Using vSphere Auto Deploy to configure a Stateless ESXi image for VMware vCloud Networking and Security 5.1.x and 5.5.x (2036701)
VMware vCloud Networking and Security 5.1.x/5.5.x provides vShield App and vShield Endpoint VIBs that can be applied to an ESXi boot image using Image Builder. This article documents how to access these VIBs, apply it to the boot image, and set up Auto Deploy. In addition, any pre/post deployment steps required to provision a fully functional stack capable of running vCloud Networking and Security 5.1.x/5.5.x solutions are also explained.
Auto Deploy can be configured to bring up a Stateless ESXi host with a certain image profile and host profile. For example, when using Image Builder, you can use Auto Deploy to bring up all hosts in a cluster with the base image profile (ESX-Base) and host profile (Host-Base) automatically.
To configure this you will need go to the vCloud Networking and Security install page on any host. You should be presented with an option to install the vShield App. Select Install VSA and configure the appropriate parameters. You can then choose to install on all hosts at this point.
Note: Before proceeding consult the product system requirements to validate the version of vShield Manager you are using to manage the vShield App, and vShield Endpoint components. For more information see Installing vCloud Networking and Security 5.1 best practices (2034173). In addition, the vShield App installation includes both vShield App and vShield Endpoint components.
Configuring a Stateless ESXi Image for vCloud Networking and Security 5.1.x/5.5.x
- Use the Stateless ESXi on which we successfully installed vShield App above to create a new Host Profile called Host-VSA for our example.
- Ensure your firewall is configured properly. vCenter Server at times might not be fast enough to pick the firewall configuration changes done on the host by the VIB. Before using the host to create a new host profile verify that the firewall changes are reflected on vCenter Server and ESXi. Go to ESX configuration > Security Profile > Firewall > Incoming Connections, and ensure an entry for DVfilter is visible. If it is not visible, click Refresh to pull the latest configurations from the host.
- Locate the VIBs for vCloud Networking and Security depending on the version you are using on the vShield Manager server. It should be named similar to VMware-vShield-fastpath-2.0.0-XXXXXX.zip, where XXXXXX is the file name of the build number. This file is the offline-bundle for the VSA module and is located on your vShield Manager server. For example:
Note: After a successful vShield App installation when an ESXi host reboots the first time, it may come up with the vShield App SVM in an orphaned state. In this case reboot the ESXi host again, and the vShield App virtual machine will show the correct state.
- Use Image Builder to incorporate VMware-vShield-fastpath-2.0.0-XXXXXX.zip into the ESX-Base image, resulting in a new Image Profile called ESX-VSA.
- Create/Update a deploy rule to use ESX-VSA and Host-VSA as the profiles to provision Stateless ESXi hosts.
- Whenever existing Stateless ESXi hosts reboot, they will come up with the right VIB and configuration, and should work transparently.
Note: If different ESXi hosts use different Image Profile and Host Profiles, you would need to update all of them, basically repeat the above steps for each set of profiles.
Installing vShield App on a new Stateless ESXi host
This assumes that the above steps have already been followed, and new ESXi host are already using ESX-VSA and Host-VSA profiles.
- Go to vShield Manager install page for the new host. You should see that vShield Apps is already installed.
- Select uninstall, and let it complete. vShield Manager may report an error indicating that the VIB uninstallation encountered issues. This error can be safely ignored.
- In the installation page, select the option to install vShield App.
Note: Before selecting the install option, ensure that the host is not in Maintenance Mode.
- Select Install VSA, configure the parameters, and proceed with the installation. The installation should now be successful.
Note: Since this host is already using ESX-VSA and Host-VSA profiles, no more steps are required to handle a reboot.
Uninstalling vShield App on a Stateless ESXi host
- Create/update deploy rules to use ESX-Base and Host-Base as profiles to provision Stateless ESXi.
- Go to vShield Manager and uninstall vShield App from all the hosts. vShield Manager may report an error indicating that the VIB uninstallation encountered issues. This error can be safely ignored.
- Reboot your ESXi hosts to remove the VIB and host configuration (this is optional).
Note: If you want to uninstall vShield App only from selected hosts, do not change the deploy rules. Uninstalling from vShield Manager is sufficient.
For more information on using vSphere Auto Deploy, see Understanding vSphere Auto Deploy (2005131).
- Using vSphere Auto Deploy to configure a Stateless ESXi image for VMware vCloud Networking and Security 5.1.x and 5.5.x (2036701)