000webhost

Web hosting

Saturday, December 3, 2011

VMware VCP Research Notes

I've recently been required to use virtualisation increasingly in order to complete some project work. In order to get up to speed regarding the technologies currently available I've been working my way through VCP certification books. In this post are some of my research notes for the VCP-310 Exam.

Note that while this post is for VMWare, much of the same functionality is also supported by the Open Source Equivalent Xen (though the methods for interfacing and configuring these features mightn't be as slick at this stage) or through its enterprise equivalent XenServer. I may post my research notes regarding Xen but I feel its more likely that I may contribute towards the project in another way and as it stands a lot of the documentation out there is already of a high standard (though slightly fragmented).



Note, that the VI client/VirtualCentre is not the only method of monitoring/configuration for VMware. Its possible to use the Service Console to achieve many basic tasks.


Introducing VMware Infrastructure 3

Virtualisation is the process of adding an additional layer between hardware and software to allow multiple instances of any Operating System to be installed on the same set of hardware (desktop or server) through the concept of virtualisation of hardware. Control between the top software layer and the underlying hardware is handled through software known as a 'Hypervisor'.

Why You Need Virtualisation
It allows for consolidation of hardware, reduced power consumption,

Types of Virtualisation
Bare Metal - ESX/ESXi, XenServer
Host-Based Virtualisation - VMware Workstation/Server, MS Virtual PC, MS Hyper-V, VirtualBox
Application Virtualisation - Cameyo
Storage Virtualisation - StarWind, OpenFiler, FreeNAS

Virtual Machine Overview
Hardware is essentially 'virtual' and can be added/removed/configured at will through Hypervisor

*.vmx - VMware hardware configuration/specification details are supplied in this file
*.vmdk - VMware file which contains the hard drive equivalent of a physical hard drive. It may be split into smaller files to allow for compatibility with the underlying OS/filesystem (if we are talking about Type 2 hypervisors and older OSs/filesystems of course)

Isolation - one VM is independent of another
Encapsulation - VM's are contained inside of files
Hardware independence - VM's are unaware of actual hardware. Interaction is conducted through Hypervisor
Compatibility - standard x86/x64 architecture

Simulation and Emulation
Simulation - subset of the real thing (flight simulator)
Emulation - attempt to port hardware to software (SNES emulator)
Virtualisation - install software on virtual hardware (hypervisor)

Virtual and Physical Machine Comparison
Physical - underutilise resources, hardware bound, replication complex
Virtual - not hardware bound, standard x86 environment, collection of files can be easily managed

Why VMware Infrastructure 3?
Mainly enterprise features such as VMotion, Distributed Resource Scheduler (DRS) which allows for automated switching of VM's from one host to another if there are resource disparities and performance problems exist on the current host but not another

VMWare Infrastructure 3 Suite
ESX Vs ESXi - main difference is that ESX uses a Service Console (SC) as its management system unlike ESXi which relies of a seperate management utility but has a smaller memory footprint (32MB)

Virtual Symmetric Multi-Processing (SMP) - virtual CPU's using both logical and physical
Virtual Centre - control ESX from a Windows application
VMotion - allows live, transparent movement of VM's from one ESX host to another
Storage VMotion - allows live, transparent movement of VM files from one ESX host to another
Update Manager - handles patching of host as well as VMs
Convertor - convert physical to virtual
High Availability - restart a VM on a different ESX host
Distributed Resource Scheduler (DRS) -
Consolidated Backup (CB) -

Virtual Machine Filesystem (VMFS) - designed to be a lightweight filesystem designed for any VM's under ESX/i

The VMkernel
Proprietary kernel made by VMWare that acts as a bare metal hypervisor/resource regulator.

The Service Console
- Apache Tomcat Web Server
- Firewall
- SSH access
- SNMP agents

The VI Client
Use this Windows application to connect to an ESX host and/or Virtual Centre.

Planning, Installing, and Configuring ESX

Minimum Hardware Requirements
These change from one version to another. Please consult the the VMware website for more up to date details.


Disk Partitioning
Maximum of 4 primary partitions. Using extended partitions can increase this number. Maximum number of IDE disks is 63 while the maximum number for SCSI disks is 15.

/boot - boot files
/ - root of the SC OS
swap - swap partition
/var/log - log files
VMFS-3 - VM's are stored here
vmkcore - dump information is stored here after a system crash or Purple Screen of Death (PSOD)

Installation Using a CD-ROM
Basically identical to a Linux distribution installation. Graphical and Text modes are available.

Post-Installation Configurations
VI Client - installation by downloading the client from the IP address of the web server on the ESX/i host
SSH - use the VI client to create a user account if required. If remote root access is required than modify the relevant option in /etc/ssh/sshd_config
SC Memory Allocation - use the VI client to increase the default memory allocation from 272MB upwards (recommendation is between 272-800MB)
NTP Client - use the VI client

Troubleshooting Installation
Hardware Issues and Misconfigurations - hardware compatibility/reliability and misconfiguration
Purple Screen of Death - CPU/memory problems are the most likely to occur. Dump file can be sent to VMware to aide analysis and troubleshooting
Diagnostic Data Collection - look for recent changes (hardware, software, or environmental), and any console errors. Create a diagnostic data dump by using the VI client

Licensing VMware Infrastructure 3

Two main components that need to be licensed:
- ESX
- VirtualCenter

ESX Server Licensing
Foundation - starter edition with no enterprise features
Standard - foundation edition + HA
Enterprise -all standard + enterprise features


Host Vs Server Licensing Mode
- Evaluation Mode
- Serial Number
- License Server (Server Based, C:\Program Files\VMware\VMware License Server\Licenses)
- Host License File (Host Based, /etc/vmware/vmware.lic)

VirtualCenter Licensing
VirtualCenter Foundation - up to 3 ESX hosts
VirtualCenter - up to 200 ESX hosts

How the License Key Works
Per Processor - all VI3 software licenses per processor except for VirtualCentre
Per Instance - traditional one licence per machine, only VirtualCentre uses this form

License Server
Similar in concept to Windows licensing server if you've ever used one. Best practice is to install it on the same system where you have installed VirtualCentre.

Working with the License Server
You can change the location where license files if need be. Restart the License Server service in order re-read the license files or else use 'VMware License Server Tools'. License server uses following two processes/ports.

lmgrd.exe - 27000, TCP
vmwarelm.exe - 27010, TCP

Use 'netstat' to verify to ensure that these processes are running.

Losing the License Server
If the license server goes down there is a 14 day grace period during which you to perform maintenance. Use HA ability of ESX in order to deal with redundancy issues. VirtualCentre not impacted by license server outage as it uses a cache version of the license file.

Virtual Networking Options

Obviously, if you have VM's you'll need some way to 'bridge the gap' between physical and virtual networking hardware. You can achieve this through Virtual Switches as well as Virtual NICs.

What Are Virtual Switches?

Virtual equivalent of physical switches. Allow for isolated VM network which would afford the opporunity to create a DMZ, or provide fault tolerance and HA.

Virtual Switches:
- are software objects on the VMkernel of every ESX host
- can have between 8-1016 ports
- can be serviced by one of more physical NICs
- virtual NICs have unique MACs just like physical NICs
- allow for connectivity via 801.2q (known as VLAN tagging)
- can support port groups or connection types

Comparing Physical and Virtual Switches
Similarities:
- both have MAC address tables
- both check each frame's MAC address destination upon receiving it
- both forward frames to one or more ports
- both avoid unnecessary deliverables
Differences:
- STP not required/supported on VS
- inter VS connectivity not possible
- forwarding data table is unique to each VS
- VS isolation prevents loops (hence, STP not required)

Type of Virtual Switches
Internal Virtual Switch - no interaction with exterior physical networks
Single Adapter Virtual Switch - interaction with exterior physical networks via single NIC
Multiple Adapter Virtual Switch - interaction with exterior physical networks via multiple NICs

Type of Virtual Switch Ports
Basically switch ports which share the same connection type.
Service Console - allows for communication to/from the Service Console. vswif0 is automatically associated with vSwitch0. Think about multiple SC ports and SC NIC team for redundancy
VMkernel - allows for configuration for technologies such as VMotion, iSCSI, NAS/NFS
Virtual Machine - connects virtual to physical network

VLANs in Virtual Networking
Similar in concept to physical VLANs but virtual VLANs can also group virtual VLANs together.


Trunk Ports
Same conceptually as trunking of VLANs on physical switches.

802.1Q VLAN Tagging
Same conceptually as tagging of VLANs on physical switches.

Virtual Switch Policies
General - total number of ports
Security - promiscuous mode, MAC address changes, forged transmits (port security feature on Cisco switches)
Traffic Shaping - average/peak bandwidth and burst size
NIC Teaming - fault tolerance, redundancy, load balancing

Load Balancing
Route Based on Originating Virtual Port ID
Route Based on Source MAC hash
Route Based on IP Hash
Explcit Failover Order

Network Failover Detection
Link Status - detects cable connection
Beacon Probing - detection via hearbeat

Notify Switches
Performance tweak to allow for quicker update of physical switch lookup tables.
- physical NIC failover when a virtual NIC begins to use a new physical NIC to communicate
- a new NIC is added to a NIC team

Failback
Adjust how failed NICs come back. Whether they will become active again or return to standby mode.

Explicit Failover Order
Control order in which NICs failover.

Networking Maximums


Storage Operations

Currently four forms offered:
- local storage
- fibre channel
- iSCSI
- Network Attached Storage (NAS)

Transfers can either occur at:
block-level - similar to accessing local storage. iSCSI and FC are good examples of this
file-level - similar to network based shares such as SMB

Fiber Channel
Most efficient, reliable, and best performing but also most expensive of all storage options. High pseed protocol which allows for transport between nodes at up to 8GB.

ESX extends FC capabilities by allowing SAN Boot, VMFS Datastores, Enterprise Features, and allowing VMs access to Raw LUNs.

FC SAN Architecture
Host Bus Adapters - similar to NIC in that it has a UUID known as a World Wide Name (WWN) which identifies this adapter to Fibre Channel Networks
Fibre Channel Switches - also known as 'fabric'. SImilar in function to network switches but alo provie security as well
Logical Unit Numbers - group of disks
Storage Systems - actual collection of disks ready to be designated into LUNs
Storage Processor - brain that create LUNs, implements security, and controls access to LUNs

Masking
Uses HBAs or SCSI controllers to hide LUNs from view of OS. This is particularly important for certain types of OS that seek to write data to every single LUN they come across (Windows will write a signature) which could lead to data corruption if the LUN is being used by multiple systems.

Zoning
Equivalent of VLANs in the storage world.
Hard Zoning - implemented at FC switch level. Prevents physical access to any device that is not a member of the zone. More secure option.
Soft Zoning - security through obfuscation of relevant ports. Access still possible via directly accessing the physical address

FC Addressing
vmhba0(physical label and number):1(target number):23(LUN number):4(partition number)

Internet Small Computer System (iSCSI)
Basically SCSI commands over Ethernet. Cheaper than FC and with Ethernet speeds already at 10GigE performance disparities are rapidly disappearing. Like FC, ESX extends iSCSI capabilities by allowing SAN Boot, VMFS Datastores, Enterprise Features, and allowing VMs access to Raw LUNs.


iSCSI Addressing
iqn (iSCSI Qualified Name).2011-01 (year and month when organisation registered a valid domain/subomain).com.company (reversed domain):ipstor (alias which is optinal and represents)

Software Initiator
Basically, a driver which allows access to SCSI targets. When configuring the software initiator's parameters, there are two options to select from:
- one VS with two port groups
- two VS
You also need to open TCP, 3260 on the SC firewall.

Dynamic Discovery
Use IP address/Port to discover available LUNs.

CHAP Authentication
Use password/secret authentication to access LUNs (or not).

Hardware Initiator
Better performance than software initiator and takes some load off of the ESX host. Allows booting of ESX host off of SAN LUN and Static Discovery

Network Attached Storage (NAS)

ESX Features on NFS Datastores
VMotion, DRS, HA, and VCB.

Configuring NFS Datastores
Following parameters can be configured.

Share name, subnet (which subnets can access the share), sync, rw, no_root_squash (root access enabled)

Virtual Machine File System
Ultra light weight file system with minimal overhead. File locking as opposed to volume locking to allow for higher performance on concurrent access. File locking management is via metadata file. Entire partition is locked when metadata file is locked. Hence, LUN sizing critical in order to reduce possibility of I/O being a performance bottleneck.


Extending a Datastore
Maxiumum VMFS volume size is 2TB. Can be overcome through 'extents' of which there can be 32. You can add extents but can't remove them non-destructively (to the entire datastore) at this stage. Note that metadata file is stored in first extent. Losing this file will cause data loss across all other extents.

Multipathing
Basically allowing for redudant paths to LUNs. Two strategies:
Fixed - explicitly dictate path options
Most Recently Used (MRU) - obviously use the most recently used and after switch to the older/other path

Administration with VirtualCentre

Allows you to manage ESX from a Windows application.

Planning and Installing VC
Along with enterprise features it also apovides, Upate Manageer, Converter Enterprise, and Guided Consolidation. Depending on configuration various network ports may need to be opened on the system's firewall. Need to install: database server, license server, VC server, VI client.


VC Blueprint
Core Services - provision scheduler, events logging, etc...
Distributed Services - VMotion, HA, DRS, etc...
Additional Services - Converter, Updater, etc...
Database Interface

ESX host managemen
Active Directory Interface
Virtual Infrastructure Application Programming Interface (VI API) and Virtual Infrastructure Software Development Kit (VI SDK)

Hardware Prerequisites for VMware Centre

Designing a Functional VC Inventory
- folders
- datacentres
- clusters

Administration with VirtualCentre
VMware Infrastructure Client Tabs
- inventory (details of your current network)
- scheduled tasks (overnight restarts, etc...)
- events (alarms messages go here, first point for troubleshooting)
- administration (role, session, license, log management, etc...)
- maps (Visio like network diagram)
- consolidation (consolidate physical into VM)

Lockdown Mode
Block direct access to ESX hosts. Only allow via VC.

Plug-ins
Update Manager and Convertor Enterprise are two base plug-ins for VCentre. Many have since been created by third parties.



Virtual Machine Operations

VM Defined
See top of this post.

Virtual Hardware
Based on Intel 440BX and NS338 SIO chipset

VM Files
*.vmx: VM configuration file
*.vmdk: all information about HDD file
*.*-flat.vmdk:
*.log: log file
*.nvram: BIOS of VM
*.vswp: VM swapfile
*.vmsd: details of snapsnots of VM

Creating a VM
No explanation required if you've ever used any virtualisation software before.

Understanding VMWare Tools
Please see previous post from this blog.

Templates

Guest OS Customisation

Windows-Based OS Guest Customisation
To customise Windows installation drop files in following directory.

C:\Documents and Settings\All Users\Application Data\VMware\VMware VirtualCentre\Sysprep\

Linux Guest Customisation
- Computer Name
- Domain Name
- DHCP/IP Settings
- DNS

Deploying VM
- Create new
- Deploy from Template
- Clone

Managing VMs
Cold Migration
Move VM's while powered off. Allows you to move VM files as well moving the VM to a new host.

What are Snapshots?
Settings, memory, and disk states.
*#-delta.vmdk - files that register changes from base for this VM. # sequential starting from 1
*#.vmdk - snapshot description
*#.vmsn - state of the memory for this VM

VMWare Converter Enterprise
- P2V and V2V
- third-party VMs to ESX VMs
- restore VCB images to ESX VMs
- export ESX VMs to other formats
- customise VC VMs

Converter Enterprise Components
- Server (initiates actual conversion process)

- CLI (carries out commands issued by VI client or CLI)

- Agent (prepares physical machine for conversion)

- Client Plug-in (modifies VI GUI and enables Converter Enterprise Features)

Cloning
- Converter Enterprise is capable of the following:
- Hot Cloning
- Cold Cloning
- System Reconfiguration
- Remote Cloning
- Local Cloning

Cloning Modes
Volume based - useful when resizing disks. Supported via hot and cold cloning.

Disk based - exact copy of disk. Only supported via cold cloning.

Guided Consolidation
Ideally used in SME with about 100 physical servers. Only Windows systems can be discovered and analysed at this stage. Both physical and virtual machines can be detected. It relies on the 'Capacity Planner' and 'Converter' service to run.

Discovery and Analysis
You need a user account with certain privileges to work:
- member of local administrators group on VC server
- Log on as Service user right
- Read access to AD
- administrator rights on target machines

VMware Infrastructure Security and Web Access

VI Security Model:
User and group - accounts allowed to login
Role - set of permissions applicable to a role
Privilege - an allowed action for a user
Permission - right assigned to an object in the inventory and grants a user/group the right to interact with that object according to existing role/privileges


VC Security
Local or Domain (in relation to Windows authentication credentials)

ESX Server Security
Being Linux there is the root account as well as a 'vpxuser' account which is used to sent ESX commands.

Web Access
IP address of ESX host or VC.

Managing VMware Infrastructure Resources

VM CPU and Memory Management
Limit - maximum resources a VM may consume
Reservation - minimum required for VM to work properly
Shares - a method of reserving more memory and CPU time

VMotion
Migration from one ESX host to another transparently. Prerequisites for it to work properly include:
- access to all datastores on which the VM is configured
- virtual switches are labelled the same
- access to the same physical networks
- compatible CPUs
- GigE network connection

Distributed Resource Scheduler (DRS)
Automated load balancing of CPU/memory resources with a DRS cluster.
DRS Automation - works in three modes manual (suggests only), partially automated (DRS works on just powered on VMs but only suggests on subsequent VMs), and fully automated (VC handles everything). Works on 5 levels which dictate the level of performance enhancement from 'Most Conservative' (only when required) to 'Aggressive' (if there is just the smallest possibility of performance enhancement begin the migration process).

DRS Cluster Validity
Green - resource pool is fine for resources
Yellow - resource pool is overcommitted
Red - DRS cluster or HA rules have been violated which means the cluster is 'invalid'

DRS Rules
Allows you to reduce the chances of a single point of failure or increase performance by setting rules so that certain VMs should run by themselves (affinity) at all times or otherwise they should be migrated as a group (anti-affinity).


Monitoring VMware Infrastructure Resources

Resource Optimisation Concepts
Primary two issues with performance optimisation with regards to managing VM's are vCPU and vMemory.

Virtual CPU
1-4 vCPU per host. Hardware Execture Context (HEC) is the same as a thread on a
physical CPU.

Hyperthreading
Feature that was brought about by the Intel Pentium 4 chip and has been used since. Allows for multiple threads to be executed simulatenously on the same CPU. However, when CPU usage is already high contention issues may come into play. At a certain point there are diminishing returns for using HT.

vCPU Load Balancing
VMkernel is responsible for scheduling vCPUs and SC. SC always remains scheduled on CPU 0/first HEC while others are re/scheduled every 20 milliseconds.

Virtual Memory
VMkernel uses:
- transparent memory page sharing (same memory pages that are only being read share the same page)
- balloon-driver/vmmemctl (VMware tools driver inside guests which allows others to use its unused allocated memory when under strain)
- VMkernel swap (method of last resort for memory but just like real memory there will be a performance hit. Swap file is deleted/created on start/shutdown of VM. Swap file is difference beteween VM's memory limit and reservation.)

Monitoring Virtual Machines and Hosts
- CPU
- Memory
- Disk
- Network

Monitoring with Alarms
When certain thresholds are reached you can perform actions such as run a script, send an email, send an SNMP trap, or even SMS.


Backup and High Availability
In theory, similar to physical backup techniques.

Backup Scenarios
- backup agent within the VM
- backup the actual VM files (try to keep data and OS seperate for obvious reasons)

Host Backup Options
- service agent in SC
- imaging software for the ESX host

VMware Consolidated Backup
Means of file or image level backup using snapshots. Snapshot it then copied to location where backup proxy server can back it up.
- transparent, live backups
- backup load is moved away from ESX host
- backup agent is optional since VMware Tools provide backup functionality as well

High Availability
Ensure that VMs from failed hosts can be restarted on other hosts. Fault-tolerance ensures that VMs can be accessed in uninterruptedly in the event of host failure. Uses a heatbeat every 15s to determine host failure.

Virtual Machine Failure Monitoring
VMware Tools use a heatbeat every 20s to determine VM failure. This technology then uses this to determine if a restart of the actual VM is required.

HA Configuration Prerequisites
- VirtualCentre
- DNS Resolution
- Access to shared storage
- Access to same network

Service Console Redundancy
VMware HA will warn you if there is no SC redundancy. Either use port groups on different VS or use NIC team to a single SC port. You'll require certain ports to be open in order to achieve HA and state synchronisation on SC VS.


Host Failover Capacity Planning
Common sense should prevail here but it is likely that financial constaints will play an enormous impact on the level of redundancy that you can provide.

Host Isolation
Take certain steps in case of VM isolation.
Leave Powered On
Power Off
Use Cluster Setting

Virtual Machine Recovery Priority
High - restarted first
Medium - default

Low - restarted last
Use Cluster Setting - cluster setting
Disabled - VM doesn't power on

Clustering
Cluster-in-a-box - all VMs on one ESX host
Cluster-across-boxes - VMs spread across multiple ESX hosts with central storage
Physical-to-virtual cluster - mix of VM and physical hardware

- as usual thanks to all of the individuals and groups who purchase and use my goods and services
http://sites.google.com/site/dtbnguyen/
http://dtbnguyen.blogspot.com.au/

Friday, December 2, 2011

Virtualisation Options

If you grew up several decades ago, then you would know the impact that vritualisation has played in both the server as well as the desktop space. It has allowed companies to reduce the total number of physical servers within the network while also allowing for extra capabilities such as high availability, redundancy, clustering and so on. It has also allowed private users to experiment with a multitude of different operating systems and applications without having to possess a expensive, high-end hardware in your home network.

Of late, I've been working on a project that requires the evaluation of current software based Unified Threat Management (UTM) devices. Obviously, I've tried using the usual suspects in terms of virtualisation such as VMWare, Xen, VirtualBox, Hyper-V, Proxmox, and VirtualPC, in both Type 1 and Type 2 hypervisor format.


However, I've found the most versatile for my needs has been, 'VMWare Server'. It can sit as an application on top of an existing Operating System, it can run other 'Hypervisors' within itself (such as XenServer and ESX/i), virtual hardware is reasonably easy to add/remove/configure, and there are reasonable logs and diagnostic messages for when and if a problem arises.

That does not mean that it is not without its 'quirks' though. Due to the way 'virtual networks' work you'll need to set read/write permissions on relevant /dev/vmnet? device files in order to achieve promiscuous mode automatically (this can also be achieved by setting them up manually using the 'promisc' option with the 'ifconfig' command and while 'iptraf' does provide the option the various /dev/vnet? device files do not seem to show up as options).


Switching to a singular technology can also lead to unusual consequences during 'changing times'.


I personally experienced a strange issue of sorts with VMWare whereupon switching between the various NIC modes (host/NAT/custom/bridge) would not take effect when using a particular VM appliance but did using others. The only way to get around it was by re-creating the VM.

Note, that in many cases performance and functionality of guest Operating Systems can be increased through add-ons such as VMWare Tools and third-party tools. Also, there may be a significant performance overhead/hit depending on your existing setup.


Not surprisingly, hardware technology has made significant strides towards commoditisation in consumer class hardware. In most cases, modern CPU's will have such capabilities built into their existing architecture. I used to use upgraded Dell Optiplex GX280/GX520 desktops because they were smaller, consumed less power, and were quite simply quieter. If you don't have specific, 'Whitebox Virtualisation Hardware' though there are options available should you wish to customise ESX/i or provide enhanced driver support.



Friday, November 25, 2011

Server Auto-Configuration

If you've ever been involved with Linux Server Administration than you'll be more than aware of the many and varied automation/configuration options out there such as 'Chef', 'Babushka', and 'Puppet'. I've recently been working on similar technologies but to better comprehend and implement them I've had to review how the current systems work and their capabilities.

'Puppet' seems to operate in a client/server architecture using so called 'manifests' which are basically a set of instructions pertaining as to what actions you would like to complete. For instance, the remote installation of a package, the creation of a file, the setting of a certain set of permissions and so on. The 'manifests' themselves are then compiled (checked for syntax and other errors) and then applied to relevant 'nodes' within your network. Due to its relative maturity it is often available in most of the popular distribution repositories.


'Chef' has obviously been more Debian orientated. It took a while before I actually found a set of RPMs for my system. Prior to that though, I tried creating RPMs using the GIT repository with a set of autobuild 'Ruby' scripts. However, due to the state of the respositories of the time the build seemed to be broken. I used this as a learning opportunity with regards to RPM packaging (I used to create DPKG packages years ago for another project and have done some minimal RPM packaging. DPKG are basically 'ar' and RPM are basically 'cpio' archive files respectively if you're curious (much like the ZIP and other archival format)). I didn't do any research prior to testing my theories prior to test my problem solving abilities. Basically, symlinks aren't a viable means of dealing with naming issues in packaging.  Copying files/directories (though this would violate best practice) and changing of version strings in the SPEC file are the more 'valid' option. As indicated in the SPEC file itself RPM is very 'Makefile' like in the way that it is structured. In fact, if you've ever written a 'Makefile' you'll be very much at home. Use 'rpmlint' in order to check for possible problems, 'rpmdev-extract' to extract a SPEC file from an existing SRPM, and 'rpmbuild' with relevant options in order to build an installable RPM.


Obviously, I found a relevant repository later on but it was very interesting getting a better idea of the process of creating RPMs. Check out 'alien' and 'checkinstall' if you have time which, by the way is an easy manual Perl install if you can't find the required package for your distribution. There is a web based interface that seems fairly sparse, a Command Line Interface (CLI), as well as what seems to be an extensive set of online 'recipes' to allow for all sorts of remote configuration, with support for Perl as well as support for automated provisioning of servers. Note that this extra functionality seems to come at the cost of some simplicity. There are a myriad of tools that are used, certificate systems that need to be setup, and unlike 'Puppet' you will definitely need to read through at least the Quick Start documentation in order to use it. Even then, the instructions make extra assumptions... Also, as with any other large, complex Open Source project its in constant state development and may have 'issues' from time to time.


'Babushka' seems to be a work in progress and feels like a stripped down version of a more complete configuration management system. Even the documentation is incomplete at this stage. However, it deals with most of the more important issues such as remote installation of packages, dependencies, and remote configuration.


If none of these options appeal than its fairly easy to build a custom configuration/automation system using Python's 'paraminko', Perl's 'Net::SSH', and Ruby's 'Net::SSH' libraries.


http://www.openvas.org

- as usual thanks to all of the individuals and groups who purchase and use my goods and services
http://sites.google.com/site/dtbnguyen/
http://dtbnguyen.blogspot.com.au/

Wednesday, November 9, 2011

IPTables Review

With all manner of configuration (CLI as well as GUI based) tools available to us now with regards to firewall configuration sometimes its hard to justify learning or knowing raw IPTables rules. Recently, I had to do some revision for a project that I've been working on (it involves automated generation of firewall rules). Some of the materials that I used included the following.

http://firehol.sourceforge.net/fwtest.html?

- as usual thanks to all of the individuals and groups who purchase and use my goods and services
http://sites.google.com/site/dtbnguyen/
http://dtbnguyen.blogspot.com.au/

Software Design Patterns

I recently picked up a book on Java certification (it was on sale). Obviously being Java there was a lot of coverage with regards to OOA, OOD, OOP, UML and so on. One of the more interesting sections was regarding was so called, 'Design Patterns'. Basically, a while back some computer scientists discovered that often certain problems/programs followed a similar pattern. Moreover, you could use these (as long as you recognise and are aware of them) patterns to reduce time/effort spent on designing/building new programs by using templates of these patterns. These templates ultimately became known as 'Design Patterns' and cover everything from development of GUI applications to layout of elements on a webpage.

http://c2.com/cgi/wiki?DesignPatterns

- as usual thanks to all of the individuals and groups who purchase and use my goods and services
http://sites.google.com/site/dtbnguyen/
http://dtbnguyen.blogspot.com.au/

Playing With an Android

While Windows is not the most secure Operating System in the world its certainly the most convenient. I used to install literally everything that came off the cover discs of magazines just to see what they were like simply because installation/configuration/removal was so simple. The Internet opened up the world even further. Over the last few years, 'smartphones' have become increasingly popular and tweaks/mods have made them almost as functional as desktop computers. My first foray into the Android world was a HTC Tattoo. To really exploit its capabilities though I've been exploring the the Android ADK/SDK (note that the 'HTC Dream Composite ADB Interface' driver is required for you to work with ADB and you'll need to have the 'Android ADK/SDK Platform-tools' package installed for you to do anything really interesting). Its essentially a Linux/UNIX platform with a suitable GUI on top and you can install all the same types/classes of programs that you would otherwise do on a fully fledged computer. The real difference is that unlike a lot of other platforms this one has basically been made for 'tweakers' and as such development of complementary software/hardware is significantly higher than most other platforms that I've come across. In fact, interfacing with the real world via robotics is easily possible via off the shelf kits at your local electronics store.

Tuesday, November 8, 2011

HP Pavilion dv2000 Laptop Troubles

One of the things that I like to do in my spare time is tinker with computer software/hardware. Recently, I came across a product design/implementation that I thought should never have occurred/existed. Perhaps it was a one in a million case but based on my research it wasn't. It was a HP Pavilion dv2000.

Based on what I was told the working system was left in storage (inside a house so thermal/weather issues shouldn't have really been an issue) and hadn't been touched in several months. When it was turned on, all the LED's lit up but the machine didn't seem to 'boot'. There was nothing on either the LCD or an external monitor. Research and intuition thought that it had something to do with the discrete graphics chip (Nvidia) but I couldn't be sure until I had opened/examined the machine.

If you've ever opened up a laptop you've probably figured out that it is a pain and they often have design compromises with regards to accessibilty, cooling issues, and so on. A tip for those who attempt to disassemble this machine, go for the top/middle screws, then attack the left side of the top panel first and then attack the right hand side of the top panel after turning the screen towards you temporarily (you'll understand why if you ever try this). Then remove the keyboard and finally separate the main shell/panels after removing the relevant screws.

When I finally took a closer look at the graphics chip and the connection to the mainboard I noticed that some 'balls' were completely flattened and obviously could not have been connected to the mainboard. Moreover, some balls ended up being in contact with others. Removal/reshaping of damaged balls was obviously a possibility but as I've previously discovered (and documented in this blog) 're-flowing' is only a temporary solution. A 're-ball' is the only real medium/longer term solution since its an inherent design fault that never should have existed.


Obviously, I tried a re-balled mainboard. However, after re-connecting everything I discovered that the lid switch which is used to detect when to suspend the notebook was dead which led to backlighting issues and is another known design fault with this particular notebook. While a fix is possible longer term it is likely to fail anyhow and the ability to hibernate can still be accessed by using the power button. Research indicates that the 'best solution' is bypassing the problem by merely disconnecting the lid connector to the mainboard.


At the end of all of this I discovered that the power switch wires had come loose. I didn't realise was how fragile something like this was and how difficult it was to solder using a general purpose iron (though I eventually got it). From a practical perspective the wires are too small to strip easily (unless you have specialised equipment). In fact, I used small nail clippers! Thereafter, you'll notice that you must apply a coating over the wires in order for the connection to remain stable after re-assembling the laptop. I tried liquid electrical tape but while it is a good insulator it isn't as strong you would really want. Moreover, there are time issues associated with drying/curing.

Normal tape is possible but I found that it lacked 'adhesive power'. I finally tried, 'industrial strength adhesive tape'. It reminds of 'gaffa tape' but is more pliable making it easier to fit around gaps and wires. Personally, it feels like a cross between liquid adhesives and tapes. Brilliant stuff and but not as thick as 'gaffa tape' which may cause panels to be slightly out of kilter when re-assembling the machine.


Once the laptop was re-assembled you may find that device drivers may need to be updated. I discovered that I needed to manually force the Conexant HD Audio drivers to be used in order for them to work. Windows/software based hardware auto-detection just didn't work.

- as usual thanks to all of the individuals and groups who purchase and use my goods and services
http://sites.google.com/site/dtbnguyen/
http://dtbnguyen.blogspot.com.au/

Monday, October 31, 2011

SNMP Monitoring

Recently, I've been working on a project which involves remote monitoring and configuration of server and network devices. Obviously, my research has led me to further discover the intricacies of the SNMP protocol and agents which can often provide extensive monitoring and configuration capabilities.

I've obviously been looking at native and third-party, proprietary and open source, SNMP agents for Windows and Linux. No doubt, configuration parameters can vary drastically depending on the information and level of configurability that you desire but they all rely on similar concepts and use similar vocabulary. These concepts are best outlined in the following locations.


The best example of its structure is probably represented by the following picture.


It will most likely remind you of postal addressing systems, directory service hierarchies and other hierarchal structures such as those used by Domain Service System (DNS) with each level being represented by numbers and/or shorthand strings. At the end of the hierarchy is a string/counter/number which represents the value of the concerned attribute of the piece of hardware and/or software in question at any point in time. These attributes can range from the name of the installed Operating System, to the total number of bytes sent on a particular Network Interface Card (NIC).

Based on the intent on my project it seems clearer that using SNMP as a basis for monitoring may be overkill (though I'll add some SNMP functionality). While it allows for a more finer grained image of the situation, it is also clear that much of this information is redundant especially when you are using 'generic hardware' (whether it is server and or desktop class). As such, it becomes more obvious the reasoning behind extensive templates that often accompany more mature monitoring systems such as ZenOSS, Zabbix, and Dell OpenManage.

While it is clear that SNMP is a useful and mature protocol there have clearly been moves to modernise it (for instance, through enhanced security, accessibilty, and configurability) and there are alternative technologies such as Link Layer Discovery Protocol (LLDP) and Cisco Discovery Protocol (CDP).

http://www.networking-forum.com/blog/?p=662

- as usual thanks to all of the individuals and groups who purchase and use my goods and services
http://sites.google.com/site/dtbnguyen/
http://dtbnguyen.blogspot.com.au/

Friday, October 21, 2011

NVIDIA Laptop Graphics Chip Repair

Sometimes you'll encounter a continuing problem over and over again. One of the ones that has come to light for me has been related to discrete NVIDIA graphics chip on laptops (across multiple brands believe it or not including HP, Compaq, Dell, and Apple) which have revolved around excess heat not being dispersed adequately which means that over time the graphics chip can come away from the logic board. A lot of the time this results in an unbootable laptop with the following symptons, power and LED indicator lights turn on accompanied by a black screen. Even though there has been a partial recall of affected laptops there are many 'out in the wild' which still have the same problem.

While conventional solder and mechanical pressure can be used as a means of providing a medium to long term fix on traditionally packaged and attached chips this is not the case with Ball Grid Array (BGA) graphics chips which seems to be a more popular methodology moving forward.

However, the probem is when you have mounting issues they aren't so easy to fix if you don't have the required, proper equipment required in order to complete the job. Moreover, often taking it to a 'professional' may cost the same amount as a new laptop/logic board. Numerous accounts online of this particular problem and some creative and unusual solutions have been proposed that are more 'cost effective' (but are also shorter term fixes). Some of these include:

- stripping down the machine down to the logic board and then 're-flowing' it by putting it in a convection oven or even using direct heat such as using a butane torch
- wrapping it in insulating material, turning it on and using the laptop's own heat in order to 're-flow' the connections
- using direct heat and a BGA kit in order to remove the damaged chip from the logic board, the 'balls', and then using the included solder balls (often of higher quality than the original) to fix problem areas

However, one thing I have been considering is whether or not it is feasible to attempt another solution. Namely, creating the solder balls themselves (too difficult on a large scale), or else using solder wick in order to clean up damaged BGA balls and then using flux gel in order to crudely create 'balls' between the graphics chip and the logic board. While I have been able to partially resurrect one board with this method I'll need more time to determine whether or not whether it is a complete long term fix...

Thursday, October 20, 2011

VERITAS Backup Exec Research Notes

The following represents some notes that I compiled while researching VERITAS Backup Exec (a commercial backup software solution that has since been purchased by Symantec). Obviously, these notes are based on an older version of Backup Exec so use your discretion.

Intro to Backup

Murphy's Law
SLA - Service Level Agreement
Full - complete copy of all files
Incremental - only files changed since last backup
Differential - all files changed since last full backup
Online Backup - everything accessible all the time
Nearline Backup - data from backup periodically archived to secondary backup server. Requires minimal effort to restore backup to main
Offline Backup - files unavailable during backup

Disaster Recovery Technologies : Hardware

Tape - linear, cheap, high storage capacity density
Hard Drives - less mobile, medium price per unit storage capacity,
Portability
Price
Network Bandwidth
Removable Disks - portable
Optical Media - cheap, portable,
NAS - relatively inexpensive now, RAID
SAN - can be expensive

Disaster Recovery Technologies : Software

Server-based Backup - server/administrator determines backup configuration
Client-based Backup - client/users determines backup configuration
Frozen Image Backup - live snapshot of files possible
SAN-based Backup - backup to SAN
LAN-free Backup - typically uses a SAN to backup using a dedicated Fibre connection
Server-free Backup - client system/software initiates the backup. Stored to tape/SAN

Applying Technologies : Client-based system

One computer
Software Choices
Backup Program on Each Machine
Backup client on each machine with a single, central backup server
Backup Program on Each Machine - often OS includes basic backup capabilities. Free options available but they often from lack of support, flexibility, and robustness
Client Controlled on a Network - user configuration, schedule, backup server stores on tape. User configuration uncommon because users want to backup everything, most users aren't technially aware eough, and most administrators want a consistent environment
Scheduling
Backup Jobs - sometimes also called policies
Generic Troubleshooting - hardware and/or software issues, test partial/complete backup and restores

Applying Technologies : Network-based System

WAN/LAN - primary difference is physical distance between systems
Server-based Solutions - most are server based with a administration utility
Heterogenous Environments - most commercial solutions now have the ability to operate across multiple platforms by using an 'agent'
Replication - latest copy and transparency during failure but server/bandwith requirements are greater along with extra resources for extra hardware/server. Run-Time Vs Traditional Vs Frozen Image backup
Scheduling Issues - timezones, resource consumption, mutual exclusion
Networking Utilization Issues - schedule during off hours, hard to schedule in a genuine 24/7 environment though
SAN Solutions - cost, compatiblity, configuration
Tape Sharing - shared tape drives, tape libraries, robotic libraries
Tape Rotation - saves from wear, space by not having irrelevant backups; schemes include daily, GFS (Grandfather-Father-Son), Tower of Hanoi
Looking Ahead in Backup Technology - increased sophistication/capacity of tape solutions, maturation of disk solutions, NAS/SAN technologies continue to evolve, new technologies will come into existance

Introduction to Backup Exec

Single and Multi-Server Editions
Remote Agents - best to check support for your OS prior to evaluating/purchasing
Autoloader/Robotic Library Support
Library Expansion Option (LEO)
Advanced Open File Option (AOFO)
Backup Options for Various Databases - MS Exchange/SQL/Sharepoint, Oracle, Lotus Domino, SAP
Intelligent Disaster Recovery (IDR) - known as bare metal restore now, involves a scripted installation of a minimal OS and then restoring to some initial configuration/restoration point from there
Shared Storage Option (SSO) - used by various servers/systems to access the same medium

Backup Exec Installation : Suggestion and Pitfalls

Install latest Service Pack/Patches
Update Microsoft Data Access Components (MDAC) - OLEDB32.dll
Update Microsoft Installer (MSI) - MSI.DLL
Check HCL/System Requirements
Try to have dedicated chain/channel for the storage/backup medium
Security Considerations - use the account that was automatically created, don't try to customise it as it can result in strange permission errors

Getting Your Hardware to Get Along with Backup Exec

Drive Pools - drives from the same server
Cascaded Drive Pools - used to deal with when normal drives can't deal with size of backup. Responsibilty of backups fall to these particular drives if the normal drives pools are unable to
Hardware Configuration Problems - determine whether it is a program, OS, BIOS issue. Use the built-in Wizard to try solve other issues
ADAMM (Advanced Device and Media Management) Log
Install drivers (all drivers in one package) from website if necessary, http://support.veritas.com
BEUTILITY.EXE - to reset hardware tracking databases, BEDB.MDF/BE_DLO.MDF
Database Catalogue - backup jobs, media set information, hardware statistics, automatically backed up after 24 hours of programs/services running
Physical Issues - BIOS, Power Cycle (server and media drives), physical connections

Media Rotations

Overwrite Protection - to stop media from being overwritten prematurely
Append Period - stops any data from being appended to media at all as opposed to overwritten
Media Sets - set of media based on overwrite/append settings
Retired/Scratch/Imported Media
Retention
Time-to-Recovery - balance between time/convenience/cost
Granularity - frequency of backups

Backup and Restore

Shadow Copy Components - System State/User Data/Service State
Remote Selections - will remove redundant data from backup selection by default
The Remote Agent for Windows Servers (RAWS) - must be installed on remote server to complete remote backup, can be installed by going to Tools > Serial Numbers and Installation or running setupaa.cmd
The Advanced Open File Option (AOFO) - must remove Remote Agent if already installed otherwise just install AOFO and it will install RAWS as well
Backup Performance - Avoiding Bottlenecks
Advanced Backup Options
Pre- and Post-Job Commands - run custom scripts
IP-only backup - as opposed to NETBIOS addressing/resolution
Backup Folders - backup to an arbitrary folder (NAS/SAN) rather than media
Hierarchical Storage Management (HSM)
Test Runs

An Introduction to Using Backup Exec with Other Platforms

Microsoft Exchange - allows for "brick level" backup of mailboxes
Microsoft Outlook - need to install MAPI compatible email client on media server (normally Outlook). Backup Exec logs in each user individually and downloads all emails to allow for "brick level" backup
Information Store - Backup Exec uses ESEBCLCLI2.DLL or EDBBCLI.DLL (Exchange 5.5) to communicate with Exchange
Types of Exchange Database Backups - Full/Database&Logs (flush committed logs), Incremental/Logs (flush committed logs), Differential/only transaction logs, Copy/same as Full (none of the transaction logs are deleted though)
Microsoft SQL Server - SQL Enterprise Manager must be installed on media server.
Types of SQL Database Backups - Database (backup everything along with transaction logs), Log (backup only transaction logs and delete old transaction logs from database), Log No Truncate (same as Log but does not delete old transaction logs from database), Consistency Check Before Backup (check database consistency before backup. This may cause a performance hit on a high transaction/traffic server though)
UNIX and Linux - be_agnt.tar

- as usual thanks to all of the individuals and groups who purchase and use my goods and services
http://sites.google.com/site/dtbnguyen/
http://dtbnguyen.blogspot.com.au/

Becoming a Priest/Monk, Random Stuff, and More

- once upon a long time ago I thought about becoming a priest/monk. Today we'll explore what a religious life means. Some people want ...