Search icon CANCEL
Subscription
0
Cart icon
Your Cart (0 item)
Close icon
You have no products in your basket yet
Save more on your purchases! discount-offer-chevron-icon
Savings automatically calculated. No voucher code required.
Arrow left icon
All Products
Best Sellers
New Releases
Books
Videos
Audiobooks
Learning Hub
Newsletter Hub
Free Learning
Arrow right icon
timer SALE ENDS IN
0 Days
:
00 Hours
:
00 Minutes
:
00 Seconds
Arrow up icon
GO TO TOP
Mastering VMware vSphere 6.7,

You're reading from   Mastering VMware vSphere 6.7, Effectively deploy, manage, and monitor your virtual datacenter with VMware vSphere 6.7

Arrow left icon
Product type Paperback
Published in Mar 2019
Publisher Packt
ISBN-13 9781789613377
Length 756 pages
Edition 2nd Edition
Tools
Arrow right icon
Authors (4):
Arrow left icon
Martin Gavanda Martin Gavanda
Author Profile Icon Martin Gavanda
Martin Gavanda
Andrea Mauro Andrea Mauro
Author Profile Icon Andrea Mauro
Andrea Mauro
Paolo Valsecchi Paolo Valsecchi
Author Profile Icon Paolo Valsecchi
Paolo Valsecchi
Karel Novak Karel Novak
Author Profile Icon Karel Novak
Karel Novak
Arrow right icon
View More author details
Toc

Table of Contents (20) Chapters Close

Preface
Who this book is for
What this book covers
To get the most out of this book
Get in touch
1. Evolution to vSphere 6.7 FREE CHAPTER 2. Designing and Planning a Virtualization Infrastructure 3. Analysis and Assessment of Existing Environments 4. Deployment Workflow and Component Installation 5. Configuring and Managing vSphere 6.7 6. Life Cycle Management, Patching, and Upgrading 7. Managing Networking Resources 8. Managing Storage Resources 9. VM Deployment and Management 10. VM Resource Management 11. Availability and Disaster Recovery 12. Securing and Protecting Your Environment 13. Analyzing and Optimizing Your Environment 14. Troubleshooting Your Environment 15. Building Your Own VMware vSphere Lab

What's new in VMware vSphere 6.7?

In every VMware vSphere edition, there are a lot of new features available, and version 6.7 is no different. VMware vSphere 6.7 was released on April 17 2018, and by the end of 2018 there should be an upcoming U1 release.

At a high level, the new version focuses on the following four main areas of innovation:

  • Simplified and efficient management at scale: There are several improvements in scaling and managing large deployments.
  • Comprehensive built-in security: You should be able to run your workloads anywhere while still offering unmatched security features to your virtual machines.
  • Universal app platform: Following the VMware vision, vSphere 6.7 could be a single platform to support any application on any cloud, as discussed previously.
  • Seamless hybrid cloud experience: This is all about integration with cloud environments, especially, with VMware Cloud on AWS.

Key features

Let's dive a little bit deeper. At a technical level, the different improvements are as follows:

vSphere Client (HTML-5)

There is not much to say about the new HTML-5 client. Everyone has been waiting for this, and at this stage, more than 95% of the features are fully integrated into the new HTML-5 client.

In the upcoming release of VMware vSphere 6.7U1, everything will be available in the HTML-5 client as stated at https://blogs.vmware.com/vsphere/2018/08/under-the-hood-vsphere-6-7-update-1.html.

The HTML-5 interface is much faster than the old Flex client, and from my perspective, it is more intuitive than the old client:

Improved vCenter Server Appliance (vCSA) monitoring

The management of the vCSA has been redesigned (you can access it through a web browser through https://IP or FQDN of VCSA:5480) and there are a whole bunch of improvements.

The overall health of all services is visible in the VAMI interface, and you can restart individual services directly from the UI as well as seeing when a particular disk is running out of space:

Improved vCenter backup management

Until version 6.7, you had the option to create a manual backup only, but everybody was missing an option to define the backup schedule as well. Of course, it was possible to do that through the CLI and with a bit of scripting, but that was not convenient. However, this is no longer the case. In VMware vSphere 6.7, you can easily define a backup schedule directly from vCSA management interface:

ESXi single-reboot upgrades

A lot of improvements were made regarding an upgrade procedure between major vSphere versions. In the past, there were two reboots. However, since vSphere 6.7, only one reboot has been required during the upgrade. That does not seem like a big thing, but when working with complex infrastructures, this can save a lot of time. Also, please note that when upgrading from VMware vSphere 6.5 to 6.7, you will experience this feature as well. 

ESXi Quick Boot

To keep things simple, Quick Boot is a way of restarting ESXi without going through the physical hardware reboot process. This is the first implementation of this feature, so only a limited subset of physical hardware is supported. So, how does it work? A second ESXi image is created and updated and, when rebooting new ESXi, the image is booted directly instead of doing a full reboot. Again, the purpose here is to save time.

Currently, the following hardware platforms are supported:

  • HPE ProLiant DL360 Gen10 Server
  • HPE ProLiant DL360 Gen9 Server
  • HPE ProLiant DL380 Gen10 Server
  • HPE ProLiant DL380 Gen9 Server
  • Dell R640
  • Dell R630
  • Dell R740
  • Dell R740xd
  • Dell R730
  • Dell R730xd
To check whether or not your system is compatible with Quick Boot, run this command on the ESXi host from the shell: /usr/lib/vmware/loadesx/bin/loadESXCheckCompat.py.
You can also have a look at the knowledge base at https://kb.vmware.com/s/article/52477.

 

Support for Remote Direct Memory Access (RDMA)

vSphere 6.7 introduces new protocol support for  RDMA over Converged Ethernet (RoCE) (pronounced rocky) v2, a new software Fiber Channel over Ethernet (FCoE) adapter, and iSCSI Extension for RDMA (iSER). This feature is particularly useful for applications that require extremely low latency and high bandwidth. Please note that when RDMA is used, most of the ESXi network stack is bypassed, and when used in pass-through mode, this also means that vMotion is not available, so this will be useful specifically for scale-out applications with their high-availability mechanisms:

vSphere persistent memory

Persistent memory is a new storage class used for extremely demanding workloads. Persistent memory, also called non-violated DIMM (NVDIMM), provides much higher performance compared to SSDs at lower costs than DRAM. Furthermore, latency is minimal—around 1 microsecond compared to low milliseconds with SSDs. To use vSphere persistent memory, you must use the latest hardware version, 14. The virtual machines can be configured with one NVDIMM controller and a maximum of 64 NVDIMM devices:

Virtual Trusted Platform Module (vTPM)

In physical systems, TPM is a chip that securely stores secrets which are used to authenticate the physical platform (PC, server). The secrets can be passwords, private keys, or certificates. The use of TPM is particularly useful for securing a system and ensuring that the data held in it is safe in case of theft, for example.

A vTPM is similar to a physical TPM device, except the cryptographic operations are performed in the vSphere layer. Instead of storing the secrets in a hardware component, they are stored in the .nvram file which is encrypted using VM encryption. vTPM is not dependent on the physical TPM at all so you can leverage this feature even if you do not have a physical TPM device.

TPM 2.0

Since vSphere 5.x, there has been support for TPM 1.2. In vSphere 6.7, VMware introduced support for TPM 2.0. Please note that TPM 2.0 and TPM 1.2 are two entirely different implementations and there is no backward compatibility with these.

If you are running 6.5 on a server with TPM 2.0, you will not see the TPM 2.0 device because there's no support in 6.5 for TPM 2.0. New features in 6.7 do not use the TPM 1.2 device.

The TPM module is used to store the fingerprint of the ESXi image securely. If there is any manipulation of the image, or if it is not correctly signed, the digitally signed fingerprint will not match.

By enabling TPM, you can then ensure that ESXi has booted using only digitally signed code.

Microsoft virtualization-based security (VBS)

Microsoft VBS is a Windows 10 and Windows Server 2016 security feature that enhances security by creating an isolated region of memory called a memory enclave, using the hypervisor capabilities of Windows. This is used to protect critical systems or security assets such as authenticated user credentials with a credential guard.

To leverage VBS in a VM, the virtual machine must be presented with the same hardware as a bare-metal server. The only difference is that the hardware is virtualized. The following requirements must be met:

  • Virtual hardware version 14
  • Nested virtualization enabled
  • Secure boot enabled
  • EFI firmware

Here is an overview of Microsoft virtualization-based security:

Per-VM Enhanced vMotion Compatibility (EVC)

EVC is a cluster-level feature which makes it possible to vMotion virtual machines across different generations of a CPU within the cluster by masking CPU features based on your baseline. vSphere 6.7 has taken EVC to the next level. In VMware vSphere 6.7, you can even configure EVC on a per-VM basis so every single virtual machine can have its own EVC configured. The idea here is to be able to freely move your VMs across different environments, particularly to VMware Cloud on AWS:

Hybrid linked mode

This feature allows you to link your on-premises vCenter Single Sign-On (SSO) domain with a vCenter Server located in VMware Cloud on AWS.

The idea here is to be able to access both on-premises and cloud environments from the single vCenter web client as well as to be able to vMotion your workloads between those two environments. You will also have the option to share tags and categories across vCenter Servers as well as finally sharing unified users and groups management:

Instant Clone

One of the new features in vSphere 6.7 is Instant Clone. This is not exactly a new feature, however. In the past, the technology was referred to as a VMFork; since vSphere 6.7, it has been fully integrated into vSphere itself as the Instant Clone feature. So, what is it? Imagine a situation in which you need to instantly create and customize (new IP addresses, DNS names, and so on) dozens or even hundreds of VMs from a source VM, and you need to customize them as well.

The way that it works internally is similar to snapshot technology, in which the new changes are written to a delta disk, so all the VMs have a similar base disk at the beginning of their life cycle, but individual changes in those VMs are not affecting each other. You can now add memory as well, so you have new VMs running from the same point in time as the source VM. This feature might be particularly useful in CI/CD workflows where you need to test your application on a large number of nodes:

Configuration maximums

In every version of VMware vSphere, there is an increase in configuration maximums. VMware released a new website on which you can compare different versions with each other. Please note that only versions 6.0 and newer are supported here since version 5.5 is no longer officially supported (general support ended September 19, 2018).

You can check different VMware vSphere configuration maximums for different versions at https://configmax.vmware.com/repcomp/compare.

Let us explore the most interesting configuration maximums and the comparison between VMware vSphere 6.7 and previous versions.

Virtual machine hardware 14

Every new version of VMware vSphere brings a new version of the virtual machine virtual hardware. Currently, the most recent version of VM virtual hardware is 14. Some features, like NVDIMM devices, a virtual TPM, or a Microsoft VBS are available only with the newest virtual hardware version.

A complete feature list and corresponding configuration maximums can be found in hardware features, available with virtual machine Compatibility settings.

The following table summarizes some of the maximum numbers for each VM virtual hardware in the different version of vSphere:

Feature 

ESXi 6.7 and later ESXi 6.5 and later  ESXi 6.0 and later 
Hardware version 14 13 11
Maximum memory (GB)  6,128  6,128  4,080 
Maximum number of logical processors  128 128 128
Maximum number of cores (virtual CPUs) per socket  128 128 128
NVMe Controllers  4 4 N/A
Maximum video memory (MB)  128 128 128
Maximum graphics memory (GB)  2 2 2
PCI passthrough  16 16 16
Serial ports  32 32 32
Virtual RDMA  Y Y N/A
NVDIMM controller  1 N/A N/A
NVDIMM device  Y N/A N/A
Virtual I/O MMU  Y N/A N/A
Virtual TPM  Y N/A N/A
Microsoft VBS  Y N/A N/A

A few other changes exist in version 14:

  • The maximum number of virtual disks per Paravirtual SCSI (PVSCSI) adapter raised to 64 for a total maximum of 256 disks per VM (60 before)
  • Support for per-VM EVC

As usual, it is always recommended to upgrade to the newest version of VM virtual hardware, but as always, this is not required. There are some reasons not to upgrade, for example, backward ESXi compatibility. It is not recommended to run a mixed environment without having all hosts or clusters on the same version. However, if you want to use any of the new features mentioned here (such as persistent memory or Microsoft VBS) you will have no choice but to upgrade.

Upgrading the VM virtual hardware does require a reboot of the virtual machine, so take this into consideration and plan such a task during the maintenance window.

ESXi 6.7 hypervisors

In vSphere 6.7, the ESXi host limits increased only slightly compared to version 6.5, and new hardware and new devices are now supported. New 50 GbE and 100 GbE network interface cards were also made available in version 6.7.

The following table summarizes the configuration maximums for an ESXi host:

Feature ESXi 6.7 ESXi 6.5 ESXi 6.0
Logical CPUs per host 768 576 480
Virtual CPUs per host 4,096 4,096 4,096
Virtual CPUs per core 32 32 32
RAM per host 16 TB 12 TB 12 TB
Virtual machines per host 1,024 1,024 1,024
LUNS per host 1,024 512 256
Non-volatile memory per host 1 TB N/A N/A

vCenter Server 6.7

There is no change in configuration maximums for the vCenter Server compared to version 6.5. Please keep in mind that vCSA should be your default choice when installing a new vCenter Server and VMware vSphere 6.7 is the last supported version for vCenter Server on Windows. Furthermore, only vCSA will be available:

vCenter Server maximums    vCenter Server 6.7 vCenter Server 6.0 vCenter Server 6.0
vMotion operations per datastore    128 128 128
Storage vMotion operations per host    2 2 2
Storage vMotion operations per datastore    8 8 8
Non-vMotion provisioning operations per host    8 8 8
Hosts per vCenter server    2,000 2,000 2,000
Total number of libraries per VC    1,000 1,000 20
Powered-on virtual machines per vCenter server    25,000 25,000 10,000
Total items per library    1,000 1,000 20
Registered virtual machines per vCenter server    35,000 35,000 15,000
Linked vCenter servers    15 15 10
Total content library items per VC (across all libraries) 2,000 2,000 200
Hosts in linked vCenter servers    5,000 5,000 4 000
Powered-on virtual machines in linked vCenter servers  50,000 50,000 30,000
Registered virtual machines in linked vCenter servers    70,000 70,000 50,000

VMware vSphere 6.7 Editions

Different license levels are available from VMware, covering everything from small business to remote office and branch office, all the way up to a standard enterprise license. In each license type, there are usually multiple options available, each covering a different subset of VMware vSphere functionality.

VMware vSphere Editions

VMware vSphere Editions are the key licensing options available. These focus on standard enterprise companies, and the license is assigned to each physical CPU installed. Please note that you always need to buy a license for the vCenter server itself as well.

There are two vCenter Server licenses available:

Product feature

vCenter foundation

vCenter standard

Host manageable

Max four ESXi hosts

Unlimited ESXi hosts

vCenter High Availability (HA)

Not available

Only for the vCSA

vCenter backup and restore

Not available

Only for the vCSA

Linked mode

Not available

Yes

 

vCenter Foundation is a vCenter server that has a limited functionality (although it provides all cluster services, such as VMware HA an Distributed Resource Scheduling (DRS)) as well as the maximum number of supported hosts. vCenter Standard has no limitations at all.

Once you have your vCenter Server, then you need to assign a proper license to your ESXi host, and again, multiple options are available.

In VMware vSphere 6.7 U1 (which was announced during the writing of this book but has not been released yet), the new edition will be available as VMware vSphere Platinum.

VMware vSphere Platinum edition has the same capabilities as Enterprise Plus but with one big advantage—AppDefense.

If you are interested in more information about AppDefense, feel free to have a look at https://www.vmware.com/products/appdefense.html.

Let's focus on features you can find in different vSphere editions:

  • Business Continuity and Security: Features focusing on improved availability, enhanced uptime, and advanced security features are as follows:

Product features

VMware vSphere Standard

VMware vSphere Enterprise Plus

VMware vSphere with operations management

VMware vSphere Platinum

vMotion

Cross-vSwitch/Cross- vCenter/Long Distance/Cross-Cloud

Cross-vSwitch/Cross- vCenter/Long Distance/Cross-Cloud

Cross-vSwitch/Cross- vCenter/Long Distance/ Cross-Cloud

Cross-vSwitch/Cross- vCenter/Long Distance/ Cross-Cloud

vSphere HA

Y

Y

Y

Y

Storage vMotion

Y

Y

Y

Y

Fault Tolerance

2-vCPU

8-vCPU

8-vCPU

8-vCPU

vShield Endpoint

Y

Y

Y

Y

vSphere Replication

Y

Y

Y

Y

Support for 4K Native Storage

Y

Y

Y

Y

vSphere Quick Boot

Y

Y

Y

Y

vSphere Single Reboot

Y

Y

Y

Y

vCenter High Availability

vCenter Server Standard

vCenter Server Standard

vCenter Server Standard

vCenter Server Standard

vCenter Backup and Restore

vCenter Server Standard

vCenter Server Standard

vCenter Server Standard

vCenter Server Standard

vCenter Server Appliance Migration Tool

vCenter Server Standard

vCenter Server Standard

vCenter Server Standard

vCenter Server Standard

vCenter Server Appliance Converge Tool

vCenter Server Standard

vCenter Server Standard

vCenter Server Standard

vCenter Server Standard

TPM 2.0 Support and Virtual TPM

Y

Y

Y

Y

FIPS 140-2 Compliance & TLS 1.2 Support as Default

Y

Y

Y

Y

Cross vCenter Encrypted vMotion

Y

Y

Y

Y

Virtual Machine Encryption

Y

Y

Y

Automated Discovery of Application Assets, Intent, and Communication

Y

Contextual Intelligence of Application State

Y

Orchestrated or Automated Responses to Security Threats

Y

Integration with Third-Party Security Operations Tools

Y

  • Resource prioritization and enhanced application performance: Features aimed for improved performance, workload optimization, and application control:

Product features

vSphere Standard

vSphere Enterprise Plus

vSphere with operations management

vSphere Platinum

Virtual Volumes

Y

Y

Y

Y

Storage Policy-Based Management

Y

Y

Y

Y

Distributed Resource Scheduler (DRS

Y

Y

Y

Distributed Power Management (DPM)

Y

Y

Y

Storage DRS

Y

Y

Y

Storage I/O Control

Y

Y

Y

Network I/O Control

Y

Y

Y

Single Root I/O Virtualization (SR-IOV) support

Y

Y

Y

vSphere Persistent Memory

Y

Y

Y

NVIDIA GRID vGPU

Y

Y

Y

Proactive HA

Y

Y

Y

Predictive DRS

Y

  • Automated administration and provisioning: Features enabling streamlined operations and automation of the environment:

Product features

vSphere Standard

vSphere Enterprise Plus

vSphere with operations management

vSphere Platinum

Content Library

Y

Y

Y

Y

vCenter Server Appliance Enhanced Linked Mode with Embedded Platform Services Controller

vCenter Server Standard

vCenter Server Standard

vCenter Server Standard

vCenter Server Standard

Storage APIs for Array Integration, Multipathing

Y

Y

Y

Y

Distributed Switch

Y

Y

Y

Host Profiles and Auto Deploy

Y Y Y

VMware vSphere Essentials Kits

VMware vSphere Essentials Kits are for small businesses and combine virtualization for up to three physical servers with centralized management using VMware vCenter Server® for Essentials. vCenter Server for Essentials has a similar capability to vCenter Foundation, but the limit is only three ESXi hosts. Also, Essentials Kits are bundled in a single SKU which contains ESXi licenses as well as the vCenter Server license. There are two different Essentials Kits available:

vSphere Essentials Kit

vSphere Essentials Plus Kit

Overview

Server virtualization and consolidation with centralized management

Server virtualization and consolidation plus business continuity

vCenter Server

vCenter Server for Essentials

vCenter Server for Essentials

License entitlement

Three servers with up to two processors each

Three servers with up to two processors each

Features

ESXi

ESXi, vMotion, high availability, vShield endpoint, vSphere replication

Remote Office Branch Office (ROBO) editions

VMware vSphere ROBO is designed for IT infrastructure located in remote, distributed sites. This delivers improved service levels, standardization, availability, and compliance.

The idea of ROBO edition is that you have one vCenter Server in your HQ and then different ROBO sites that you centrally manage. You can, of course, deploy vCenter Server Foundation as a local management platform in each ROBO site as well.

You can run up to 25 VMs in a single ROBO site, but you can't assign multiple license packs in the single site. However, you can distribute the single license among multiple sites (ROBO site 1 contains 5 VMs, ROBO site 2 contains 10 VMs, and ROBO site 3 contains 10 VMs):

vSphere ROBO Standard 

vSphere ROBO Advanced 

Overview

Remote site server virtualization platform with business continuity and backup features

Remote site server virtualization offering business continuity and backup with advanced features such as standardization of host configurations

Centralized management

vCenter Server for Essentials

vCenter Server for Essentials

License entitlement

Pack of 25 virtual machines

Pack of 25 virtual machines

vCenter Server (sold separately)

vCenter Server Standard

vCenter Server Standard

Features

ESXi, vMotion, Storage vMotion, High Availability, Fault Tolerance (2-vCPU), vShield Endpoint, vSphere Replication, Hot-add, Content Library

ESXi, vMotion, Storage vMotion, High Availability, Fault Tolerance (4-vCPU), vShield Endpoint, vSphere Replication, Hot-add, Content Library, Host Profiles, Auto Deploy, Distributed Switch

You have been reading a chapter from
Mastering VMware vSphere 6.7, - Second Edition
Published in: Mar 2019
Publisher: Packt
ISBN-13: 9781789613377
Register for a free Packt account to unlock a world of extra content!
A free Packt account unlocks extra newsletters, articles, discounted offers, and much more. Start advancing your knowledge today.
Unlock this book and the full library FREE for 7 days
Get unlimited access to 7000+ expert-authored eBooks and videos courses covering every tech area you can think of
Renews at £13.99/month. Cancel anytime
Visually different images