Showing posts with label #IT. Show all posts
Showing posts with label #IT. Show all posts

Wednesday, August 31, 2016

#VMworld Architecting VSAN the VCDXway @simonlong_ & @rayheffer

Great Session presented by Simon Long and Ray Heffer. Before getting into VSAN you need to understand some basic terms:
  1. FTT - Failures to Tolerate - How many hosts needed to tolerate failures
  2. Flash Read Cache Reservation - SSD capacity reserved as read cache for the virtual machine object
  3. Object Space Reservation - the reserve specified as a percentage of the total object address space
  4. Failure Tolerance Method - can be set to either performance or capacity
  5. Witness - ESXi host used for tie breaking
  6. Sparse Swap - provisions VM without space reservation for VM swap
VSAN Objects are all files that make up a VM such as the VMDK and snapfile. When an object is deployed on VSAN it will have related items distributed across hosts. These related items are referred to as Components and are the building blocks of all Objects.

In addition you have SAN Disk Groups that are used to pool flash and magnetic disks. Disks groups are composed of 1 cache disk and at least 1 capacity disk.

VSAN supports View Storage Accelerator. View Storage Accelerator stores commonly used read blocks in DRAM on the ESXi hosts. The Minimum number of Hosts is for VSAN is 2 while the maximum is 64. 2 does not include the witness host. There is a branch architecture that can be done with a 2 host configuration with the witness located elsewhere. VSAN does not support SIOC, Storage DRS or SE Sparse Disk.

When integrating Horizon it will automatically create different VSAN Storage policies based on the Desktop Pool type deployed. If you manually change the Storage policies then a Refresh, Recompose or Rebalance will switch them back to the defaults.

There are 6 default VSAN Storage Policies such as Dedicated Linked Clone, Floating Full Clone, Replica and Persistent Disk that are created by Horizon. It is a good idea to change the FTT setting for the Replica Policy to 2. Is is also a good idea to create a Golden Master VM and Default SAN policy as well.


When you are building out a Horizon environment it is important to understand the business requirements as well as the constraints. In addition use should look to remove all your Single Points of Failures "SPOF" in your design.

While you can deploy View on a Virtual SAN Stretched Cluster, you do have to be careful as the java connection service communication between Connection servers is not latency tolerant. It may be better to have separate View Pods using version Horizon 7 vs. a single Pod depending on the latency between datacenters.
 
 
 
 

Tuesday, August 30, 2016

#VMworld How to Deploy VMware NSX with CISCO Infrastructure

This session is presented by Ron Fuller @ccie5851 and Paul Mancuso @pmancuso

NSX has over 1700+ customers and growing. A few common usecases are micro-segmentation, remote access and IT automation. The sesison will focus on how to integrate Cisco Nexus/ACI and UCS environments. 

NSX provides a faithful reproduction of networking services and infrastructures in software. It is a distrubuted architecture so as you scale out compute you scale out capacity. In addition there is an Firewall component and an integrated API for automation.

NSX Manager is the centralized management plane. Three NSX controllers make up the control plane. In addition the distributed Logical Router "dLR" controls adjecency.

NSX requires three clusters; an infrastructure and management cluster, compute cluster and an Edge cluster. These can be rack servers or integrated UCS blades. On the Edge cluster we would deploy Edge services like the dLR.

We suggest in the logical segmentation of traffic; Management, vMotion, VXLAN and storage networks for standard virtualization. NSX introduces two new VLANs, a transit network for VXLANs and one for Software Bridging between the virtual and physical network. We recommend that the software bridiging is done on the Edge cluster.

In a standard configuration, you end up with 3 IP stacks; Management, VXLAN and the VMotion network. VMware's VXLAN is multicast free. You can use either unicast or a hybrid mode. This is done through L2 frame encapsulation and VXLAN Tunnel EndPoints of "VTEP's". 

VXLAN can be segregated by creating a Transport Zone which is a collection of VXLAN prepared ESXi clusters. Only 1 vDS per ESX cluster can be enabled for VXLAN. Note: if you are running NSX on those ESX clusters you do not need vSphere Enterprise to create a vDS. You get that capability through NSX licensing. Only the VMware vDS is supported so you cannot use Nexus framework.

NSX creates dvUplink port-groups for VXLAN enabled hosts. This uplink carries the VXLAN traffic. NSX Switching requires only two things: an MTU of 1600 and IP Connectivity. NSX is truely agnostic from an underlying switch perspective. 

It is easy to say configure MTU 1600 in your environment put it does take some planning to ensure it is configured on your Cisco framework. VXLAN encapsulation traffic is a 1600 UDP frame. All links belonging to fabric mut be enabled with Jumbo MTU. The risk is that if it is not configured properly you could black hole network traffic so ensure you plan accordingly.

When we look at common Cisco Datacenter Pod topologies, NSX is agnostic. It is important however for VXLAN transport that the VLAN is common between Cisco Pods. For UCS Blades VMware does have some tuning guides for both the B series and C series blades to help you properly tune for NSX\VXLAN traffic. In addition there are NSX Design Guides for the NSX and Cisco UCS and Nexus 9000 infrastructure.






Monday, August 29, 2016

#VMworld VMworld General Session: Day 1

Theme for this year’s session is Be Tomorrow

Pat Gelsinger is introduced as the CEO



Pat challenges the audience to determine which way they will go in the future. VMware is helping customers and partners face forward to deal with the challenges in a digital world. Digital Transformation is the buzz word of 2016. Digital Transformation implies that it needs different management frameworks. VMware says nonsense to this as all business today is digital.

One of the important questions to ask with Digital Transformation is "Is it real?” Pat sites GE as being the only company still part of the Dow industrial average after 12 decades. This is because they are constantly innovating. The next company Pat mentions is CVS and their mobile application that helps track everything they do for the company and their customers.

IDC says that approx. 20% of business are leading in digital transformation. 8 of 10 however don't get it. Are the companies that are not moving forward leaning on their traditional IT methods? What VMware is building is transformational. 

In 2006 Amazon started their Cloud Platform. In 2006 98% where running in traditional IT. 2% where in Public Cloud which was largely salesforce. In 2011 7% of workloads where in Public Cloud with 6% in Private Cloud. In 2016 15% in Public and 12% in Private Cloud. In 2021 according to VMware data will be split 50/50.

When does Public Cloud exceed Private Cloud? The estimate is 2030. There is also a shift in where customers are running their workloads. Managed Cloud Services are growing by 18%. The dominant shift is customers Private Clouds running in someone else's datacenter.

Device proliferation is making end user devices a replacement market. But IoT is exploding and in 2019 it is expected that devices will exceed the number of human devices connected to the web. VMware believes that in this new world as Cloud takes route IT expands not decreases.

VMware and IDC looked at the industries that are embracing cloud such as the construction, professional services, securities, insurance and transportation industries. One major increase in the use of Cloud is through the business units in an organization. Business usage is increasing by through Shadow IT. In an average industry there are cloud, SaaS and mix personal of devices. IT is typically in charge of security in this environment. Ironically IT is responsible for everything but control very little. This sets up a struggle of freedom vs control.

VMware has been working on this through the SDDC. The datacenter will be software and programmable. NSX and Virtual SAN are in the rapid adoption phase "the tornado phase" described in the book "Crossing the Chasm".

VMware Announced today vCloud Air 0 downtime migration to their Cloud. But VMware is not stopping there. VMware Introduces the VMware Cross-Cloud Architecture. VMware Cloud Foundation is the name of this solution. This is not just new pricing and packaging, the foundation extends management and security to Public Cloud. The first partner in this model is IBM.
Robert Leblanc the Sr. VP of IBM is introduced. Robert mentions that they have 500 clients in the cloud with 50% growth month over month. In addition to providing software defined datacenters they also provide desktops as a service. IBM and Cloud Foundation provides the vRealize software as a service.


VMware Cloud Foundation provides visibility in both VMware and Non-VMware Private and Public Clouds. Guido Appenzeller the Chief Technology Strategy Office at VMware is introduced. Guido asks "is IT necessary with Public Cloud?” Even in an age with mega clouds IT is required but the way we manage is different. Citi Bank takes the stage to describe their cloud strategy. The challenge for the bank is can an automated self-service environment be hybrid, leverage commodity components and be secure?


How will the bank deal with the complexity of bursting to Cloud? One of the Banks challenges is automating in a standard way across different Cloud APIs. In addition security is absolute and has to function in a multi-jurisdictional and complaint manner.

Guido asks if VMware can VMotion and manage across multiple hardware providers, why not multiple Public Clouds? VMware Cloud Services is introduced and it will be delivered as a SaaS offering. The demo is started through the VMware Cloud Services management interface. Guido adds a developer users Public Cloud credentials. The tool then sucks up all the resources the user has been developing. Now we can see all the instances the user is running. We can now look at this by application. In the demo the tiers are exposed as well as the costs of the workloads. Guido opens up Security Services to look at the network traffic flow to see if it is secure. This looks to be an Arkin vRealize Network Insight integration.

Part of the suite is NSX; they switch back to VMware's Cloud Services interface. They then deploy the application with an NSX cloud gateway as part the application in the Amazon Public Cloud. The demo switches back to vRealize Network Insight "Security Services" to show that the insecure network traffic flow is now closed.

Guido reiterates that they have done micro-segmentation and secure policy in the Public Cloud. The demo now migrates the workloads between different geographies to different Public Cloud environments (Azure and AWS in the demo). Guido reiterates that they cloned and migrated different workloads across Public Clouds. This is an early tech preview at this time.

Pat returns to stage with Michael Dell who explains how Dells Converged Infrastructure approach is complementary to VMware's Private Cloud Strategy. Pat challenges everyone to take the time to learn these new technologies at the show.