• Some users have recently had their accounts hijacked. It seems that the now defunct EVGA forums might have compromised your password there and seems many are using the same PW here. We would suggest you UPDATE YOUR PASSWORD and TURN ON 2FA for your account here to further secure it. None of the compromised accounts had 2FA turned on.
    Once you have enabled 2FA, your account will be updated soon to show a badge, letting other members know that you use 2FA to protect your account. This should be beneficial for everyone that uses FSFT.

anyone playing with NSX yet?

shnelson

Limp Gawd
Joined
Feb 10, 2012
Messages
145
Something we're thinking about rolling out in our production environment, just got it running in the lab yesterday and it only took us a few hours to block ourselves out of vcenter with a deny any any rule...

Closest recovery I could find was a blog article indicating that you could invoke the NSX manager api to issue a sort of config reset, but it didn't really enlighten me on how.

I know some of you guys are on the bleeding edge of this technology, figured it would be worth a discussion here before I blew everything away and re-deployed.
 
I haven't had a chance to even crack it open yet. Lately it seems I barely have enough time to shave. (or so my wife says) :D Subscribing to this thread.
 
Well, we're back in business after finding an engineer on our staff with REST api experience. The blog article used as reference is here: http://telecomoccasionally.wordpres...g-from-distributed-firewall-vcenter-lock-out/

The deployment has been less than smooth for us so far, it almost feels like an unfinished product with poor documentation. Don't want that to be my final verdict though, much of this is likely user error.
 
Dot - I've done a ton with it.

Never, EVER, have NSX manage the hosts that VC is on. For NSX, you ~must~ have a management cluster - it's a requirement, as that's where the 3 controllers will go, and they ~cannot~ be on managed hosts (bad things will happen).
 
Dot - I've done a ton with it.

Never, EVER, have NSX manage the hosts that VC is on. For NSX, you ~must~ have a management cluster - it's a requirement, as that's where the 3 controllers will go, and they ~cannot~ be on managed hosts (bad things will happen).

Just so I understand this correctly. You will have your VM cluster with VC and then your management cluster that will just be standalone ESXi installs?
 
Just so I understand this correctly. You will have your VM cluster with VC and then your management cluster that will just be standalone ESXi installs?

Nah - have a (minimum) 3 node cluster with VC, SRM, other management stuff on it, and the 3 NSX controllers. Then have a Payload cluster that's your actual real workloads.
 
Nah - have a (minimum) 3 node cluster with VC, SRM, other management stuff on it, and the 3 NSX controllers. Then have a Payload cluster that's your actual real workloads.

I'm confused, your previous post mentions not to put the 3 NSX controllers on managed hosts or problems arise. A 3 node cluster to me = 3 managed hosts does it not? Just looking for clarification.

Our production environments are managed by physical VC blades, I had to "make due with what I have" in the lab & host the virtual center VM in the same cluster as NSX.


This is going to be a pretty complex implementation for our team. We're forced to move away from a current solution due to no support beyond 5.1, NSX is a bit over-spec'ed for our requirements but it's the only solution that continues to do what we require (mostly VM based firewall rules without getting into too much detail). Have you seen any successful implementations of NSX in a dual virtual center environment (VI & VDI)? Does the same NSX manager handle both?
 
Not on NSX managed hosts. You want the NSX controllers on plain-old VC managed, no-NSX networking hosts. Good ol vSwitch or DVS with no vwires.

Effectively, don't try to put the NSX controllers inside the things they're managing and working on and you'll be fine.

You'd need 2 NSX managers for 2 VCs right now.
 
Ah, thanks for the clarification - makes sense now!

You've also dodged the dual VC environment question in the same fashion as our local reps - I hope this is on the roadmap for sooner than later :).


I may have many questions for you, but still have much to wrap my head around first!
 
I would like to play with NSX but the price is "too expensive."

Once everything is running on ESXi.Next with the better vCenter service "distribution" I may attempt to play with NSX again.

Nick
 
Back
Top