Showing posts with label #VMworld2016. Show all posts
Showing posts with label #VMworld2016. Show all posts

Wednesday, August 31, 2016

#VMworld Architecting VSAN the VCDXway @simonlong_ & @rayheffer

Great Session presented by Simon Long and Ray Heffer. Before getting into VSAN you need to understand some basic terms:
  1. FTT - Failures to Tolerate - How many hosts needed to tolerate failures
  2. Flash Read Cache Reservation - SSD capacity reserved as read cache for the virtual machine object
  3. Object Space Reservation - the reserve specified as a percentage of the total object address space
  4. Failure Tolerance Method - can be set to either performance or capacity
  5. Witness - ESXi host used for tie breaking
  6. Sparse Swap - provisions VM without space reservation for VM swap
VSAN Objects are all files that make up a VM such as the VMDK and snapfile. When an object is deployed on VSAN it will have related items distributed across hosts. These related items are referred to as Components and are the building blocks of all Objects.

In addition you have SAN Disk Groups that are used to pool flash and magnetic disks. Disks groups are composed of 1 cache disk and at least 1 capacity disk.

VSAN supports View Storage Accelerator. View Storage Accelerator stores commonly used read blocks in DRAM on the ESXi hosts. The Minimum number of Hosts is for VSAN is 2 while the maximum is 64. 2 does not include the witness host. There is a branch architecture that can be done with a 2 host configuration with the witness located elsewhere. VSAN does not support SIOC, Storage DRS or SE Sparse Disk.

When integrating Horizon it will automatically create different VSAN Storage policies based on the Desktop Pool type deployed. If you manually change the Storage policies then a Refresh, Recompose or Rebalance will switch them back to the defaults.

There are 6 default VSAN Storage Policies such as Dedicated Linked Clone, Floating Full Clone, Replica and Persistent Disk that are created by Horizon. It is a good idea to change the FTT setting for the Replica Policy to 2. Is is also a good idea to create a Golden Master VM and Default SAN policy as well.


When you are building out a Horizon environment it is important to understand the business requirements as well as the constraints. In addition use should look to remove all your Single Points of Failures "SPOF" in your design.

While you can deploy View on a Virtual SAN Stretched Cluster, you do have to be careful as the java connection service communication between Connection servers is not latency tolerant. It may be better to have separate View Pods using version Horizon 7 vs. a single Pod depending on the latency between datacenters.
 
 
 
 

Tuesday, August 30, 2016

#VMworld How to Deploy VMware NSX with CISCO Infrastructure

This session is presented by Ron Fuller @ccie5851 and Paul Mancuso @pmancuso

NSX has over 1700+ customers and growing. A few common usecases are micro-segmentation, remote access and IT automation. The sesison will focus on how to integrate Cisco Nexus/ACI and UCS environments. 

NSX provides a faithful reproduction of networking services and infrastructures in software. It is a distrubuted architecture so as you scale out compute you scale out capacity. In addition there is an Firewall component and an integrated API for automation.

NSX Manager is the centralized management plane. Three NSX controllers make up the control plane. In addition the distributed Logical Router "dLR" controls adjecency.

NSX requires three clusters; an infrastructure and management cluster, compute cluster and an Edge cluster. These can be rack servers or integrated UCS blades. On the Edge cluster we would deploy Edge services like the dLR.

We suggest in the logical segmentation of traffic; Management, vMotion, VXLAN and storage networks for standard virtualization. NSX introduces two new VLANs, a transit network for VXLANs and one for Software Bridging between the virtual and physical network. We recommend that the software bridiging is done on the Edge cluster.

In a standard configuration, you end up with 3 IP stacks; Management, VXLAN and the VMotion network. VMware's VXLAN is multicast free. You can use either unicast or a hybrid mode. This is done through L2 frame encapsulation and VXLAN Tunnel EndPoints of "VTEP's". 

VXLAN can be segregated by creating a Transport Zone which is a collection of VXLAN prepared ESXi clusters. Only 1 vDS per ESX cluster can be enabled for VXLAN. Note: if you are running NSX on those ESX clusters you do not need vSphere Enterprise to create a vDS. You get that capability through NSX licensing. Only the VMware vDS is supported so you cannot use Nexus framework.

NSX creates dvUplink port-groups for VXLAN enabled hosts. This uplink carries the VXLAN traffic. NSX Switching requires only two things: an MTU of 1600 and IP Connectivity. NSX is truely agnostic from an underlying switch perspective. 

It is easy to say configure MTU 1600 in your environment put it does take some planning to ensure it is configured on your Cisco framework. VXLAN encapsulation traffic is a 1600 UDP frame. All links belonging to fabric mut be enabled with Jumbo MTU. The risk is that if it is not configured properly you could black hole network traffic so ensure you plan accordingly.

When we look at common Cisco Datacenter Pod topologies, NSX is agnostic. It is important however for VXLAN transport that the VLAN is common between Cisco Pods. For UCS Blades VMware does have some tuning guides for both the B series and C series blades to help you properly tune for NSX\VXLAN traffic. In addition there are NSX Design Guides for the NSX and Cisco UCS and Nexus 9000 infrastructure.






#VMworld VMworld General Session Day 2



Sanjay Poonen @spoonen is introduced 

Sanjay wants to discuss the world going digital. For example Sanjay talks about his kid’s education being transformed through after-hours learning like https://www.khanacademy.org/ @khanacademy. Three years ago the end user computing industry was a small part of VMware's business and now it is a huge part of their portfolio.

If we think about the Apps today, there is approx. 50% of the world that is still client-server today. In addition some are web and the others are truly Mobile apps. We have brought this world together in Workspace One. This allows you to marry consumer simplicity with enterprise security.

Sanjay will cover how apps and identity work together as well as desktop and mobile and the underlying security principals. Sanjay transitions to a live demo of Workspace One. Research has shown that users pull their phone out of their pocket 90 times a day for approx. 100 seconds at a time. End User solutions have to provide value under those conditions.

The first thing that is show is single sign-on "SSO" providing simple access to all your business applications. Client-server, web and mobile apps are shown is a single pain of glass, In addition through the integration of boxer (the email application that was acquired by VMware). Integration is shown with AirWatch providing security across different storage repositories such as Google drive. In addition a swipe approval component was built into Workspace One. The integration of Horizon is shown by accessing a desktop through Workspace One.

Sanjay introduces Stephanie Buscemi @sbuscemi the Executive Vice President of Saleforce. Stephanie talks about the partnership with VMware and Saleforce One. Stephanie shows Salesforce wave and the ability to see how sales are doing over the quarter is, look at opportunities along with the opportunity data. In addition all the deal dynamics are available to move the deal forward on your mobile device. The SSO for Saleforce One is all provided through Workspace One.

Sanjay mentions that through the VMworld App you get a free license for VMware Workstation or Fusion. The VMware Horizon team has been innovating like crazy. Sanjay mentions the IBM Softlayer agreement enabling them to bring Desktop as a Service "DaaS" to more customers. According to IDC Horizon leads the market. AirWatch also leads both the IDC and Gartner magic quadrants.

VMware is building out an entire IoT platform that is on display on the show floor. Sanjay transitions to Windows 10 and Workspace One integration. Sanjay shows a demo where a user tries to copy sensitive data from O365 and pasting to twitter. Through Secure Conditional Access the cut and paste is prevented. Now conditional access is shown through the perspective of a user attempting to open data on a spreadsheet on a Horizon desktop. Through the application of NSX security policies the ability to access that data is removed demonstrating micro-segmentation. 

VMware Tanium TrustPoint ( http://www.vmware.com/radius/introducing-vmware-trustpoint-powered-tanium/ ) is demo'd onstage which enables human like queries to see live data in the environment. For example the demo looks for a specific MD5 hash running. The interface brings up every process in the environment that is running the hash. TrustPoint Trace is demo'd which provides deep analytics for what is happening in the environment on the endpoint. You can then look for anything malicious and see if it is running across the environment. Most organizations would take weeks to provide this information while VMware Tanium Trustpoint is doing it in seconds.

Ray O'Farrell @ray_ofarrell the CTO of VMware is introduced. Ray talks about Cloud-Native applications which is a fundamental shift in management frameworks. With a container strategy it is often confusing to understand who you are serving; developers, operations or the end users? The truth is that with Cloud-Native applications, it is all of them.

Kit Colbert @kitcolbert the CTO of the Cloud Platform Business Unit is introduced. Container usage is moving from the early adopters to the enterprise. The speed of containers makes the value evident for developers. From an IT perspective it is much more difficult to manage. Really since VMware does this with VMs it is easy to extend this approach to Containers. This is done through VMware Enterprise Container Platforms. 

vSphere Enterprise Containers are designed for customers that are running a mix of containers and VMs. Within vSphere there is a Docker compatible API. This was ok for the initial release but a Container registry and a developer based portal was required. These have now been integrated into vSphere Enterprise Containers. This is demo'd live onstage along with the ability to enable certain developers and deploy the container through the new portal. From a VM admin perspective all the containers are shown as individual VMs. 

The demo moves to the integration of the Service Composer using NSX security groups being applied to containers. The management of these containers are fully integrated to vRealize Operations Manager. The demo works up the vRealize Suite showing integration of container deployment through vRealize Automation. The Container management portal in vSphere Enterprise Containers is also built into vRealize Automation.

Kit switches gears to the Photon Platform. Photon Platform is geared towards the scaled-out enterprise container workload. The demands for speed and elasticity in these types of platforms are very complex problems to solve. The Photon Platform is open sourced like vSphere Enterprise Containers; a commercial offering called VMware-Pivotal Cloud Native Stack is also available. Kit reiterates that no matter where you are on the adoption of containers VMware has a solution. 

Rajiv Ramaswami the EVP/GM Networking and Security is introduced. The average cost of a data breach is $4 million dollars. With NSX micro-segmentation you can solve this problem by applying a per app firewall through policy. Using NSX your security is always on. 

Rajiv mentions that vRealize Network Insight is free to run an assessment to understand the current security profile of your organization. After an assessment, you need to install NSX. To simply the creation of policies, an early tech-preview is shown of the Micro-segmentation planner. The Micro-segmentation planner allows you to visualize and automatically create Security Policy rules. Once they are created you can push a button to apply these rules.

Yanbing Li @ybhighheels is introduced to talk about Virtual SAN. Virtual SAN is directly implemented as part of vSphere. It is Software Defined Storage. Since Virtual SAN launched they have grown to 5000 customers. VMware is adding 100 Virtual SAN customers a week. Virtual SAN is now becoming mainstream. 40% of the fortune 1000 companies have deployed Virtual SAN today. 64% of these customers are using Virtual SAN for business critical workloads. Several service providers are also looking at Virtual SAN such as IBM and OVH.com. 

An early tech-preview is shown of Virtual SAN capacity planning in which the analytics predict a performance problem is coming, leveraging vRealize Automation a policy is applied which moves the workloads to a 3rd party cloud (no info on how this was done under the covers, maybe Virtual SAN stretched cluster..).

Ray finishes with VMware Cloud Foundation which is a hyper-converged software platform for Private and Public Cloud. VMware's vision recognizes that you will have to deal with a multi-cloud environment with many types of applications from traditional, SaaS and cloud native delivered to any device.  Ray challenges the audience to learn the cross cloud products, engage with VMware and be a leader in this new era.