Showing posts with label Whats New?. Show all posts
Showing posts with label Whats New?. Show all posts

Wednesday, June 28, 2017

Part 6 - Configuration & Compliance Dashboards in vRealize Operations 6.6.
























Welcome to the next post of the series on What's New with vRealize Operations Manager 6.6. In the last few parts of this series, I have been writing about the out of the box dashboards available in vROps 6.6.

In this post I will talk about the last out of the box category of Configuration & Compliance. I have skipped Workload Balance for now as it is more than a dashboard in vRealize Operations 6.6. I will share a series of post on that topic in the days to come.

Let us focus on the category of Configuration & Compliance. Here is how Configuration & Compliance shows up on the Getting Started Page:




The Configuration and Compliance category caters to the administrators who are responsible to manage configuration drifts within a virtual infrastructure. Since most of the issues in a virtual infrastructure are a result of inconsistent configurations, dashboards in this category highlight the inconsistencies at various levels such as Virtual Machines, Hosts, Clusters and Virtual Networks. You can view a list of configuration improvements that helps you to avoid problems that are caused because of misconfigurations.

Your IT security teams can also measure your environment against the vSphere hardening best practices to ensure that your environment is fully secured and meets all the compliance standards.

Key questions these dashboards help you answer are :

  • Are the vSphere clusters consistently configured for high availability and optimal performance?
  • Are the ESXi hosts consistently configured and available to use?
  • Are the Virtual Machines sized and configured as per recommended best practices?
  • Are virtual switches configured optimally?
  • Is the environment configured in accordance with the vSphere Hardening Guide?


Let us look at each of these dashboard and I will provide a summary of what these dashboards can do for you along with a quick view of the dashboard:


Cluster Configuration

The Cluster Configuration Dashboard provides you a quick overview of your vSphere cluster configurations. It highlights the areas which are important to deliver performance and availability to your virtual machines. The dashboard quickly highlights if there are clusters which are not configured for DRS, HA or Admission Control to avoid any resource bottlenecks or availability issues in case of a host failure.

The heatmap on this dashboard, quickly identifies if you have hosts where vMotion was not enabled as this would not allow the VMs to move from or to that host. This could cause potential performance issues on the VMs living on that host if the host gets too busy. The dashboard also provides you a quick view of how consistently your clusters are sized and whether the hosts on each of those clusters are consistently configured. 

The Cluster Properties view in this dashboard allows you to easily report on all these parameters by simply exporting the data and share the same with relevant stakeholders within your organization.





Host Configuration

The Host Configuration dashboard provides you a quick overview of your ESXi host configurations and capture inconsistencies to take corrective actions. Along with configurations, the dashboard measures the ESXi hosts against the vSphere best practices and calls out if it finds a deviation which can impact the performance or availability of your virtual infrastructure.

While you can always view this data using the dashboards, the ESXi Configuration view on this page allows you to export this data and share the same with administrator responsible to manage the hosts. 



Network Configuration

The Network Configuration dashboard provides a detailed view of virtual switch configuration and utilization. On selecting a virtual switch you can see the list of ESXi hosts, DV port Groups and virtual machines which are being served by the select switch.

You can easily identify any misconfigurations within various network components by reviewing the properties listed in the views within the dashboard. The drill down to the virtual machine levels allows you to track important information such as IP address and MAC address assigned to the virtual machines.

A network administrator can use this dashboard to get a visibility into the virtual infrastructure network configuration.



VM Configuration

The Virtual Machine Configuration dashboard focuses on highlighting the key configurations of the virtual machines in your environment. The goal of this dashboard is to help you find inconsistencies of configuration within your virtual machines in order to take quick remediation measures. This helps you safeguard the applications which are hosted on these virtual machines by avoiding potential issues due to misconfigurations. 

Some of the basic issues the dashboard focuses on includes identifying VMs running on older VMware tools versions, VMware tools not running or virtual machines running on large disk snapshots. VMs with such symptoms can lead to potential performance issues and hence it is important to ensure that they do not deviate from the defined standards.

This dashboard is complimented with an out of the box report named "Virtual Machine Inventory Summary" which can be used to report the configurations highlighted on this dashboard for quick remediation. 
 




vSphere Hardening Compliance

The vSphere Hardening Compliance dashboard measures you environment against the vSphere Hardening Guide and lists down the objects which are non-compliant. You can see the trend of High Risk, Medium Risk and Low Risk violations and see the overall compliance score of your virtual infrastructure.

The dashboard also allows you to drill down into various components to check compliance for your ESXi hosts, Clusters, Port Groups and virtual machines using heatmaps.

Each non-compliant object is listed in the dashboard with recommendations on remediation required to secure your virtual infrastructure.


     

     In case you are like me, and don't like to READ. You can see the dashboards in action in this video playlist:

See all dashboards in action here.


More to come.. Stay Tuned!!


Friday, September 30, 2016

vROps Webinar Series - Part 9 - What's New with vRealize Operations 6.3

Here is the recording for the episode 9  vRealize Operations Manager Webinar Series 2016. During this episode we discussed about the new features and functionalities of vRealize Operations Manager 6.3. With this release of the product, we can clearly see that VMware is clearly working on enhancing the user experience and the user interface with some great new features and UI changes.

I would encourage you to watch this session to understand the full potential of the product and how you can use the new features to meet your requirements and ease out operations in your Virtual / Cloud environments.

Special thanks to Simon Eady and Iwan Rahabok for delivering this as a team.

So without further ado, here is the recording for this session:






Note : It is recommended that you watch the video in HD quality for a great experience.




Monday, September 19, 2016

vROps Webinar 2016 - Announcing Part 9 : What's New with vRealize Operations Manager 6.3

It's the time of the month when I would like to invite you to join the next episode of our year long vROps Webinar Series. As we move towards winters, we would like to take a zoom out view at the vRealize Operations Manager solution with a What's New Episode. For the past 8 months, we have gone pretty deep into most of the product features and I believe it is time when we review the product in it's current form and shape. In my opinion, this could not be done better than sharing about the new features & functionalities available in the latest version of vRealize Operations Manager.
While throughout the journey of this series we have discussed various versions of the product, this time around our focus would be on vRealize Operations 6.3.

There are a number of blog articles available which talk about the new features available in the product, however with this episode we will look into the new features in action through a Live Demo as always. I think it is important to see the new features in action to understand the use cases associated with those new features.

So without further a do, save the date in your calendars and join use for the next episode of vRealize Operations Webinar Series 2016.

Day & Date          : Thursday, 29th September 2016

Time                     : 1:30 PM - 2:30 PM  (SGT)

Event                    : vROps Webinar 2016

Topic                     : Part 9 : What's New with vRealize Operations Manager 6.3

Speakers               : Simon Eady / Sunny Dua

WebEx Link          : Join WebEx Meeting


NOTE - Don't forget to mark your calendars by saving the Date!! Feel free to forward the invite to anyone who might be interested. It's open to all!!


Sharing & Spread the Knowledge!!

Wednesday, October 10, 2012

vShield Endpoint Now Available to vSphere Customers!!

With the Introduction of vSphere 5.1, all the editions (essential plus or higher) of vSphere have the vShield Endpoint component bundled along with them. This basically means that you would no longer have to shell out dollars to use the functionality of Endpoint. This enables you to offload the Anti-Virus tasks to a service virtual machine, which runs on each ESXi server to ensure that all the malicious activities and data can be scanned on this service VM. This protects your virtual machines against virus attacks and other malicious activities. This will also avoid any Storage, CPU or RAM bottlenecks which might be seen in the environment due to traditional Anti-Virus Scans using an anti-virus agent inside each virtual machine.

As mentioned before, with the release of vSphere 5.1, Endpoint functionality is available at no extra cost to customers with valid SnS contract for Essentials Plus or higher. vSphere 5.1.x, 5.0.x and 4.0 U3 customers can download Endpoint from the respective vSphere download pages. No Endpoint license is needed.

Once you have the EndPoint service VM, you can use vShield Manager to configure this for all the ESXi servers in you data-center  Now, you would need to go to your anti-virus vendor and get to the version of antivirus which supports the Endpoint appliance. This will allow you to migrate from the primitive methodology of anti-virus scans and make your virtual infrastructure more robust, secured and efficient.

The diagram below gives you a visualization of how this works using Trend Micro Deep Security:-

Courtesy: Trend's Website


Below is the list of the popular Antivirus vendors who have already developed a solution around vShield Endpoint:-





On the Roadmap (Source: Google Search)

> Symantec Endpoint
> F-Secure
> Sophos
> Lumension


I can see that most of the existing and new security vendors would develop around Virtualization as they all understand that their products need to adopt the Virtualization and Cloud agility as well. Looking at the benefits this is a more futuristic approach of providing endpoint security in a data-centerI can see this change taking us towards the era of, Anti-Virus as a Service (AVaaS) where-in Security vendors would provide customized endpoint products to data-centers and end users as a commodity service. 

Another contribution to the Cloud from VMware. Kudos!!


***********************************************
Update to Article    Monday, December 3rd, 2012
***********************************************

As per the latest market update, Symantec today announced availability of its first anti-malware software protection that supports VMware's security architecture known as vShield, becoming the latest anti-malware vendor to do so following similar moves by Trend Micro, Kaspersky Lab and McAfee, among others.
Symantec Endpoint Protection (SEP) 12.1.2 can be used to scan, detect, block and remediate against anti-malware....

More can be read here -

http://www.networkworld.com/news/2012/120312-symantec-vshield-264655.html

Wednesday, August 29, 2012

vSphere 5.1 - The ROOT access is no longer COMMON

Just wanted to give you a bite into the new and enhanced ESXi 5.1 feature which improves the way Administrators access the Shell of ESXi. The traditional way of accessing the highest privileges on an ESXi shell was to use the "root" account. Even if you are a LDAP user or a locally added user on the ESXi, you would have to switch to the root account by using the shell command "su" which will grant you root level access to initiate commands on the ESXi shell.

But with the latest version of vSphere 5.1 the administrative privileges can be removed from the default root account and individually assigned to Local Users which will provide them full access to the ESXi shell.

This is a cool enhancement, as this not only makes the platform more secure, but it also improves the auditing  of the ESXi shell activity as the logging will now display the name of the user who is accessing the shell and performing administrative tasks. In previous versions it was literally impossible to track that who logged in with root access as the logs will just show that the tasks are performed by "root" user.

Lets see what kind of use cases this will help:-

a) Organizations would not have to worry about resetting root password as there policy of password management as root can now be disabled, hence they will have one less account to manage.

b) Having to share a password (root user password) among admin team members is no longer required, ensuring no unauthorized access, end to blame games and a sense of accountability among VMware Administrators of an organization.

c) Monitoring and Auditing becomes easier as the log will reflect the name of the "username" who performed any activity instead of "root", hence making it easier to audit activities.

Another smart add on to this feature is the ability to auto terminate sessions which are left idle due to human error. For Example - An admin with full shell access logged into a ssh session while troubleshooting an issue from the system of his storage admin and he forgot to logout before taking that important call from his boss. Now the storage admin has full access to the Shell which could possibly be an issue"

In order to avoid such situations a new advance variable UserVars.ESXiShellInteractiveTimeOut is available to set a timeout value for any ESXi shell access. As soon as the timeout limit is reached, the session would be terminated, making the shell inaccessible for the unauthorized user.

Do remember to use this excellent feature in your environments to make it more secure, reliable &  manageable.







Tuesday, August 28, 2012

VMware vSphere 5.1 - What's new with this version?

As promised, a quick post to see whats changed after 1st day of  VMworld 2012.

Well I hope I can keep up with the word QUICK, because of the number of new things VMware has announced in a single day. I will give you the highlights and then some interesting links to follow which will give you tons of great reads on this latest release of VMware.



  • vRAM Entitlement is a concept of past - After a huge row about vRAM restrictions which were introduced last year with the announcement of vSphere 5.0, VMware relaxed the vRAM tax to 32 GB entitlement on Standard Edition, 64 GB Entitlement on Enterprise Edition and 96 GB vRAM entitlement on Enterprise Plus Edition of vSphere. This scheme of things ran for an year, however in the last customer survey done by VMware, they found that customers are not very happy about the limitations as this makes the entire capacity planning exercise a bit complex. VMware heard the customer and BOOM... the plan just changed. Yes no more vRAM tax. Just license each populated  processor socket on the server and you are good to go.
  • Feature Flow & New Editions- The editions have just become more beefier. Yes, you got it, the features from higher versions of vSphere like Enterprise & Enterprise Plus have flown down to the Standard edition making it more attractive and affordable for the SMB segment. For an example, Storage vMotion, VMware FT, vShield Zones, Hot Add etc. An important thing to note is that this has not affected the prices of these editions, yes you can get this at the same price. In addition to this a new edition is launched which can be seen as a new Avatar of the Standard edition along with Operations Management which allows you to lay your hands on Behavioral Performance Management & Capacity Planning. So you can not only be a smart SMB with Virtualization, but would also have the capability to manage it.
  • New Features Added - As always the VMware R&D teams are quick to react to customer requirements and this time around they were able to change the Monster VM's to SUPER MONSTER by giving them 64vCPU capability. SR-IOV is another feather in the cap which will now allow you to share special hardware devices between virtual machines. vMotion without Shared Storage is another one which would help those who cannot afford shared storage.
  • Data Protection - aka VDP (VMware Data Protection) just replaces the VMware Data Recovery (VDR) technology with a much widely accepted EMC Avamar backup appliance. VDP is a part of all the license editions hence all the VMware customers would have the liberty to throw the traditional backup equipment out of the window and use the more smarter and efficient way to backup virtual machines. Yes, you can still use your existing backup mechanisms if you wish too.
  • vSphere Replication - One of the coolest solution which I encountered with host based replication. You will not be wrong to say that this was introduced to help customers use SRM without identical storage and array based replication, but this feature was such a hit that VMware has made it native to the vSphere Platform. So now you can replicate virtual workloads as and when you need. SRM may not be needed if your use case is just replicating for a point in time backup. I am sure the smart customers of VMware would find 100 of use cases by the time they upgrade to vSphere 5.1 to get there hands on FREE vSphere replication.
  • vShield Endpoint is a part of all the editions - Must appreciate the fact that how VMware wants its customers to choose the best way of securing there virtual machines. vShield Endpoint which was a licensed product and came with a price tag is now FREE and is part of all the editions. Time to call your Anti-Virus and Malware vendors and ask them to help you transition to a more effective way of performing Antivirus scans by offloading to the Endpoint Service VM and saving your environment from deadly Anti-Virus scan storms. Way to go.
Here is a quick snap of what I discussed above:-






































Well for those who want to learn more about other license changes, here is the link to go to:-

vSphere 5.1 - Licensing, Pricing & Packaging - http://www.vmware.com/files/pdf/vsphere_pricing.pdf

For the TECHIES below are the bunch of links which will give you oodles of information about what VMware is upto with this release:-


All the above technical whitepapers have some great information about the new vSphere Platform. 

Apart from these great reads from the Technical Marketing teams of VMware, you can also see these features in action on the VMware Now Website at http://www.vmware.com/now.html?skip=y

Go to the Topics Guide section on this page to get a Deep Dive on all the topics mentioned above.



Enjoy the read. I will try some of them in my home lab and share my findings on how they make a difference.

Till then...

Happy Virtualizing
Sunny Dua