donderdag, mei 24, 2007

WTS: Using ThreadMaster to Tame Rogue Applications

Duane Bradley has written an excellent tutorial on how to deploy & configure the free tool Threadmaster to "tame" CPU usage for specific applications on a Terminal Server or Citrix box. Read the article here

dinsdag, mei 22, 2007

Microsoft: Technet Magazine A guide to deploying WTS

James D. Silliman has written a short but insightful article in Technet Magazine on deploying Windows Terminal Services on a Windows 2003 platform. In the article, he discusses GPO’s, security filtering, Folder redirection, installing Office using templates and admin installl, some licensing info, etc.

Definitly a good read for people new to Terminal Services. Read the article here

Microsoft: Its all about Virtualization now...

Yesterday, I attended the TechNet Webcast: Windows Server 2008: Server Virtualization Solution Scenario. It was quite interesting (although not as technical as I had hoped).

To summarize, Microsoft’s virtualization strategy is divided in 4 types of “virtualization”:

  1. Desktop virtualization: desktops/servers can be virtualized on your local desktop using Virtual PC technology. Nothing new here.
  2. Application virtualization: Microsoft bought Softricity a few months ago, one of the leading companies for applications virtualization. They are now selling Softgrid as their application virtualization solution (and a good one I might add). Softgrid 4.1 is now the current version, and version 4.2 will be released soon. Zerotouch (a web portal front end) was dropped.
  3. Presentation virtualization: this one is quite funny (and the most surprising). As you might know, Server 2008 will have a bunch of new “Citrix-like” features for Terminal Services like load balancing, TS Web Access, TS gateway (SSL tunnel), remote (published) apps and UPD (called “easy print”). So now, Terminal Services is looked upon as being “presentation virtualization”. BTW, Citrix already uses the term “application virtualization” for its Metaframe Presentation Server solution.
  4. Server virtualization: Oh yes, the combination of Virtual Server 2005 R2 (SP1) and/or Windows Server 2008 virtualization (“Viridian”) and System Center Virtual Machine Manager (now in Beta 2). SC VMM version 1.0 will be released in 2007, mainly to manage VS 2005 R2. A new release of SCVMM 2.0 will be released as soon as Viridian is ready (stripped of some features or not ;)) in 2008. So stay tuned!

During the presentation, a comparison was made between VMware ESX server and Windows Server 2008 with Windows Server Virtualization. The thing to note here is that VMware uses drivers in its hypervisor model, while WSV uses no drivers in their hypervisor. Instead, they deploy drivers directly in Virtual Machine instances. I can’t wait to compare it (even with hot-add & live-migration features stripped) to ESX!

maandag, mei 21, 2007

VMware: deploying a VM using a custom sysprep.inf answer file

You can create a template VM and use sysprep to rename, reSID, etc. a new VM. The difference between the default approach and my approach is that in my approach you can completely configure your VM as you would like (for example, use the correct regional settings).

In our example below you will notice that the regional settings default to Belgium/Dutch. You can change this (or other settings) using the setupmgt.exe found in de DEPLOY.CAB on your windows 2003 CD-ROM.

The steps:

  • Create a template VM, install the latest VMware tools and convert your VM to a Template

    IMPORTANT: make sure the VM is not joined to a domain, otherwise the Join to Domain section during the sysprep will fail.
  • Download the sysprep 1.1 files from http://www.microsoft.com/download and unzip them in the following directory on your VirtualCenter server: C:\Documents and Settings\All Users\Application Data\VMware\VMware VirtualCenter\sysprep\1.1 (you can also use the unzipped content in the deploy.cab on the windows CD-ROM located under SUPPORT\TOOLS)
  • Create a custom sysprep.inf file using the setupmgr.exe file found in deploy.cab. The content should look similar to the following:

    ;SetupMgrTag
    [Unattended]
    OemSkipEula=Yes
    [GuiUnattended]
    AdminPassword=<yourpassword>
    EncryptedAdminPassword=NO
    OEMSkipRegional=1
    TimeZone=105
    OemSkipWelcome=1
    [UserData]
    ProductID=12345-67890-12345-67890-12757
    FullName="MyCompanyName"
    OrgName="MyCompanyName"
    [RegionalSettings]
    LanguageGroup=1
    SystemLocale=00000813
    UserLocale=00000813
    InputLocale=0813:00000813
    [SetupMgr]
    DistFolder=C:\sysprep\i386
    DistShare=whistlerdist
    [Identification]
    JoinDomain=<NetBIOS Domain Name>
    DomainAdmin=<administrator name or delegated user>
    DomainAdminPassword=<Password>
    [Networking]
    InstallDefaultComponents=Yes
  • In the VI Client when connected to your VirtualCenter, go to Edit => Customization Specifications. Create a new customization file.
  • Select the appropriate OS type (in our case Windows) and check “Use custom sysprep answer file”. Fill out an appropriate name (like “Sysprep Windows 2003 SP2”)
  • In the next screen, select Import a file and browse to your sysprep.inf file or copy/paste the contents in the sysprep.inf text field
  • When using DHCP, select Typical Settings in the next screen. Select Custom settings when using a static IP.

    IMPORTANT: Make sure to fill out the default gateway & alternate gateway with the same gateway IP (this is a known issue)
  • Make sure Generate New SID is selected in the next screen
  • The Sysprep customization should know be available to use in combination with your template.

vrijdag, mei 18, 2007

Microsoft: WTS Step-By-Step guides in upcoming Win2K8

Microsoft has released some very interesting step-by-step guides related to (amongst others) Terminal Services:

  • Windows Server Longhorn Beta 3 Release TS Gateway Server Step-By-Step Setup Guide.doc
  • Windows Server Longhorn Beta 3 Release TS Licensing Step-By-Step Setup Guide.doc
  • Windows Server Longhorn Beta 3 Terminal Services RemoteApp Step-By-Step Guide.doc
  • What's New in Terminal Services for Microsoft Windows Server Code Name Longhorn.doc

Download them here

Microsoft: Requesting TSCALs for Win2K8

To be able to test the new features in WTS Windows Server 2008, Microsoft has made available test TSCALs (Terminal Services Client Access Licenses). You can request batcehs of 20 Per-user or Per-device licenses. Go to this website to request & have fun!

Microsoft: Terminal Services in Windows Server 2008

Patrick Rouse has written an excellent article on new TS features that will be available in Windows Server 2008.

To summarize:

  • TS Easy Print: this will be Microsoft’s answer to Universal Printer driver solutions. As you know, there was already a “fallback” mode available in Windows 2003. TS Easy Print will be available with the new RDC 6.1 client
  • Per-Session default printer: This feature ensures that different sessions logged on with the same user name retain session specific default printers
  • SSO (Single-Sign on) when using Vista/Server 2008 combinations. 
  • Dual-monitor support
  • Terminal Services RemoteApp: his feature provides Seamless Windows & Session Sharing functionality to users with Remote Desktop Client 6.x. Also, Session sharing will be available (as seen in Citrix MPS releases)
  • Terminal Services Load balancing: With the new Terminal Services Session Broker, Win2K8 Terminal Servers can be effectively load balanced based on:
    • Session Count
    • Weight
    • Black hole avoidance (avoid a new TS from being overloaded with new logon requests)
    • Drain mode (aka redirect new logins to other TS servers)
  • Terminal Service Web Access: Similar to Citrix Web Interface, this IIS Portal delivers RemoteApp Connection information to a client with the Remote Desktop 6.x Client.
  • Terminal Services Gateway: Similar to Citrix Secure Gateway, this feature provides RDP over HHTPS (443) traffic from DMZ to your trusted network.

Definitely check it out here

dinsdag, mei 15, 2007

VMware: May patches for ESX 3.0.1

VMware has released new patches for ESX 3.0.1:

ESX-4825991 Patch | 05/15/07 | Critical Patch
ESX-5095559 Patch | 05/15/07 | Security Patch
ESX-5140477 Patch | 05/15/07 | Security Patch
ESX-6657345 Patch | 05/15/07 | General Patch
ESX-6704314 Patch | 05/15/07 | Security Patch
ESX-7281356 Patch | 05/15/07 | General Patch
ESX-7302867 Patch | 05/15/07 | Critical Patch
ESX-7408807 Patch | 05/15/07 | General Patch
ESX-7557441 Patch | 05/15/07 | General Patch

donderdag, april 26, 2007

Microsoft: Terminal Services Load Balancing in LH Beta 3

After announcing TS Easy Print, Microsoft made an even bigger announcement at BriForum Chicago: Longhorn will have Load Balancing! It goes to show, that Microsoft thinks really highly of BriForum A big compliment to Brian as far as I'm concerned! The Load Balancing capabilities will be included in Longhorn Beta 3 for the first time.

Read the article on Thincomputing here

VMware: TSX Nice 2007 presentations now available

The presentations from TSX Nice are available here

Microsoft: Longhorn Beta 3 and the UPD "Easy Print"

Longhorn (Terminal) Server will have its own "universal printer" functionality. It should be available (I have not checked it) in the Beta 3 Longhorn Server version (released & available for download NOW).

Microsoft calls it: Easy Print. It's based on the Microsoft XPS document standard (which is similar to PDF). The "Easy Print" feature of Longhorn server is quite comprehensive though and is more than just a universal print driver in that it:

  • Supports (nearly) every printer 
  • Compresses the data stream send to the TS Client 
  • Enables you to use the properties (UI) of the native printer driver 
  • Allow you to specify which printer gets redirected into your Longhorn TS Session

Tnx to bink.nu for the info

zaterdag, april 21, 2007

VMware: definitive guide to ... VMware

Check out this post on VMTN forums! It has all the links/references/... you would ever dream of! Tnx to Arne for the info.

woensdag, april 18, 2007

VMware: PAM Password Aging in ESX 3.0.1

As you know, the service console for ESX 3.0 is a modified version of Red Hat Enterprise Linux 3 Update 6.0. By default, a password aging & complexity policy is active. Password aging policies are set:

  • Maximum days = 90 days by default
  • Minimum days = 0 days (you can change your password whenever you want)
  • Warning time defaults to 7

Normally, the root and vpxuser have no password aging by default (value is –1).

You can disable the password aging policy as follows:

  • For all newly created users (disable globally):
    esxcfg-auth --passmaxdays=0 (or –1)
  • For existing users:
    chage -M -1 (or 0) <username>

dinsdag, april 17, 2007

VMware: VCB(mounter) "Error: Host unreachable"

Today I discovered that there is an issue with VCB(mounter) and .vmx/.vmdk placement.

For some reason, our P2V tool had placed all config files (.vmx, log files, etc.) on /vmfs/volumes/datastore 1/<Servername> and our .vmdk files on /vmfs/volumes/datastore 2/<Servername>. In a normal environment, config files and vmdk files are kept together.

As you can see in the screenshot, the initial snapshot gets created but no operations can be performed and a timeout occurs after 45 minutes.

vcbMounter created a snapshot, and placed the snapshot files by default in the /vmfs/volumes/datastore 1/<Servername> folder where our .vmx resides. For some reason, VCB(mounter) is not able to “find” our original .vmdk files.

You have 2 options in this scenario:

  1. If you don’t want to have your .vmx and your .vmdk files togheter: change the Virtual Machine Working Location from the location where the .vmx file resides to the datastore location where the .vmdk files reside and (re)add to the VirtualCenter inventory.

    This can be done by editing the .vmx file and adding the following parameter:
    workingDir = "/vmfs/volumes/454b27d2-f2172987-4798-0017085ce0dd/<ServerName>/"

    Note the UID notation, and not the linked name

  2. If you want your .vmx and .vmdk files together: migrate your VM using a “cold" migration and relocate your .vmx (configuration files) to the datastore where your .vmdk files reside (see also my previous article here). This is the easiest & fastest approach.

woensdag, april 11, 2007

VMware: Handy trick to rename a Virtual Machine

Just a quick trick. As you all know, you can rename a Virtual Machine in VirtualCenter. However, the name changes but the files (.vmdk, .vmx, etc.) still have their previous name. Renaming all filenames/references manually is a daunting & error prone task.

Just shut down your VM and migrate it to a different datastore. All relevant files/folders will be renamed! Isn’t that easy or what?

Microsoft: Multiple Password "Policies" in Longhorn Server

Geert Baeke has posted an interesting article on how to deploy multiple password "policies" with Longhorn April CTP build. Check it out here

donderdag, april 05, 2007

VMware: bundled patch ESX-6431040

Be aware of the fact that patch ESX-6431040 is a bundled tgz, so it will not work with the ESX autopatching scripts you can find in the community. The following patches are contained within this bundle:

  • ESX-1161870
  • ESX-3416571
  • ESX-5011126
  • ESX-7737432
  • ESX-7780490
  • ESX-8174018
  • ESX-8852210
  • ESX-9617902

I personally unpacked the main patch, repackaged all extracted patches (they have a normal patch structure and are extracted in subdirectories) and added them to my patches list.

woensdag, april 04, 2007

VMware: Running VirtualCenter in a VM

VMware has released a technical note on running VC in a VM. I personally don't like running VC in a VM, for the reasons covered in the technote. I do like the concept to P2V your existing physical VC (connected to an external SQL/Oracle DB) and use it in a DR scenario.

Some things to note when deploying VC in a VM:

  • You need to obtain a host-based license & an initial standalone ESX host, as you cannot boot your VC without a (host- or server-based) license :)
  • Shutting down/maintenance on your Virtual VirtualCenter can be tricky: you need to locate VC & connect to an ESX host to power on VC or change your hardware config for your VC.

Download it here

maandag, april 02, 2007

VMware: configuring a static MAC address in a VM

Sometimes it can be necessary to configure a static MAC address in a VM. A typical issue during P2V is an application that has its licensing based on the MAC address.

VMware has defined that VirtualCenter does not use the following range: 00:50:56:00:00:00 to 00:50:56:3F:FF:FF where 00:50:56 is the OUI.

The steps:

  1. Power off & remove the server from the VirtualCenter inventory. This is a necessary step, because VC will overwrite your settings during Power On!
  2. Edit the .vmx file and locate the following generated MAC address:
    Ethernet0.addressType =
    and
    Ethernet0.generatedAddress =
  3. Change the value for ethernet0.addressType from “vpx” to “static”
  4. Change ethernet0.GeneratedAddress to ethernet0.Address
  5. Change the current MAC to a MAC address in the following range:
    00:50:56:00:00:00-00:50:56:3F:FF:FF
  6. In VirtualCenter, select an ESX host and go to storage
  7. Browse the data store & locate your VM
  8. Right-click on the .vmx file, and select Add to inventory
  9. Power On the server. Issue the command ipconfig /all and locate the VMware NIC. Your manually assigned MAC address should be there.

I know you can set your MAC address inside Windows, but I would avoid this.

vrijdag, maart 30, 2007

VMware: autopatching ESX with an FTP repository

Dominic Rivera from vmprofessional has posted a more advanced Perl script for patching different versions of ESX. He uses an FTP repository & does an MD5SUM check before installing the downloaded patch. Check it out here!

Sources are available:

Script:
http://www.vmprofessional.com/material/esx-autopatch.pl

Pre-compiled patchlist.txt
http://www.vmprofessional.com/material/3.0.1/patchlist.txt
http://www.vmprofessional.com/material/3.0.0/patchlist.txt