Tagged: VMware

Hardening Guide 1

VMware vSphere Hardening

Today, many companies have virtualized farms for their server infrastructure or desktop infrastructure and cloud services. The companies have critical information on their virtualized farms and keeping safe them is one of big concerns. Big companies or even small companies have security teams and the teams tries to keeping secure the environments in different layers. Most of the security products are working on physical layer or network and application layer but what about Hypervisor layer? vSphere Hardening VMware publishing a hardening guide for each vSphere version to help administrator to keep their environments more secure. vSphere hardening guides are available in the below link as Excel files: Download – Hardening Guides Previously, VMware had published an application to analyzing your vSphere environment and report you any security issue according to hardening guides. VMware Sphere Compliance Checker was available up to vSphere 5.5 and that’s not available for vSphere 6.x but you can use “VMware vRealize Configuration Manager” on this regard. Anyway, you can check and change security configurations accordion to hardening guides on your servers manually.

ESXi Reliable Memory Technology 0

ESXi Reliable Memory Technology

VMware has introduced new feature for kernel protection against memory error in ESXi. VMware called the new feature: Reliable Memory Technology or RTM. The feature is one of new features in ESXi 5.5! ESXi use a zone of memory that it’s more reliable than other offsets of memory, so risk of PSOD will be reduced. Also when part of memory has error, ESXi will stop to using the part of memory. There is some other technique against memory corruption or memory health error such as memory mirroring but Reliable Memory Technology can help you on this regard without loosing half of your memory capacity. Because memory mirroring is just like to RAID 1 on hard disks. Dell has introduced another feature on its server by using Reliable Memory Technology and called the new feature: Fault Resilient Memory or FRM. Fault Resilient Memory will provide “Fault Resilient Zone” and ESXi will put its kernel to the zone. The features can protect ESXi kernel and VMs as well. So if you have critical service on a VM, you can force ESXi to keep its memory on RTM or FRM zone to avoid memory error and down time for the machine. You can configure...

nested virtualization 0

ESXi Virtual Appliance

As you may know, you can install hypervisors on virtual machines for testing purpose. When you had installed ESXi on virtual machine, you did nesting virtualization. But think about installation process, any installation needs around 20 minutes and if you cloned a ESXi machine, it will be not worked properly on other virtual machine and you have to change your configuration manually. Now there is good solution and it’s ESXi virtual appliance. You can download ESXi OVA file and import it to your host or vCenter and also you can configure it during import process. ESXi virtual appliance is available at the below links: ESXi 6.0 Virtual Appliance download link ESXi 5.5 Virtual Appliance download link  ESXi virtual appliance maybe updated after releasing new version. The last versions are: ESXi 6.0 U2 ESXi 5.5 U3 The ESXi virtual appliance including the below configurations: ESXi 6.0 U2: ESXi 6.0 Update 2 GuestType: ESXi 5.x (backwards compat) vHW 10 2 vCPU 6GB vMEM 2 x vmxnet3 vNIC 1 x 2GB HDD (ESXi Installation) 1 x 4GB SSD (for use w/VSAN, empty by default) 1 x 8GB SSD (for use w/VSAN, empty by default) VHV added dvFilter Mac Learn VMX params added disk.enableUUID VMX param added...

hv replica job re ip 2

Re-IP Rule on Linux VM: Best Solution in Veeam Backup and Replication 7.x Version and Newer

Veeam Backup & Replication is one of the best backup and replication software that you can use them in your virtual environment. Veeam BR be able to IP customization during disaster-recovery and you can have your virtual machines in a DR site with different IP plan. But Veeam BR just support Windows VMs for IP customization or “Re-IP Rule”. So what can we do about Linux virtual machines and others?

vSphere HA virtual machine monitoring action 0

vSphere HA virtual machine monitoring action

When you enabled HA on a clster, some definition alarm will be activated. “vSphere HA virtual machine monitoring action” is one of them, this alarm has two triggers: vSphere HA enabled VM reset with screenshot. vSphere HA is resetting VM. These are useful alarms for troubleshooting and know, what was happened for a virtual machines during fail-over. Also you can find the screenshot on the VM’s folder as a PNG file. [quotes_and_tips]  

VMware products and their virtual hardware version 0

VMware products and their virtual hardware version

This table lists VMware products and their virtual hardware version: Virtual Hardware Version Products 10 ESXi 5.5 Fusion 6.x Workstation 10.x Player 6.x 9 ESXi 5.1 Fusion 5.x Workstation 9.x Player 5.x 8 ESXi 5.0 Fusion 4.x Workstation 8.x Player 4.x 7 ESXi/ESX 4.x Fusion 3.x Fusion 2.x Workstation 7.x Workstation 6.5.x Player 3.x Server 2.x 6 Workstation 6.0.x 4 ACE 2.x ESX 3.x Fusion 1.x Player 2.x 3 and 4 ACE 1.x Lab Manager 2.x Player 1.x Server 1.x Workstation 5.x Workstation 4.x 3 ESX 2.x GSX Server 3.x Consider this information about virtual hardware versions when dealing with related problems: A VMware product cannot power on a virtual machine with a virtual hardware version that is higher than what it supports.Note: If a virtual machine is created on a VMware product that supports a given virtual hardware version and is then migrated to a VMware product that does not support this level of virtual hardware, it does not power on. Consult the chart above. Virtual machines created by VMware products and versions located higher up in the chart cannot be powered on by products lower on the chart. A VMware product can power on a virtual machine with...