Useful links on EC2\FSX with new features

https://aws.amazon.com/about-aws/whats-new/2019/11/amazon-fsx-for-windows-file-server-adds-support-for-high-availability-microsoft-sql-server-deployments/

https://aws.amazon.com/about-aws/whats-new/2019/11/amazon-ec2-auto-scaling-supports-max-instance-lifetime/

https://aws.amazon.com/about-aws/whats-new/2019/11/amazon-ec2-auto-scaling-supports-instance-weighting/

https://aws.amazon.com/about-aws/whats-new/2019/11/amazon-fsx-windows-file-server-supports-managing-file-shares-via-powershell/

https://aws.amazon.com/about-aws/whats-new/2019/12/amazon-ec2-spot-now-provides-instance-launch-notifications-via-amazon-cloudwatch-events/

Posted in AWS, EC2 | Tagged , | Leave a comment

Memories of 2019

2019 started with the lot of new surprises in the company roadmap and one of the main change is to move the on-perm to the cloud which means reducing the VMware footprint. Initially it was tough to accept the change but it was good planing on the change from the management end like providing enough training on the AWS\Azur and once team is having sufficient knowledge and confident then start on migrating the work load to the cloud.

I was put in AWS Training and lot of new learnings which allowed to prepare for the certification and  after several months of preparation and experience, completed the AWS solution architect certification. Last three months started migrating the application  to AWS which is very challenging to understand the current design of the application and  planning on it to run in cloud.Gained some experience in CHEF and last two months started working on CI\CD  also with few python  automation.

Past four years I got the opportunity to attend the VMware conference but this year  since the focus is on the cloud, didnt get the chance to attend but at the same time had change to attend my first AWS-Reinvent which is awesome for learning and explore new  services in AWS..

It was a good year and looking forward 2020 to learn more in cloud services.

Posted in 2019, AWS | Tagged | Leave a comment

VCSA6.5 failed to login using AD credentials

One of our vCenter was having issue to login using the AD Credentials . We verified the DNS and the other VC ‘s which connects to the same DNS and AD , found no issues.

When we checked the websso.log , noticed the below error.

2019-11-25T16:08:43.717Z vsphere.local        8d2b3655-340a-46db-b879-5b680911c743 ERROR] [IdentityManager] Failed to authenticate principal [ADUSER@ADDOMAIN] for tenant [vsphere.local]com.vmware.identity.interop.idm.IdmNativeException: Native platform error [code: 851968][null][null]

atcom.vmware.identity.interop.idm.LinuxIdmNativeAdapter.AuthenticateByPassword(LinuxIdmNativeAdapter.java:180)
atcom.vmware.identity.idm.server.provider.activedirectory.ActiveDirectoryProvider.authenticate(ActiveDirectoryProvider.java:279)
atcom.vmware.identity.idm.server.IdentityManager.authenticate(IdentityManager.java:2777)
atcom.vmware.identity.idm.server.IdentityManager.authenticate(IdentityManager.java:9145)
at sun.reflect.GeneratedMethodAccessor29.invoke(Unknown Source)
at sun.reflect.DelegatingMethodAccessorImpl.invoke(Unknown Source)
at java.lang.reflect.Method.invoke(Unknown Source)
at sun.rmi.server.UnicastServerRef.dispatch(Unknown Source)
at sun.rmi.transport.Transport$2.run(Unknown Source)
at sun.rmi.transport.Transport$2.run(Unknown Source)

We tried by rebooting the VC and also removing and adding the AD , even-though we are able to search the AD objects but the authentication was getting failed and finally  the below steps  fixed the issue.

  1. Removed the VC from the domain.
  2.  Deleted the computer account from the AD
  3.  Re-added the VC back to the domain.
  4.  Rebooted the VC, tested connection which was working fine.
Posted in Joining PSC with AD, Platform Services Controller (PSC ), Vcenter Appliance, vCSA 6.0, VCSA6.5, VMware | Tagged , , | Leave a comment

Error while migrating vSphere VMs to Amazon with AWS Server Migration Service

By the help of the link , configured the AWS Server Migration Service and at final stage of the sync it got failed with the error ” Instance failed to boot and establish network connectivity”

So we stopped all the non-microsoft services on the windows instance and tried the sync and it got completed successfully.

Posted in AWS, AWS Server Migration Service, VMware, Windows | Tagged , , | Leave a comment

Useful links to refer the CloudFormation functions.

AWS CloudFormation Templates – Sample CloudFormation templates, solutions, and snippets

CloudFormation::Init Documentation

Using AWS CloudFormer – Introduction and walkthrough for AWS CloudFormer

List of Services Supported in CloudFormation

JSON Formatter and Validator – Free tool for validating JSON templates

How to Use Nested Stacks – How to modularize your CloudFormation stacks

Conditionally-launch-aws-cloudformation-resources-based-on-user-input

Posted in AWS | Tagged , | Leave a comment

Solution for the SMB1 AD Authentication issue – ESXi 6.5U3 update

As per my previous blog on SMB1 AD authentication issue in 6.5u1 , VMware communicated that it will be fixed  after the 6.7 U2 update but it looks like in the recent 6.5 U3 update it got fixed.In the release notes they mentioned some fix related to AD and we tested with few hosts and able to connect the AD now without issue.

https://docs.vmware.com/en/VMware-vSphere/6.5/rn/vsphere-esxi-65u3-release-notes.html

PR 2268193: Managing the Active Directory lwsmd service from the Host Client or vSphere Web Client might fail

Managing the Active Directory lwsmd service from the Host Client or vSphere Web Client might fail with the following error: Failed – A general system error occurred: Command /etc/init.d/lwsmd timed out after 30 secs.

This issue is resolved in this release.

Before:

 VMware ESXi 6.5.0 build-8294253

VMware ESXi 6.5.0 Update 2

After:

VMware ESXi 6.5.0 build-13932383

VMware ESXi 6.5.0 Update 3

Posted in ESX command, ESXi issue, ESXi Patches, VC6.0 Appliance Installation Issue, vCSA 6.0, VCSA6.5, VMware | Tagged , | Leave a comment

VCSA Shell is disabled.

One of our VC is down because of the space issue and not able to login to the Shell.

Followed the below steps to fix the same.

  • Accessed the VCSA on Grub mode
  • Found “/” and /storage/log partitions were full.
  • Released some space in both partitions and rebooted the VCSA
  • We were able to SSH into the VCSA , however found vmware-cm service was failing to start with below error:

Stderr = su: cannot not open session: Permission denied 

  • Checked root expiration date and found it was expired.
  • Reset root password.
  • Restarted services, but issue continue.
  • Tried rebooting the VCSA
  • All the services came up.
Posted in ESXi issue, Vcenter Appliance, vCSA 6.0, VCSA6.5, VMware | Tagged , , , | Leave a comment

Useful links on various AWS topics

Centralized Logging – AWS Answers | https://aws.amazon.com/answers/logging/centralized-logging/

AWS Developer Forums: Discussion Forums | https://forums.aws.amazon.com/index.jspa

Amazon Web Services – Labs · GitHub | https://github.com/awslabs

GitHub – awslabs/aws-shell: An integrated shell for working with the AWS CLI. | https://github.com/awslabs/aws-shell

Region Table | https://aws.amazon.com/about-aws/global-infrastructure/regional-product-services/

AWS Regions and Endpoints – Amazon Web Services | https://docs.aws.amazon.com/general/latest/gr/rande.html

AWS Service Limits – Amazon Web Services | https://docs.aws.amazon.com/general/latest/gr/aws_service_limits.html

AWS IP Address Ranges – Amazon Web Services | https://docs.aws.amazon.com/general/latest/gr/aws-ip-ranges.html

Error Retries and Exponential Backoff in AWS – Amazon Web Services |https://docs.aws.amazon.com/general/latest/gr/api-retries.html

Cloud Solutions by Application – Amazon Web Services (AWS) | https://aws.amazon.com/solutions/

AWS – Application Architecture Center | https://aws.amazon.com/architecture/

AWS Simple Icons | https://aws.amazon.com/architecture/icons/

Compliance Programs – Amazon Web Services (AWS) | https://aws.amazon.com/compliance/programs/

Case Studies & Customer Success – Amazon Web Services (AWS) | https://aws.amazon.com/solutions/case-studies

AWS Certification – AWS Cloud Computing Certification Program | https://aws.amazon.com/certification/

CI/CD on AWS

Click to access serverless-cicd-for-the-enterprise-on-the-aws-cloud.pdf

EC2 Template-  https://templates.cloudonaut.io/en/stable/ec2/

Posted in AWS | Tagged , | Leave a comment

EVC Mode on cluster for encryption

In our POC for our new application , noticed the significant differences on the performance on two different environment which is running on same hardware model.Even though the network layer is different from the environment A and B  the issue is when the data is copied locally .

Later we noticed when we change the EVC Mode from Intel Nehalem Generation to Intel Ivy Bridge a good performance improvement.

From the VMware blog  , it is mentioned that ” For most enterprise applications you can see there is no, or an almost immeasurable, performance impact when using EVC. But, there are certain corner cases, like encryption, that are crippled when instructions sets like AES-NI set are not available (Example: Oracle Transparent Data Encryption, OpenSSL)” so our data in POC is also encrypted and to make sure we setup the test VM and configured the Apache for the speed test with SSL on port 1000.

The htdocs folder was in localdisk (tintri NFS datastore) and tested with localdisk (local SAS disk datastore)

dlspeed=$(echo -n “scale=0; ” && curl -k https://localserver:1000/100MBfile -w “%{speed_download}” -o /dev/null -s | sed “s/\,/\./g” && echo “/1048576”); echo “$dlspeed” | bc -q

EVC mode disabled – 136MB/s 

EVC mode with “Intel Ivy Bridge” – 183MB/s

EVC mode with “Intel Nehalem Generation” – 41MB/s

As per the VMware Blog also they mentioned the test result and for encryption there is a huge different so when setting up the new cluster , we should understand the type of application and traffic type , based on that we have t select the cluster EVC mode.

Note : Anything above Nehalem Generation wont be supported by VMware 7.0 version for HP Gen8 old hardware models so pls check the VMware compatible guide and choose the EVC mode.

Refer:

Click to access vmware-vsphere-evc-performance-white-paper.pdf

https://blogs.vmware.com/vsphere/2014/06/enhanced-vmotion-compatibility-evc-affect-performance.html

Intel CPU EVC Matrix (VMware Enhanced vMotion Compatibility)

Posted in Dell, ESXi issue, HP, Vcenter Appliance, vCSA 6.0, VCSA6.5, VMware | Tagged , , | Leave a comment

SRM IP customization issue on Redhat VMs

During the DR test we have noticed that few of  the Redhat  5\6\7 VMs were failing with various errors like ( “A general system error occurred: vix error codes = (3016,0)”,”Error – Timed out waiting for VMware Tools after 900 seconds”) on IP customization part and we have tried few option but it looks like VMware tools 10.1.x is the cause for the login delay and VMware has recommended to upgrade the SRM to 8.1.1 version.

IP customization might be failing due to the login delays with 10.1.x and above tools which uses SAML token authentication on the OS whereas 10.0.9 and below uses VIX authentication using VM tools when they are running on OS.

With SRM 8.1.1 we have added a delay in the code so the timeout value for this specific task is increased which can allow the customization script to be completed at OS level:

https://docs.vmware.com/en/Site-Recovery-Manager/8.1/rn/srm-releasenotes-8-1-1.html

{SRM 8.1.1 Release Notes – Refer “IP customization during recovery might fail due to delay in the completion of the SRM guest enrollment script”}

As a workaround, we can downgrade to VM tools 10.0.9 version until the upgrade can be performed.

Posted in SRM, VMware | Tagged , , , | Leave a comment