Best practices in virtualization AD DC?

Are there some best practices when you have an Active Directory domain controller that is running in a virtual machine?

Or a possible problem.

Take a look on:

Re: Tips for virtualizing domain controllers?

http://geekswithblogs.NET/NTpro/Archive/2005/07/27/48375.aspx

See also notes to Microsoft:

http://support.microsoft.com/kb/888794 - considerations on domain controller hosting Active Directory in a VM

Don't forget to manage time in a straight path:

http://www.vmware.com/pdf/vmware_timekeeping.pdf - measurement of time in Machines virtual VMware

And, if you use the DRS, add rules anti-affinites to separate DC on different ESXs.

André

Tags: VMware

Similar Questions

  • Best practices in virtualization XenApp?

    Are there some best practices when you have a XenApp running in a virtual machine?

    Or some setting parameters.

    See also:

    http://www.VMguru.nl/WordPress/2009/12/best-practices-XenApp-on-vSphere/

    http://www.thegenerationv.com/2009/10/optimizing-XenApp-on-VMware-ESX.html

    André

  • Best-practice for hardware virtualization?

    Hardware virtualization is disabled by default when I create new virtual machines in my VMware clusters. But what are the best practices for this what settings are recommended? Are there reasons NOT to activate the hardware virtualization?

    IMO there is no advantage in allowing virtualization of hardware if you have no need for the virtual machine (for example, a virtual host of the ESXi).

    André

  • Best practices Networking ESXi 5

    Good afternoon.

    Hate me help, docks as best practices para uma infraestrutura of rede receber o Vmware (ESXi 5 + vCenter vConverter) autonomous.

    Switch, VLAN, NIC?

    Obrigado

    Olá amigo, good afternoon.

    Leave aqui um trecho do livro "Virtualização - Central Datacenter do Componente" em than comenta, sober os conceitos uma rede virtual cloud:

    An e VMware a Savvis sugerem some measures Segurança interesting than sao Speaker aqui operacionais:

    Lado provedor:

    • Manter as redes for sao to leave da infraestrutura virtualizada isoladas. Insulation pode ser feito com os rocking or utilizando segmentacao through VLAN. Outro Método PODES use uma want Kanada Doi methods e o conceito of virtual switch.
    • Manter as redes of members isoladas. Manter as redes of members e isoladas interfaces controlled devidamente.
    • Manter as redes used para verificaram maquinas e tolls IP isoladas em redes roteaveis nao. Estas redes precisam ser rapidas e ao mesmo tempo sao suscetiveis an attacks.
    • Manter as redes back clients isoladas. Estas redes should ser isoladas das redes e members should divertir firewall between as redes para avoid security problems.
    • Fornecer seguro aos recursos nuvem client access. Client OS usually precisam ter access has recursos dentro da e nuvem para isto e Chipre o provedor disponibilize um Portal com encriptacao para Segurança effect.
    • Backups to maintain E restores seguros e consistent. Provedor deve to maintain this appearance basico realize e recursos back to maintain backup um processo rapido restore.
    • Autenticacao strong mechanisms, auditoria e autorização. OS provedores should please has autenticacao segura, access so aos recursos waiting rooms recursos providenciar e.
    • Use models seguros e configuracao gold images do sistema operational e das management. Estas reduzem os problemas com configuracoes inadequadas measures. Also o provisionamento maquinas tolls deve obedecer an entrar em being Produção antes criteria preestabelecidos.
    • Members of recursos para avoid attacks do tipo back.

    Client side:

    • Practices of mercado Seguir para a Segurança sistemas operacionais back. OS administradores should seguir as mesmas rules used no ambiente interno relativas to back sistemas operacionais, como manter os last Segurança no patches of Segurança configuracao gold images.
    • Following to encrypt data. Dados follows sistemas important should mantidos encriptados forse ainda but os possíveis ataque para ser to rede.

    Espero ter helped.

  • Best practices: multiple partitions on a single vmdk or partition by vmdk

    Hello all-

    I would like to get your opinions on the best practices for the vmdk file server installation program.

    The drive C partition would be allotted for the operating system, while E, F... to store the data of the partitions.

    configuration 1:

    vmdk1 = thick disk of provisioned by a partition of drive c.

    vmdk2 = thickness accommodation provisioned disk partitions E, f...

    Installer 2

    vmdk1 = thick disk of provisioned by a C partition

    vmdk2 = thick disk of provisioned by a partition E

    vmdk3 = thick disk of provisioned by a partition F

    .......

    Also the partitions of multiple data configured as independent + permanent virtual disks due to snapshots. My logic is that OS (C drive) is used for snapshots in test of new software for example while the data partitions act as the storage disks that need to keep the most recent files regardless of the return to an older snapshot. BTW data partitions regularly are Word, excel, photos and so on.

    also, I realize that I could have a single example, E: data with several shared folders partition, but given that each folder is for another Department could cause more trouble when space more and more in the future. Great VMDK could take more time to develop. Not sure again.

    Thank you

    Hello

    in general, virtualization does not change much on the disk IO.

    You can use the same rules that you would use to size a physical server.

    Multiple vmdk mean multiple targets for your I/o load.

    Best solution if IO load/troughput high or low response time should be reached, you create multiple VMDK and spread over several data stores.

    HtH

  • Best practices for the reader to 'Data' between VM?

    Hello

    So on my box ESXI, I have a 250 GB drive. I was wondering what the best practice is to have a 'data' drive shared between VM? I'm pretty new to virtualization so would like to view

    I would basically following drive configuration...

    Win 2008 R2 - 60 gb

    Win 2008 R2 - 60 gb

    Ubuntu 10.10 - 20 GB

    (Shared between the two areas of 2008) DATA - 100 GB

    Thank you.

    The only way to do this is to assign the drive to a virtual machine and create a network share. Unless you use a file system that supports concurrent access to files, an attempt to present the disk to several systems would probably end by the corruption of data.

    André

  • Best practices for managing strategies of path

    Hello

    I get conflicting advice on best practices for managed paths.

    We are on version 4.0 of ESXi connection to a HP EVA8000. Best practices guide HP recommends setting the strategy of railways handle on Round Robin.

    This seems to give two active paths to the optimized controller. See: http://h20195.www2.hp.com/v2/GetPDF.aspx/4AA1-2185ENW.pdf

    We used certain consultants and they say that the best practices of Vmware for this solution is to use the MRU policy which translates a single path to the optimized controller.

    So, any idea what good practice is best practice? Does make a difference?

    TIA

    Rob.

    Always go with the recommendation of the storage provider.  VMware recommendation is based on the characteristics of the generic array (controller, capable ALUA failover methods, etc.).  The storage provider's recommendation is based on their performance and compatibility testing.  You may want to review their recommendations carefully, however, to ensure that each point is what you want.

    With the 8000, I ran with Round-Robin.  This is the option of creating more robust paths available to you from a failover and performance point of view and can provide performance more even through the ports on the storage controller.

    While I did of the specific tests/validation, the last time that I looked at the docs, the configuration of HP recommends that you configure each IO to the ports in the switch configuration.  This adds the charge to the ESX host, the switch to other ports, but HP claims that their tests showed that it is the optimal configuration.  It was the only parameter I wondered in their recommendation.

    If you haven't done so already, be sure to download the HP doc on configuring ESX and EVA bays.  There are several parameters that you must configure the policy path, as well as a few scripts to help make the changes.

    Virtualization of happy!

    JP

    Please consider awarding points to useful or appropriate responses.

  • What is the best practice to merge both vMware vSphere environments?

    We recently bought another company that also manages vMware 4.

    They have a 4-node cluster and we have a 3 a node. Each is managed by its own vcentre.

    What would be the best practice to migrate all the guests and the hosts on the server main vCentre.

    Thank you

    Lance

    I choose one of the vCenters, unplug and remove hosts from the other and connect them to those elected. Configure the cluster after that (all in the same or keep the separation of the group, which I think is the best)

    You can also use related modes.

    Marcelo Soares

    VMWare Certified Professional 310/410

    Master virtualization technology

    Globant Argentina

    Review the allocation of points for "useful" or "right" answers.

  • / var/log is full. Best practices?

    One of the score of the newspaper of our host is 100% full. I'm not the practice administrator for this host, but manage/deploy the virtual machines it for others to use.

    I was wondering what's the best practice to deal with a more complete log partition? I found an article that mentioned editing the file /etc/logrotate.d/vmkernel/ so that files

    be compressed more often and saved for less often, but there was no real clear instructions on what to change and how.

    Is the only way to investigate on the console itself or the directory/var/log via putty? No there is no way to see VIC?

    Thank you

    Hello

    To solve the immediate problem, I would transfer to any newspaper in/var/log with a number at the end is dire.1,.2, etc. to a temporary storage outside the ESX host location. You could run something similar to the following command of the scp to do:

    scp /var/log/*.[0-9]* /var/log/*/*.[0-9]* host:TemporaryDir
    

    Or you can use winscp to transfer of the ESX host in a windows box. A you get the files from existing logs from the system for later playback, use the following to clear the space:

    cd /var/log; rm *.[0-9]* */*.[0-9]*
    

    I would therefore consist logrotation thus directed by hardening for VMware ESX.

    Best regards, Edward L. Haletky VMware communities user moderator, VMware vExpert 2009
    "Now available on Rough Cuts: url = http://www.astroarch.com/wiki/index.php/VMware_Virtual_Infrastructure_Security' VMware vSphere (TM) and Virtual Infrastructure Security: ESX security and virtual environment ' [url]
    Also available url = http://www.astroarch.com/wiki/index.php/VMWare_ESX_Server_in_the_Enterprise"VMWare ESX Server in the enterprise" [url]
    [url =http://www.astroarch.com/wiki/index.php/Blog_Roll] SearchVMware Pro [url] | URL = http://www.astroarch.com/blog Blue Gears [url] | URL = http://www.astroarch.com/wiki/index.php/Top_Virtualization_Security_Links Top security virtualization [url] links | URL = http://www.astroarch.com/wiki/index.php/Virtualization_Security_Round_Table_Podcast Virtualization Security Table round Podcast [url]

  • Conversion - best practices

    What is the best practice to convert a physical server to a virtual server? I installed the ESXi server and have installed the VMware Converter on the physical server I want to convert. I want to migrate the server and then turn off the physical server, what is the best way to do this?

    The best way to virtualize an ad server is to create a new domain controller and synchronize all the data first, then transfer the roles to the new virtual domain controller. Then demote the original domain controller.

    Definatley not clone hot the DC is discoraged, you will get all sorts of errors subsequently with tombstone objects. Also the way I suggest that there is still no interruption of service.

    With regard to the exchange server, either on your domain controller, I would recommend that put it on a separate server and installation that from scratch as is currently on a domain controller. Of course, it's license allows you to do.

    Andy, VMware Certified Professional (VCP), http://www.vmadmin.co.uk/

    If you have found this information useful please give points by using the buttons at the top of the page accordingly.

  • Best practices for virtualized file servers?

    Hello

    I wonder if anyone has a best practice ideas for a virtualized file server.

    I need to virtualize file server Windows 2003 with data from the 400GO file. Virtual machines are stored on an ISCSI SAN (MSA2012i). There is plenty of space on the VMFS

    I'm trying to decide if it will be better to put the data from file server (IE file shares) on the VMFS as a virtual drive or the data to another volume of SAN and present it to the file via ISCSI initiator server.

    I know that I can do both - I'm looking for some advice.

    Any suggestions greatly appreciated.

    Hello and welcome to the forums.

    How will you do your backups?

  • Best practices Apple ID

    I help the family members and others with their Apple products. Probably the problem number one revolves around Apple ID I saw users follow these steps:

    (1) share IDs among the members of the family, but then wonder why messages/contacts/calendar entries etc are all shared.

    (2) have several Apple IDs willy-nilly associated with seemingly random devices. The Apple ID is not used for anything.

    (3) forget passwords. They always forget passwords.

    (4) is that I don't really understand. They use an e-mail from another system (gmail.com, hotmail.com, etc) as their Apple ID. Invariably, they will use a different password for their Apple ID than the one they used for other email, so that they are constantly confused about which account to connect to.

    I have looked around for an article on best practices for creating and using Apple ID, but could not find such a position. So I thought I would throw a few suggestions. If anyone knows of a list or wants to suggest changes/additions please feel free. Here are the best practices for normal circumstances, i.e. not cooperate accounts etc.

    1. every person has exactly 1 Apple ID.

    2. do not share Apple ID - share content.

    3. do not use an email address of another counts as your Apple ID.

    4. When you create a new Apple ID, don't forget to complete the secondary information to https://appleid.apple.com/account/manage. It is EXTREMELY important questions your email of relief and security.

    5. the last step is to collect the information that you entered in a document and save to your computer AND print and store it somewhere safe.

    Suggestions?

    I agree with no. 3, it is no problem with using a addressed no iCloud as the primary ID, indeed, depending on where you set up your ID, you may have no choice but to.

  • Best practices Upgrade Path - Server 3 to 5?

    Hello

    I am trying a migration and upgrade of a server in the Profile Manager. I currently run an older mac mini Server 10.9.5 and Server 3 with a vast installation of Profile Manager. I recently successfully migrated the server itself out of the old mac mini on a Xserve end 2009 of cloning the drive. Still of double controls everything, but it seems that the transition between the mini and the Xserve was successful and everything works as it should (just with improved performance).

    My main question is now that I want to get this software-wise at day and pass to the Server 5 and 10.11. I see a lot of documentation (still officially Apple) best practices for the upgrade of the Server 3 to 4 and Yosemite, but can't find much on the Server 5 and El captain, a fortiori from 3 to 5. I understand that I'll probably have to buy.app even once and that's fine... but should I be this staging with 10.9 to 10.10 and Server 4... Make sure that all is well... and the jump off 10.11 and Server 5... Or is it 'safe' (or ok) to jump 3 to 5 Server (and 10.9.5 to 10.11.x)? Obviously, the AppStore is pleased to make the jump from 10.9 to 10.11, but once again, looking for best practices here.

    I will of course ensure that all backups are up-to-date and make another clone just before any which way that take... but I was wondering if someone has made the leap from 3-5... and had things (like the Profile Manager) still work correctly on the other side?

    Thanks for any info and/or management.

    In your post I keep the Mini running Server 3, El Capitan and Server 5 install the Xserve and walk through setting up Server 5 by hand. Things that need to be 'migrated' as Open directory must be handled by exporting the mini and reimport on Xserve.

    According to my experience, OS X Server facilities that were "migrated" always seem to end up with esoteric problems that are difficult to correct, and it's easier to adopt the procedure above that to lose one day try.

    YMMV

    C.

  • What is the best practice to move an image from one library to another library

    What is the best practice to move an image from a photo library to another library of Photos ?

    Right now, I just export an image on the desktop, then remove the image from Photos. Then, I open the other library and import these images from the office in Photos.

    Is there a better way?

    Yes -PowerPhotos is a better way to move images

    LN

  • Code/sequence TestStand sharing best practices?

    I am the architect for a project that uses TestStand, Switch Executive and LabVIEW code modules to control automated on a certain number of USE that we do.

    It's my first time using TestStand and I want to adopt the best practices of software allowing sharing between my other software engineers who each will be responsible to create scripts of TestStand for one of the DUT single a lot of code.  I've identified some 'functions' which will be common across all UUT like connecting two points on our switching matrix and then take a measure of tension with our EMS to check if it meets the limits.

    The gist of my question is which is the version of TestStand to a LabVIEW library for sequence calls?

    Right now what I did is to create these sequences Commons/generic settings and placed in their own sequence called "Functions.seq" common file as a pseduo library.   This "Common Functions.seq" file is never intended to be run as a script itself, rather the sequences inside are put in by another top-level sequence that is unique to one of our DUT.

    Is this a good practice or is there a better way to compartmentalize the calls of common sequence?

    It seems that you are doing it correctly.  I always remove MainSequence out there too, it will trigger an error if they try to run it with a model.  You can also access the properties of file sequence and disassociate from any model.

    I always equate a sequence on a vi and a sequence for a lvlib file.  In this case, a step is a node in the diagram and local variables are son.

    They just need to include this library of sequence files in their construction (and all of its dependencies).

    Hope this helps,

Maybe you are looking for

  • How can I activate mode lost and in the air of the ipad?

    I put my air of Apple ipad to lost when she was taken without permission. I used "find my phone" app to track down. After retreaving, I don't know how turn it back on or take off the lost mode. I went through "icloud" and "devices" to try to unblock,

  • Failure to build LabVIEW application on Linux using "Shared library".

    In order to create a LabVIEW application on linux without X display, I have respected the LabVIEW VI using the shared library for Linux. I did it by clicking with the right button on construction Specifications and selecting New > Shared Library, and

  • Transfer of office tof a new Summit of laptop

    I have office installed on my laptop software, this laptop is damaged and cannot be repaired, because the motherboard is damaged. I am buying a new laptop. Can I transfer desktop software to the new laptop by installing it on the new laptop?

  • TextArea text change event

    I use TextArea to a text box.  I would like to record automatically when the text is entered or modified in the TextArea box.  I tried TextEvent.TEXT_INPUT and that has not worked.  Which event should I listen to? Thank you!

  • My payment is not

    OK when I cancelled my subscription to creative cloud, that I just forgot to update my debt card informationthe next thing you know I raised an email saying that my payment has no cause that I didn't update my debit card, I have been negligent in thi