1602
Page 28
HOL-SDC-1602
HOL-SDC-1602
Page 29
HOL-SDC-1602
HOL-SDC-1602
Page 30
HOL-SDC-1602
HOL-SDC-1602
Page 31
HOL-SDC-1602
HOL-SDC-1602
Page 32
HOL-SDC-1602
Expand vcsa-01a.corp.local
Use the twist arrow to expand vcsa-01a.corp.local until you can see the two hosts and
virtual machines.
HOL-SDC-1602
Page 33
HOL-SDC-1602
Right-click on esx-01a.corp
Another usability enhancement is the right-click actions.
Try this by right-clicking on 'esx-01a.corp.local'. The first thing you should notice is that
the menu itself appears much faster.
The second thing to notice is the menu items are no more than one layer deep. This
helps to avoid searching through multiple layers of menus to find the task you need.
HOL-SDC-1602
Page 34
HOL-SDC-1602
HOL-SDC-1602
Page 35
HOL-SDC-1602
Recent Tasks
In the Recent Tasks pane, you will find the most recent tasks, updated in real time
making it easier to view. In the Recent Tasks pane, you have the ability to:
1. Pin the Recent Tasks pane to another part of the vSphere Web Client (more in this
later!).
2. View additional tasks.
3. Hide the Recent Tasks pane.
HOL-SDC-1602
Page 36
HOL-SDC-1602
Customizing the UI
You can also move the Recent Tasks pane (or any other pane) by clicking and dragging
the pane on the title bar.
Left-click and drag anywhere on the Recent Tasks title bar. You'll notice four areas
indicating where you can dock the Recent Tasks pane. Let's move it over the right side
by dragging it in the direction of the right arrow. Move your mouse to the two blue
arrows to the right until that side of the screen turns blue, then click your mouse to
move the pane there.
HOL-SDC-1602
Page 37
HOL-SDC-1602
HOL-SDC-1602
Page 38
HOL-SDC-1602
Move it Back!
In its current position, most of the useful information the Recent Tasks pane provides is
cut off.
Let's move it back to its original location on the bottom of the screen by clicking the
Recent Tasks title bar and dragging it to the bottom.
HOL-SDC-1602
Page 39
HOL-SDC-1602
That's Better!
This layout seems to work better for me, but it is subject to personal preference which is
one of the best parts of the vSphere Web Client, being able to customize it to how it
works best for you.
Lesson Clean Up
To prepare for the next lesson, click on the thumbnail to hide the Recent Tasks pane
back to the bottom of the vSphere Web Client. This will give us more real estate for the
lessons that follow. If the Recent Tasks pane is needed, the lesson will guide you to it.
HOL-SDC-1602
Page 40
HOL-SDC-1602
HOL-SDC-1602
Page 41
HOL-SDC-1602
Conclusion
If you would like hands on experience with VMCA, be sure to check out Module 7 Simplified Security and Compliance in this lab.
HOL-SDC-1602
Page 42
HOL-SDC-1602
HOL-SDC-1602
Page 43
HOL-SDC-1602
profiles as you require for an object type. For example, you can create a profile for a
virtual machine with Memory-Demand model 2 GB and another profile with MemoryDemand model 4 GB. vRealize Operations Manager uses Custom Profiles to calculate
how many virtual machines with this Memory-Demand model can fit in your
environment. You can see this calculation in the What Will Fit panel of the Capacity
Remaining tab on a container object. You can also use the profiles to populate metrics
when you create projects.
HOL-SDC-1602
Page 44
HOL-SDC-1602
HOL-SDC-1602
Page 45
HOL-SDC-1602
Note: Allocation is the total amount of resource you configure to the VM, while demand
is the amount of that resource which that VM is asking for. Depending on the type of
environment you monitor, such as a production environment versus a test or
development environment, whether you over allocate at all and by how much depends
on the workloads and environment to which the policy applies. From a high level
perspective Allocation based capacity planning will be more conservative while Demand
HOL-SDC-1602
Page 46
HOL-SDC-1602
based Capacity Planning will be less conservative but closer to reality as it is a good
indication of how much resources are really demanded and used in your datacenter.
HOL-SDC-1602
Page 47
HOL-SDC-1602
HOL-SDC-1602
Page 48
HOL-SDC-1602
HOL-SDC-1602
Page 49
HOL-SDC-1602
HOL-SDC-1602
Page 50
HOL-SDC-1602
HOL-SDC-1602
Page 51
HOL-SDC-1602
HOL-SDC-1602
Page 52
HOL-SDC-1602
HOL-SDC-1602
Page 53
HOL-SDC-1602
HOL-SDC-1602
Page 54
HOL-SDC-1602
HOL-SDC-1602
Page 55
HOL-SDC-1602
HOL-SDC-1602
Page 56
HOL-SDC-1602
HOL-SDC-1602
Page 57
HOL-SDC-1602
When CPU stress on your virtual machines exceeds a critical, immediate, or warning
level, the alert triggers the recommended action without user intervention.
HOL-SDC-1602
Page 58
HOL-SDC-1602
HOL-SDC-1602
Page 59
HOL-SDC-1602
HOL-SDC-1602
Page 60
HOL-SDC-1602
HOL-SDC-1602
Page 61
HOL-SDC-1602
HOL-SDC-1602
Page 62
HOL-SDC-1602
HOL-SDC-1602
Page 63
HOL-SDC-1602
HOL-SDC-1602
Page 64
HOL-SDC-1602
HOL-SDC-1602
Page 65
HOL-SDC-1602
HOL-SDC-1602
Page 66
HOL-SDC-1602
HOL-SDC-1602
Page 67
HOL-SDC-1602
HOL-SDC-1602
Page 68
HOL-SDC-1602
HOL-SDC-1602
Page 69
HOL-SDC-1602
HOL-SDC-1602
Page 70
HOL-SDC-1602
Summary
When the workload in your cluster becomes imbalanced, you can move the workload
across your objects to rebalance the overall workload in your cluster. The container can
be a cluster, data center, or a custom data center.
HOL-SDC-1602
Page 71
HOL-SDC-1602
Will it fit?
Where will it fit best?
Do I need to Power Off the VM?
Does the VM have any Affinity Rules?
Can I keep it on the same datastore?
Reserve capacity now?
Rebalance capacity containers?
Note: in vRealize Operations 6.1 the Initial Placement part of the WLP is only available
via the REST API. The concept is for other VMware products such as vRealize Automation
and 3rd party tools to programmatically query vRealize Operations to determine the
right place to deploy a new VM and then for vRealize Operations to return the results of
best candidate ESXi host.
HOL-SDC-1602
Page 72
HOL-SDC-1602
Rebalance Alerts
When the workloads on the hosts in the cluster, data center, or custom data center
have a significant difference in their workloads, a Rebalance type Alert will be triggered.
You can then look at the alert to verify whether the alert is triggered on a cluster. You
can click the alert to view the causes for the alert and identify the source of the
imbalance problem.
When workloads become imbalanced, the following alerts can trigger on clusters, data
centers, and custom data centers:
Cluster has unbalanced workload
HOL-SDC-1602
Page 73
HOL-SDC-1602
HOL-SDC-1602
Page 74
HOL-SDC-1602
HOL-SDC-1602
Page 75
HOL-SDC-1602
available hosts, which leaves more room for demand spikes, but can run up
licensing and power costs. Good for populations with erratic demand.
3. Change Datastore - change or not the datastore the VM resides on as part of the
Rebalancing action.
4. Datastore Selection Options - Do not use datastore on local disk and/or exclude
datastores that contain specific words in the name.
5. Virtual Machines selected to move during balance - Select Virtual Machines with
smallest demand first or with largest demand first.
HOL-SDC-1602
Page 76
HOL-SDC-1602
Summary
When it comes to managing operations in a virtualized data center, there are some key
aspects that you need to tackle and one of the key ones is the ability to understand
resource usage and then be able to rebalance it intelligently. With the new Intelligent
Workload Placement capability of vRealize Operations 6.1, we match the workload to
your specific IT and business needs and recommend the best placement location.
And as your workloads change and your environment evolves and grows, you can
leverage the Intelligent Placement and Proactive Rebalancing capabilities to ensure
performance that meets the needs of your business.
Note: for a deeper dive on Workload Placement capability please refer to lab HOLSDC-1610.
HOL-SDC-1602
Page 77
HOL-SDC-1602
HOL-SDC-1602
Page 78
HOL-SDC-1602
HOL-SDC-1602
Page 79
HOL-SDC-1602
HOL-SDC-1602
Page 80
HOL-SDC-1602
HOL-SDC-1602
Page 81
HOL-SDC-1602
Navigate to esx-01a.corp.local
In the top right corner of the Web Client, type "esx-01a" into the search bar and then
click on the link for esx-01a.corp.local
HOL-SDC-1602
Page 82
HOL-SDC-1602
HOL-SDC-1602
Page 83
HOL-SDC-1602
HOL-SDC-1602
Page 84
HOL-SDC-1602
HOL-SDC-1602
Page 85
HOL-SDC-1602
HOL-SDC-1602
Page 86
HOL-SDC-1602
HOL-SDC-1602
Page 87
HOL-SDC-1602
HOL-SDC-1602
Page 88
HOL-SDC-1602
HOL-SDC-1602
Page 89
HOL-SDC-1602
HOL-SDC-1602
Page 90
HOL-SDC-1602
HOL-SDC-1602
Page 91
HOL-SDC-1602
Select Hosts
1. Click on the "New hosts..." icon to select the hosts to add to the VDS.
2. Select esx-01a at this time.
Click OK (not shown) to close the host selection popup.
Click Next (not shown) when you return to the host list.
HOL-SDC-1602
Page 92
HOL-SDC-1602
HOL-SDC-1602
Page 93
HOL-SDC-1602
HOL-SDC-1602
Page 94
HOL-SDC-1602
HOL-SDC-1602
Page 95
HOL-SDC-1602
HOL-SDC-1602
Page 96
HOL-SDC-1602
Verify Assignment
1. Verify that each VMkernel adapter is mapped to the correct VDS port group.
2. Click "Next"
HOL-SDC-1602
Page 97
HOL-SDC-1602
Analyze Impact
There should be "No impact" - click "Next" to continue.
HOL-SDC-1602
Page 98
HOL-SDC-1602
Migrate VM Networking
1. Drill down to the "Network adapter 1" on the linux-micro-01a VM.
2. Click "Assign port group"
3. In the "Select Network" popup, select the "VM Network" and click OK.
Click "Next" (not shown) to continue.
Note that you could simply select the VM and assign all vNICs to a new Port Group. We
did it this way to demonstrate that you have granular control of where vNICs are
migrated in the new network scheme.
HOL-SDC-1602
Page 99
HOL-SDC-1602
HOL-SDC-1602
Page 100
HOL-SDC-1602
HOL-SDC-1602
Page 101
HOL-SDC-1602
HOL-SDC-1602
Page 102
HOL-SDC-1602
HOL-SDC-1602
Page 103
HOL-SDC-1602
HOL-SDC-1602
Page 104
HOL-SDC-1602
Confirm Removal
Click Yes.
HOL-SDC-1602
Page 105
HOL-SDC-1602
HOL-SDC-1602
Page 106
HOL-SDC-1602
HOL-SDC-1602
Page 107
HOL-SDC-1602
HOL-SDC-1602
Page 108
HOL-SDC-1602
HOL-SDC-1602
Page 109
HOL-SDC-1602
HOL-SDC-1602
Page 110
HOL-SDC-1602
HOL-SDC-1602
Page 111
HOL-SDC-1602
HOL-SDC-1602
Page 112
HOL-SDC-1602
3) New IP Qualifier.
That means users have options to select packets based on system traffic types, MAC
header or IP header fields. In this example we will create qualifier based on system
traffic.
Select New System Traffic Qualifier from the drop down menu
HOL-SDC-1602
Page 113
HOL-SDC-1602
HOL-SDC-1602
Page 114
HOL-SDC-1602
HOL-SDC-1602
Page 115
HOL-SDC-1602
HOL-SDC-1602
Page 116
HOL-SDC-1602
HOL-SDC-1602
Page 117
HOL-SDC-1602
HOL-SDC-1602
Page 118
HOL-SDC-1602
HOL-SDC-1602
Page 119
HOL-SDC-1602
HOL-SDC-1602
Page 120
HOL-SDC-1602
HOL-SDC-1602
Page 121
HOL-SDC-1602
HOL-SDC-1602
Page 122
HOL-SDC-1602
HOL-SDC-1602
Page 123
HOL-SDC-1602
HOL-SDC-1602
Page 124
HOL-SDC-1602
HOL-SDC-1602
Page 125
HOL-SDC-1602
HOL-SDC-1602
Page 126
HOL-SDC-1602
HOL-SDC-1602
Page 127
HOL-SDC-1602
HOL-SDC-1602
Page 128
HOL-SDC-1602
HOL-SDC-1602
Page 129
HOL-SDC-1602
HOL-SDC-1602
Page 130
HOL-SDC-1602
HOL-SDC-1602
Page 131
HOL-SDC-1602
New IP Qualifier
1. Select ICMP from the Protocol drop down menu
2. Select Source address is and set to192.168.100.130
3. Click OK
HOL-SDC-1602
Page 132
HOL-SDC-1602
HOL-SDC-1602
Page 133
HOL-SDC-1602
HOL-SDC-1602
Page 134
HOL-SDC-1602
HOL-SDC-1602
Page 135
HOL-SDC-1602
HOL-SDC-1602
Page 136
HOL-SDC-1602
HOL-SDC-1602
Page 137
HOL-SDC-1602
HOL-SDC-1602
Page 138
HOL-SDC-1602
HOL-SDC-1602
Page 139
HOL-SDC-1602
HOL-SDC-1602
Page 140
HOL-SDC-1602
HOL-SDC-1602
Page 141
HOL-SDC-1602
HOL-SDC-1602
Page 142
HOL-SDC-1602
HOL-SDC-1602
Page 143
HOL-SDC-1602
HOL-SDC-1602
Page 144
HOL-SDC-1602
Launch tshark
In this module, we will use Tshark, a terminal based network traffic analyzer similar to
WireShark.
To launch it, double click on the Tshark icon on the desktop. We've added a filter to only
look at ICMP traffic to/from 192.168.100.131 (base-w12-01b).
HOL-SDC-1602
Page 145
HOL-SDC-1602
HOL-SDC-1602
Page 146
HOL-SDC-1602
HOL-SDC-1602
Page 147
HOL-SDC-1602
HOL-SDC-1602
Page 148
HOL-SDC-1602
Navigate to base-w12-01b
1. In the Web Client quick search bar, type "site-b"
2. Click the link for the Distributed Switch "vds-site-b"
HOL-SDC-1602
Page 149
HOL-SDC-1602
HOL-SDC-1602
Page 150
HOL-SDC-1602
Edit Properties
1. Type Encapsulated Remote Mirroring - Destination in the Name field
2. Enable its status.
3. Click Next
HOL-SDC-1602
Page 151
HOL-SDC-1602
Select sources
There are two options to Select sources, you can select Ports in a list or directly type in a
Port IDs range like 2-8 for example.
1. Click the first + icon to select Port IDs from a list.
HOL-SDC-1602
Page 152
HOL-SDC-1602
Select Ports
Selecting from a list is easier than typing a Port Range, you see the Connected Entity
here, so you can easily select the VMs you want to monitor.
Click on the checkbox for the Port ID connected to the full-sles-01a entity. Be careful to
select the correct one, the order of your list may differ.
Click OK.
HOL-SDC-1602
Page 153
HOL-SDC-1602
HOL-SDC-1602
Page 154
HOL-SDC-1602
Select destinations
Click the green + icon.
Add IP Address
1. Type the IP address of the Control Center where we will analyze the mirrored traffic:
192.168.110.10
2. Click OK.
HOL-SDC-1602
Page 155
HOL-SDC-1602
Next
Click Next.
Ready to complete
Review your Port Mirroring Session settings.
Click Finish.
Confirm settings
1.
Your Encapsulated Remote Mirroring - Destination Port mirroring session is now
Enabled.
HOL-SDC-1602
Page 156
HOL-SDC-1602
2.
To confirm the settings you can select Encapsulated Remote Mirroring - Destination
and click on the Sources and Destinations tabs.
You should have the same information as:
Status: Enabled
Connectee: base-w12-01b
Traffic Direction: Egress
Destination: 192.168.110.10 (not displayed in this screen capture, available behind the
Destinations tab).
Click on the pencil and update your configuration accordingly until you get the same
result.
HOL-SDC-1602
Page 157
HOL-SDC-1602
Troubleshooting Notes
1. Check the linux-micro-01b PuTTY session to see if the ping is still running. If that's
not the case, re-launch it.
2. Double check the Encapsulated Remote Mirroring - Destination session settings
(see previous step).
3. Make sure you've applied this Encapsulated Remote Mirroring configuration to
vds-site-b and not vds-site-a.
HOL-SDC-1602
Page 158
HOL-SDC-1602
HOL-SDC-1602
Page 159
HOL-SDC-1602
Migrate...
1. Click on Actions
2. Select Migrate...
HOL-SDC-1602
Page 160
HOL-SDC-1602
HOL-SDC-1602
Page 161
HOL-SDC-1602
HOL-SDC-1602
Page 162
HOL-SDC-1602
Select network
Click Next
HOL-SDC-1602
Page 163
HOL-SDC-1602
HOL-SDC-1602
Page 164
HOL-SDC-1602
Review Selections
Compare your selections with the following yellow boxes.
If that looks the same on your side click Finish, click Back otherwise.
HOL-SDC-1602
Page 165
HOL-SDC-1602
HOL-SDC-1602
Page 166
HOL-SDC-1602
Check Requirements
In this lesson we will check the requirements to implement LACP v2 on vSphere.
HOL-SDC-1602
Page 167
HOL-SDC-1602
LACP v2 requirements
Before jumping in, please note the following restrictions when using LACP v2:
A vSphere Distributed Switch version 5.5 is required.
Only same speed links can be combined to form a LAG.
Only one LAG can be made active in the teaming configuration of a Port
Group.
No other uplinks can be active or in standby mode at the same time,
failover will be handled at the LACP level.
HOL-SDC-1602
Page 168
HOL-SDC-1602
HOL-SDC-1602
Page 169
HOL-SDC-1602
Navigate to vds-site-b
1. In the web client quick search type "vds"
2. Click on the link for the Distributed Switch "vds-site-b"
HOL-SDC-1602
Page 170
HOL-SDC-1602
HOL-SDC-1602
Page 171
HOL-SDC-1602
vds-site-b Enhance
Let's add Enhanced LACP Support by opening the Features widget and clicking the
"Enhance" link under Link Aggregation Control Policy.
HOL-SDC-1602
Page 172
HOL-SDC-1602
HOL-SDC-1602
Page 173
HOL-SDC-1602
Validate prerequisites
Everything looks good, click "Next"
HOL-SDC-1602
Page 174
HOL-SDC-1602
Ready to Complete
Ready to go, click Finish to enhance our VDS.
HOL-SDC-1602
Page 175
HOL-SDC-1602
HOL-SDC-1602
Page 176
HOL-SDC-1602
Click OK.
HOL-SDC-1602
Page 177
HOL-SDC-1602
LAG created
Your lag1 is now created.
If you don't see lag1 in the list, you may need to refresh the Web Client.
In the next step we'll confirm the creation of our LAG in our host.
HOL-SDC-1602
Page 178
HOL-SDC-1602
Launch PUTTY
Click Start > PuTTY
HOL-SDC-1602
Page 179
HOL-SDC-1602
Connect to esx-03a.corp.local
1. Select esx-01b.corp.local in the Saved Configurations list
2. Click Open.
HOL-SDC-1602
Page 180
HOL-SDC-1602
HOL-SDC-1602
Page 181
HOL-SDC-1602
HOL-SDC-1602
Page 182
HOL-SDC-1602
HOL-SDC-1602
Page 183
HOL-SDC-1602
HOL-SDC-1602
Page 184
HOL-SDC-1602
Add hosts
Click the green + to add Hosts to the list
Select Hosts
1. Select both hosts by clicking on the checkbox in the heading
2. Click OK.
HOL-SDC-1602
Page 185
HOL-SDC-1602
HOL-SDC-1602
Page 186
HOL-SDC-1602
HOL-SDC-1602
Page 187
HOL-SDC-1602
HOL-SDC-1602
Page 188
HOL-SDC-1602
HOL-SDC-1602
Page 189
HOL-SDC-1602
HOL-SDC-1602
Page 190
HOL-SDC-1602
HOL-SDC-1602
Page 191
HOL-SDC-1602
HOL-SDC-1602
Page 192
HOL-SDC-1602
Apply to all
1. To replicate the configuration of esx-01b.corp.local on esx-02b.corp.local click on
Apply to all
2. Click Next.
HOL-SDC-1602
Page 193
HOL-SDC-1602
Analyze impact
vCenter tells you there isn't any impact on network dependent services, so you can
relax and click Next.
HOL-SDC-1602
Page 194
HOL-SDC-1602
Ready to complete
click Finish to proceed and wait until the operation completes.
HOL-SDC-1602
Page 195
HOL-SDC-1602
HOL-SDC-1602
Page 196
HOL-SDC-1602
HOL-SDC-1602
Page 197
HOL-SDC-1602
HOL-SDC-1602
Page 198
HOL-SDC-1602
HOL-SDC-1602
Page 199
HOL-SDC-1602
HOL-SDC-1602
Page 200
HOL-SDC-1602
HOL-SDC-1602
Page 201
HOL-SDC-1602
HOL-SDC-1602
Page 202
HOL-SDC-1602
HOL-SDC-1602
Page 203
HOL-SDC-1602
Ready to complete
Click Finish and close the wizard window.
Congratulations, your LACP configuration is now complete for your lag1. In a real-world
scenario we would do the same process for the Management, Storage and vMotion
networks or we could also share a common LAG depending on NICs availability and
network requirements.
HOL-SDC-1602
Page 204
HOL-SDC-1602
But, you know the drill, your time at VMworld 2015 is valuable so let's not repeat
ourselves and wrap up this module in the next chapter.
HOL-SDC-1602
Page 205
HOL-SDC-1602
Close wizard
Close the LAG migration wizard
HOL-SDC-1602
Page 206
HOL-SDC-1602
Topology
1. Select Topology
2. Select on the VM Network Port Group.
3. Click on the gray arrow in front of lag1 to see the implementation details for each
host.
This confirms Data traffic will use the newly created lag1 which use 3 physical NICs on
each host.
Conclusion
This concludes our LACP lab module. Keep in mind when implementing this features the
following requirements:
VDS 5.5 and a physical switch implementing LACP are both required.
Only same speed links can be combined to form a LAG.
Only one LAG can be made active in the teaming configuration of a Port
Group.
No other uplinks could be active or in standby mode at the same time,
failover will be handled at the LACP level.
Regarding the maximums, you can have up to 32 LAGs per host but the number of
NICs on a host is also limited to 32 if you have 1 Gbe interfaces, or 8 for 10 Gbe
ones.
HOL-SDC-1602
Page 207
HOL-SDC-1602
So, for example, you can only create 16 LAGs with two 1 Gig interfaces each.
Thanks for taking the time to learn about LACP in vSphere 5.5.
If you want to know even more about LACP configuration, continue to the next optional
lesson, or skip it and go directly to the next module if you are short on time.
HOL-SDC-1602
Page 208
HOL-SDC-1602
HOL-SDC-1602
Page 209
HOL-SDC-1602
HOL-SDC-1602
Page 210
HOL-SDC-1602
If you do so, all the traffic going out this LAG will comply to this setup no matter the
configuration of the originating Port Group.
HOL-SDC-1602
Page 211
HOL-SDC-1602
Confirm Overrides
Port Policies is now overridden. (You may have to update the Web Client to see the
changes)
That conclude the LACP lesson of the HOL-SDC-1602 Hands on Lab.
HOL-SDC-1602
Page 212
HOL-SDC-1602
Managing NSX
This lab does not include NSX capability due to resource constraints. However, the
video in the next step is provided for an overview of the vRealize Operations
Management Pack for NSX. For a deeper level of understanding of NSX, please consider
the following lab:
HOL-SDC-1624 VMware NSX and the vRealize Suite
HOL-SDC-1602
Page 213
HOL-SDC-1602
HOL-SDC-1602
Page 214
HOL-SDC-1602
VVOL Management
VVOL is beyond the scope of this lab.. See HOL-SDC-1627 "VMware Software Defined
Storage - Advanced Topics" for an overview of VVOL.
HOL-SDC-1602
Page 215
HOL-SDC-1602
VSAN Management
In this module we will show how you can monitor Virtual SAN 6 using the vRealize
Operations Manager Management Pack for Storage Devices (MPSD). This module only
provides a high level preview of VSAN integration and management. For a deeper level
of understanding of VSAN, please consider the following labs:
HOL-SDC-1608 Virtual SAN 6 from A to Z
HOL-SDC-1602
Page 216
HOL-SDC-1602
HOL-SDC-1602
Page 217
HOL-SDC-1602
HOL-SDC-1602
Page 218
HOL-SDC-1602
HOL-SDC-1602
Page 219
HOL-SDC-1602
HOL-SDC-1602
Page 220
HOL-SDC-1602
When you install vCenter Server or deploy the vCenter Server Appliance with an
external Platform Services Controller, you must first install the Platform Services
Controller. During installation of the Platform Services Controller, you can select whether
to create a new vCenter Single Sign-On domain or join an existing domain. You can
select to join an existing vCenter Single Sign-On domain if you have already installed or
deployed a Platform Services Controller, and have created a vCenter Single Sign-On
domain. When you join an existing vCenter Single Sign-On domain, the data between
the existing Platform Services Controller and the new Platform Services Controller is
replicated, and the infrastructure data is replicated between the two Platform Services
Controllers.
With Enhanced Linked Mode, you can connect not only vCenter Server systems running
on Windows but also vCenter Server Appliances. You can also have an environment
where multiple vCenter Server systems and vCenter Server Appliances are linked
together.
In the image example below you can see how we can search across all linked vCenter
Server systems.
HOL-SDC-1602
Page 221
HOL-SDC-1602
As with any environment, the way it is configured is based on the size of the
environment (including expected growth) and the need for high availability. These
factors will generally dictate the best configuration for the Platform Services Controller
(PSC).
HOL-SDC-1602
Page 222
HOL-SDC-1602
load balancers will result in "best effort" support. See the vendor documentation
regarding configuration details for any load balancer used.
With vCenter 6.0, connectivity to the Platform Services Controller is stateful, and the
load balancer is only used for its failover ability. So active-active connectivity is not
recommended for both nodes at the same time, or you risk corruption of the data
between nodes.
HOL-SDC-1602
Page 223
HOL-SDC-1602
HOL-SDC-1602
Page 224
HOL-SDC-1602
HOL-SDC-1602
Page 225
HOL-SDC-1602
HOL-SDC-1602
Page 226
HOL-SDC-1602
HOL-SDC-1602
Page 227
HOL-SDC-1602
Unified Management With vRealize Operations Dashboard which span 2 vCenter Servers
This Dashboard is using the Environment Overview widget which displays the health,
risk, and efficiency of resources for a given object from the managed inventory. In this
case we can see that the dashboard spans the two vCenter Servers environments we
have in our inventory. As you click on one of the vCenter Server Objects, its entire
topology is then being highlighted making it easier to understand health and workload
issues in the context of the inventory relationships. You can then toggle between the
badges to see different information such as Workload, Stress, Capacity and Time
Remaining etc...
HOL-SDC-1602
Page 228
HOL-SDC-1602
now enables extremely fast migrations at speeds exceeding 60 Gigabits per second. In
this module we are going to take a closer look at cross vCenter Servers vMotion.
HOL-SDC-1602
Page 229
HOL-SDC-1602
A Familiar View
Feel free to click the push pins for the "Alarms", "Work In Progress" and "Recent Tasks"
panes. This will give you a little more room to work. You open the pane by clicking on
the closed pane and then re-close it by clicking on the closed pane button again.
Click on "Hosts and Clusters".
HOL-SDC-1602
Page 230
HOL-SDC-1602
Focus on linux-micro-01a
Expand both vCenter inventories.
1. Navigate to the linux-micro-01a virtual machine, it should be powered on. If not,
please power it on.
2. Make sure you are on the Summary tab
HOL-SDC-1602
Page 231
HOL-SDC-1602
HOL-SDC-1602
Page 232
HOL-SDC-1602
HOL-SDC-1602
Page 233
HOL-SDC-1602
HOL-SDC-1602
Page 234
HOL-SDC-1602
HOL-SDC-1602
Page 235
HOL-SDC-1602
HOL-SDC-1602
Page 236
HOL-SDC-1602
Login proceeds
Public key SSH authentication is set up so no password is required.
Migrate the VM
Minimize the current PuTTy session (don't close it!) and go back to the vSphere Web
Client.
HOL-SDC-1602
Page 237
HOL-SDC-1602
HOL-SDC-1602
Page 238
HOL-SDC-1602
HOL-SDC-1602
Page 239
HOL-SDC-1602
HOL-SDC-1602
Page 240
HOL-SDC-1602
Select storage
Accept the default storage options and click Next.
HOL-SDC-1602
Page 241
HOL-SDC-1602
Select Folder
1. Select the Discovered virtual machines folder
2. Then click Next.
Then continue with the Wizard selecting all the default options then click "Finish".
HOL-SDC-1602
Page 242
HOL-SDC-1602
Monitor Ping
Switch back to the PuTTy session and Command prompt and watch the pings. You may
see a packet drop or a slightly longer delay during the vMotion cut over. Notice that
Layer 2 networking for the VM Network is stretched between the two sites and that the
VM retains its IP address when it migrates between sites.
HOL-SDC-1602
Page 243
HOL-SDC-1602
HOL-SDC-1602
Page 244
HOL-SDC-1602
Monitor linux-micro-01a
1. Click on 'linux-micro-01a'
2. Select the Monitor tab
3. Then Events
You will notice that all the events for the VM were carried over as it moved to the new
vCenter Server. This is also true for any of the performance data.
HOL-SDC-1602
Page 245
HOL-SDC-1602
HOL-SDC-1602
Page 246
HOL-SDC-1602
HOL-SDC-1602
Page 247
HOL-SDC-1602
HOL-SDC-1602
Page 248
HOL-SDC-1602
Conclusion
Cross vCenter vMotion is a powerful new capability with a number of use cases. It could
be used to migrate between legacy Windows vCenter and a new vCenter appliance or
anytime if makes sense to migrate VMs to a completely new set of virtual infrastructure.
And of course it can be used to migrate VMs between data centers for planned
maintenance or other business purposes without interruption.
In Summary to enable migration across vCenter Server instances, your environment
must meet these requirements:
The source and destination vCenter Server instances and ESXi hosts must be
running version 6.0 or later.
HOL-SDC-1602
Page 249
HOL-SDC-1602
Both vCenter Server instances must be in Enhanced Linked Mode and must be in
the same vCenter Single Sign-On domain so that the source vCenter Server can
authenticate to the destination vCenter Server.
Both vCenter Server instances must be time-synchronized with each other for
correct vCenter Single Sign-On token verification.
For migration of compute resources only, both vCenter Server instances must be
connected to the shared virtual machine storage.
HOL-SDC-1602
Page 250
HOL-SDC-1602
Case Study
The CIO of BigTelco has decided to implement a cloud-enabled datacenter to
accommodate the agility and scalability requirements of their customers. He is in the
final stage of closing an agreement with the CIO of Rainpole Systems, a software
development firm that is interested in having BigTelco host their cloud infrastructure.
For Rainpole Systems, this new cloud initiative will help redefine their development
model and radically improve time to market for a wave of new customer facing
applications.
Rainpole has asked for the ability to rapidly deploy and maintain hundreds of servers
within hours to meet potential demand. In an effort to prepare for the cloud computing
partnership, the infrastructure teams at BigTelco have committed to spinning up
VMware vSphere Servers on demand to host RainPole System's new projects. To
streamline the numerous server deployments, the CIO has asked you and your team of
engineers to find the best way to adapt BigTelcos cloud environment for this new
challenge. You and your team have decided to leverage VMware vSphere Auto Deploy
and stateless ESXi features.
HOL-SDC-1602
Page 251
HOL-SDC-1602
Environment Overview
The diagram above shows the high-level architecture for the Auto Deploy lab.
HOL-SDC-1602
Page 252
HOL-SDC-1602
Host Customization - Stores information that the user provides when host
profiles are applied to the host. Host customization might contain an IP address or
other information that the user supplied for that host.
Verify Prerequisites
Auto Deploy relies on 3 basic software services: DHCP, TFTP, and DNS. These three
systems need to be running and configured in order for Auto Deploy to work correctly.
Below you will find the configurations that need to be in place.
For this lesson, we have a router called vPodRouter, which is a linux virtual machine
that also works as a TFTP and DHCP server. The ControlCenter (the machine that you
are currently logged into), hosts our DNS server.
HOL-SDC-1602
Page 253
HOL-SDC-1602
Important
Please be aware that the TFTP installation and DHCP configuration was already done for
you in this lab, so you do not need to do it. The following DHCP examples are only for
your information.
DHCP Examples
Once you have a DHCP server ready to use, you will need to do some additional
configuration in order for your new host to receive the right IP address. Below are the
tasks you should perform.
1. Create a IP reservation in DHCP for your host, using the MAC address of a NIC on
your new host and choosing a desired IP address. This will cause your host to
always boot with the same address.
2. You will also need to set the option Boot Server Host Name to point to your
TFTP server address, and the option Bootfile Name to indicate the ESXi boot
image file name.
The way this is configured differs depending on the DHCP server platform. See the
examples for both Windows and Linux next.
Remember, this has already been done for you in this lab, so do not attempt
to perform these steps.
HOL-SDC-1602
Page 254
HOL-SDC-1602
HOL-SDC-1602
Page 255
HOL-SDC-1602
HOL-SDC-1602
Page 256
HOL-SDC-1602
DNS Configuration
DNS resolution is critical, because after our host receives an IP address, vCenter will be
attempting to communicate with it by fully qualified domain name. Therefore, a host
entry needs to be created, pointing the new stateless ESXi host's name to the address
you configured it to receive in DHCP.
HOL-SDC-1602
Page 257
HOL-SDC-1602
1.
2.
3.
4.
5.
Open Firefox.
Click on the Site A Web Client shortcut
Enter username administrator@corp.local
For password, type VMware1!
Click on Login
HOL-SDC-1602
Page 258
HOL-SDC-1602
HOL-SDC-1602
Page 259
HOL-SDC-1602
HOL-SDC-1602
Page 260
HOL-SDC-1602
HOL-SDC-1602
Page 261
HOL-SDC-1602
Open WinSCP
Now we will copy the files we just extracted to our TFTP server.
1. Open WinSCP using the shortcut on the desktop.
HOL-SDC-1602
Page 262
HOL-SDC-1602
HOL-SDC-1602
Page 263
HOL-SDC-1602
HOL-SDC-1602
Page 264
HOL-SDC-1602
HOL-SDC-1602
Page 265
HOL-SDC-1602
HOL-SDC-1602
Page 266
HOL-SDC-1602
HOL-SDC-1602
Page 267
HOL-SDC-1602
HOL-SDC-1602
Page 268
HOL-SDC-1602
HOL-SDC-1602
Page 269
HOL-SDC-1602
HOL-SDC-1602
Page 270
HOL-SDC-1602
HOL-SDC-1602
Page 271
HOL-SDC-1602
Do not click Next just yet. There is one more option we need to configure.
HOL-SDC-1602
Page 272
HOL-SDC-1602
HOL-SDC-1602
Page 273
HOL-SDC-1602
For the purposes of this exercise, we are using the VMware provided depot with one of
the default Image Profiles. For the sake of time in the lab, the Software Depot has
already been downloaded to a local folder that we will configure Auto Deploy to use.
The next few steps in this document will give specific commands to run from the
PowerCLI with brief explanations. If you would like further details on each command, at
the PowerCLI prompt type: help <cmdlet>
The key components of the software architecture are:
VIBs
Image Profiles
Software Depots
HOL-SDC-1602
Page 274
HOL-SDC-1602
HOL-SDC-1602
Page 275
HOL-SDC-1602
HOL-SDC-1602
Page 276
HOL-SDC-1602
ESXi image depots can be downloaded from the VMware Website as part of the vSphere
downloads or created by you with Image Builder. The image depot within C:\Software\
ESXi600-201507001.zip. is, at the time of this writing, the latest standard ESX 6.0.0
image depot available from VMware.
HOL-SDC-1602
Page 277
HOL-SDC-1602
HOL-SDC-1602
Page 278
HOL-SDC-1602
$DeployNoSignatureCheck=$true
2.
HOL-SDC-1602
Page 279
HOL-SDC-1602
In this case, we simply specified the new host by name. However, we can match on
server vendor (HP, Dell, etc.), or we can specify hosts within a given IP address range.
Note: This can take a little bit to complete.
Add-DeployRule RainpoleBoot
You should see the output above, summarizing your new active rule.
HOL-SDC-1602
Page 280
HOL-SDC-1602
HOL-SDC-1602
Page 281
HOL-SDC-1602
HOL-SDC-1602
Page 282
HOL-SDC-1602
HOL-SDC-1602
Page 283
HOL-SDC-1602
HOL-SDC-1602
Page 284
HOL-SDC-1602
HOL-SDC-1602
Page 285
HOL-SDC-1602
HOL-SDC-1602
Page 286
HOL-SDC-1602
HOL-SDC-1602
Page 287
HOL-SDC-1602
HOL-SDC-1602
Page 288
HOL-SDC-1602
HOL-SDC-1602
Page 289
HOL-SDC-1602
Conclusion
Auto Deploy Possibilities:
Auto Deploy has two options that we can choose from. In this lesson we just used the
Auto Deploy Stateless Caching.
Auto Deploy Stateless Caching This feature allows you to cache the host's image
locally on the host or on a network drive and continue to provision the host with Auto
Deploy
Auto Deploy Stateful Installs This feature allows you to install hosts over the
network without setting up a complete PXE boot infrastructure. After the initial network
boot, these hosts boot like other hosts on which ESXi is installed.
This completes our lesson, "Configuring Auto Deploy." VMware thanks you for taking
time to explore how you can utilize Auto Deploy to quickly scale up your cloud
environment.
HOL-SDC-1602
Page 290
HOL-SDC-1602
Centralized Management of VM
Content
A new feature introduced in vSphere 6 is the Content Library. The Content Library are
container objects for VM templates, vApp templates, ISO images and other files across
your vSphere environment. vSphere administrators can use the templates in the library
to deploy virtual machines and vApps in the vSphere inventory. Sharing templates and
files across multiple vCenter Server instances in same or different locations brings out
consistency, compliance, efficiency, and automation in deploying workloads at scale.
In this lesson, we will walk through the process of creating a Content Library and
synchronizing it to a second vCenter Server.
HOL-SDC-1602
Page 291
HOL-SDC-1602
Create a New VM
Let's create a very small VM for this lesson. Due to lab constraints this will speed up the
lesson and reduce the amount of storage required.
Click on the VMs and Templates icon in the Home tab.
HOL-SDC-1602
Page 292
HOL-SDC-1602
HOL-SDC-1602
Page 293
HOL-SDC-1602
HOL-SDC-1602
Page 294
HOL-SDC-1602
HOL-SDC-1602
Page 295
HOL-SDC-1602
HOL-SDC-1602
Page 296
HOL-SDC-1602
Select Storage
Click "Next"
HOL-SDC-1602
Page 297
HOL-SDC-1602
Select Compatibility
Click "Next"
HOL-SDC-1602
Page 298
HOL-SDC-1602
Select a guest OS
Click "Next"
HOL-SDC-1602
Page 299
HOL-SDC-1602
Customize Hardware
Very important - make sure you set the hard disk size to 1MB before clicking "Next" this is not a practical size, of course. We are only doing this to make the template copy
go very quickly. Also, set the network to VM Network.
HOL-SDC-1602
Page 300
HOL-SDC-1602
Ready to complete
Verify the hard disk size is 1MB and click "Finish" to create the new VM.
HOL-SDC-1602
Page 301
HOL-SDC-1602
Content Libraries
Now click on the 'Content Libraries' tab.
HOL-SDC-1602
Page 302
HOL-SDC-1602
Objects
Finally, click on the 'Objects' tab.
To create a new Content Library, click on the 'Create a New Library' button.
HOL-SDC-1602
Page 303
HOL-SDC-1602
HOL-SDC-1602
Page 304
HOL-SDC-1602
HOL-SDC-1602
Page 305
HOL-SDC-1602
HOL-SDC-1602
Page 306
HOL-SDC-1602
HOL-SDC-1602
Page 307
HOL-SDC-1602
HOL-SDC-1602
Page 308
HOL-SDC-1602
HOL-SDC-1602
Page 309
HOL-SDC-1602
HOL-SDC-1602
Page 310
HOL-SDC-1602
Progress...
You can follow the progress of the task in the Tasks Console. You can see the Template
was cloned to an OVF package, Exported as an OVF template, then transfered to the
Content Library.
HOL-SDC-1602
Page 311
HOL-SDC-1602
Content Libraries
Next select the 'Content Libraries' tab.
HOL-SDC-1602
Page 312
HOL-SDC-1602
Template Added
Click on the Related Objects tab.
Here we can see the template that we just cloned to the content library.
HOL-SDC-1602
Page 313
HOL-SDC-1602
Edit Settings...
Right click on the 'StandardVMTemplates' content library and select 'Edit Settings...'
Copy URL
In the Edit Library window, click the 'Copy Link' button next to the subscription URL and
click OK. We will need this when we setup the synchronization to the other vCenter
Server.
HOL-SDC-1602
Page 314
HOL-SDC-1602
Home
Click on the Home icon and select Hosts and Clusters.
HOL-SDC-1602
Page 315
HOL-SDC-1602
Select vcsa-01b.corp.local
Select the second vCenter Server, 'vcsa-01b.corp.local'.
Click the 'Related Objects' tab, then click the 'Content Libraries' tab. You may have
to scroll a bit to the right to see it.
HOL-SDC-1602
Page 316
HOL-SDC-1602
In the vCenter Server drop down box, select 'vcsa-01b-corp,local' and click 'Next'.
HOL-SDC-1602
Page 317
HOL-SDC-1602
HOL-SDC-1602
Page 318
HOL-SDC-1602
HOL-SDC-1602
Page 319
HOL-SDC-1602
HOL-SDC-1602
Page 320
HOL-SDC-1602
Tasks Console
You can see in the Tasks Console the Content Library being created and then
synchronized.
You may need to click the refresh button to see an update.
HOL-SDC-1602
Page 321
HOL-SDC-1602
HOL-SDC-1602
Page 322
HOL-SDC-1602
Click on Templates
Click on the Templates tab to view the available Templates.
Right-click on Tiny-VM-Template
Right-click on Tiny-VM-Template and select New VM from This Template.
HOL-SDC-1602
Page 323
HOL-SDC-1602
Select a Resource
Click on Cluster Site B, then click Next.
HOL-SDC-1602
Page 324
HOL-SDC-1602
Review Details
Click Next on the Review Details Page.
Select Storage
In the Select virtual disk format, select 'Thin provision' from the drop-down menu. Also,
make sure ds-site-b-nfs01 is selected as the datastore.
Depending on what modules in this lab you have completed previously, you may see
additional datastores.
Click Next.
HOL-SDC-1602
Page 325
HOL-SDC-1602
Select Networks
Leave the default VM network selected and click Next.
Ready to Complete
Review your settings and click Finish to deploy the new VM!
HOL-SDC-1602
Page 326
HOL-SDC-1602
Monitor Progress
You can monitor the progress of the new virtual machine being created.
When all tasks have been completed successfully, you may proceed to the next step.
HOL-SDC-1602
Page 327
HOL-SDC-1602
HOL-SDC-1602
Page 328
HOL-SDC-1602
New VM Created
Expand vcsa-01b.corp.local and Datacenter Site B and you see your newly created VM!
HOL-SDC-1602
Page 329
HOL-SDC-1602
Conclusion
This concludes this lesson.
HOL-SDC-1602
Page 330
HOL-SDC-1602
HOL-SDC-1602
Page 331
HOL-SDC-1602
HOL-SDC-1602
Page 332
HOL-SDC-1602
HOL-SDC-1602
Page 333
HOL-SDC-1602
In the "Top 25 VMs by Memory Usage(%)" Top N widget, click on the VM "Phoenix-UATPod12a" and note the graph information in the Sparkline Chart below it.
This is an example of dashboard interaction. We will explore this more in the next step.
If you would like to know more about any widget, you can simply click on the "?" icon in
the widget menu to open the documentation to the page covering that widget.
HOL-SDC-1602
Page 334
HOL-SDC-1602
HOL-SDC-1602
Page 335
HOL-SDC-1602
HOL-SDC-1602
Page 336
HOL-SDC-1602
Select the resource which is of the object type "VCHS Virtual Machine" (the middle
resource) by clicking on it.
NOTE: Depending on your screen size, you may need to click the '>>' to see the
filtering option.
HOL-SDC-1602
Page 337
HOL-SDC-1602
HOL-SDC-1602
Page 338
HOL-SDC-1602
HOL-SDC-1602
Page 339
HOL-SDC-1602
Module 5: Optimize
Workload Performance
While Maintaining
Business Priorities - (60
Minutes)
HOL-SDC-1602
Page 340
HOL-SDC-1602
HOL-SDC-1602
Page 341
HOL-SDC-1602
HOL-SDC-1602
Page 342
HOL-SDC-1602
HOL-SDC-1602
Page 343
HOL-SDC-1602
HOL-SDC-1602
Page 344
HOL-SDC-1602
HOL-SDC-1602
Page 345
HOL-SDC-1602
HOL-SDC-1602
Page 346
HOL-SDC-1602
HOL-SDC-1602
Page 347
HOL-SDC-1602
HOL-SDC-1602
Page 348
HOL-SDC-1602
HOL-SDC-1602
Page 349
HOL-SDC-1602
HOL-SDC-1602
Page 350
HOL-SDC-1602
HOL-SDC-1602
Page 351
HOL-SDC-1602
Select Network
1. We are not going to change anything in here, so just hit "Next".
HOL-SDC-1602
Page 352
HOL-SDC-1602
HOL-SDC-1602
Page 353
HOL-SDC-1602
Click On "Finish"
Press "Finish".
HOL-SDC-1602
Page 354
HOL-SDC-1602
HOL-SDC-1602
Page 355
HOL-SDC-1602
The above features are in addition to NetIOC features already available in vSphere 5,
such as:
The ability to assign bandwidth reservations, along with bandwidth limits and shares,
provides you with immense flexibility to control and isolate network resources. A
bandwidth reservation guarantees that the network port (the term network port is used
in this paper to describe a VM vNIC, or a vSphere kernel NIC) is guaranteed a specified
amount of transmit bandwidth under all circumstances. This is a much more powerful
feature compared to the fair shares and bandwidth limit features available in previous
versions of vSphere. While you could control the relative priorities of different VMs by
assigning different shares, the proportion of bandwidth assigned could have fallen to
less than the desired expectation if there were a lot of competition between different
traffic flows. Bandwidth reservation enforces a minimum guarantee and thereby
provides a much easier way of consolidating VMs, guaranteeing them bandwidth, and
not worrying about the effect of virtualization on application performance.
Networking - vds-site-a
Select the Networking tab.
Now select 'vds-site-a'. You may have to expand out vcsa-01a.corp.local to see it.
HOL-SDC-1602
Page 356
HOL-SDC-1602
Resource Allocation
Next, select the 'Manage' tab, the 'Resource Allocation'.
Make sure you are on the 'System traffic' tab.
HOL-SDC-1602
Page 357
HOL-SDC-1602
HOL-SDC-1602
Page 358
HOL-SDC-1602
HOL-SDC-1602
Page 359
HOL-SDC-1602
HOL-SDC-1602
Page 360
HOL-SDC-1602
Note that you do not need to restart the VM in order to apply the new configuration.
Networking - vds-site-a
By using Network Resource Pools, you can configure bandwidth allocation for virtual
machines across the entire Virtual Distributed Switch (vDS). Once you reserved
bandwidth for virtual machine traffic, you can use Network Resource Pools to assign
quotas of the bandwidth, that is aggregated across the physical adapters on the switch,
to the virtual machines. A virtual machine receives bandwidth from a Pool through the
Distributed Port Group the virtual machine is connected to.
Lets assume you have an application that is sensitive to latency and requires
bandwidth to always be available. For instance, a VoIP application. In this scenario, a
new NIOC Resource Pool should be created with a guarantee of bandwidth. Let's get
started.
1. In the vSphere web client go to Network Tab
HOL-SDC-1602
Page 361
HOL-SDC-1602
HOL-SDC-1602
Page 362
HOL-SDC-1602
3. Click OK
HOL-SDC-1602
Page 363
HOL-SDC-1602
View
Now let's make sure that the Network Bandwidth we have reserved for the "linuxload-02a" VM in one of the previous steps, is honored at the Network Resource pool
level. Still in the vSphere web client
1. Go to Network Tab
2. vds-site-a
3. Manage
4. Resource Allocation
HOL-SDC-1602
Page 364
HOL-SDC-1602
HOL-SDC-1602
Page 365
HOL-SDC-1602
HOL-SDC-1602
Page 366
HOL-SDC-1602
HOL-SDC-1602
Page 367
HOL-SDC-1602
Summary
So far in this modules we have looked at Resource Pools, Network and Storage I/O
Control to enable control over usage of resources based on business priorities.
HOL-SDC-1602
Page 368
HOL-SDC-1602
Resource pools allow you to delegate control over resources of a host (or a cluster), but
the benefits are evident when you use resource pools to compartmentalize all resources
in a cluster. Create multiple resource pools as direct children of the host or cluster and
configure them. You can then delegate control over the resource pools to other
individuals or organizations. Using resource pools can result in the following benefits:
Flexible hierarchical organizationAdd, remove, or reorganize resource pools or
change resource allocations as needed.
Isolation between pools, sharing within poolsTop-level administrators can make
a pool of resources available to a department-level administrator. Allocation
changes that are internal to one departmental resource pool do not unfairly affect
other unrelated resource pools.
Access control and delegationWhen a top-level administrator makes a resource
pool available to a department-level administrator, that administrator can then
perform all virtual machine creation and management within the boundaries of
the resources to which the resource pool is entitled by the current shares,
reservation, and limit settings. Delegation is usually done in conjunction with
permissions settings.
Separation of resources from hardwareIf you are using clusters enabled for
DRS, the resources of all hosts are always assigned to the cluster. That means
administrators can perform resource management independently of the actual
hosts that contribute to the resources. If you replace three 2GB hosts with two
3GB hosts, you do not need to make changes to your resource allocations. This
separation allows administrators to think more about aggregate computing
capacity and less about individual hosts.
Management of sets of virtual machines running a multitier service Group
virtual machines for a multitier service in a resource pool. You do not need to set
resources on each virtual machine. Instead, you can control the aggregate
allocation of resources to the set of virtual machines by changing settings on
their enclosing resource pool.
Use Network I/O Control to configure rules and policies at the virtual machine level and
to assure that I/O resources are always available for your business-critical applications.
NIOC monitors the network. Whenever it sees congestion, it automatically shifts
resources to your highest-priority applications as defined by your business rules. Thanks
to NIOC, your administrators can be more productive, you can extend virtualization
across more workloads and your infrastructure can become more versatile.
Use Storage I/O Control to configure rules and policies to specify the business priority of
each virtual machine. When I/O congestion is detected, Storage I/O Control dynamically
allocates the available I/O resources to virtual machines according to your rules,
improving service levels for critical applications and allowing you to virtualize more
workloads, including I/O-intensive applications.
HOL-SDC-1602
Page 369
HOL-SDC-1602
HOL-SDC-1602
Page 370
HOL-SDC-1602
HOL-SDC-1602
Page 371
HOL-SDC-1602
HOL-SDC-1602
Page 372
HOL-SDC-1602
Name: Production
Group Type: Enviornment
Policy: Production Policy
Keep group membership up to date: box is ticked
Select Object type...: vCenter Adapter --> Virtual Machine
HOL-SDC-1602
Page 373
HOL-SDC-1602
HOL-SDC-1602
Page 374
HOL-SDC-1602
Name: Test-Dev
Group Type: Enviornment
Policy: Test-Dev Policy
Keep group membership up to date: box is ticked
Select Object type...: vCenter Adapter --> Virtual Machine
HOL-SDC-1602
Page 375
HOL-SDC-1602
Note: you might need to wait 60 seconds before you refresh the alerts page again to see
the alert displaying as it may take about a minute for the new alert to trigger based on
the new group membership.
Once you see the alert listed, click on the alert link to view its details.
HOL-SDC-1602
Page 376
HOL-SDC-1602
HOL-SDC-1602
Page 377
HOL-SDC-1602
HOL-SDC-1602
Page 378
HOL-SDC-1602
Select a Host
1. Select any of the ESXi Hosts
2. Then hit "Begin Action".
Note: as you can see there is an Affinity Rule Details section where it is mentioned if
there any affinity rules which are about to be broken. In our case no affinity rules are
defined.
HOL-SDC-1602
Page 379
HOL-SDC-1602
HOL-SDC-1602
Page 380
HOL-SDC-1602
Summary
In this Module we have looked at how we can enable controls such as Shares,
Reservations, Limits, SIOC, NIOS over how resources are utilized in vCenter and then
how can these controls dictate how vRealize Operations trigger alert and report on
performance and capacity of resources. In vRealize Operations a custom object group is
a container that includes one or more objects. vRealize Operations Manager uses
custom groups to collect data from the objects in the group, and report on the data
collected.
Why Use Custom Object Groups In vRealize Operations?
HOL-SDC-1602
Page 381
HOL-SDC-1602
You use groups to categorize your objects and have vRealize Operations Manager collect
data from the groups of objects and display the results in dashboards and views
according to the way you define the data to appear.
You can create static groups of objects, or dynamic groups with criteria that determines
group membership as vRealize Operations Manager discovers and collects data from
new added to the environment.
When you create a custom group, and assign a policy to the group, vRealize Operations
Manager can use the criteria defined in the applied policy to collect data from and
analyze the objects in the group. vRealize Operations Manager reports on the status,
problems, and recommendations for those objects based on the settings in the policy.
HOL-SDC-1602
Page 382
HOL-SDC-1602
HOL-SDC-1602
Page 383
HOL-SDC-1602
HOL-SDC-1602
Page 384
HOL-SDC-1602
HOL-SDC-1602
Page 385
HOL-SDC-1602
HOL-SDC-1602
Page 386
HOL-SDC-1602
Impact: Health
Criticality: Warning
Alert Type and Subtype: VirtualizationHypervisor: Capacity
Wait Cycle: 1
Cancel Cycle: 1
HOL-SDC-1602
Page 387
HOL-SDC-1602
HOL-SDC-1602
Page 388
HOL-SDC-1602
HOL-SDC-1602
Page 389
HOL-SDC-1602
HOL-SDC-1602
Page 390
HOL-SDC-1602
Add Recommendations
Recommendations are instruction to the users to help fix the problem identified by the
symptoms. We will first add a recommendation to add more hosts to the cluster.
1. Search the text "add more hosts"
2. Then drag and drop "Add more hosts to the cluster to increase memory capacity" to
the right pane area.
3. We are then going to add an action so now click on the "+" sign.
HOL-SDC-1602
Page 391
HOL-SDC-1602
HOL-SDC-1602
Page 392
HOL-SDC-1602
HOL-SDC-1602
Page 393
HOL-SDC-1602
Summary
The newly created Alert definition is now added to you Alert Definition list and it is
active for all ESXi Hosts objects in your environment. After each collection cycle, the
collected data is compared against all the symptom expressions in the alert definitions.
If the symptom expressions you have added to this alert definition is true for 3
consecutive collection cycles then the alert is generated for the host system. Generated
alerts are listed in the alerts lists for your environment and on the alerts tab for any
ESXi host system. The alerts will include the symptoms and the recommendations to
resolve the problem including any actions if needed.
You can use this process to modify or add other alerts to vRealize Operations ensuring
you are notified when problems occur.
HOL-SDC-1602
Page 394
HOL-SDC-1602
Module 6: Ensure
Business Continuity and
Availability - (30 Minutes)
HOL-SDC-1602
Page 395
HOL-SDC-1602
HOL-SDC-1602
Page 396
HOL-SDC-1602
(multiple/sec). Also note that in versions prior to 6.0, FT required shared storage where
both the Primary and Secondary copies of the FT-protected VM would share the same
VMDK files. However, in vSphere 6.0 in order to add additional protection to the FTprotected VM, the Primary & Secondary VM use unique VMDK's.
FT logging (traffic between hosts where primary and secondary are running) is very
bandwidth intensive and will require a dedicated 10GbE NIC on each host. If FT doesnt
get the bandwidth it needs the impact is that the protected VM will run slower and result
in higher latency to client applications.
HOL-SDC-1602
Page 397
HOL-SDC-1602
This video shows how to protect virtual machines with VMware Fault Tolerance (FT). Due
to resource constraints in the Hands On Labs environment we're unable to demonstrate
this live for you.
HOL-SDC-1602
Page 398
HOL-SDC-1602
HOL-SDC-1602
Page 399
HOL-SDC-1602
HOL-SDC-1602
Page 400
HOL-SDC-1602
HOL-SDC-1602
Page 401
HOL-SDC-1602
Enable HA
1. Tick the box next to "Turn on vSphere HA" and
2. "Protect against Storage Connectivity Loss"
We will simulate our failure by disconnecting storage on the host, so we need this
feature enabled.
HOL-SDC-1602
Page 402
HOL-SDC-1602
HOL-SDC-1602
Page 403
HOL-SDC-1602
Verify HA is Enabled
Click on the "Summary" tab
HOL-SDC-1602
Page 404
HOL-SDC-1602
HOL-SDC-1602
Page 405
HOL-SDC-1602
HOL-SDC-1602
Page 406
HOL-SDC-1602
HOL-SDC-1602
Page 407
HOL-SDC-1602
HOL-SDC-1602
Page 408
HOL-SDC-1602
Check HA Status
1. Click on Cluster Site A-1
2. Then the Monitor tab.
3. Click the vSphere HA button
4. Select the "Datastores under APD or PDL" option. Notice that esx-01a is showing a
failure because of APD (All Paths Down) was detected for storage.
HOL-SDC-1602
Page 409
HOL-SDC-1602
Note HA Alert
In a few moments, you should notice a new Alarm appear in the web client (look to the
right side of the web client) indicating an HA failover is in progress.
NOTE: This may take a few minutes to appear.
HOL-SDC-1602
Page 410
HOL-SDC-1602
HOL-SDC-1602
Page 411
HOL-SDC-1602
HOL-SDC-1602
Page 412
HOL-SDC-1602
HOL-SDC-1602
Page 413
HOL-SDC-1602
HOL-SDC-1602
Page 414
HOL-SDC-1602
HOL-SDC-1602
Page 415
HOL-SDC-1602
HOL-SDC-1602
Page 416
HOL-SDC-1602
Module 7: Simplified
Security and Compliance (30 Minutes)
HOL-SDC-1602
Page 417
HOL-SDC-1602
HOL-SDC-1602
Page 418
HOL-SDC-1602
HOL-SDC-1602
Page 419
HOL-SDC-1602
HOL-SDC-1602
Page 420
HOL-SDC-1602
HOL-SDC-1602
Page 421
HOL-SDC-1602
HOL-SDC-1602
Page 422
HOL-SDC-1602
HOL-SDC-1602
Page 423
HOL-SDC-1602
HOL-SDC-1602
Page 424
HOL-SDC-1602
HOL-SDC-1602
Page 425
HOL-SDC-1602
HOL-SDC-1602
Page 426
HOL-SDC-1602
HOL-SDC-1602
Page 427
HOL-SDC-1602
HOL-SDC-1602
Page 428
HOL-SDC-1602
Start WinSCP
Click the Windows Start button, type "winscp" in the search bar. Click on the WinSCP
shortcut to start the program.
HOL-SDC-1602
Page 429
HOL-SDC-1602
HOL-SDC-1602
Page 430
HOL-SDC-1602
Login as root
Enter username "root" and click "OK"
HOL-SDC-1602
Page 431
HOL-SDC-1602
HOL-SDC-1602
Page 432
HOL-SDC-1602
HOL-SDC-1602
Page 433
HOL-SDC-1602
HOL-SDC-1602
Page 434
HOL-SDC-1602
HOL-SDC-1602
Page 435
HOL-SDC-1602
HOL-SDC-1602
Page 436
HOL-SDC-1602
HOL-SDC-1602
Page 437
HOL-SDC-1602
HOL-SDC-1602
Page 438
HOL-SDC-1602
HOL-SDC-1602
Page 439
HOL-SDC-1602
HOL-SDC-1602
Page 440
HOL-SDC-1602
HOL-SDC-1602
Page 441
HOL-SDC-1602
HOL-SDC-1602
Page 442
HOL-SDC-1602
HOL-SDC-1602
Page 443
HOL-SDC-1602
HOL-SDC-1602
Page 444
HOL-SDC-1602
HOL-SDC-1602
Page 445
HOL-SDC-1602
HOL-SDC-1602
Page 446
HOL-SDC-1602
This will append the CA certificate to the machine certificate. View the resulting file by
executing
cat machine_ssl.cer
HOL-SDC-1602
Page 447
HOL-SDC-1602
/usr/lib/vmware-vmca/bin/certificate-manager
We want to replace the VMCA Root certificate with our custom CA signing certificate and
replace all certificate Selection option 2.
The SSO password is "VMware1!"
Next we will selection option 2 to import the certificate and key.
Provide the path for the custom root certificate
/tmp/machine_ssl.cer
Provide the path for the key
/tmp/root_signing_cert.key
HOL-SDC-1602
Page 448
HOL-SDC-1602
Configure certool.cfg
Enter "Y" at the "Continue Operation" prompt.
Next we will be prompted to configure certool.cfg - for this lab we will just accept the
default values but ideally you would use values meaningful to your enterprise.
Notice that the Hostname value requires you to enter the FQDN of the PSC. Use
"psc-01a.corp.local" and press Enter.
HOL-SDC-1602
Page 449
HOL-SDC-1602
After the import, the PSC services will be restarted - this may take a couple of minutes.
Just wait until it is completed.
HOL-SDC-1602
Page 450
HOL-SDC-1602
HOL-SDC-1602
Page 451
HOL-SDC-1602
HOL-SDC-1602
Page 452
HOL-SDC-1602
ssh vcsa-01a.corp.local
Use the password "VMware1!" for root login
Enter the command
/usr/lib/vmware-vmca/bin/certificate-manager
to start the Certificate Manager
HOL-SDC-1602
Page 453
HOL-SDC-1602
HOL-SDC-1602
Page 454
HOL-SDC-1602
HOL-SDC-1602
Page 455
HOL-SDC-1602
HOL-SDC-1602
Page 456
HOL-SDC-1602
HOL-SDC-1602
Page 457
HOL-SDC-1602
HOL-SDC-1602
Page 458
HOL-SDC-1602
This is an optional part of the lesson and unless you plan to take other lessons that
incorporate vR Ops it is not necessary to proceed.
HOL-SDC-1602
Page 459
HOL-SDC-1602
Login to vrops-01a
Open the Chrome browser and click on the bookmark for vrops-01a.
Enter user name "admin"
Password "VMware1!"
Click "Login"
HOL-SDC-1602
Page 460
HOL-SDC-1602
HOL-SDC-1602
Page 461
HOL-SDC-1602
HOL-SDC-1602
Page 462
HOL-SDC-1602
Re-establish Trust
The vCenter Adapter will be selected by default. Also, the vcsa-01a instance will be
selected by default.
Click on "Test Connection" to initiate an SSL communication test.
Note the "Review and Accept Certificate" window shows the new "Issued to" information
we configured for the VCSA (i.e. "AcmeOrg Engineering").
Click "OK" to trust this new certificate. Click "Save Settings" to complete.
Repeat these steps for each solution adapter and each instance name (i.e. both
instances of vCenter Adapter and both instances of the vCenter Python Actions
Adapter).
Close the Manage Solution window when you have completed re-establishing trust for
all four instances.
HOL-SDC-1602
Page 463
HOL-SDC-1602
HOL-SDC-1602
Page 464
HOL-SDC-1602
Open PuTTY
Click on the PuTTY icon in the taskbar.
HOL-SDC-1602
Page 465
HOL-SDC-1602
Connect to esx-01a.corp.local
Select the saved session for esx-01a.corp.local and click "Open" to start your session.
You will automatically be logged into root.
HOL-SDC-1602
Page 466
HOL-SDC-1602
HOL-SDC-1602
Page 467
HOL-SDC-1602
HOL-SDC-1602
Page 468
HOL-SDC-1602
HOL-SDC-1602
Page 469
HOL-SDC-1602
HOL-SDC-1602
Page 470
HOL-SDC-1602
HOL-SDC-1602
Page 471
HOL-SDC-1602
Verify Permissions
Enter the command
esxcli system permission list
to validate that our user has Admin access to the host. Leave the PuTTY session open
for the next lesson.
HOL-SDC-1602
Page 472
HOL-SDC-1602
HOL-SDC-1602
Page 473
HOL-SDC-1602
esxcli system account set -i=nocuser -p="correct horse battery" -c="correct hor
HOL-SDC-1602
Page 474
HOL-SDC-1602
Again, our password quality check works, disallowing the short phrase (remember we
require at LEAST 4 words in the phrase). OK, let's try a phrase that should give us
success. Enter the command
esxcli system account set -i=nocuser -p="correct horse battery staple" -c="corr
Note we do not get an error indicating the password update was successful.
HOL-SDC-1602
Page 475
HOL-SDC-1602
HOL-SDC-1602
Page 476
HOL-SDC-1602
esx-01a.corp.local
Click on esx-01a.corp.local.
HOL-SDC-1602
Page 477
HOL-SDC-1602
Settings
Click on the Manage tab, then Settings and then Authentication Services.
HOL-SDC-1602
Page 478
HOL-SDC-1602
Join Domain
Click the Join Domain button.
HOL-SDC-1602
Page 479
HOL-SDC-1602
HOL-SDC-1602
Page 480
HOL-SDC-1602
HOL-SDC-1602
Page 481
HOL-SDC-1602
HOL-SDC-1602
Page 482
HOL-SDC-1602
HOL-SDC-1602
Page 483
HOL-SDC-1602
Conclusion
Thank you for participating in the VMware Hands-on Labs. Be sure to visit
http://hol.vmware.com/ to continue your lab experience online.
Lab SKU: HOL-SDC-1602
Version: 20160411-074555
HOL-SDC-1602
Page 484