Wednesday, July 30, 2014

What is SCCM?

SCCM  provides:
 An installation mechanism for all types of software
- Applications
- Operating System deployments
- OS and Application Updates (patching)
 Software distribution – gets the software to where the computers are
 Portals to allow users to initiate software installation
 Malware mitigation (endpoint protection)
 Asset data collection (inventory) – hardware and software details in depth, including software usage (metering)
 Software asset analysis – including some license management
 Configuration policy verification and enforcement – settings management, including power settings, firewall policies, and roaming user configuration
 Wake-on-LAN – the ability to powers up computers when needed
 Network Access Protection
 Remote control
This is a lot for any system, and all of these are done on a wide diversity of devices on almost any scale in often complex environments. Given all that, it shouldn’t surprise anyone that there are opportunities for improvement. That’s why Microsoft frequently provides new releases and encourages a strong partner ecosystem.Specific ConfigMgr features that are sometimes challenging and often cause concern within organizations:
1. Content Distribution
- Competition with other uses for Wide Area Network (WAN) links can cause conflicts with other business priorities. Traditional approaches of restricting SCCM traffic to avoid that problem can cause deployments to take too long
- Organizations with many locations, as in dozens to thousands, find that the standard Distribution Point model introduces single points of failure, can be difficult to keep running reliably, as well as being costly to deploy
2. Software Asset Management
- ConfigMgr does an excellent job of collecting a wide variety of asset data but its features for turning data into practical information and actions are limited
3. Self-Service Application Portal
- SCCM 2012 embraces a user-centric model but its end-user portal provides only basic features and often does not meet the expectations of today’s sophisticated users and administrators
4. PC Power Management
- SCCM enables the deployment of power management
policies and the collecting of state data but it does little more to maximize power savings
5. Wake-on-LAN
- Waking sleeping computers is a powerful mechanism to expedite computer management and improve end-user productivity, but ConfigMgr wake-on-LAN often does not work well in production environments
6. Operating System Deployment
- Operating System Deployment (OSD) takes many steps and requires a wide variety of resources, making it especially
complex. This is especially true in some scenarios such as organizations with numerous remote locations or where it can be difficult to justify deploying costly server infrastructure

Saturday, July 26, 2014

x86 Server Virtualization Infrastructure

At least 70% of x86 server workloads are virtualized, the market is mature and competitive, and enterprises have viable choices.

Citrix is focusing its energies on making XenServer an attractive hypervisor for two markets: cloud infrastructure (optimizing integration with its own CloudPlatform offering); and desktop virtualization (supporting its market-leading XenDesktop and XenApp offerings, particularly in the area of graphics processing unit [GPU] virtualization)

Oracle VM is Oracle's implementation of the Xen hypervisor, which leverages intellectual property tied to Oracle Linux and was also put together based on intellectual property acquired from Sun Microsystems and Virtual Iron, which also had Xen-based offerings. Oracle has further integrated these technologies into a more coherent and packaged solution with the Oracle VM 3.2 release in 2013 (and an update release is imminent).

Oracle VM is managed by Enterprise Manager 12c, Oracle's system management product. Enterprise Manager can monitor and manage the entire stack — from applications to infrastructure — allowing application and platform administrators to get contextual insight into their virtualization environment. Enterprise Manager 12c also acts as the service delivery platform for cloud services, such as IaaS, leveraging the infrastructure and virtualization resources provided by Oracle's VM product portfolio. 

This portfolio includes Oracle VM (an x86 architecture product, based on Xen); Oracle VM Server for SPARC (based on Sun Logical Domain [LDOM] technology); Oracle Solaris Zones (Oracle has changed the Solaris Containers' product name to Oracle Solaris Zones); Oracle Linux Containers; and potential software appliances using Oracle VM, storage and other related virtualized infrastructures.

Oracle still favors Oracle VM for software licensing and pricing — for example, with processor pinning (allowing the specification of a limited number of processors being used by a VM, which can reduce software costs when live migration is not required). This approach and flexibility do not extend to the Hyper-V certification.

Parallels now offers a virtualization suite consisting of three virtualization packages: Parallels Containers (for Windows and Linux); Parallels Cloud Server (which includes Parallels Containers, Parallels Hypervisor and Parallels Cloud Storage); and Parallels Automation for Cloud Infrastructure (including Parallels Cloud Server and service provider tools).

The Parallels Containers product allows applications to run in lightweight, separate containers, offering processor affinity and memory protection and isolation. Compared with hypervisor-based solutions, the Parallels Containers offering enables much-higher server densities and can reduce OS software and administration costs. The Parallels Containers product also offers portability and live workload migration. The whole architecture of containers enables a workload and container to spin up faster with less performance overhead than VM solutions.

Parallels Cloud Server also includes Parallels Server Bare Metal, enabling service providers to offer traditional VMs on the same physical node as containers. Parallels Cloud Server combines Parallels Containers and Parallels Hypervisor with Parallels Cloud Storage to enable a complete high-availability solution on commodity hardware by creating a cloud storage pool from existing server hard drives.

vSphere 5.5 in September 2013, including scalability improvements (for example, broader reach for the vCenter Server Appliance), an expanded vSphere Web Client for management, Virtual SAN, server-side caching (vFlash), 62TB Virtual Machine Disks (VMDKs). Furthermore, the vCenter Site Recovery Manager (SRM) now works with Storage DRS and Storage vMotion.


Thursday, July 24, 2014

Storage Concepts

Ø  Storage Tier
0 - Special Functionality
1 - Enterprise (15,000 rpm)
2 - Modular (10,000 rpm)
3 - General Purpose (7,200 rpm SATA)
Connectivity Tier :
A - Fibre Attached
B - iSCSI Attached (not yet available)
C - NAS (not yet available)


Ø  A SAN uses the SCSI(Small Computer Storage Interconnect) and FC (Fibre Channel) protocols to move data over a network and store it directly to disk drives in block format

Ø  Benefits of a SAN:
·         Removes the distance limits of SCSI-connected disks
·         Greater performance
·         Increased disk utilization
·         Higher availability to storage by use of multiple access paths
·         New disaster-recovery capabilities
·         Online recovery:
·         Reduction of servers
·         Increased input/output (I/O) performance and bulk data movement
·         Nondisruptive scalability
·         Storage on demand

What Makes a SAN ?

Ø  The parts: All the hardware you use to create a SAN; the switches, cables, disk arrays, and so forth
·         HBA , GBIC, Fiber-optic cables,
·         Hubs, Switches, Gateway, Router.
·         Storage arrays, Modular arrays, Monolithic arrays

Ø  The protocols: The languages that the parts use to talk to each other
·         Fibre Channel protocol, SCSI protocol

Ø  Modular arrays
·         Modular arrays come with shelves that hold the disk drives. Each shelf can hold between 10 to 16 drives Modular arrays usually fit into industry-standard 19" racks
·         Modular arrays almost always use two controllers with separate cache memory in each controller,and then mirror the cache between the controllers to prevent data loss. Mostmodern modular arrays have between 16 and 32GB of cache memory
Ø  Monolithic arrays
·         Monolithic arrays have many controllers, and those controllers can share direct access to a global memory cache (up to hundreds of gigabytes) of fast memory. This method of sharing access to a large global or monolithic cache is why these arrays are also called monolithic.


Ø  Gigabit Interface Converter (GBIC)
·         The GBIC is formally known as a transceiver;it can be a transmitter and a receiver.it has a laser inside that converts billions of digital bits into light pulses to be transmitted over optical fiber.In older HBAs, the transmission device was called a Gigabit Link Module (GLM) .two kinds of GBICs, defined by the wavelength of light that the laser inside generates: short-wave (500 m) and long-wave (10 km).


Ø  Cables
·         9μm, 50μm, and 62.5μm.
·         When 9μm cables are used to transmit data over long distances, they’re called dark fiber cables. That’s because you cannot see the laser light being transmitted with the naked eye, and if you ever did look into one of these cables, it would fry your eyeballs. Single-mode optical signals can travel much farther than multimode signals.
·         Cable connectors come in two different types. An SC connector (SC stands for Subscriber connector) is the standard optical connector for 1Gbit Fibre Channel. An LC connector (LC stands for Lucent connector) is standard for 2Gbit and 4Gbit Fibre Channel cable.

Ø  N_Ports (node ports), L_Ports (loop ports), G_Ports (global ports), F_Port (fabric port), FL_Port (fabric-to-loop port), E_Port (switch-to-switch expansion port) or a T_Port ( Trunk port), NL_port (node-to-loop port),

Ø  The disks inside a disk array are first arranged into RAID sets and then sliced up into partitions. The partitions are then assigned a LUN, and the LUN is assigned to a server in the SAN.


Ø  The WWN of the storage array is known as the World Wide Node Name or WWNN. The resulting WWN of the port on the storage array is known as the World Wide Port Name or WWPN.

Ø  no more than seven servers allocated per storage port (again, this is for each Gbps of bandwidth,but this is still a pretty good rule of thumb for even faster SAN components).Using this configuration allows those seven servers to share the connection and therefore the bandwidth of the storage port. This is commonly called the fan-in ratio of the storage port.

Ø  Having too many servers per port also means each port has only so many I/O operations it can support at one time (the maximum queue depth of the port). Most current storage arrays support at least 256 queues per port (some support 512). So if you want each server to be able to queue up 32 I/O operations at one time (which is a good best practice), limit the number of servers to eight per port (256/32 = 8). Most HBA vendors configure the default queue depth for their HBA drivers at 32 anyway, so this is a good default fan-in ratio for server-to-storage port.

Ø  An Infiniband adapter is called an HCA, or Host Channel Adapter; an iSCSI network card is called a TOE adapter, or TCP/IP Offload Engine adapter.

Ø  Multipathing Solutions:
·         Hewlett- Packard AutoPath, SecurePath
·         Microsoft MPIO
·         Hitachi Dynamic Link Manager
·         EMC PowerPath
·         IBM RDAC, MultiPath Driver
·         Sun MPXIO
·         VERITAS Dynamic Multipathing(DMP)


Ø  Zoning is also important because it can be used to keep storage of various servers separate from each other, keep SAN traffic localized within each zone, and separate different vendor storage arrays in the same fabric.zoning can be used as a method of making the SAN more secure.
Soft zoning: Zones are identified by World Wide Name

Hard zoning: Zones are identified by physical switch port

HDD Types

SCSI
Ø  Small Computer System Interface, or SCSI (pronounced scuzzy[1]), is a set of standards for physically connecting and transferring data between computers and peripheral devices. The SCSI standards define commands, protocols, and electrical and optical interfaces. SCSI is most commonly used for hard disks and tape drives, but it can connect a wide range of other devices, including scanners and CD drives. The SCSI standard defines command sets for specific peripheral device types; the presence of "unknown" as one of these types means that in theory it can be used as an interface to almost any device, but the standard is highly pragmatic and addressed toward commercial requirements.
Ø  SCSI is an intelligent, peripheral, buffered, peer to peer interface. It hides the complexity of physical format. Every device attaches to the SCSI bus in a similar manner. Up to 8 or 16 devices can be attached to a single bus. There can be any number of hosts and peripheral devices but there should be at least one host. SCSI uses hand shake signals between devices, SCSI-1, SCSI-2 have the option of parity error checking. Starting with SCSI-U160 (part of SCSI-3) all commands and data are error checked by a CRC32 checksum. The SCSI protocol defines communication from host to host, host to a peripheral device, peripheral device to a peripheral device. However most peripheral devices are exclusively SCSI targets, incapable of acting as SCSI initiators—unable to initiate SCSI transactions themselves. Therefore peripheral-to-peripheral communications are uncommon, but possible in most SCSI applications. The Symbios Logic 53C810 chip is an example of a PCI host interface that can act as a SCSI target.


SAS
Ø  Serial Attached SCSI (SAS) is a computer bus used to move data to and from computer storage devices such as hard drives and tape drives. SAS depends on a point-to-point serial protocol that replaces the parallel SCSI bus technology that first appeared in the mid 1980s in data centers and workstations, and it uses the standard SCSI command set. SAS offers backwards-compatibility with second-generation SATA drives. SATA 3 Gbit/s drives may be connected to SAS backplanes, but SAS drives may not be connected to SATA backplanes.

SATA

Ø  Serial ATA (SATA or Serial Advanced Technology Attachment) is a computer bus interface for connecting host bus adapters to mass storage devices such as hard disk drives and optical drives. Serial ATA was designed to replace the older ATA (AT Attachment) standard (also known as EIDE). It is able to use the same low level commands, but serial ATA host-adapters and devices communicate via a high-speed serial cable over two pairs of conductors. In contrast, the parallel ATA (the redesignation for the legacy ATA specifications) used 16 data conductors each operating at a much lower speed.
Ø  SATA offers several advantages over the older parallel ATA (PATA) interface: reduced cable-bulk and cost (reduced from 80 wires to seven), faster and more efficient data transfer, and hot swapping.
Ø  The SATA host adapter is integrated into almost all modern consumer laptop computers and desktop motherboards. As of 2009, SATA has replaced parallel ATA in most shipping consumer PCs. PATA remains in industrial and embedded applications dependent on CompactFlash storage although the new CFast storage standard will be based on SATA.[2][3]

iSCSI

Ø  In computing, iSCSI (pronounced /aɪˈskʌzi/ "eye-scuzzy"), is an abbreviation of Internet Small Computer System Interface, an Internet Protocol (IP)-based storage networking standard for linking data storage facilities. By carrying SCSI commands over IP networks, iSCSI is used to facilitate data transfers over intranets and to manage storage over long distances. iSCSI can be used to transmit data over local area networks (LANs), wide area networks (WANs), or the Internet and can enable location-independent data storage and retrieval. The protocol allows clients (called initiators) to send SCSI commands (CDBs) to SCSI storage devices (targets) on remote servers. It is a popular Storage Area Network (SAN) protocol, allowing organizations to consolidate storage into data center storage arrays while providing hosts (such as database and web servers) with the illusion of locally-attached disks. Unlike traditional Fibre Channel, which requires special-purpose cabling, iSCSI can be run over long distances using existing network infrastructure.

Saturday, July 19, 2014

Intel VT

Ø  Intel Virtualization Technology (VT). Formerly known as Vanderpool, this technology enables a CPU to act as if it were several CPUs working in parallel, in order to enable several operating systems to run at the same time in the same machine.


Ø  You may confuse virtualization with multitasking or even with Hyper-Threading. On multitasking, there is a single operating system and several programs running in parallel.  On virtualization, you can have several operating systems running in parallel, each one with several programs running. Each operating system runs on a “virtual CPU” or “virtual machine”. And Hyper-Threading simulates two CPUs where there is just one physical CPU for balancing performance using SMP (Symmetric Multi Processing), and these two CPUs cannot be used separately.

Ø  Of course if a CPU has both Hyper-Threading and Virtualization Technology each virtual CPU will appear to the operating system as if two CPUs are available on the system for symmetric multiprocessing.

Ø  If you pay close attention, Virtualization Technology uses the same idea of Virtual 8086 (V86) mode, which is available since 386’s. With V86 mode you can create several virtual 8086 machines to run DOS-based programs in parallel. With VT you can create several “complete” virtual machines to run full operating systems in parallel.

Ø  CPUs with Virtualization Technology have some new instructions to control virtualization. With them, controlling software (called VMM, Virtual Machine Monitor) can be simpler, thus improving performance compared to software-only solutions.

Ø  How It Works

Ø  Processors with Virtualization Technology have an extra instruction set called Virtual Machine Extensions or VMX. VMX brings 10 new virtualization-specific instructions to the CPU: VMPTRLD, VMPTRST, VMCLEAR, VMREAD, VMWRITE, VMCALL, VMLAUCH, VMRESUME, VMXOFF and VMXON.

Ø  There are two modes to run under virtualization: root operation and non-root operation. Usually only the virtualization controlling software, called Virtual Machine Monitor (VMM), runs under root operation, while operating systems running on top of the virtual machines run under non-root operation. Software running on top of virtual machines is also called “guest software”.


Ø  To enter virtualization mode, the software should execute the VMXON instruction and then call the VMM software. Then VMM software can enter each virtual machine using the VMLAUNCH instruction, and exit it by using the VMRESUME. If VMM wants to shutdown and exit virtualization mode, it executes the VMXOFF instruction.

Amazon Web Services

Ø  Amazon Machine Images (AMIs) contain pre-configured software such as an operating system, application server, and applications. You use these templates to launch your server instances,

Ø  Amazon Elastic Compute Cloud (Amazon EC2) is an Amazon Web Service (AWS) you can use to access servers, software, and storage resources across the Internet in a self-service manner.

Ø  A security group defines firewall rules for your instances. These rules specify which incoming network traffic is delivered to your instance.

Ø  An Amazon EBS volume serves as network-attached storage for your instance.

Ø  Terminating an instance effectively deletes it.This differs from stopping the instance; you are still charged for a stopped instance, and you can restart a stopped instance.

Ø  Amazon EBS volumes can persist even after your instance goes away. If you created and attached an EBS volume in the previous step, it was detached when you terminated the instance.

Ø  Amazon Virtual Private Cloud (Amazon VPC). Amazon VPC is a web service that enables you to create a virtual network topology—including subnets and route tables—for your Amazon Web Services (AWS) resources.VPC to leverage advanced networking features such as private subnets, outbound security group filtering, network ACLs, Dedicated Instances, and VPN connections.

Ø  Connectivity from lab/development VPCs to Expedia's network is setup using secure IPSec VPN tunnels, as is production connectivity from all Amazon regions except US East.  Production connectivity between Amazon's US East region and Expedia's data centers in Phoenix and Chandler is via AWS Direct Connect.  Direct Connect uses dedicated 10Gb circuits between Expedia's data centers and the AWS US East region, decreasing Expedia's bandwidth costs and making for more consistent network performance.All inbound communications from AWS are subject to firewall restrictions; communications are denied by default.

Ø  EC2 Linux instances can use LDAPS to authenticate users and groups against Expedia's Active Directory domains, relieving the need to manage separate user accounts or LDAP directories.  Development EC2 instances will authenticate using SEA domain users and groups while production EC2 instances will authenticate using EXPESO domain users and groups.

Ø  The AWS Management Console Gateway (http://awsportal) enables the use of SEA domain accounts and groups for federated authentication and authorization to the AWS console, removing the need to manage users and groups in Amazon Identity and Access Management (IAM).  This portal can be used with all accounts, not just those with VPCs connected to Expedia's network.

Ø  Name resolution services are available for EC2 instances in AWS.  These DNS servers host secondary (read-only) copies of Expedia DNS zones.

Ø  Elastic IP addresses are static IP addresses designed for dynamic cloud computing. Additionally, Elastic IP addresses are associated with your account, not specific instances. Any Elastic IP addresses that you associate with your account remain associated with your account until you explicitly release them. Unlike traditional static IP addresses, however, Elastic IP addresses allow you to mask instance or Availability Zone failures by rapidly remapping your public IP addresses to any instance in your account.



Profile, Environment and Performance Management

AppSense Environment Manager enables you to control and manage all levels of user access to the desktop and server environment of your organization by providing easy to configure GUI-driven logon processes, comprehensive application lockdown capabilities and self healing for enforcing your policies.

The AppSense Environment Manager system consists of the AppSense Environment Manager console and the Environment Manager Agent. The console is an administrative tool to create and manage configurations. The Agent resides on the controlled computers and receives configurations from the AppSense deployment system to manage the machine and user environment. Environment Manager can operate either in Standalone or Full Deployment modes. In Standalone Mode, the console saves its settings directly to the local system. In Full Deployment mode, multiple configurations can be deployed to the controlled computers in a variety of formats depending on your system requirements. This guide describes the use of AppSense Environment Manager in Standalone Mode.

AppSense Performance Manager provides workload management of network bandwidth, CPU and memory resources. Performance Manager also provides automated application memory optimization, which significantly reduces page file usage, leading to significant increases in system capacity.

There are 4 key components to an AppSense Application Manager solution –
Agent that sits on every virtual desktop.
Profile server(s) that these agents communicate with (runs on Windows Server)
Microsoft SQL Server which the profile servers use to host all volatile / configuration data (runs on Windows Server).
Management Centre (an optional service that supports agent deployment and configuration management). This service component is not currently in scope, but if it does get adopted in the future it also need to run on a Windows server with access to a back end supporting SQL Server database.
It is proposed to leverage the same SQL Server database deployed in support of the Broker (Desktop Delivery Controller) and Virtualisation Management (Virtual Centre) services above.
It is proposed to run instances of the profile server on every shared Desktop Delivery Controller/Virtual Centre/Environment Manager server as detailed above.

Azure Active Directory vs. On-Premises Active Directory

Ø  Active Directory capabilities that are part of Windows Server actually include several different roles,
o   Active Directory Certificate Services (AD CS),
o   Active Directory Lightweight Directory Services (AD LDS),
o   Active Directory Federation Services (AD FS),
o   and Active Directory Rights Management Services (AD RMS)
When you think about Active Directory you're talking about a true directory service that has a hierarchical structure (based on X.500) that uses DNS as its locator mechanism and can be interacted with via LDAP. In addition, Active Directory primarily uses Kerberos for authentication. Active Directory enables organizational units (OUs) and Group Policy Objects (GPOs) in addition to actually joining machines to the domain, and trusts are created between domains.
Azure AD, while having some aspects of a directory service, is really an identity solution and allows users and groups to be created but in a flat structure without OUs or GPOs. You can't join a machine to Azure AD.
Azure AD is focused around identity throughout the Internet, where the types of communication are typically limited to HTTP (port 80) and HTTPS (port 443) and are used by all types of devices—not just corporate assets.

Authentication is performed through a number of protocols such as SAML, WS-Federation, and OAuth. It's possible to query Azure AD but instead of using LDAP you use a REST API called AD Graph API. These all work over HTTP and HTTPS.