VMware HOL (HandsOnLabs) What’s New with vSphere 6.5

What's New with vSphere 6.5

HOL-1710-SDC-6-MYVMW-HOL . 1 hrvmware

  1. vCenter High Availability
    1. Essentially a 3 node HA vCenter cluster to eliminate protect from failures in hosts, hardware or appliances
    2. VAMI / vCenter Server Appliance Management Interface is now called; “vCenter Server Appliance Management UI” so I guess it’s VAMUI
    3. Totally incorrect instructions have you logging in vCenter Client, not the appliance mgt; look for the appliance MGMT link (local:5480)
    4. Look at various network and system utilization stats.
    5. Create support bundle, backup, shutdown, etc.
  2. Update Manager
    1. Next release of Update Manager is integrated with VCSA (VCenterServerAppliance) No longer will you be able to connect to Update Manager installed on a Windows Server
    2. To start the Update Manager on VCSA just start the service.
    3. Run on internal PostgreSQL DB.
    4. VCSA and UM run on the same DB instance but separate databases.
    5. For those not used to UM, it is used to patch and update ESXi hosts, install third party software on hosts, I.E., HP Firmware for example. Updates VMware tools.
  3. Content Library
    1. Lists all content like .ISOs, templates, vApps, scriptsvmwarecontentlibrary
    2. Enhancements include things like being able to mount .ISO to VM direct from Content Library
    3. Create new virtual machine with custom specification from Content Library
    4. Content Libraries can be synchronized across two vCenter servers.
    5. Create a new Content Library and sync to it.
  4. SOIC / Storage IO Control
    1. Show up by Host Profiles in “Policies and Profiles”
    2. Create multiple SIOC Policies
    3. Storage policies are defined by disk, so each disk could have different policy, for example on a DB server.
  5. HTML 5 Host Client (webclient)
    1. Walk through common features
    2. Generating GSS Support Bundle (Global Support Services)
  6. Encrypt VMs
    1. Add a Key Management Server
    2. Set up encryption storage policy
    3. Create encrypted VM, encrypt an existing VM
    4. Decrypt multiple VMs simultaneously.
    5. Encryption is essentially just another type of Storage Policy.
  Visit HOL here; http://hol.vmware.com/
VMware vCenter 6.0 VCSA – Where is the .OVA?

Um, Yeah, there is no OVA with vCenter Server Appliance 6.0

We take a quick look at setting up vCenter Server Appliance (VCSA) 6.0 since it’s a bit different with no .OVA option. In fact, there is a VMware KB article they created because so many people were asking where to find the .ova download. With 6.0, there is ONLY an .ISO.  That’s the only option to download. You should be able to download VCSA 6.0 or VCSA 6.0U1 here.

If you remember the old process, you could set up one host, connect to the host with vSphere Client, and then import the .OVA and you’d be up and running in mere minutes.

Fortunately, the new process is almost as simple, as long as you get a couple of pieces right up front. Please watch the video from our YouTube Channel and we walk through the process. Essentially, you 1) download the .iso, 2) install the Client Integration Plugin and 3) install / push / import the VCSA to a host.

70-412 and 70-417 Study Guide List

Over the past few months I have posted a series of Study Guides targeted at 70-412, which would alsoServer2012TOC be useful for 70-417.  I want to put a hyperlinked Table of Contents here to show what order would be best to review them. These are study guides from the FREE Pluralsight training.



Here are the hyperlinks;

1) Configure Active Directory

2) Configure High Availability

3) Configure Network Services

4) Configure Continuity and Disaster Recovery

5) Configure File and Storage Solutions

6) Configure Identity and Access Solutions

Other useful links on this effort would be;

MCSA and Build a LAB

Server 2012 R2 – New Features of R2

Windows Server 2012 R2 (70-412) File and Storage Solutions – Study Guide

Prepare yourself for the Microsoft MCSA 70-412 exam. This course explores how to implement an advanced DHCP solution, implement an advanced DNS solution, and deploy and manage IP Address Management.

These notes are my personal notes from the FREE training on Pluralsight. You can get your FREE signup through technet/MSDN or Dreamspark. The title of this course is exactly the title of this post. These notes are from this specific course only. I use these as a refresher Study Guide. POWERSHELL topics and2012GregShieldscmdlets are in purple. I have a few notes with the “DEMO” each time the training included a DEMO just so you can see how many demos there were which were really helpful. Thanks to Greg Shields @ConcentratdGreg, the trainer, contact info at the end.

“Storage” – think more than just file server.

  1. Configure and Optimize Storage
    1. Configure Storage Spaces
      1. local disks
      2. create a Storage Pool
      3. all storage shows up (unused and available) in the PRIMORDIAL POOL
      4. new storage pool wizard
        1. during wizard can allocate “automatic” but can choose “manual” or “hot spare”
        2. leave it as automatic, can set RAID
      5. Then create a disk out of the storage pool. Then can create volumes on those disks as well.
      6. storage tiers checkbox is grayed out as tiering is not set up.
      7. can set simple/mirror/parity (RAID) in this wizard
      8. next button lets you choose thin or fixed provisioning.
      9. after creation, then create a volume on the new disk
      10. can enable data deduplication in next field (have to turn on the ROLE)
        1. general purpose or VDI de-dupe
        2. can choose exclusions, schedule, etc. Throughput optimization.
    2. Configure Tiered Storage
      1. Start with creating a new storage pool. Has the different type disks (SSD and spinning)
        1. (hack to create each with VMware workstation)
          1. Get-PhysicalDisk
          2. Get-PhysicalDisk | ft friendlyname,size,mediatype
          3. can set them in PS to be and appear as SSD or mechanical
          4. Set-PhysicalDisk -mediatype HDD
          5. So essentially you are setting them to have some SSD and some HDD so you can set up tiering.
        2. Now you have a different option in the wizard (Faster tier, Standard tier)
        3. the tiering is handled by the windows subsystem, no mgmt
        4. can set specific files to SSD by PS; Set-FileStorageTier
    3. Implement Thin Provisioning and TRIM
      1. we already talked about creating THIN
      2. tiered is THICK – cannot do THIN tiered
      3. see if THIN provisioning fits your needs
      4. TRIM – file delete notification. reclaim storage space. File Delete Notification is ON by default.
      5. disable file delete notification by registry setting if you want as it does add some overhead.
      6. PS Optimize-Volume
    4. Configure iSCSI Target and Initiator
      1. provides a method for any of the above disks accessible over network
      2. Target = where storage is, Initiator is who needs the storage,
      3. Configure; easier to create the initiator first (the remote network server)
        1. tools/start iSCSI initiator get alert box to start service each time
      4. iSCSI console
        1. quick connect option might not be the best for enterprise use
      5. you have to click the ADVANCED button to choose adapter and initiator IP (critical when using a separate storage network)
      6. at this point, we haven’t create the storage target on the fileserver yet
      7. new iSCSI virtual disk wizard
        1. create new iSCSI disk name, size, dynamically expanding, etc.
        2. next screen asks for target name, and the previously created one shows up. (which is why we created it first)
        3. can enable CHAP authentication
        4. “CONNECT”, then go to ADVANCED to verify IP, network, etc. If you don’t specify the right network, you could end up sending storage traffic over your production network.
        5. the remote server shows the disk just like it was a local disk, needing brought online, format, etc.
        6. PS commands for iSCSI
          1. Connect-IscsiTarget
          2. Disconnect-IscsiTarget
    5. Configure iSNS (Internet iStorage Name Service Server)
      1. used to simplify management of complex and large iSCSI setups (who is that?)
      2. registers initiators
      3. to register targets, you need PS command Set-WmiInstance -namespace root\wmi -Class WT_iSNSServer -Arguments @{ServerName=”actual server name”}
      4. after that, initiators and targets both show in iSNS console
    6. Manage Server Free Space using Features on Demand.2012SpecifyAlternateSourcePath
      1. basically allows you to remove unused roles to save space.
      2. this gives you the Specify Alternate Source Path window (screenshot)
      3. this is a good article to show where it searches.
      4. you can create a “feature file store” and put it on the network. it’s the SXS folder.
  2. Configure Advanced File Services
    1. Configure a NFS file datastore
      1. NFS more interested in computers not users
      2. “Server for NFS” ROLE (under file server)
      3. New NFS Sharing tab on share properties
      4. incoming client settings, permissions (which machines)
      5. by DEFAULT all machines have read access, and root access is disallowed.
      6. PS NfsShare, Get-NfsShare, etc.
    2. Configure file access auditing
      1. 50 new sub-categories, but same way to set up as previously
      2. Group Policy or local security policy
      3. 9 different original policies. Audit Object Access. Typically this is how we used to turn this on
      4. “Advanced Audit Policy Configuration”
      5. SACL; auditing view on file/folder properties, now you can also add CONDITIONS.
    3. Configure BranchCache
      1. transparent; cache documents in remote locations. I.E., branch offices. Bandwidth was historical a reason. Used to need Enterprise Windows versions, limiting it’s use. Now any version of Windows 8 works. Turn it on and don’t think about. File server, web server, or BITS data.
      2. First access of document initiates the copy to the branch.
      3. Distributed Mode (stores on desktop machine) or server based Hosted Mode.
      4. file is split into chucks that are hashed then only changed chunks are updated.
      5. One piece only does files, different piece does Web and BITS. These are in different places in FEATURES
      6. Turn it on via GPO, choose hash type, configure client side “turn on branch cache”, set hosted cache server name, set cache expiration, etc.
      7. You can pre-populate bia PS Publish-BCFileContent, Export-BCCachePackage
  3. Implement Dynamic Access Control (DAC) DAC is supposedly heavily represented on 70-412 and 70-417 tests. Here is a great example and scenario about how to use DAC in a real-world situation, from the Microsoft Storage Team; http://mints4.rssing.com/chan-3739609/all_p2.html
    1. Addresses file permissions getting lost/changed during file moves. New security requirements also drive this advancement in security.
      1. needs to have characteristics set in AD
      2. Also settings on file servers.
      3. Scenario; you can filter all documents for SSN, and then disallow anyone from viewing such document unless the user is in certain group, site, etc.
      4. Can filter and scan files as they are updated (SSN added to file that did not previously have one)
      5. Think big IF THEN statement; IF this user is in FINANCE group, AND user is in DENVER, then allow read/write/etc.
      6. DAC scans documents regularly to keep up with changes.
    2. Configure User and Device Claim Types
      1. Install File Server Resource Manager ROLE (screenshot)2012FileServerResourceManager
      2. CLASSIFICATION tab in properties on your file server now.
      3. Active Directory Administrative Center (different from ADUC) has DAC
        1. Trying to get steps in order here;
        2. create claim types in ADAC for USERS
        3. Resource properties for files set up in ADAC / DAC console. Some examples built in are; Personal Use, Project, Intellectual Property, Immutable (?), Department, Compliancy, Personally Identifiable Information, etc. Then there are different values; NOT PII, Public, Low, Moderate, High, and you can create/edit values. These are set up then used later in AD to apply to files and folders
        4. Resource property lists ( add resource property to global) This is just a container of resource properties. Grouping these makes it more manageable to attach to documents. To use this, use PS Update-FSRMClassificationproperyDefinition, which enables the property list. Now it shows up on folder/share/file “Properties” as a new TAB. Users aren’t going to use this manually very much so you have to use server options; screen templates, file screens, classification management. This is the first step to determine what type of content you’re looking for in files / folders. You can scope to specific types of files; user files/ backup files, application files, etc. Scope this down to only the ones interested in, or you can get into resource issues. After picking scope, then choose the TYPE of classifier; for this a “content classifier” which looks at file content. Then you set the content classifier to “high, low, etc.” to apply that to hits that it finds. then you build the classification parameters which are detailed search expressions. you can look up the patterns on the internet or wherever like this one for SSNs.  Now schedule to determine when and how often it searches. Check-box ” enable fixed schedule” then choose the times/dates/recurrence. You CAN force it to “run now” to see if it works. It allows logging and post scan reports. When if finds a HIT, then it actually will show as an updated “properties” tab on the file. You also can configure email request assistance and notification for remediation.
        5. Create new central access rule. This is in ADAC / DAC to set up how you want to apply the settings above to control access based on the detail above. Generally apply to “authenticated users” , they get access when certain defined conditions exist; user is in Kansas City, and belongs to HR, etc.
        6. Create central access policy is how the rule above gets applied to file servers. Then use Group Policy to deploy. New GPO for DAC policy. This would apply to File Servers. Then go back to properties on the share/folder and there is a “Central Policy” tab that you have to choose the policy.
        7. I guarantee this is a test question that MS uses. Keep in mind test questions are random so it might not be on EVERY test, but it’s on one I took.
    3. Implement Policy Changes and Staging
    4. Create and Configure Resource Properties and Lists
    5. Configure File Classification
    6. Perform Access Denied Remediation
    7. Create and Configure Central Access Rules and Policies
Windows Server 2012 R2 (70-412) Continuity and Disaster Recovery – Study Guide

Prepare yourself for the Microsoft MCSA 70-412 exam. This course explores how to implement an advanced DHCP solution, implement an advanced DNS solution, and deploy and manage IP Address Management.

Videos at the bottom (WinRE)

These notes are my personal notes from the FREE training on Pluralsight. You can get your FREE signup through technet/MSDN or Dreamspark. The title of this course is exactly the title of this post. These notes are from this specific course only. I use these as a refresher Study Guide. POWERSHELL topics and2012GregShieldscmdlets are in purple. I have a few notes with the “DEMO” each time the training included a DEMO just so you can see how many demos there were which were really helpful. Thanks to Greg Shields @ConcentratdGreg, the trainer, contact info at the end.

All, or nearly all, sections include DEMOS so I’m not notating that separately.2012TrainingRecommendedOrder

These training courses should be preferably taken in this order (screenshot).

  1. Configure and Manage Backup Solutions
    1. Configure Windows Server Backups FEATURE
      1. Compared to NT backups, this focuses on VOLUMES.
      2. Pretty fully featured technology today.
      3. If you want to do Bare Metal backups, you need to check that along with System State, System Reserved, and probably the C or OS drive.
      4. Advanced settings
        1. excluded files
        2. VSS settings
          1. copy vs. full (are you using some other backup application, if so you use COPY)
      5. Destination
        1. local volume
        2. remote shared folder
        3. Optimize backup performance = types of backups (full, incremental, etc.)
      6. POWERSHELL WB = Windows Backup
      7. Get-WBJob
      8. Stop-WBJob
      9. Get-WBVSSBackupOption
    2. Configure Azure Backups
      1. designed to just get a back up into the Cloud
      2. Create “Backup Vault” tied to subscription and choose location
      3. Download Vault credentials, and download and install Azure Backup Agent
      4. Is now called MICROSOFT Azure Backup NOT Windows Azure Backup
      5. set up encryption; Microsoft cannot recover data
      6. Azure looks almost the same as a Windows backup. File and folder; just data, not system restore.
    3. Configure role-specific backups
      1. Backup Operators is the default, maybe too many permissions for many cases; can shut down system.
      2. Create your own role for backup files and directories and restore files and directories
    4. Manage VSS settings using VSS Admin
      1. extended from original design (previous versions for users) to now include backups (quiescence)
      2. VSS writer (specific by vendor for the application, Exchange, Oracle, AD, SQL, etc.
      3. the VSS requester is the partner to the writer
      4. PS vssadmin list writers
      5. vssadmin list providers
      6. vssadmin add shadowstorage /for=c: /on=f: /maxsize=20% set location for VSS
      7. vssadmin create shadow /for=c:     create vss shadow copy, very quick nearly instantly
      8. vssadmin can remove, revert, etc.
  2. Recover Servers (restore)
    1. individual file or folder recovery
      1. backup from – choose location, then choose files and folders (other choices volumes, applications, system state, or virtual machines)
      2. can put back in same, or different location
    2. Bare metal server recovery
      1. boot into WINRE (WINdows Recovery Environment) and also here; Tom’s Guide; when to use RE
        1. one option is to use shutdown command shutdown /r /o /t 02012NewShutdownSwitches (Check out Windows 8 new shutdown switches here)
        2. the /o is a new switch
        3. This is a gui based windows recovery console. Allows you to find the system image, install drives, connect to network locations to find image. Do you want to repartition drives.
        4. Don’t even need DVD media.
        5. Here is a link to a video of the WINRE console.
        6. The F8 replacement is WINRE
        7. msconfig – set what startup you get for NEXT boot to boot into safe mode, AD repair, etc. In case boots are so fast you can’t see F8
        8. you can also boot to windows DVD
        9. From WINRE you can boot to command prompt view, and you can manipulate unmounted drive (OS is not mounted). You can tell because command prompt is on the X drive which is the WINRE OS
          1. startrep (start repair scan)
          2. bootrec (boot record repair) Fixmbr, Fixboot, ScanOS, RebuildBcd
          3. Advanced boot options (looks like the F8 options)
            1. safe mode, with networking, with command prompt, boot logging, debugging, low-resolution video, last known good, disable restart, disable early launch anti-malware etc., etc.
        10. Configure the boot configuration data store
        11. multi boot menu to offer recovery options (not multi os boot)
          1. bcdedit
          2. bcdedit /export c:\save (export and save config)
  3. Configure site level fault tolerance
    1. Configure Hyper-V Replica, including Replica Broker and VMs
      1. Replica is NOT failover clustering
      2. provides a way to keep another copy of VM files (usually at remote site)
      3. Replica CAN work with failover clusters
      4. Replica is NOT OS specific; you can set it up with just shell VM, no OS to prove it
      5. Kerberos – not encrypted traffic, requires trusted AD
      6. certs – encrypted, no trusted domain needed
      7. set up on each VM individually
      8. configure frequency
      9. can also set up scheduled recovery points
      10. VSS for application consistent recovery points
      11. you can do the initial replication via external media, network, choose other machine, etc.
      12. set failover TCP/IP
      13. on the TARGET location server there is “test failover” under network adapter in Hyper-V Manager
      14. PLANNED failovers all start from the SOURCE location
      15. UNPLANNED start from Destination location (thought is that the source location is down, or offline)
      16. Adding Replica to Failover Cluster, need to
        1. Need to add the Hyper-V Replica Broker ROLE
    2. Configure Multi Site Clustering, including network settings, Quorum, and Failover Settings
    3. Configure Hyper-V Replica Extended Replication
      1. create a second replication site
      2. this is initiated from the TARGET location of the original source.
      3. most other stuff is the same
    4. Configure Global Update Manager
      1. https://technet.microsoft.com/en-us/library/dn265972.aspx#BKMK_GUM
      2. When a state change occurs such as a cluster resource is taken offline, the nodes in a failover cluster must be notified of the change and acknowledge it before the cluster commits the change to the database. The Global Update Manager is responsible for managing these cluster database updates. In Windows Server 2012 R2, you can configure how the cluster manages global updates. By default, the Global Update Manager uses the following modes for failover cluster workloads in Windows Server 2012 R2:
    5. Recover a Multi Site Failover Cluster
      1. make sure you can support the IP and network configuration in the failover site
      2. same Cluster Manager is used to manage stretch (multi site) clusters
      3. configure preferred owners to deselect the DR site
      4. QUORUM
        1. node and file share is preferred
        2. even number of hosts per location preferred
        3. Force start without a quorum; https://msdn.microsoft.com/en-us/library/hh270275.aspx
Installing Hyper-V Role in VMware Workstation; error Hyper-V cannot be installed: A hypervisor is already running

This quick post and video shows how to get past the Hyper-V cannot be installed: “A hypervisor is 2012HyperVErroralready running” error when trying to install the Hyper-V Role on a server running as a VM on VMware Workstation. This is common in a virtual lap scenario for certification study.

To resolve this issue, change the guest OS type to Hyper-V.Caution: Hyper-V functionality inside VMware Fusion is experimental and is unsupported.To change the guest OS type to Hyper-V:

  1. Shut down the virtual machine.
  2. Click Virtual machine > Settings.
  3. Select General and change the guest OS type to Hyper-V (unsupported).
  4. Select Processors & Memory in the Settings.
  5. In the Advanced options of Processors & Memory, select Enable hypervisor applications in the virtual machine
  6. Reboot the virtual machine to enable Hyper-V.

The video is here

Windows Server 2012 R2 (70-412) Configure Network Services – Study Guide

Prepare yourself for the Microsoft MCSA 70-412 exam. This course explores how to implement an advanced DHCP solution, implement an advanced DNS solution, and deploy and manage IP Address Management.


These notes are my personal notes from the FREE training on Pluralsight. You can get your FREE signup through technet/MSDN or Dreamspark. The title of this course is exactly the title of this post. These notes are from this specific course only. I use these as a refresher Study Guide. POWERSHELL topics and2012GregShieldscmdlets are in purple. I have a few notes with the “DEMO” each time the training included a DEMO just so you can see how many demos there were which were really helpful. Thanks to Greg Shields @ConcentratdGreg, the trainer, contact info at the end.

All, or nearly all, sections include DEMOS so I’m not notating that separately.


  1. Implement an Advanced DHCP Solution
    1. Create and configure superscopes and multicast scopes
      1. superscopes – combine multiple DHCP scopes to have broader range of addresses
      2. initial subnet didn’t have enough addresses
      3. when you run out of addresses;
        1. define by geographical location; floor, building, city, etc.
        2. assign multiple network IPs to router (downside is network admin involvement)
        3. DHCP RELAY – we’ve been there…allows DHCP traffic to cross router
        4. DEMO
          1. In DHCP, create superscope, then add multiple scopes to it
          2. Multicast scope –
            1. create Multicast scope, pick start/end IP, set TTL
            2. unlikely would be allowed on most modern networks
            3. most common use is WDS or other desktop deployments
    2. Configure DHCP filters and policies
      1. nodes in DHCP mmc
        1. filters; allow or deny by MAC
        2. then have to “enable” by checkbox
        3. can set exemptions
        4. Policies; what options will the managed machines get
          1. vendor class
          2. MAC
          3. FQDN
        5. Then set what treatment those hosts that fit the policy actually get
    3. Implement DHCPv6
      1. Not a lot of real world use yet
      2. NOT very simple
      3. built into IPv6 can auto assign anyhow. Don’t believe it read this article…IPv6 address autoconfiguration
      4. This would be used for anything beyond what the protocol can do.
      5. CANNOT assign a default gateway
      6. CAN assign most other options
      7. NOT really needed for auto assignment, more used for address control
      8. DEMO
        1. click on IPv6, right click “new scope”
        2. etc. pretty much like IPv4
        3. beware of test questions about WHY you would use it.
    4. HA for DHCP – failover and split scopes
      1. split scopes (the old way)
        1. 80% / 20% is the most common (I’m sure I’ve seen test questions that said that was wrong though).  Well the 80/20 split scope is Microsoft best practice see here.
        2. Can be messy recovering from a server outage; the DHCP databases don’t know anything about what the other one is doing.
      2. DHCP Failover
        1. one DB
        2. can use 100% of scope
      3. DEMO
        1. split scopes (split scope configuration wizard)
        2. DHCP Failover
          1. per scope
          2. “Configure Failover”
          3. set load balance or hot standby and some other settings
          4. you can enable message authentication via shared secret
          5. Configure DNS registration, can discard as well
    5. DHCP Name Protection2012DHCPNameProtection
      1. mainly for non-windows computers (screenshot)
      2. prevents non-windows from registering a name that is already in use.
    6. DNS Registration
        1. Configure DNS registration, can discard as well
  2. Implement an Advanced DNS Solution
    1. Configure Security for DNS, including DNSSEC, DNS Socket Pool, and Cache Locking
      1. DNSSEC does not necessarily require certs.
      2. To enable you “sign” the zone.
      3. Key Master is the authoritative DNS server that generates and manages the key for the zone.
      4. when you create the new key, then you have all kinds of options
      5. Needs to be AD integrated zone
      6. KSK – Key Signing Key and ZSK – Zone Signing Key
      7. Trust Anchor (for authenticating non-authoritative server
      8. Then GP is used to tell clients to ask for the DNS key
      9. “name resolution policy”, checkbox for enable DNSSEC
      10. create rules to determine who it applies to
      11. DNS Socket Pool (in response to Kaminsky attack DNS vulnerability)
        1. randomizes the SOURCE PORT to not be using TCP/53 and UDP/53
        2. enabled by default, but you tweak settings like number of ports
        3. DnsCmd /config /socketpoolsize 100000
        4. DnsCme /info /socketpoolsize
      12. Cache Locking
        1. Locks cache after update in cache.
        2. cannot be overwritting by a percentage of TTL
        3. default is 100% of TTL
        4. DnsCmd /config /cachelockingpercent 50
    2. Configure DNS Logging
      1. two places it can be configured depending on what you want
      2. event logging (1)  goes into event logs
      3. debug logging (2) goes into file
    3. Configure Delegated Administration
      1. under “security” tab
      2. for you to delegate activities, you MUST have AD integrated zone (test question?)
    4. Configure recursion
      1. disabled by default
      2. servicing servers outside your network
      3. should be ON on external server to prevent DNS attacks
    5. Configure Netmask ordering
      1. common use – WSUS
      2. essentially allows DNS server give a client an address that corresponds to the subnet that they are in. For traveling users.
      3. First response goes to server with same subnet
    6. Configure Global Names Zone
      1. for needs that used to be handled by WINS
      2. short name resolution
      3. create a zone called “GlobalNames”
      4. will contain short names
      5. you have to explicitly enable on all DNS servers
      6. dnscmd servername /config /enableglobalnamessupport 1
    7. Analyze Zone level statistics
      1. Get-DNSServerStatistics -zonename company.local
      2. DNSLint
        1. graphical display of internal/external on .htm file
        2. dnslint 
  3. Deploy and Manage IP Address Management – IPAM
    1. Provision IPAM via manual or GP
    2. IMPORTANT NOTE: to change  the IPAM provisioning method (like from manual to automatic) you must UNINSTALL and REINSTALL!
      1. install FEATURE
      2. configure from Server Manager
      3. choose database (internal or SQL)
      4. GPO Name prefix (manual configuration of IPAM is tedious and not recommended)
      5. run PS command Invoke-IpamGpoProvisioning -Domain ….creates the Group Policies and links them.
      6. Run IPAM server discovery
      7. Choose the ones you want and set them to managed.
        1. managed servers need to show up in “security filtering’ box on the GPO
        2. machine has to receive and apply the GP before it shows as “unblocked” and “managed”
        3. IPAM is more of a “push” instead of pulling in existing IP use
        4. IP Address block
          1. 1 or more IP ranges
        5. Add address range (block of IPs or open range that IPAM can use)
        6. can add reservations and VIPs
        7. along with normal DNS, gateway and other information
    3. Configure server discovery
    4. create and manage IP blocks and ranges
    5. migrate to IPAM
      1. tasks / import IP addresses (imports from .csv). certain mandatory columns for IPAM imports – IPAddress,IPAddressState,AssignmentType,ManagedByService,ServiceInstance,AssetTag
    6. monitor utilization of IP address space
      1. lirrlw pie chart by each range, can be adjusted for the entire server
    7. delegate IPAM administration
      1. there is an “ACCESS CONTROL” link on the very bottom left to set up roles and access.
      2. several default roles but you can create your own customized roles and set the policy settings
    8. Manage IPAM collections
      1. request new addresses (fine and allocate) “find next”
      2. RECLAIM ip addresses that are no longer used, delete resource records and DHCP reservations if exist.
      3. EVENT CATALOG – log viewer of IPAM events
      4. ADDRESS RANGE GROUPS – group by custom fields you defined during IP creation
    9. configure IPAM database storage
      1. PS Move-IPAMDatabase (moved internal IPAM DB to SQL if you want)
      2. lots of IPAM powershell commands (automation possibilities)
How to create RDM mappings for SQL Clustering with MSCS on VMware 6.0

How to create RDM mappings for SQL Clustering with MSCS on VMware 6.0

Using vSphere 6.0

Using vSphere 6.0

For the sake of this discussion, we’re building two VMs for use in a two node failover MSCS cluster for SQL 2012.  We’ll simply call them A and B.

We will be using the Web Client for this, since that’s the direction VMware is pushing. However, the Fat (C#) client is faster for this task as it takes fewer steps.  For example, on the fat client, when you create the first RDM mapping, it will automatically create a new, second SCSI controller. When on the web client, you have to manually create the SCSI controller first, then start building the RDM drives.

The documentation in the 6.0 documents is very sparse, and I don’t think it’s even complete or accurate so this took a bit of effort to figure out and get set up.

Add a new SCSI Controller (we had issues with other “types” and use VMware Paravirtual exclusively now)

Add a new disk;
mscs3Select the target LUN by LUN ID;

Choose your new SCSI controller 1 (not like picture) and pick an unused SCSI ID.


This shows the proper SCSI controller and ID selection.

After creating this, go to the Windows OS on A, bring disk online, initialize, format, name, label, etc.

Now go to server Node B and add a RDM pointing to that exact same file.

You told it to store the VMDK pointer “with the server” so go to that datastore and fine the VMDK that was created by the new drive creation on A. When you create this drive in VMware on B, then you can go into the OS on the B node and the drive should show up there labeled and formatted and drive lettered.

If you keep track of it as you go, you can add several drives at once on A (2,3,4,5,6,7…) and it will create them all at once, then go over to B and add/create them all at once. But you have to keep your VMDK names and LUN IDs straight so you know which one is which. Doing one at a time is slower but less confusing.


How to tell (after it’s created) which VMDK file a new RDM is using on A, so you can find the correct VMDK when you create B;

Go to “Edit Settings” then at the top there is a “Manage other disks”

Open that button, then drop down the details on the disk you’re looking at and it will show you the VMDK and datastore. This VMDK is just a “pointer” or “mapping” file to the LUN.



Pick the SAME SCSI controller and port that you did on A;

Set LUNS as “perennially reserved”.  If this is not set right, the ESX HOST will take HOURS to boot, depending on how many RDMs it has to scan. Ours took 2.75 to boot. When this was set right via esxcli, they would boot in about 6 minutes, counting the HP specific boot processes. This is addressed in this KB, scroll down to the “perennially reserved” section. ESXi/ESX hosts with visibility to RDM LUNs being used by MSCS nodes with RDMs may take a long time to start or during LUN rescan (1016106)




Windows Server 2012 R2 (70-412) MCSA and the 70-412 Exam – Study Guide Part 2 – build a lab

These notes are my personal notes from the FREE training on Pluralsight. You can get your FREE signup through technet/MSDN or Dreamspark. The title of this course is exactly the title of this post. These notes are from this specific course only. I use these as a refresher Study Guide. POWERSHELL topics and2012GregShieldscmdlets are in purple. I have a few notes with the “DEMO” each time the training included a DEMO just so you can see how many demos there were which were really helpful. Thanks to Greg Shields @ConcentratdGreg, the trainer, contact info at the end.

As mentioned previously, the second section of this course seem like it was going to focus on how to build a lab in preparation for training, so I broke it into a separate post.

Windows Server 2012 R2 (70-412) MCSA and the 70-412 Exam

Building Your 70-412 R2 Environment

  1. VMware workstation
    1. please note; VM Workstation is a licensed product; you have to PAY for it. You can get a 30

      My physical lab 5 DL380 G5s (one not in picture) and two DL360 G5s. The G4s are being decomissioned.

      day trial of VM Workstation here. Also, if you have ever passed a VMware certification (like me) then you get a free license as one of your benefits. So, for example, I have a permanent license for Workstation 10, but cannot upgrade without buying a new license. I suppose you could do this lab on VBOX also if you have familiarity there. At the end of this I will also post some links to good sites about virtual labs.

  2. VM infrastructure and IP scheme
  3. Forest infrastructure
  4. Understanding the Network Infrastructure
  5. VyOs router for network routing
  6. Use of templates or clones. Discussion of Linked Clones to minimize disk use. Linked Clones are a VMware specific ability. VMware Linked Clones use the same virtual disks as the parent. So you could have 10 linked clones using one set of disks, with a very much improved storage use scenario especially in a lab.
  7. Reviewing lab IP scheme and host design;
    1. 4 Domain Controllers
    2. 1 File Server
    3. 2 NLB hosts
    4. 5 Failover Cluster hosts
    5. 1 Certificate server
    6. 1 RMS (Rights Management Server)
    7. 1 ADFS (Active Directory Federation Services)
    8. 1 desktop
    9. Total of 1,2,3 let’s see 16 machines looks like all in VM Workstation running on one PC
  8. Forest infrastructure
    1. company.whatever
    2. separate forest to test ADFS
    3. three different sites
    4. 4 subnets; VMware Workstation doesn’t support subnetting which is why we have VyOS
  9. Setting up VYOS
    1. default username and pw is “vyos”
    2. setting up multiple NICs to support the subnetting
    3. adding 4 more NICs
    4. Configured VYOS
    5. Configured internal home router for the appropriate vlans

Ok that’s about it. It does looks like a pretty good way to set up this all in a virtual lab. I’d like to see how it performs but probably pretty well since he put all the drives on a separate SSD.

Here are some of the other links I have gathered on building a lab. Some focus on low power (electricity costs), some focus on being quiet (don’t need the disturb the spouse) and some on different things. I’ve had the good fortune to be able to collect some HP G5 servers which I have been able to use, using iSCSI and / or VMware VSAN for storage. I used this lab to study for and pass my VCP-DCV5.1 test.


Labs in general

While this one could go under “low noise” or “low power” they’re not really stated goals so I’m putting it here, it’s one of the best; http://packetpushers.net/vmware-vcdx-lab-the-hardware/

Similar lab build; http://rickmur.com/home-lab-server/

A more expensive ($3,000.00) work office targeted option using HP / CDW parts; (can this run ILO?) https://virtualizationreview.com/blogs/virtual-mattox/2012/03/build-cheap-screaming-virtualization-lab-server.aspx

Another good follow along lab; http://ethancbanks.com/2014/03/15/my-home-lab-esxi-5-5-server-build-and-the-logic-behind-it-all/ but this guy had a couple of Cisco SG300-52 switches that are worth min $400.00 each so not really cheap.


Nested / Low Power / Low noise or some combination

“nested” generally simply means you have one hypervisor running on another, or one hypervisor running as a VM.

Nested lab on VMware Workstation; low cost; http://www.heathreynolds.com/2014/02/building-nested-esxi-lab-on-vmware.html

Nested lab on ONE DL380 G5; http://www.running-system.com/how-to-build-a-nested-lab-on-a-hp-dl380-g5-server-step-1/ You can sometimes get a G5 on Craigslist for cheap or free. I got a couple for free, and I got a couple for as little as $90.00. There are thousands of these G5s still in production and they are solid hardware. Anything older than G5 won’t have processors that will support virtualization.

First one I have seen specifically on VMware 6.0 which just came out a few months ago; http://www.vladan.fr/nested-esxi-6-in-a-lab/

This looks cool; Intel NUC, low power (15w with 5 running VMs) http://www.vclouds.nl/how-to-build-a-low-cost-low-power-and-fast-esxi-home-lab/

Around 30w; https://matthill.eu/projects/vmware-esxi-low-power-home-lab/

VBOX lab


In my experience, Memory is going to be the first constraint on a lab system no matter which method you choose. After that, probably storage. On nested environments (like this Pluralsight training) SSD would be a great idea.