Posts

Showing posts with the label vsphere

VMware is making ESXi free for 8.0U3e

Image
Yes you hear me right. Check out the vSphere 8.0U3e  release notes . VMware is releasing the ESXi 8.0U3e as an entry-level hypervsor.  To download, head to https://support.broadcom.com/ and create an account if you have not done so.  Follow the screenshot below: Software> VMware Cloud Foundation>My Downloads Next click on Free Software Downloads available HERE. Scroll down to VMware vSphere Hypervisor and click on it. You will be lead to it. You will be able to download it. It will be about 618Mb That is definitely a good news for those who needs it for Home lab testing. But not sure if this going to be a one off. Also to note, it is on a 60 days trial but not sure if it behaviour the same as pre-broadcom after expiry. Thanks to Joey Ware for tipping off in Facebook group.

Hackers Exploit VMware Vulnerability that give Hypervisor Admin

You might have come across the above concern one that was published here . Since the day VMware vSphere was made available, ESX Admins user group if created in Active Directory will be given admin rights to ESXi when a user is place as a member of ESX Admins group. This was not new. I think some people do not know this existed. Moving forward, it seem hackers are now targeting this function to gain admin rights to the hypervisor. For companies that have concern over this and like to change this group membership name, you can follow this KB . Hope this address the concerns.

vSphere 8 Security Enhancements

Many of our customers have done vulnerability assessment (VA) on vSphere ESXi and often highlighted out the vulerable items such as SHA1 and TLS 1.0, etc.  Some of it were there but not in used and we could not manually remove them such as SHA1, MD5, etc. While some of them were to support lower version such as TLS 1.1 and 1.0.  With vSphere 8, the security enhancement has made uplift to remove unwanted security bundles and as well to support only secured transport connection via TLS 1.2. On top of that, it also added daemons to now run in their own sandboxes instead of in the hypervisor world needing higher permissions which were unneeded and prone to vulnerability attacks. What is new for security is a timeout for SSH shell when enabled on ESXi host. So administrators, no longer are to leave the SSH shell connected for infinite time or even worse forgetting to disconnect and logout of the endpoint where they are connected to the ESXi shell. Lastly, if your hardware used for ...

Are all Hypervisors made equal?

Image
There are lots of content available nowadays especially with the Broadcom acquisition of VMware, there are many on how to migrate off VMware and feature function comparison. One of the great content that is easily digestible from 2TekGuys . Below is a breakdown from the video on the features that was mentioned available on other hypervisors in comparison with VMware vSphere. I am not going to go into feature beyond mentioned in the video. Here are the list of features mentioned: Load Balancing : Moving using live migration of virtual machines (VMs) between hosts to due to contention. Backup : Support of backup from popular backup vendors or from hypervisor vendor themselves. Storage : Able to utilize external network storage/SAN or hypervisor own hyper-converged storage only. Live Migration : Ability to move VMs without any downtime between hosts. Having specialized on VMware vSphere for a long time in my career and been in a technical role from picking up VMware. I am always amazed by...

VMware Perpetual License EOA Support

If you have not read this blog from Broadcom by Hock Tan check it out . It helps to outline few things that has been confusion for many. First, the old perpetual licensing from any vendor including VMware, are sold in two parts. 1. perpetual license, 2. Support and Subscription (SnS) Part 1, basically let you own the license and do what you deem fit with it. And part 2, allows you to log a case for support assistance, and upgrade or downgrade the license and have patches and security release whenever its available as long the product is still supported. From the blog, it clarify once again that part 1 is true, customers are allow to use the perpetual license even if its out of support as long as they deem fit. " To ensure that customers whose maintenance and support contracts have expired and choose to not continue on one of our subscription offerings are able to use perpetual licenses in a safe and secure fashion, we are announcing free access to zero-day security patches for sup...

Dell VxRail Appliance Design and Best Practices

Image
If you have not heard of Dell VxRaill appliance, you might just want to check it out. Just giving a short summary, this is a purposeful engineered appliance between Dell and VMware. Optimized to run vSphere, and vSAN which is VMware hypervisor and HCI solution. It comes with its own lifecycle management deeply integrated with VMware vCenter Server for lifecycle management as well. Such a beast of all appliance definitely comes with some design and best practices which will help you get the most out of it. So the right guy who have it al written down would be, Victor Wu . Victor is no stranger to Dell and VMware. He has been a great advocate on the two and more. This is not his first and won't be his last book I suppose.  I was fortunate to have received a copy from him. Definitely worth a read if you are trying to get updated and understand more why some of the design and best practice. Some of it could also be used on other systems.  Do check it out  Dell VxRail System D...

VMware vRealize Operations Nvidia Management Pack

For users who have been using Nvidia GPU for machine learning processing and huge data processing, many a times, you like to know how is the GPU card been utilize and if its is sufficient.  If you are running VMware platform you will be in luck. vRealize Operations (vROps) has just the management pack from Nvidia can help you on that. If you are using GPU on your VM and you are not using Nvidia GRID (aka Nvidia AI Enterprise - NAIE) technology but using a passthrough, you might want to explore of Nvidia GRID can meet your requirement. Only certain application required the entire GPU card that is when you use passthrough. However, if that is not the case, you might have over provision your card and might be wasting resource that can be use by other. To give you a quick explanation, Nvidia GRID was the technology that is introduced by Nvidia and supported by VMware vSphere to slice your GPU just like how you do it on CPU with partnership between the two companies. With GPU sharing, y...

VMware vSphere License Expiry

Recently recent questions on the impact with license expiry. Especially important when most licensing are going into subscription model. But regardless of the license type, the effect are the same. Let just dive right in. During vSphere 5, I did an article regarding this issue where license expires on vCenter Server. The KB that was describing it has also been removed. The functions are partially working as stated. In fact, in vSphere 5.5, this has been documented . Today with vSphere 7, vCenter Server expiry of license is now shown in the doc . As well for the ESXi Server is documented . It is a now a clear cut that all ESXi hosts will be disconnected which also means no vSphere HA or vSphere DRS will work since this requires the hosts to be managed by vCenter Server. For other solutions, please check the respective documentation of the products to have a better understanding.

VMware Tools Missing!

Image
 Recently, I was in a Facebook group, VMware vExpert and one member actually posted this. He was running a VDI environment and notice his VMware Tools got uninstalled and was not able to install successful after several attempt. This is a VMware issue, but let's looks more into it. With further check, the user did a update to their ESXi host, and vSphere auto update the VMware Tools to every virtual machine that got rebooted. During the installation, whether auto or manual triggered by user, it fails. With an investigation by the member, it seems his anti-virus has blocked the installation. But wait right here, how did vSphere did auto update of VMware Tools? Isn't that trigger normally by using the vCenter Update Manager (prior to vSphere 7.0) or vCenter Lifecycle Manager (vSphere 7.0 onwards)? A good thing the member found this article by one of our VCDX. It seems that there is an auto update of VMware Tools to patch ESXi host if you check that on as show by vMiss.net. vSph...