• Some users have recently had their accounts hijacked. It seems that the now defunct EVGA forums might have compromised your password there and seems many are using the same PW here. We would suggest you UPDATE YOUR PASSWORD and TURN ON 2FA for your account here to further secure it. None of the compromised accounts had 2FA turned on.
    Once you have enabled 2FA, your account will be updated soon to show a badge, letting other members know that you use 2FA to protect your account. This should be beneficial for everyone that uses FSFT.

Single server - multipurpose

dbxuau

n00b
Joined
Apr 26, 2007
Messages
54
I am looking for insight into my situation with respect to the best approach for virtualization, or if its even needed. Currently at the office I work at, we have a single HP proliant server running a xeon 5504 and 8 gb of ram + a couple raid arrays. 2008 R2 is the OS. What we use it for is active directory to manage the other 10 employee desktops, file storage, Sage ACT! customer database hosting with sql, Office products like outlook, and another client-server quoting software. We have 3 other people out of state who sign in via remote desktop hosting so they can have a desktop to function above said software.

I'd like to know what I can do to make this setup more efficient, as it seems a bit crude, especially with having people out of the area signing in to remote desktop sessions. The way I see it, this is the traditional server setup that is a has-been. I have played with a few of the vmware products such as vmware server, esxi free, vmware player etc and have felt my way around pretty good so far but am lost as to implement "virtualization" into a company profile like ours. Thanks for any tips, cheers.
 
The problem that exists for you right now is that your server is doing all these things and to do that kind of migration your going to need some sort of medium to migrate data over to so you have no loss of data, with AD will be your biggest headache especially if u setup anything beyond the normal AD stuff like Exchange or other email programs that integrate with their accounts. for SQL and File Storage its all dependent but u would have to migrate in a ways to get that off the storage to even get this box ready for any form of Virtualization. the remote in makes the server unsecure and it can be very dangerous to have standard users logging into your DC. i mean in general i would split this out but its a tad omplex where u are right now.

I mean its doable but keep in mind that there is potential loss of data at hand for a company data is important.
 
If I were you I would P2V the current server and put the exported VM on an external hard drive. Rebuild your RAID for RAID 5 with 1 hot spare.

Then install your Hypervisor OS (Hyper-V or ESXi). If you decide to go Hyper-V just install directly to the array, if you go ESX install to a SD card or USB stick.

Import your current AD machine.

Build 4 new machines.

AD02
AP01
FSP01
TS01

Migrate all your file and printer shares to FSP01.

Migrate all your applications to AP01

Have all your outside people log into TS01.

Migrate all AD Roles to AD02.

Finally delete your P2V machine, and install server 2008 r2 on a spare desktop or laptop in the office. Call it AD01 and make it the primary domain controller, DNS, DHCP etc. Hang a couple eSATA 2TB disks off this physical box, and install Veeam or Acronis Virtual Edition for backups.

Now you have a dedicated file and print server, a dedicated app server, a dedicated terminal server, a virtual AD, and a physical one (good for redundancy) and a solid backup plan for your whole environment. You will find that doing things this way will bring some improvements to the network, but the big thing is now management. You don't have normal applications running on an AD server, you can break up apps if needed (say ACT! and Timberline couldn't run on the same server you now have somewhere else you can put them).
 
I agree with C7J0yc3. Use Hyper-V and do something similar to his suggestion.

Hey C7J0yc3, how many OS licenses min can he get away with. I believe Server 2008 Hyper-V R2 was free, am I correct?
 
I agree with C7J0yc3. Use Hyper-V and do something similar to his suggestion.

Hey C7J0yc3, how many OS licenses min can he get away with. I believe Server 2008 Hyper-V R2 was free, am I correct?

No matter what you do (ESX or HyperV) You are going to need a minimum of a Server 2008 R2 Enterprise license for your hypervisor (Host OS +4 guests). If you are planning to expand this server out like crazy, you may want to consider a 2 socket datacenter license which will allow for unlimited VMs.

You will also need another 2008 R2 Standard License for your stand alone machine if you decide to do that.

Standard Licenses are going to be about $700 ea
Enterprise Licenses are about $2,500
A 2 CPU Datacenter License will be about $3,200.

You will also need to factor in the cost of TS and AD cals. Unless you purchased software assurance on your 2003 CALs you will need to buy new ones (OS comes with 10, a pack of 5 is something like $130). Then you will need to buy 1 TS cal for every user that uses the TS (they come in packs of 5, and are about $50 each, just buy what you are going to use in this case).

If you decide to go VMware you can use the free version (however against the EULA for a production server in a business environment), but I would recommend an essentials license ($500) or an Essentials plus license ($4500) depending on how much you plan to grow into a virtual environment.
 
Gdamn, is there any other options to do this without going bankrupt haha? It seems like I need to duplicate my hardware and software OS licenses just to redo all of this. I figure if its working fine at the moment I better not touch it. I really do appreciate the input all of you have given so far, it surely is an eye opener as to what is involved.
 
Technet is for testing software, not for an office/prod environment...

Now Action Pack would work well for this.

Action Pack is pretty limited, and unless you need the Win7, and office licenses too, you would be better off just buying the software, not to mention I don't pay an annual fee (unless you SPLA the license, and that is a different matter all together).

OP: Technically you don't need to buy any new hardware, you just buy software. If you decide not to go with a dual server setup (Which you could, no problem, you just loose your physical AD, so if your hypervisor goes down, you are stuck) you would just be buying the 2008 R2 Enterprise License and then a ESXi license if you decide to go that way, or just the windows license if you go hyper v.

Lets say you have 15 users total, and you were a good legal boy and bought 15 AD CALs already. Because your current server is 2008 R2, you do not need AD CALs. So to make my setup work (with dual boxes)

Purchase 16GB kit of RAM for 24GB in your Hypervisor $260
Purchase 2008 R2 Datacenter License $3,200
Purchase 5 pack TS CAL for remote users $250
Purchase ESXi Essentials $500 + $65 1 year production support (free upgrades).
Redeploy Current 2008 R2 Standard License on another piece of hardware (can be that old Pentium D desktop you have sitting in your cube, doesn't need to be crazy, just 64bit).
Total cost $4,275. To do a full virtualization, that is really pretty cheap, not to mention if you decide to throw up a new server for a new application you just do so, no new hardware costs, no new licensing costs, pay once, and you are done.
 
C7Joyce I really appreciate your input. That seems like a feasible and reachable budget number. When I get back from work I will respond on here with a few more questions. Feel free to keep posting ideas people, peace out.
 
Curious question, Couldn't I load up ESXi on the server along with Server 2008 R2 as a VM. As separate VM's I could load up windows 7 instances that are attached to the domain VM and use RDP for those people out of state to patch into the win7 vm's? That sounds like a cheaper alternative. Any input? perhaps my idea is crazy lol.
 
Curious question, Couldn't I load up ESXi on the server along with Server 2008 R2 as a VM. As separate VM's I could load up windows 7 instances that are attached to the domain VM and use RDP for those people out of state to patch into the win7 vm's? That sounds like a cheaper alternative. Any input? perhaps my idea is crazy lol.

If you are talking about doing that many VM's I would do a datacenter license of Windows 2008R2 and let them remote into those.
 
If you are talking about doing that many VM's I would do a datacenter license of Windows 2008R2 and let them remote into those.

2008 R2 Licensing doesn't cover Windows 7. Should you buy Datacenter you get access to

2008 R2
-Datacenter
-Enterprise
-Standard

2008
-Datacenter
-Enterprise
-Standard

2003 R2
-Datacenter
-Enterprise
-Standard

2003
-Datacenter
-Enterprise
-Standard

http://www.microsoft.com/windowsserver2008/en/us/licensing-datacenter.aspx

If you are using single Windows 7 Pro VMs instead of a TS, that's fine, you could do that, however that's going to be $140 a VM for each Windows 7 license (Windows 7 has no virtualization licensing).

As far as P2Ving your current 2008 R2 server you can absolutely do that (and was my first step in suggested conversion) but again if you want more 2008 R2 servers you need to buy the appropriate licensing.
 
Lets pretend I just want to use Hyper-V inside the server 2008 r2 standard box that I currently have running. For the sake of experimenting, is the following order correct?

1. install the Hyper-V role
2. create new vm + install windows 7 from dvd onto it
3. attach that vm's os to the domain
??? is it that easy?

Next question would be, how do I access that vm if im out of the network? Currently RDP works with the main server OS as it has been for years. We have 5 CAL's purchased. I have the WAN DNS pointed to our zzz.company.com which is port forwarded to 3389 on the server. What do I have to setup for accessing the vm windows 7? Thank you a ton!
 
Guest VMs will behave just like other machines on your internal network, you can access them the same way. As long as you can log into one machine, you can RDP into any VM from there. But forwarding 3389 to your server for RDP is a bad idea, use a VPN instead or a Remote Desktop Gateway (HTTPS). If you must use RDP through NAT you can set up a rule to use a different WAN port to forward traffic to another internal IP on port 3389.

Example external-IP:3390 NAT to 192.168.0.2:3389

Also, vSphere > Hyper-V
 
Last edited:
2008 R2 Licensing doesn't cover Windows 7. Should you buy Datacenter you get access to

2008 R2
-Datacenter
-Enterprise
-Standard

2008
-Datacenter
-Enterprise
-Standard

2003 R2
-Datacenter
-Enterprise
-Standard

2003
-Datacenter
-Enterprise
-Standard

http://www.microsoft.com/windowsserver2008/en/us/licensing-datacenter.aspx

If you are using single Windows 7 Pro VMs instead of a TS, that's fine, you could do that, however that's going to be $140 a VM for each Windows 7 license (Windows 7 has no virtualization licensing).

As far as P2Ving your current 2008 R2 server you can absolutely do that (and was my first step in suggested conversion) but again if you want more 2008 R2 servers you need to buy the appropriate licensing.

You are correct but Windows 2008 R2 can be made to look like Windows 7 or you could just let them use the OS as is.
 
@shiznit, when you say once you log into the machine, i can connect to any vm from there... how exactly? Im not clear on how that works.

@riddlerthc, what would you do in my situation? Keep using the server as a TS server too?
 
Lets pretend I just want to use Hyper-V inside the server 2008 r2 standard box that I currently have running. For the sake of experimenting, is the following order correct?

1. install the Hyper-V role
2. create new vm + install windows 7 from dvd onto it
3. attach that vm's os to the domain
??? is it that easy?

Yes it is that easy.

Next question would be, how do I access that vm if im out of the network? Currently RDP works with the main server OS as it has been for years. We have 5 CAL's purchased. I have the WAN DNS pointed to our zzz.company.com which is port forwarded to 3389 on the server. What do I have to setup for accessing the vm windows 7? Thank you a ton!

First off you should never NAT RDP for a server directly to the outside. There are many exploits for Microsoft RDP.

If you were to have 3 windows 7 boxes your best approach would be to setup a VPN and have users connect to that. Once the user has connected to the VPN then they connect to their windows 7 desktop through remote desktop.

@RiDDLeRThC I understand that you can make 2008 R2 look like 7 using the Desktop Experience Pack, however wanted to make sure that OP understood that if he buys a DC license it doesn't come with actual Win 7 licenses if he wanted to run actual Win 7 instead of a TS that looks like Win 7.
 
I am curious how "Remote Desktop Virtualization Host " fits in to all of this. So far its been left uninstalled since it appears to be useless so far. I just successfully RDP'd into my vm, woot. Are there any other tips for having vm's connected to the domain through hyper-v?
 
@shiznit, when you say once you log into the machine, i can connect to any vm from there... how exactly? Im not clear on how that works.

@riddlerthc, what would you do in my situation? Keep using the server as a TS server too?
Your VMs will have NICs and IP addresses just like any other machine, you just RDP to the IP address or host name of a VM and log in.

I'm not sure what you mean when you say "server", are you referring to the physical computer you are using? Forget about the NAT straight to a server for RDP. If your windows password ever gets compromised someone will have access to your internal network and if you are running the Hyper-V role on the same server you RDP into, they will have control of the host machine of all your VMs.

My suggestion:

Download vSphere 4.1 evaluation (and use the free license after 60 days)
Buy a vSphere book
use ESXi as your hypervisor
for each role use a separate 2008 R2 VM (assuming you are buying Datacenter Edition)
set up a pfSense or Astaro VM (the already have one-file virtual appliances for ESXi) and only use VPN to connect to your internal network
 
Last edited:
I am curious how "Remote Desktop Virtualization Host " fits in to all of this. So far its been left uninstalled since it appears to be useless so far. I just successfully RDP'd into my vm, woot. Are there any other tips for having vm's connected to the domain through hyper-v?

RDVH is used for VDI. It serves as a session broker for users, as well as supporting RemoteFX features for Hyper-V guests.

You don't need it.

As far as your VMs are concerned, no there isn't anything else you need to do. Just drop em in, give em an IP, and let em free. It really is that easy.
 
Back
Top