Tuesday, 24 January 2012

Configuring Active Directory Authentication on ESX


 

To enable active directory authentication on ESX servers you need to do the following...

1. Ensure that it is currently disabled and config is clear before starting: 
/usr/sbin/esxcfg-auth --disablead

2. Confirm the AD kerberos firewall port is blocked:
/usr/sbin/esxcfg-firewall -q activeDirectorKerberosService activeDirectorKerberos is blocked.

3. Enable Active Directory Authentication:
/usr/sbin/esxcfg-auth --enablead --addomain=abc.com.pk --addc=dc1.abc.com.pk

4. Confirm the AD kerberos firewall port is open:
/usr/sbin/esxcfg-firewall -q activeDirectorKerberosService activeDirectorKerberos is enabled.

5. Add an AD username:
/usr/sbin/useradd myaduser1

6. Now try logging into the ESX server on the console and via SSH.
It should allow you to use your active directory password for each AD user you added.


Checking the users on the ESX server:
getent passwd

root:x:0:0:root:/root:/bin/bash
bin:x:1:1:bin:/bin:/sbin/nologin
daemon:x:2:2:daemon:/sbin:/sbin/nologin
adm:x:3:4:adm:/var/adm:/sbin/nologin
lp:x:4:7:lp:/var/spool/lpd:/sbin/nologin
sync:x:5:0:sync:/sbin:/bin/sync
shutdown:x:6:0:shutdown:/sbin:/sbin/shutdown
halt:x:7:0:halt:/sbin:/sbin/halt
mail:x:8:12:mail:/var/spool/mail:/sbin/nologin
news:x:9:13:news:/etc/news:
uucp:x:10:14:uucp:/var/spool/uucp:/sbin/nologin
operator:x:11:0:operator:/root:/sbin/nologin
gopher:x:13:30:gopher:/var/gopher:/sbin/nologin
ftp:x:14:50:FTP User:/var/ftp:/sbin/nologin
nobody:x:99:99:Nobody:/:/sbin/nologin
nscd:x:28:28:NSCD Daemon:/:/sbin/nologin
vcsa:x:69:69:virtual console memory owner:/dev:/sbin/nologin
rpc:x:32:32:Portmapper RPC user:/:/sbin/nologin
sshd:x:74:74:Privilege-separated SSH:/var/empty/sshd:/sbin/nologin
rpcuser:x:29:29:RPC Service User:/var/lib/nfs:/sbin/nologin
nfsnobody:x:4294967294:4294967294:Anonymous NFS User:/var/lib/nfs:/sbin/nologin
pcap:x:77:77::/var/arpwatch:/sbin/nologin
vimuser:x:12:20:vimuser:/sbin:/sbin/nologin
ntp:x:38:38::/etc/ntp:/sbin/nologin
rpm:x:37:37::/var/lib/rpm:/sbin/nologin
vpxuser:x:500:100:VMware VirtualCenter administration account:/home/vpxuser:/bin/false
myaduser1:x:501:501::/home/myaduser1:/bin/bash


Additionally in vSphere client, when the ESX host is selected and the configuration tab is selected. Under the Security Profile the "Active Director Kerberos" ports will show under outgoing connections.

Configuring iSCSI Storage (Basic)


For HA, DRS, vMotion and Storage vMotion to work you need to use shared storage, in this case an iSCSI SAN.
I will show you how to configure ESX to connect to and use iSCSI SAN storage in its most basic way.

See Configuring iSCSI Storage (Advanced with CHAP) if you will be using CHAP authentication.

1. Firstly you need to ensure you have a VMkernel Port.
If you do not have a "VMkernel Port" on a vSwitch on your ESX server you will need to Create a VMkernel Port.
By default the installation of ESX only creates a "Virtual Machine" and "Service Console" port group.

2. Now the storage adaptor needs configuring. This is a software iSCSI adaptor but the method is the same. (Note that using a software ISCSI adaptor adds an extra overhead to the server).

3. In the "Storage Adaptors" section click on the iSCSI adaptor (e.g. iSCSI Software Adaptor) you want to configure, then click "Properties".

4. Click "Configure" in the iSCSI initiator properties dialog.

5. In the status section tick "Enabled" and click Ok.

6. The iSCSI initiator name and alias will be created and the status will show "enabled".

7. When using send targets click on the "Dynamic Discovery" tab.
8. Click "Add". Enter the IP of the iSCSI server and the port for discovery.
9. Click Ok and then Close.

10. You will be asked to rescan the host. Click Yes.

11. You will now see the iSCSI adaptor settings and any LUNs you have configured for this host on your SAN.

Configuring iSCSI Storage (Advanced with CHAP)


For HA, DRS, vMotion and Storage vMotion to work you need to use shared storage, in this case an iSCSI SAN.
I will show you how to configure ESX to connect to and use iSCSI SAN storage with CHAP authentication.

See Configuring iSCSI Storage (Basic) if your not using CHAP.

1. Firstly you need to ensure you have a VMkernel Port.
If you do not have a "VMkernel Port" on a vSwitch on your ESX server you will need to Create a VMkernel Port.

By default the installation of ESX only creates a "Virtual Machine" and "Service Console" port group.

2. Now the storage adaptor needs configuring. This is a software iSCSI adaptor but the method is the same. (Note that using a software ISCSI adaptor adds an extra overhead to the server).

3. In the "Storage Adaptors" section click on the iSCSI adaptor (e.g. iSCSI Software Adaptor) you want to configure, then click "Properties".


4. Click "Configure" in the iSCSI initiator properties dialog.


5. In the status section tick "Enabled" and Click Ok.


6. The iSCSI initiator name and alias will be created and the status will show "enabled". Click Close.

7. Click "CHAP..." to begin configuring the CHAP authentication credentials.


8. Now we can enter CHAP authentication details.
Entering the details here on the iSCSI initiator makes it the default settings for all targets (it can also be entered per target if you have specific settings for each target).
Enter the CHAP username and secret for the target host.
You must created these on your iSCSI SAN storage prior to this (see Changing restricted access to a Volume on an EqualLogic PS as an example).
Click Ok.


9. When using send targets click on the "Dynamic Discovery" tab.
10. Click "Add". Enter the IP of the iSCSI server and the port for discovery.


11. Click Ok and then Close. 


12. You will be asked to rescan the host. Click Yes.


13. You will now see the iSCSI adaptor settings and any LUNs you have configured for this host on your SAN.


Multiple VMkernel NICs

Multiple VMkernel NICs, Round Robin MPIO - DVS and Jumbo Frames


By creating multiple VMKernel NICs it makes it possible to have multiple paths to iSCSI SAN storage and utilize MPIO.
However to do this and implement certain performance tweaks this has to be done partly via the GUI and partly via the service console. Hopefully in the future VMware will implement additions to the GUI to allow this.

While you may have several physical network adaptors connected to a vSwitch (in this case a distributed vSwitch - DVS), the VMkernel ports are required to make different connections/sessions to the iSCSI SAN storage device(s).

In this case it is used to configure MPIO via ESX 4 and a Dell EqualLogic PS SAN array. However the process should be similar if not the same for other vendor iSCSI SAN storage.

1. Set physical switch ports to MTU 9000
For example on Cisco 3750/3560 switches:
3750(config)# system mtu jumbo 9000
3750(config)# exit
3750# reload
 

2. Set DVS to MTU 9000In vCenter go to Home --> Networking.
Create or click on the Distributed Virtual Switch (DVS) that is being used for ISCSI storage.
 


3. Create VMKNICs via GUI (Defaults to MTU 1500)

If you already have created 1 or more VMkernel ports continue...



4. Logon to the ESX service console and list the VMkernel interfaces.
Take note of the IP addresses.

/usr/sbin/esxcfg-vmknic -lInterface  Port Group/DVPort   IP Family IP Address                              Netmask         Broadcast       MAC Address       MTU     TSO MSS   Enabled Type
vmk0       56                 IPv4      10.1.1.50                            255.255.255.0 10.1.1.255    00:50:56:3b:02:8c 1500    65535     true    STATIC
vmk1       57                 IPv4      10.1.1.51                            255.255.255.0 10.1.1.255    00:50:56:37:09:82 1500    65535     true    STATIC
vmk2       58                 IPv4      10.1.1.52                            255.255.255.0 10.1.1.255    00:50:56:3c:6e:72 1500    65535     true    STATIC
vmk3       59                 IPv4      10.1.1.53                            255.255.255.0 10.1.1.255    00:50:56:3d:ef:7d 1500    65535     true    STATIC



5. List the vSwitch details
Take note of the DVPort ID for each VMKernel (vmk#) NIC

/usr/sbin/esxcfg-vswitch -lDVS Name                        Num Ports   Used Ports  Configured Ports  Uplinks
dvSwitch3-ISCSI-Storage 256                    7           256                      vmnic7,vmnic3

  DVPort ID           In Use      Client
  131                 1           vmnic3
  132                 1           vmnic7
  56                   1           vmk0
  57                   1           vmk1
  58                   1           vmk2
  59                   1           vmk3



6. Delete the VMkernel NICs that were created previously.
This is so we can add them back with an MTU of 9000, the GUI does not allow this. We also need a DV Port ID to create it via the service console.

/usr/sbin/esxcfg-vmknic -d -s dvSwitch3-ISCSI-Storage -v 56
/usr/sbin/esxcfg-vmknic -d -s dvSwitch3-ISCSI-Storage -v 57
/usr/sbin/esxcfg-vmknic -d -s dvSwitch3-ISCSI-Storage -v 58
/usr/sbin/esxcfg-vmknic -d -s dvSwitch3-ISCSI-Storage -v 59


 

7. Create VMKNICs with MTU 9000
Using the DV Port ID recorded previously we create the VMkernel port with an MTU of 9000 (for jumbo frames)
/usr/sbin/esxcfg-vmknic -a -i 10.1.1.50 -n 255.255.255.0 -m 9000 -s dvSwitch3-ISCSI-Storage -v 56
/usr/sbin/esxcfg-vmknic -a -i 10.1.1.51 -n 255.255.255.0 -m 9000 -s dvSwitch3-ISCSI-Storage -v 57
/usr/sbin/esxcfg-vmknic -a -i 10.1.1.52 -n 255.255.255.0 -m 9000 -s dvSwitch3-ISCSI-Storage -v 58
/usr/sbin/esxcfg-vmknic -a -i 10.1.1.53 -n 255.255.255.0 -m 9000 -s dvSwitch3-ISCSI-Storage -v 59 



8. Confirm the VMkernel NIC settings:
/usr/sbin/esxcfg-vmknic -l
Interface  Port Group/DVPort   IP Family IP Address                              Netmask         Broadcast       MAC Address       MTU     TSO MSS   Enabled Type
vmk0       56                 IPv4      10.1.1.50                            255.255.255.0 10.1.1.255    00:50:56:7b:02:8c 9000    65535     true    STATIC
vmk1       57                 IPv4      10.1.1.51                            255.255.255.0 10.1.1.255    00:50:56:77:09:82 9000    65535     true    STATIC
vmk2       58                 IPv4      10.1.1.52                            255.255.255.0 10.1.1.255    00:50:56:7c:6e:72 9000    65535     true    STATIC
vmk3       59                 IPv4      10.1.1.53                            255.255.255.0 10.1.1.255    00:50:56:7d:ef:7d 9000    65535     true    STATIC


9. Test that the VMkernel settings with an MTU of 9000 is working correctly:
/usr/sbin/vmkping -s 9000 10.1.1.200PING 10.1.1.200 (10.1.1.200): 9000 data bytes
9008 bytes from 10.1.1.200: icmp_seq=0 ttl=255 time=0.533 ms
9008 bytes from 10.1.1.200: icmp_seq=1 ttl=255 time=0.501 ms
9008 bytes from 10.1.1.200: icmp_seq=2 ttl=255 time=0.518 ms



10. View SCSI adaptors and confirm the adaptor used for ISCSI
/usr/sbin/esxcfg-scsidevs -avmhba0  mpt2sas           link-n/a  sas.5a4badb00ecf3400                    (3:0.0) LSI Logic / Symbios Logic Dell PERC H200 Integrated
vmhba1  lpfc820           link-n/a  fc.20000000c996a8bd:10000000c996a8bd    (4:0.0) Emulex Corporation LPe12000 8Gb Fibre Channel Host Adapter
vmhba2  lpfc820           link-n/a  fc.20000000c99aed0c:10000000c99aed0c    (5:0.0) Emulex Corporation LPe12000 8Gb Fibre Channel Host Adapter
vmhba3  ata_piix          link-n/a  sata.vmhba3                             (0:31.2) Intel Corporation 2 port SATA IDE Controller (ICH9)
vmhba32 ata_piix          link-n/a  sata.vmhba32                            (0:31.2) Intel Corporation 2 port SATA IDE Controller (ICH9)
vmhba33 iscsi_vmk         link-n/a  iqn.1998-01.com.vmware:starscream-2d842e60() Software iSCSI



11. List VMKNICs bound to the ISCSI software adaptor/usr/sbin/esxcli swiscsi nic list -d vmhba33No iSCSI Nics Found


12. Bind VMKNICs to the software ISCSI adaptorAllow more sessions per datastore, and allow MPIO multiplathing.

/usr/sbin/esxcli swiscsi nic add -n vmk0 -d vmhba33
Errors:
Add Nic failed in IMA.

This error will occur when there is more than 1 physical uplink on the switch the VMkernel NIC is connected to.
Changing the vSwitch temporarily so there is only one active adaptor and the rest to unused, will allow the VMK to be bound to the software ISCSI adaptor.
 

/usr/sbin/esxcli swiscsi nic add -n vmk0 -d vmhba33
/usr/sbin/esxcli swiscsi nic add -n vmk1 -d vmhba33
/usr/sbin/esxcli swiscsi nic add -n vmk2 -d vmhba33
/usr/sbin/esxcli swiscsi nic add -n vmk3 -d vmhba33

 


13. Confirm that all VMkernel NICs were sucessfully bounded to the ISCSI adaptor.
/usr/sbin/esxcli swiscsi nic list -d vmhba3
vmk0
    pNic name: vmnic3
    ipv4 address: 10.1.1.50
    ipv4 net mask: 255.255.255.0
    ipv6 addresses:
    mac address: b8:ac:6f:7f:ff:d8
    mtu: 9000
    toe: false
    tso: true
    tcp checksum: false
    vlan: true
    link connected: true
    ethernet speed: 1000
    packets received: 139011
    packets sent: 17613
    NIC driver: bnx2
    driver version: 1.6.9
    firmware version: 5.0.11 NCSI 2.0.5

vmk1
    pNic name: vmnic3
    ipv4 address: 10.1.1.51
    ipv4 net mask: 255.255.255.0
    ipv6 addresses:
    mac address: b8:ac:6f:7f:ff:d8
    mtu: 9000
    toe: false
    tso: true
    tcp checksum: false
    vlan: true
    link connected: true
    ethernet speed: 1000
    packets received: 139011
    packets sent: 17613
    NIC driver: bnx2
    driver version: 1.6.9
    firmware version: 5.0.11 NCSI 2.0.5

vmk2
    pNic name: vmnic3
    ipv4 address: 10.1.1.52
    ipv4 net mask: 255.255.255.0
    ipv6 addresses:
    mac address: b8:ac:6f:7f:ff:d8
    mtu: 9000
    toe: false
    tso: true
    tcp checksum: false
    vlan: true
    link connected: true
    ethernet speed: 1000
    packets received: 139011
    packets sent: 17613
    NIC driver: bnx2
    driver version: 1.6.9
    firmware version: 5.0.11 NCSI 2.0.5

vmk3
    pNic name: vmnic3
    ipv4 address: 10.1.1.53
    ipv4 net mask: 255.255.255.0
    ipv6 addresses:
    mac address: b8:ac:6f:7f:ff:d8
    mtu: 9000
    toe: false
    tso: true
    tcp checksum: false
    vlan: true
    link connected: true
    ethernet speed: 1000
    packets received: 139011
    packets sent: 17613
    NIC driver: bnx2
    driver version: 1.6.9
    firmware version: 5.0.11 NCSI 2.0.5


 
14. Now change back the vSwitch settings so that any unused uplink adaptors active again.
 



15. On the ESX server Click "Rescan..." under the Configuration tab "Storage adaptors" section.


16. On each VMFS volume Click "Properties" and then "Manage Paths"
 


17. You will now see multiple paths to the VMFS datastore (LUN).

18. Change the path selection to "Round Robin (VMware)"
 

Resize a VMs Virtual Disk

How to Resize a VMs Virtual Disk (.VMDK) 

















When you created your virtual machine you of course created the number of disks and their sizes as per the requirements, best practice guidelines or just your best estimation for its use. However, as requirements change and the amount of data in your virtual machine grows, from time to time you need add additional storage. How do you resize the virtual disk (.VMDK)?

Resizing virtual disks is relativley straight forward. However, as with anything before making changes ensure you have a backup (especially when making changes to disks).
Note: You cannot change the disk size if you take a snapshot, plus if there was an issue with the disk the snapshot would be useless anyway.

Another thing to be aware of is you can only INCREASE the size of a virtual disk. You cannot reduce the size of a virtual disk, VMware does not currently allow it as it could risk losing data. If you want to reduce the disk size you could either use VMware converter to copy the VM and resize the disks at the same time or create a new smaller virtual disk and copy the data over to it.


To Increase the size of a virtual disk (.VMDK):
1. Shutdown the virtual machine.
2. Right click on the virtual machine and select "Edit Settings".
3. On the "Hardware" tab, select the virtual disk you would like to resize and in the "Capacity" section enter the required size.


We are not finished yet. If you boot the virtual machine now the OS will not see the new size, it will only see the old size. You need to expand the volume into the new free space. Below are two methods of doing this, and depding on the guest OS and your preference depends which one you will choose.
Method 1 (Windows DISKPART) will of course only work in windows.
Method 2 (GParted) will work for any OS, including Linux and Unix provided as the filesystem type is supported by your chosen partitional utility.



Method 1 (Windows DISKPART):
1.
Click Start --> Run and type "diskmgmt.msc"
2. You will see the free space after your volume.


3.
Use DISKPART to extend the volume into all the free space:
diskpart
list volume
select Volume 0
extend
exit




4.
You will now see the volume has been extended to use all the free space.





Method 2 (GParted):
To resize the partition on the disk use your favourite partition resizing tool. If you dont have one mine is GParted, which there is a live CD for.
Download the GParted Live CD

1. Click on the "Options"  tab and go to "Boot Options".
2. Tick "Force BIOS Setup" (This will boot into the BIOS screen when the VM is powered on - This is so that you can mount and ISO image before the OS boots.)
3. Click Ok to reconfigure the virtual machine.


4. Connect the ISO image or connect the CD drive with your GParted Live CD (This is easier with force BIOS option set in step 5).

5. Boot into GParted and you will see the current partion in the now much larger disk.

6. Right click on the partion and select "Resize/Move".

7. Resize the partion to fill entire remaining space and click "Resize/Move".

8. Click "Apply" to run the resize task. After sometime depending on the size the task will complete.
9. Reboot the computer, remove the CD and boot into the OS.

10. Depending on the OS it may perform a disk check like Windows Server 2003 here.

11. You should now see the disk has been resized.

Consolidated Backup Process

VCB Process


This is the process that VCB takes to backup a VM.

Using your backup software create a backup job for the VM(s) you want to backup. The backup jobs purpose is to backup a location on the VCB server. You will know the location once you determine what type of VCB backup you are going to perform.
See Image‐level virtual machine backups.
See File‐level backups.

When the backup job is launched, the following steps take place:
Step 1
The backup software calls the pre‐backup script.

The pre‐backup script does the following:
1. Runs a pre‐freeze script in the VM. The pre‐freeze script prepares the VM for backup. (this is optional)

2. Quiesces NTFS and FAT file systems inside the VM (only for VMs running 32‐bit versions of Windows XP, Windows 2000, or Windows 2003). This ensures that no file system writes are pending at the time the snapshot is taken, allowing the creation of file‐system consistent backups.

3. Puts the virtual machine into snapshot mode.

4. Unquiesces the NTFS and FAT file systems that were quiesced.

5. Runs a post‐thaw script in the VM. (this is optional)

6. Makes the VM snapshot available to the 3rd party backup software:
See Image‐level VM backups.
See File‐level VM backups.

Step 2
The backup software performs a backup of the VM snapshot.

Step 3
The backup software runs a post‐backup script, which does the following:

1. Unmounts the VM snapshot from the backup proxy.

2. Takes the VM out of snapshot mode. Commits changes made while the VM was in snapshot mode.

Find VMs and information - vcbvmname.exe


Print E-mail
vcbvmname.exe can be used to find out a VMs name, IP address, ID and hostname. It can be found in \Program Files\VMware\VMware Consolidated Backup Framework along with the rest of the VCB commands.

Here is an example of the command:
vcbvmname -h vcserver -u vcbuser -p secretpass -s Any:

Found VM:
moref:vm-6354
name:ExampleVM1
uuid:31458901-2535-c376-1f56-5984ba3685d2
ipaddr:192.168.1.2