Have questions about how the Nutanix Platform works? Looking to get started - start here!
Recently active
Do you already have many security policies defined within one instance of Flow and, have another instance where you need the same set of policies but do not wish to recreate them? Or, do you wish to simply have a backup of your existing security policies just in case you should ever need to restore them sometime in the future?Flow has the native ability to export (and subsequently import) security policies that have already been defined previously. Policies are exported into a single binary file, which can then be transferred to a different instance of Flow or stored-away for backup purposes.Please also note that, when importing a previously exported binary file, any existing policies which are already defined within a given Flow instance are automatically removed in-favor of the newly imported policies.You can find more information regarding this within the Exporting and Importing Security Policies section of the Flow Microsegmentation Guide.
Synopsis: The goal of this workflow is to walk-through troubleshooting VM to VM communication issues in a Nutanix Cluster. Most customers are very vague when they state they have a networking issue. We will go through painting a complete picture of the network topology by asking the right questions and running commands on the Hypervisors. Initial Triage:Questions to Ask: What hypervisor is running on the cluster? What guestOS is running on the VMs? Are the VMs on the same node or different nodes? Are the VMs configured to use the same VLAN? What method is the customer using to test connectivity? Is there any Firewalls or ACLs that would stop this VM traffic? Information to gather: NIC teaming/bond configuration on node. Switch vendor and model from upstream switch. Interface configurations for the interfaces connecting to the nodes. If ESXi is the customer running on a Standard vSwitch or Distributed vSwitch? VLAN information for each VM. IP and Subnet Mas
Hi all.I’ve been trying to figure out how I can execute a PowerShell script inside a guest VM, both Linux and Microsoft, on AHV through the host but can’t find any solid information on the topic.There is a discussion called “Execute Script Inside AHV VM?” but that is only for initial configuration of the VM. I’m looking for a way to execute an arbitrary script on any running VM without having access to the VM through its default network configuration.It’s basically a hosting situation where customer VMs exist within their own isolated environments and I’m responsible for running various scripts for - among other things - joining new servers to AD, installing SQL Server, patching the OS, etc, etc.Looking at this post there seems to be a way to run scripts through NGT but when reading the Nutanix Bible that option seems to be limited to VM creation or cloning.Any workaround I can come up with doesn’t scale well when we reach thousands of VM’s and hundreds of customers. Is there a way to
Are you new to Era and want to learn more about it? Are you an experienced engineer working with the product looking for answers?Era is a database as a service (DBaaS) that automates and simplifies database administration, bringing one-click simplicity and invisible operations to database provisioning and life-cycle management. Nutanix has an article with over 50 questions answered about Nutanix Era 2.0. The article covers questions on the variety of topics, such as:Time Machines Profiles Provisioning and Cloning Across Multiple CLusters SAP HANA on Era Copy Data Management for Multiple Databases SQL Server Patching SQL Server Database Group PostgreSQL Patching Oracle Restore PostgreSQL RestoreSome of the questions answered are:Can a single Era management plane handle multiple Nutanix clusters?What type of networks are supported for Era Agents?Can two or more pre-2.0 Era instances be converged into one?What version of Oracle is supported for Oracle Restore?Can we clone a few databases
If you have a storage container on the cluster and the name starts with a “#”, you may see this error while trying to upload an image:"Could not access the URL nfs://127.0.0.1/%23ISO_Images/.acropolis/image/106ac31b-6236-4534-a2ae-808c08bb912f: Failed to parse the file size" That happens because the URL cannot have the # in the name and it gets automatically replaced with %23. Therefore, this creates the inconsistency between the container name and the URL.To resolve the issue, rename the container and remove the # from the container name and retry the image upload.Take a look at KB-10117 for more information.Check this guide on storage containers.
To verify if we have replaced DIMM on correct slot and CPU we can use the following method We can look at hardware.history file which records any replacement for example DIMM,SSD,HDD,NIC being made to that node. This file remains local to each CVM After we replace DIMM we will boot the host up Power on CVM and run following command ncc hardware_info update_hardware_info This will update the hardware.history file present in ~/config directory and it will recognize any new replacement Open hardware.history using less less ~/config/hardware.history Go to last line by pressing shift+g Check out the most recent replacement it should look something like this Mon, 05 Oct 2020 15:37:01 CDT|Component changed: Memory module{locator:P1-DIMMC1} Old values: |{serial_number: 423D07AF}|(Last Detected Mon, 05 Oct 2020 10:13:25 CDT) New values: |{serial_number: 152057A5} It mentions DIMM P1-DIMMC1 was replaced and its serial number is changed from 423D07AF to 152057A5 This is a quick and
Hi, I am working on an integration between Nutanix and Citrix but stuck at the moment at this point: Where in the Citrix Cloud can I find these values?Kind regardsChristian
Hi, I have one CVM out of space in /home, I have seen that I have the file localhost_access_host.txt with almost 20GB.Could I rotate or delete this file?In another CVM I don’t see this file.Regards,Antonio Maeso
In the first 3 Sections we saw solutions with classical snmp monitoring, dynamic monitoring with checkmk and metrics with prometheus and grafana.No we try the windows way. A Windows Application from the german vendor “Paessler” which could be tried for free for 100 sensors (not Nodes or VMs!).We download the Package here and install.After successfull Installation we get a Browser Page on Port :8080 and a LoginPrompt with default prtgadmin / prtgadmin.We login and create a new Host over the Menue Geräte/Geräte hinzufügen for our Nutanix Cluster:Zum Einsortieren hab ich hier “Virtuelle Systeme” gewählt und keinen eigenen neuen Knoten angelegtType in Name and IP from our Cluster (Nutanix Cluster IP) ATTENTION: Scroll DOWN and type in the Values from your SNMP Secrets!: After Click on OK the Host is created and a basic check is made via PING.. The System tries an autodisovery now but this is not needed for a nutanix cluster here! We klick on NOT “Automatic Discovery” (takes very long ag
The dynamic Inventory of a Hosts and the creation of Service Checks is one of the benefits of the checkmk opensource tool CheckMK. This Tool could be installed as a single Installation but it is also part OMD or Openitcockpit, which are using checkmk as an extension In my Homelab i will give a short overview of the use of checkmk with Openitcockpit with a nutanix 3 node cluser.Requirements: Enable SNMP in Prsim Centrala) Port 161/UDPb) Ein Username und Kennwörter fuer SHA und AESIf the Requirements are finished just create a new Host in Openitcockpit with Default Values. Ping is the standard Check first then. AFTER the Creation and Export of the Config we chood CHECKMK_DiscoveryWe choose SNMP V3 as Discovery Method and type in the Credentials which we prepared a step above in Prism Central.The FIRST Discovery tooks some time! If no result is shown, the credentials may we wrong or MD5 is set instead of SHA in the Auth section! If its working we get a bunch of discoverd services now:We g
Below are new knowledge base articles published on the week of September 27-October 3, 2020.KB 8607 - NCC Health Check: inconsistent_file_groups_check KB 9072 - NCC Health Check: file_server_task_stuck_check KB 9491 - NCC Health Check: container_on_removed_storage_pool KB 9728 - NCC Health Check: nearsync_stale_staging_area_check KB 9902 - NCC Health Check: vm_updates_disabled_check KB 10050 - Prism Central throwing "ErrorCode: 4" on VM update operations KB 10067 - Karbon - Private Registry Addition Troubleshooting KB 10071 - Move - Service start timed out error on Hyper-V KB 10077 - Alert ID 130096 - Failed to Recover NGT Information for VM KB 10079 - Alert ID 130095 - Failed To Recover NGT Information KB 10081 - Alert - A21014 - CassandraWaitingForDiskReplacement KB 10091 - Ubuntu 20.04 Server installation failes in guest VM running on AHVNote: You may need to log in to the Support Portal to view some of these articles.
Nutanix Clusters Console receives the results of the status checks performed by AWS to see the status of the instances.Status checks on AWS are performed every minute, returning a pass or a fail status. If all checks pass, the overall status of the instance is OK. If one or more checks fail, the overall status is impaired. There are two types of status checks, system status checks, and instance status checks. System status checks monitor the AWS systems on which instance runs. Instance status checks monitor the software and network configuration of individual instances.If Nutanix Orchestrator detects that AWS has marked system status or instance status of an instance impaired, following WARNING message will be seen in the Notification Center of the Nutanix Clusters Console: More information on - http://portal.nutanix.com/9704 What does Nutanix Cluster On AWS mean :- Nutanix Clusters provides a single platform that can span private and public clouds but operates as a single c
Nutanix Move is a very versatile tool which is used to migrate existing VMs, from various storage sources and hypervisors, into a Nutanix infrastructure. Many users have already enjoyed its functionality and ease-of-use.Often, users will migrate multitudes of VMs into their new Nutanix infrastructure using Move, and then either delete or forget about the Move VM itself thereafter. Later, when more VMs are sought to be migrated, users will either reinstall Move again or attempt to leverage the Move VM that remained from the previous migration.For those users leveraging an existing Move VM within their infrastructure and, as it is generally a good idea to use the latest version of Move when possible, it is possible to upgrade the Move VM to the latest available version right from its own dashboard (and, even by CLI if desired).You can find more information regarding upgrading Move from within the Online Upgrade section of the Move User Guide.
Hardening is the process of securing a system by reducing its surface of vulnerability, which is larger when a system performs more functions; in principle a single-function system is more secure than a multipurpose one. Reducing available ways of attack typically includes changing default passwords, the removal of unnecessary software, unnecessary usernames or logins, and the disabling or removal of unnecessary services. There are various methods of hardening Unix and Linux systems. This may involve, among other measures, applying a patch to the kernel such as Exec Shield or PaX; closing open network ports; and setting up intrusion-detection systems, firewalls and intrusion-prevention systems. There are also hardening scripts and tools like Lynis, Bastille Linux, JASS for Solaris systems and Apache/PHP Hardener that can, for example, deactivate unneeded features in configuration files or perform various other protective measures. We can implement Security Hardening features for Nutani
Application monitoring provides visibility into integrated applications by collecting application metrics using Nutanix and third-party collectors, providing a single pane of glass for both application and infrastructure data, correlating application instances with virtual infrastructure, and providing deep insights into applications performance metrics. The monitoring integrations dashboard allows you to view information about select applications, such as SQL Server instances, running in the cluster. Before you decide to enable this, there are some pre-requisites that you need to follow. To learn more about the prerequisites, click here and for more information about Application Monitoring, check the Application Monitoring Guide.
When a drive on a host (SSD or HDD) experiencing a recoverable errors, warnings or a complete hardware failure, the stargate service will mark the disk as bad. The following can be observed when a disk fail occurs. Disk is shown as a red or a plain grey in prism A critical error in Prism stating the disk went bad. Troubleshooting steps Identify the problematic disk in Prism. Check the Prism web console for the failed disk. In the Diagram view, you can see red or grey for the missing disk. Check the alerts in the Prism web console for the disk alerts, or use the following command from any of the working CVMs in the cluster to check for disks that have generated the failure messages. ncli alert ls Check to see if the disk is being recognized by the black plane. Execute the following command from the cm of the node that shows disk fail list_diks Check to see if the disk is mounted on the node. df -h Check for offline disks using NCC check disk_online_check. ncc health_checks
Using the RestAPI, we are able to pull around 300 metrics from Nutanix. Do you have a document which explains what all these metrics are, similar to the page we have for the metrics available via SNMP (https://portal.nutanix.com/page/documents/details?targetId=Web-Console-Guide-Prism-v511:man-nutanix-mib-r.html)
To start this topic, it is worth to mention the difference between the data size units. There are GBs (gigabytes) and GiBs (gibibytes). The difference is the following:GB = 1000 MBGiB = 1024 MiBSo, the difference is in binary vs decimal representation. It can be confusing, because a lot of people have never heard of gibibytes and always thought that GB is 1024 MB. In fact, it is not exactly true Why it may be confusing in Nutanix running on ESXi hypervisor?Nutanix is using MiB, GiB, TiB, etc as data size units. When you create a storage container, you get the size in binary units. For the example, i have created 2 containers with advertised capacity of 1000 GiB and 1024GiB:We can see, that the 1000 GiB container is 0.98 TiB is total size, because 1 TiB=1024 GiB.However, when we go to the vCenter, we can see a different picture:vCenter reports that the 1000 GiB container is 1000 GB in size and 1024 GiB container is 1TB. But 1 TB is 1000 GB! The problem here is that the vCenter shows teb
Below are the top knowledge base articles for the month of September 2020.KB 4116 - NX Hardware [Memory] – Alert - A1187, A1188 - ECCErrorsLast1Day, ECCErrorsLast10Days KB 7503 - NX Hardware [Memory] – G6, G7 platforms - DIMM Error handling and replacement policy KB 4141 - Alert - A1046 - PowerSupplyDown KB 1540 - What to do when /home partition or /home/nutanix directory is full KB 4158 - Alert - A1104 - PhysicalDiskBad KB 6970 - PE-PC Connection Failure alerts KB 1113 - HDD/SSD Troubleshooting KB 4519 - NCC Health Check: check_ntp KB 4409 - LCM: (LifeCycle Manager) Troubleshooting Guide KB 2090 - AHV | Host Networking KB 2473 - NCC Health Check: cvm_memory_usage_check KB 4272 - Alert - A6516 - Average CPU load on Controller VM is critically high KB 1863 - NCC Health Check: sufficient_disk_space_check KB 3741 - NGT: Nutanix Guest Tools Troubleshooting Guide KB 3784 - Alert - A1030 - StargateTemporarilyDown KB 7386 - NCC Health Check: power_supply_check KB 6945 - How Upgrades Work at N
Hey guys,I’m new at scripting/coding with python, I am trying to make a script that will automate adding a proxy, proxy whitelist and remove whitelists. This is what I have so far, but whenever it runs I get an error of “Error: Argument 'http-proxy' is specified multiple times.” import subprocessimport sysadd_whitelists = "ncli http-proxy add-to-whitelist target-type=IPV4_ADDRESS target="whitelist_Ip = ["192.168.1.1", "200.200.1.1"]login = "nutanix@192.168.1.50"add_pxy = "ncli http-proxy add name=NPX5-proxy address=proxy.npx5.local port=8080 proxy-types=HTTPS"list_proxy = "ncli http-proxy get-whitelist"#ssh connectionssh = subprocess.Popen(["ssh", "-i .ssh/id_rsa", login], stdin =subprocess.PIPE, stdout=subprocess.PIPE, stderr=subprocess.PIPE, universal_newlines=True, bufsize=0)# Send ssh commands to stdinssh.stdin.write(add_pxy)for ip in whitelist_Ip: ssh.stdin.write(a
Hi, I’m looking to understand the possible values for group_member_attributes in the POST /v3/groups request. I’ve gotten some examples from debugging the Prism UI requests (e.g. “project_name”, “vm_name”), but is there a full list published somewhere? I’d looked in the API docs and had a search of the forum but couldn’t see group_member_attributes detailed - apologies if I’ve missed it. Thanks in advance.
Hi all, I tried to get the kubeconfig renewal made by Ansible with the use of the Karbon API. All is fine except for the format of the kubeconfig file. I have a lot of \n characters and some additionnal information. Is there a way of getting a correct kubeconfig file without all these or we have to clean the file in order to get it work ?For example, this is the content of the file : {"kube_config":"# -*- mode: yaml; -*-\n# vim: syntax=yaml\n#\napiVersion: v1\nkind: Config\nclusters:\n- name: xxxx-xxxx-xxxx-\n cluster:\n server: https://xx.xx.xx.xx:443\n certificate-authority-data: LS0tLS1CRUdS0tCk1JSURyVENDQXBXZ0F3SUJBZ0lVWkJuMkxpWG13aURvbWVxQU5wWmY3emxoaEpjd0RRWUpLb1pJaHZjTkFRRUwKQlFBd2JURUxNQWtHQTFVRUJoTUNQ2tOaGJHbG1iM0p1YVdFeEVUQVBCZ05WQkFjVApDRk5oYmlCS2IzTmxNUkF3RGdZRFZRUUtFd2RPZFhSaGJtbDRNUlV3RXdZRFZRUUxFd3hKYm1aeVlTQkxZWEppCmIyNHhEVEFMQmdOVkJBTVRCSEp2YjNRd0hoY05NakF3TmpJeU1Ea3dNVEF3V2hjTk16QXdOakl3TURrd01UQXcKV2pCdE1Rc3dDUVlEVlFRR0V3SlZVekVUTUJFR0ExVUVDQk1LUTJGc2FXWnZjbTV
Era is a database as a service (DBaaS) that automates and simplifies database administration, brings one-click simplicity and invisible operations to database provisioning and life-cycle management. Era enables database administrators to provision, clone, and refresh the database clones to any point in time. Era allows administrators to define standards for their database provisioning needs with end-state driven functionality that includes High Availability (HA) database deployments. Era automates and simplifies the operations such as provisioning of databases and copy data management.Era enables you to easily provision database environments (either production or otherwise) on your Nutanix clusters. Also, you can only provision the database server VM that hosts a database, so that you can later create or clone databases on that database server. Era provisioning service includes the following components: Database engines: Custom software images that are tailor-made to enterprise needs.
Objective:Create a virtual/physical separation between different kinds of CVM traffic. Each type of traffic can be on different vLANs (virtual) or a completely different physical switch. Different type of CVM traffic are:Management: Prism, SSH, Rsyslog, SNMP, PE-PC etc. Any communication that requires the default gateway. Backplane: Mainly CVM CVM communication that happens between cluster services. Host Host and Host CVM traffic also comes under this category. Service: This is a user defined traffic type where-in he can choose a particular AOS feature to be separated out of other traffic types. RDMA: This is a type of Service traffic but only limited to Stargate service.Solution Summary:The way to achieve these separations is by creating a new interface (vNIC) on CVMs for each traffic type. By default all the traffic types happen over management interface (eth0) and user can decide to segment other traffic types to new CVM interfaces one at a time. RDMA is a special segmentation ty
Can VMs keep uuid when migrated through Xi Leap and back to original cluster?
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.