This forum is the best way to get up and running with the Nutanix platform
Recently active
Security PoliciesTraditional data centers use firewalls to implement security checks at the perimeter—the points at which traffic enters and leaves the data center network. Such perimeter firewalls are effective at protecting the network from external threats. However, they offer no protection against threats that originate from within the data center and spread laterally, from one compromised machine to another.The problem is compounded by virtualized workloads changing their network configurations and hosts as they start, stop, and migrate frequently. For example, IP addresses and MAC addresses can change as applications are shut down on one host and started on another. Manual enforcement of security policies through traditional firewalls, which rely on network configurations to inspect traffic, cannot keep up with these frequent changes and are error-prone.Network-centric security policies also require the involvement of network security teams that have intimate knowledge of network
Does anyone facing Storage performance issues on Hyper converged infra for VDI environment.
Hi all,I have a small question.For the pre-installed AHV nodes with CVM, could we able to upgrade only AOS version before creating cluster? Because the AHV version already same version as our desired version, but AOS version is not same. I know the way to re-install AHV and AOS by Foundation VM, but the way takes long time. Therefore I' d like to update for only AOS if we can.In the other hands, we can upgrade AOS from Prism UI so I will able to upgrade AOS after creating a cluster. So this question is just for my reference.My environment is belowAOS : 5.15.2 (want to upgrade to 5.15.5)AHV : 20170830.434
Hi,I would need some guidance on enabling Aide on AHV and CVM and strong password policy for the hardening.I found the guide on this link: Hardening Controller VMIf I enable the AIDE on AHV and CVM. Is there anything need to be done? Additional appliance to deploy?
Hi all,I´m attempting to create one image from a disk stored inside a volume group.While I have succesfully tested image creation for standard disks using acli and api I didn´t find how to repeat the same task for disk stored inside Volume Group.As well documented here and in ther KB articles these sample commands works:ACLIacli image.create image-name container=default-container-nnnn source_url=nfs://127.0.0.1/default-container-nnnn/.acropolis/vmdisk/uuid image_type=kDiskImageAPI with curlcurl -X POST --header 'Content-Type: application/json' --header 'Accept: application/json' -d '{ "annotation": "cloned disk image", "image_type": "DISK_IMAGE", "name": "image-name", "vm_disk_clone_spec": { "disk_address": { "vmdisk_uuid": "UUID" }, "storage_container_uuid": "UUID" }}' 'https://PE-IP-ADDRESS:9440/PrismGateway/services/rest/v2.0/images/'But when I try to use the disk uuid of the disk inside a VG the commands fails both from ACLI than API.Any suggestion/workaround?Tha
We are considering AHV for our environment. I notice that the OEM partner product list https://www.nutanix.com/partners/oem has fixed set of disks. Most of the hardware in the list are capable to be installed with more disks. For example Fujitsu servers are capable of 12 x 3.5 + 4 x 2.5 (on the rear),Can we utilize all disk slots in a configuration like 12 x 4TB NL-SAS + 4 x 1.92TB 2.5” SSD or 4 x 1.6TB NvME ?
Is there anyway I could get all the task or activity of a particular VM?
Hey all -We removed 2 nodes from 1 cluster and want to add them to another. We disconnected from vCenter and then removed them from the cluster using PE. When they were relocated to the new location, the vlan is the same and they could keep their same IP addresses, but the new cluster could not see them. It sounds like the customer had configured Distributed switches on the old cluster. Do I need to undo some of that networking to see the hosts? Would bare metal foundation be a better option and put AHV on the nodes? That is our next route, but I still think there is a problem with the network configured in ESX even for that. Is there any documentation around undoing the vmware networking for bare metal? With factory nodes, I would have just added them to the same vlan and assigned IPs using crashcart and then the cluster should have seen them. Help!
Flash Mode is a great feature ensuring that VM workloads remain within the flash (SSD) tier of storage. Once flash mode is enabled for a virtual machine, all of the disks associated with that VM (including any future created disks) automatically get added to the flash tier.However, sometimes having so many disks within the flash tier can cause performance degradation for other VMs that are not configured for flash mode (but could benefit from using the flash tier of storage) or can cause the available flash tier space to be consumed too quickly. Further, it is sometimes not desirable to have all of the disks associated with a virtual machine contained within the flash tier.Accordingly and, though not available as a Prism Web user-interface (UI) modifiable option, individual VM disks can be configured to not use the flash tier even while the VM itself is configured for Flash Mode. The procedure for removing individual VM disks from the flash tier involves using the Acropolis Command-Lin
When I try to run the Nutanix foundation applet, Java tells me that the file does not meet high or very high security requirements and that it is missing a certificate. I can’t add it to the site exception list because the file: protocol is not secure. Some guidance would be helpful.
Hi I deploy a 3 nodes cluster with ESXi 7.0 as the hypervisor successfully on AOS 5.15.3.But when I run the diagnostic.py to check the cluster performance. It always failed to boot the diagnostic VM. I tried 3 times and all is same. from the log, seems the CVM cannot reache the diagnostic VM when check the boot status.I login to vCenter and check that there is no IP address for this VM in the summary page. And I can login the diagnostic VM from the VM console, I can check the ip address which is 192.168.5.253, but I cannot ping 192.168.5.254 and 192.168.5.1. also cannot ping 192.168.5.253 from CVM.From this information, I think the CVM cannot reache the diagnostic VM and timeout, so the diagnostic.py will fail after timeout. Is there any idear for this test? I can run thie script successfully in ESXi 6.7.
Hello. i Have a 4 nodes Lenovo HX3320. When i want to install AOS it fails. Foundation 4.6AOS 5.15.4 I updated bmc firmware and reset it. But it didnt work.Can you help me with this problemhere is the log 2020-12-10 12:38:39,191Z DEBUG Setting state of <ImagingStepValidation(<NodeConfig(192.168.1.22) @e2d0>) @e5f0> from PENDING to RUNNING2020-12-10 12:38:39,197Z INFO Running <ImagingStepValidation(<NodeConfig(192.168.1.22) @e2d0>) @e5f0>2020-12-10 12:41:01,398Z DEBUG Cache HIT: key(<function common_validations at 0x03D71230>_()_{'global_config': <foundation.config_manager.GlobalConfig object at 0x054D0E90>})2020-12-10 12:41:01,405Z DEBUG Setting state of <ImagingStepValidation(<NodeConfig(192.168.1.22) @e2d0>) @e5f0> from RUNNING to FINISHED2020-12-10 12:41:01,410Z INFO Completed <ImagingStepValidation(<NodeConfig(192.168.1.22) @e2d0>) @e5f0>2020-12-10 12:41:01,415Z DEBUG Setting state of <GetNosVersion(<NodeConfig(192.1
I have 20 clusters under management of our Prism Central and would like to know the versions of NCC installed in each. Is there a way to singularly collect this info across all PE clusters? Perhaps in nCLI even?
This article contains IPMI commands for checking and setting interfaces to dedicated or shared mode. For example, after a BMC upgrade, the IPMI might not be accessible. So, you need to verify and change the interfaces to dedicated or shared mode. Note: To run ipmitool commands on an ESXI host, prefix all commands with a forward slash (/). Note: To run ipmitool commands from a remote system such as the CVM (Controller VM), add the "-I lanplus", "-H <IPMI IP>", "-U <username>" and "-P <password>" parameters to the ipmitool command. For example: nutanix@cvm$ ipmitool -I lanplus –H x.x.x.x –U ADMIN –P <password> <command> Quanta Platform Use these commands for an NX-3400 (Quanta) platform. All commands are executed dynamically and a restart is not required. Check the status. [root@host]# ipmitool raw 0x0c 0x02 0x01 0xff 0 0 An output similar to the following is displayed.1100 :00 - Shared port 1101 :01 - D
Hi,I am implementing a Nutanix Cluster with Lenovo HX5520, when I register the Prism in vCenter the process appears as completed but I cannot create virtual machines by Prism Element and when running the NCC I return communication errors with the vCenter is not stabilized. I did the communication test of the CVMs with the vCenter on ports 80 and 443 and the connection worked successfully. when checking by cli I see that the connection is ok, but it does not provide me with the settings of vcenter follows the difference from another implementation any idea what it might be?
Hello i have a 4 Lenovo HX 3320 nodes. I updated all bmc on this servers. When i am installing new aos throw Foundation 4.6 its fails with this error Hele is log 2020-12-10 12:38:39,191Z DEBUG Setting state of <ImagingStepValidation(<NodeConfig(192.168.1.22) @e2d0>) @e5f0> from PENDING to RUNNING2020-12-10 12:38:39,197Z INFO Running <ImagingStepValidation(<NodeConfig(192.168.1.22) @e2d0>) @e5f0>2020-12-10 12:41:01,398Z DEBUG Cache HIT: key(<function common_validations at 0x03D71230>_()_{'global_config': <foundation.config_manager.GlobalConfig object at 0x054D0E90>})2020-12-10 12:41:01,405Z DEBUG Setting state of <ImagingStepValidation(<NodeConfig(192.168.1.22) @e2d0>) @e5f0> from RUNNING to FINISHED2020-12-10 12:41:01,410Z INFO Completed <ImagingStepValidation(<NodeConfig(192.168.1.22) @e2d0>) @e5f0>2020-12-10 12:41:01,415Z DEBUG Setting state of <GetNosVersion(<NodeConfig(192.168.1.22) @e2d0>) @e550> from PENDIN
Many users are unaware that there are additional (beyond what is presented via the Prism user-interface) security parameters that can be employed on AHV hosts to increase the overall security of them. These security parameters are configured via Nutanix Command-Line Interface (NCLI) and include the following: Advanced Intrusion Detection Environment (AIDE) - a file and directory integrity checker High Strength Password Enforcement - configure the maximum and minimum number of characters the password must contain along with number of passwords retained in history to prevent repeated use Core Dumps - the recorded state of the working memory for a process is dumped to a file if the process ever crashes Login Banner - display a customized messages when user login to a node More information regarding these parameters, including the procedures to enable/disable them, can be found within the Hardening AHV section of the Nutanix Security Guide. Also to note, there are similar parameters
SAP helps customers migrate from traditional relational databases to their in-memory SAP HANA database to gain more agility in their business processes. Many SAP customers are searching for ways to deploy SAP HANA in an efficient, simple way that minimizes risk while preserving the benefits of an agile platform. Nutanix provides such an option. The native Nutanix hypervisor, AHV, and Nutanix enterprise cloud OS software are certified for production SAP HANA deployments. HCI for SAP HANA CertificationThe certification has two primary segments. 1. As the first step, a platform vendor (Nutanix, in this case) must validate their platform, which consists of a hypervisor and an HCI component.2. In a second step, the hardware OEM must certify a suggested configuration through some additional HCI-related tests. When both parts of the validation are complete, the solution is certified and listed in the HCI for SAP HANA category on the SAP website. The hardware OEM is then responsible for selli
Any modern environments consist of multiple layers each of which contains multiple components. There are switches and routers, firewalls, physical server, application servers, applications themselves and, of course, users. Each of the components has logs of more than one kind, location and severity. All the components interact with each other directly or indirectly. I am certain you have found yourself in a situation where to establish a root cause you had to inspect logs of more than one entity. Establishing a timeline of events is always easier when the sources of the events’ clocks are synchronised and are located in one central location. While the clocks are handled by the NTP the centralised logs location is a syslog server or in this case a remote syslog server implying that it is separate to the origination of the logs. In addition to the benefits already mentioned, remote syslog server allows to access logs for the systems that are already dead, decommissioned or replaced. Nuta
Use the Data Services IP method for external host connectivity to VGs. For backward compatibility, you can upgrade existing environments non disruptively and continue to use MPIO for load balancing and path resiliency. For security, use at least one-way CHAP. Leave ADS enabled. (Enabled is the default setting.) Use multiple disks rather than a single large disk for an application. Consider using a minimum of one disk per Nutanix node to distribute the workload across all nodes in a cluster. Multiple disks per Nutanix node may also improve an application’s performance. For performance-intensive environments, we recommend using between four and eight disks per CVM for a given workload. Use dedicated network interfaces for iSCSI traffic in your hosts. Place hosts that use Nutanix Volumes on the same subnet as the iSCSI data services IP. Use a single subnet (broadcast domain) for iSCSI traffic. Avoid routing between the client initiators and CVM targets. Receive-side sca
Hi, I have 2 Blocks (2 Nodes each) Cluster. I just added 2 DIMM Memory (2 x 32GB) in 1 of my Node. I put 2 memory on slot P1-DIMMC1 and P1-DIMMF1Before Adding DIMMAfterr Adding DIMMAfter that i ran NCC and shows warning like thisAlert from Nutanix ClusterAm i did something wrong with the steps by steps? Since in PRISM, total memory has been increased and i thought it’s just fine.
Nutanix Objects OverviewNutanix Objects™ (Objects) is a software-defined Object Store Service. This service is designed with an Amazon Web Services Simple Storage Service (AWS S3) compatible REST API interface capable of handling petabytes of unstructured and machine-generated data. Objects addresses storage-related use cases for backup, and long-term retention and data storage for your cloud-native applications by using standard S3 APIs. You no longer have to introduce an external, separately managed storage solution. Objects is deployed and managed as part of the Nutanix Enterprise Cloud OS.You can manage objects by using Prism Central or the S3-compatible REST APIs after an administrator has authorized the applications and users to access buckets accordingly.For more information on Objects architecture, refer to Nutanix Bible.Usage of ObjectsFollowing are examples of solutions you can implement by using Objects: Backup – You can integrate Objects with the backup applications such as
Hi everybody,I just found out that 531,82GB can be used from 960GB SSDs in a Nutanix cluster node. Using 1,92TB SSDs offer 1.22TB usable space.What about the 3,84TB SSDs. How much space can be used with these drives?ThanksDidi7
Pre-requiste for ESXI Upgrade Need to enable both HA, and DRS https://docs.vmware.com/en/VMware-vSphere/7.0/com.vmware.vsphere.avail.doc/GUID-1D8B1384-59A4-41E2-AF05-697FC06D9EF9.html When vSphere HA performs failover and restarts virtual machines on different hosts, its first priority is the immediate availability of all virtual machines. vSphere HA uses the virtual machine's CPU and memory reservation and overhead memory to determine if a host has enough spare capacity to accommodate the virtual machine. After the virtual machines have been restarted, those hosts on which they were powered on might be heavily loaded, while other hosts are comparatively lightly loaded.In a cluster using DRS and vSphere HA with admission control turned on, virtual machines might not be evacuated from hosts entering maintenance mode. You must manually migrate the virtual machines off of the hosts using vMotion. This behavior occurs because of the resources reserved for restarting virtual machines in th
Hello all, i have nutanix 3460 g7 4 nodes and also have disk and tape drives for backup and archival. to make it short is there any way that i can connect the disks and tape drives to the nodes so that i can make automatc backup and archival?
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.