Showing posts with label Windows. Show all posts
Showing posts with label Windows. Show all posts

Wednesday, March 11, 2015

Nesting Hyper-V with VMware ESXi 5.5

This weeks posting focuses on the setup of my home virtual lab.  I recently setup my home lab consisting of the following specs:
  • Supermicro X7DAL
    • 2 - Quad Core Intel Xeon E5440 @ 2.83 GHz (8 vCPUs)
    • 2 - NICs
    • 24 GB of RAM
    • 2 - 1 TB Hard drives
  • Evaluation version of ESXi 5.5
Most of my experience has been with VMWare so I choose this as my base system.  Now I wanted to learn more about Hyper-V and have read it could be nested within ESXi.  The following will guide you through configuring a ESXi 5.5 system to allow for nested Hyper-V usage.

In some places there are multiple ways to accomplish the same process through the vSphere client, CLI, or using a tool like WinSCP.  The end result is to modify the config files so how ever you feel comfortable.  I will be utilizing WinSCP to access the files and modify using a Windows text editor.  You can download WinSCP here: http://winscp.net/eng/index.php

  1. To start we need to ensure SSH access is enabled.  I configured mine through vSphere client but you could do this through local access also.
    • Launch vSphere and connect to ESXi system
    • Ensure your system is select in left navigation box
    • Click "Configuration" tab in right navigation box
    • Under software click "Security Profile"
    • Click "Properties" for "Services"
    • Select "SSH" and click "Options"
    • Select desired startup policy
      • I choose to automatically start
    • Click Okay until back at main vSphere page
  2. Now we need to modify our ESXi config file.  This file is located at /etc/vmware/config.
    • Launch WinSCP
    • Connect to your ESXi server through a SFTP connection
    • Navigate to root level and then to /etc/vmware/
    • Select config and Edit
    • Add the following
      • vhv.allow = “TRUE”
    • Save and close the editor
  3. Next we need to create the Hyper-V system profile, we will not be installing yet.
    • Go and create a new VM with specs you desire
      • I configured mine with following:
        • VM Hardware version 8
        • 4 vCPUs
        • 12 GB of RAM
        • 2 NICs
        • 40 GB Thin Hard drive
        • 100 GB Thin Hard drive
  4. Now we need to edit the VM Profile
    • In WinSCP navigate to VM location
      • /vmfs/volumes/[DateStore]/[VM Name]
    • Select [VM].vmx file and Edit
    • Add the following lines:
      • monitor.virtual_exec = "hardware"
      • hypervisor.cpuid.v0 = "FALSE"
    • Save and close the editor
  5. Before we install our OS we still need make some changes to our VM settings
    • Within vSphere access your VM's settings
    • Select "Options"
    • Enable CPU/MMU Virtualization for our VM
      • Under Advanced Select "CPU/MMU Virtualization"
      • Select "Use Intel VT-x/AMD-V for instruction set virtualization and Intel EPT/AMD RVI for MMU virtualization"
    • Expose CPUID to guest
      • Under Advanced Select "CPUID Mask"
      • Select "Expose the NX/XD flag to guest"
      • Click "Advanced"
      • Locate line ecx and modify to following:
        • ---- ---- ---- ---- ---- ---- --H- ----
      • Okay back to main vSphere window
  6. Finally we can install our Hyper-V OS
    • Proceed to install as normal and enjoy creating Hyper-V VMs within ESXi environment.

Following resources we used:

Monday, June 16, 2014

vSphere Client and Domain Controller

Recently in my new virtual lab I tried to install vSphere Client 5.5 on a MS Server 2012R2 Domain Controller.  To my dismay I got the following message:

"vSphere 5.5 Client cannot be installed on a domain controller"

I immediately hit Google to find a resolution.  It took about 20-30 minutes before I came across Sean LaBrie's blog "The Day to Day Findings of an IT Engineer"

In his post back on April 15, 2014 "Running into this error?" he had the same issue.

To resolve the issue you must run the installer with following switch: /VSKIP_OS_CHECKS="1"

So if you had saved the installer to your C:\ drive the command would look like this in RUN:

C:\VMware-viclient-all-5.5.x-xxxxxxx.exe /VSKIP_OS_CHECKS="1"

Once I ran the installation like this it went off without an issue.  Wanted to repost Sean's fix to help other find it quicker.

Friday, October 25, 2013

Microsoft Virtual Academy: PowerShell

Looking to learn more about Power Shell I stumbled across a link on SpiceWorks that lead me to Microsoft Virtual Academy. http://www.microsoftvirtualacademy.com/training-courses/getting-started-with-powershell-3-0-jump-start?o=3276#?fbid=aVs9FfAH2DJ

I have decided to complete and write a review of each module over the next 9 wks (1 module a week).

Starting Monday with Module 01 check back or head on over to MS site to sign up and complete your own.

Tuesday, October 8, 2013

Windows Service Account Report (Power Shell v2)

Well it has been busy.  After My two weeks away we let a group of users go which has lead to a whole new task of automating on boarding and off boarding users.  Still tweaking the scripts and will post them once I feel they are solid.  But here is a script that I pieced together in response to a post on SpiceWorks (see post here).

 Request was to pull Service Accounts from servers to see what account is running what.

Some quick searching had this resolved and then I wanted to export to file and offer up emailing the reports.

First step is setting up the source file.
On my servers I have the following structure: %root%\_scripts\source files

  • Create a text file in your source location, ensure it is a txt file
  • one server name per line
Copy the code below into a .ps1 file or you can download from my Google drive here
Update the fields highlighted in blue to meet your requirements. 

Hope this is helpful.
(If you find it helpful please head over to Spiceworks and Spice up the code to help other IT members find it: http://community.spiceworks.com/scripts/show/2212-service-account-report)

# +-----------------------------------------------------------------------------------
# | File : Service Account Report.ps1                                          
# | Version : 1.01                                          
# | Purpose : Pulls Service Accounts from list of servers
# |           Saves to individual CSV files
# |           Can Email reports
# |           Can remove reports before script exits
# +-----------------------------------------------------------------------------------
# | Maintenance History                                            
# | -------------------                                            
# | Name            Date        Version  C/R  Description        
# | ----------------------------------------------------------------------------------
# | Chris Lee     2013-10-08     1.01         Initial scirpt build
# +-----------------------------------------------------------------------------------


###SETUP START###
#-------DO NOT MODIFY-------#
#Add Exchange 2007 commandlets (if not added)
if(!(Get-PSSnapin | Where-Object {$_.name -eq "Microsoft.Exchange.Management.PowerShell.Admin"})) {ADD-PSSnapin Microsoft.Exchange.Management.PowerShell.Admin}
#Add Quest commandlets (if not added)
if(!(Get-PSSnapin | Where-Object {$_.name -eq "Quest.Activeroles.ADManagement"})) {ADD-PSSnapin Quest.Activeroles.ADManagement}
#Defines Time/Date Stamp used
$CreateStamp = Get-Date -UFormat %d_%m_%Y
###SETUP END###

###USER VARIABLES START###
#-------MODIFY AS NEEDED-------#
#Define path to server list to be used
    $path = "[PATHTOYOURSERVERLISTTEXTDOCUMENT]"
#Define path to temp/report folder include trailing \
    $temppath = "[PATHTOYOURTEMPFOLDER]"
#Email reports to admin "True" | "False"
    $email = "True"
#Delete files after script runs "True" | "False"
    $delete = "True"
#Enter System Admin
    $AdminName="[YOURADMINNAME]"
#Enter Admin Email Address
    $to="[YOURADMIN]@[YOURDOMAIN].com"
# SMTP Server to be used
    $smtp = "[YOURSMTP]"
# "From" address of the email
    $from = "ServerReports@[YOURDOMAIN].com"
#Enter Path to reports
    $file="C:\_temp\"
# Define font and font size
# ` or \ is an escape character in powershell
    $font = "<font size=`"3`" face=`"Calibri`">"
###USER VARIABLES START###

###PROGRAM VARIABLES START###
#-------DO NOT MODIFY-------#
# Get today's day, date and time
$today = (Get-date)
# Newline character
$newline = "<br>"
#Enter Subject line required for ticketing system
$subject="Service Accounts Report for " + $domain + " servers."
#Section break
$secbreak="`r`n---------------------------------------------------------------------------------------------------------------------------`r`n"
#Pull Domain information for email
$Domain = ([adsi]'').distinguishedname -replace "DC=","" -replace ",","."
###PROGRAM VARIABLES END###

###PROGRAM START###
#Loads Server list into varialbe
$a = Get-Content $path
#Declare string for report structure
$attachment = @()
#Generates CSV file with service account information for each server
foreach ($i in $a)
{ 
  Get-WmiObject win32_service -computer $i | select name, startname, startmode | Export-csv "$temppath$i.csv" -notype
  $attachment += "$temppath$i.csv"
}

#Check if email of files is desired
IF ($email -eq "True")
    {
        # Message body is in HTML font          
        $body = $font
        $body += "Dear " + $AdminName + ","+ $newline + $newline
        $body += "Attached are report(s) for service accounts on" + $domain + " servers ." + $newline 

        # Put a timestamp on the email
        $body += $newline + $newline + $newline + $newline
        $body += "<h5>Message generated on: " + $today + ".</h5>"
        $body += "</font>"

        # Invokes the Send-MailMessage function to send notification email
        Send-MailMessage -smtpServer $smtp -from $from -to $to -subject $subject -BodyAsHtml $body -Attachments $attachment
     }

#Check if removal of files is desired
IF ($delete -eq "True")
  {
    #Removes created file
    foreach ($i in $a) 
      {
        Remove-Item "c:\_temp\$i.csv" -Recurse
      }
  }

###PROGRAM END###

Monday, September 9, 2013

Server 2008: Rename Your Active Directory Domain

Server 2008: Rename Your Active Directory NetBios Name

Recently began setting up my own personal production and test networks on my personal VM host (VMware Esxi 5.1).  I had purchased a domain from GoDaddy and planed on using "internal.domain.com".

Shortly after setting up the first Domain Controller realized I need to change my NetBois to allow login as domain\user instead of internal\user.

Some quick Google searching provided the following resource:
http://www.trainsignal.com/blog/rename-active-directory-domain

Step 1: Access Domain Controller

Step 2: Open a command prompt

  • Start > Run > cmd
Step 3: Generate Domainlist.xml
  • From command prompt enter "rendom /list"
    • 2008R2 directory: C:\users\[logged in user]
Step 4: View list.xml file
  • From command prompt enter "type domainlist.xml"
Step 5: Edit Domainlist to correct NetBios name
  • Browse to file location
    • 2008R2 directory: C:\users\[logged in user]
  • Right-click and select edit (use favorite text editor if prompted)
  • Locate <!--ForestRoot -->
  • Change NetBiosName value from current (internal) to desired (domain)
    • Note I only wanted to change login from internal\user to domain\user if you wish to change domain completely update all instances of old value to new desired value.
Step 6: Verify desired changes
  • From command prompt enter "rendom /showforest"
  • Verify results
    • For domain login ensure FlatName is what you want
    • For entire rename ensure correct values for all fields
Step 7: Upload changes

  • From command prompt enter "rendom /upload"
Step 8: Prepare domain controller for update
  • From command prompt enter "rendom /prepare"
    • Best practice is to ensure all domain controllers have firewall off for remainder of operation
Step 9: Execute domain update
  • From command prompt enter "rendom /execute"
    • Verify no errors on results if so resolve before continuing (issue I ran into was firewall issues)
    • Note Domain Controllers may begin restarting. 
      • (Al-Dabbas stated his did, my experience they did not)
At this point I was able to logoff then back on as domain\user with now issues.  As I had just created the domain I did not need to continue past Step 6 of TrainSignal Blog their remaining steps walk you through updating any previous GPOs that were created.


Friday, August 9, 2013

Enable Remote Desktop (RDP) Remotely

Credit goes out to RAM. (http://community.spiceworks.com/profile/show/RAM.) on SpiceWorks for this hand tidbit.

Found nice How-To on Spiceworks written by RAM (can be found here: http://bit.ly/17vxPcK)

Problem: Remote Desktop Connection Error: This computer can't connect to the remote computer.

Possible Solution:


  • Luanch Regedit and connect to remote system
    • Start > Run > Regedit
    • Minimize Computer Tree (helps keepo things neat)
      • Click little arrow next to Computer
    • File > Connect Network Registry
      • Enter or search for target system name
      • Click OK
  • Modify fDenyTSConnections to 0
    • Under Target System name expand tree
    • Navigate: Find HKEY_LOCAL_MACHINE > SYSTEM > CurrentControlSet > Control > Terminal Server > fDenyTSConnections
    • Right-Click > Modify
    • Change value to 0 > OK
Results will very on different system have tested on WinXP and Win7 (Logged in to my system as an Admin / privileged user)