ESX_Configuration_Guide.pdf

(2603 KB) Pobierz
ESX ConfigurationGuide ESX 4.1
ESX Configuration Guide
ESX 4.1
vCenter Server 4.1
This document supports the version of each product listed and
supports all subsequent versions until the document is replaced
by a new edition. To check for more recent editions of this
EN-000328-02
703789465.001.png
ESX Configuration Guide
You can find the most up-to-date technical documentation on the VMware Web site at:
The VMware Web site also provides the latest product updates.
If you have comments about this documentation, submit your feedback to:
Copyright © 2009–2011 VMware, Inc. All rights reserved. This product is protected by U.S. and international copyright and
intellectual property laws. VMware products are covered by one or more patents listed at
VMware is a registered trademark or trademark of VMware, Inc. in the United States and/or other jurisdictions. All other marks
and names mentioned herein may be trademarks of their respective companies.
VMware, Inc.
3401 Hillview Ave.
Palo Alto, CA 94304
www.vmware.com
2
VMware, Inc.
Contents
Updated Information 7
About This Book 9
1 Introduction to ESX Configuration 11
Networking
2 Introduction to Networking 15
Networking Concepts Overview 15
Network Services 16
View Networking Information in the vSphere Client 17
View Network Adapter Information in the vSphere Client 17
3 Basic Networking with vNetwork Standard Switches 19
vNetwork Standard Switches 19
Port Groups 20
Port Group Configuration for Virtual Machines 20
VMkernel Networking Configuration 21
Service Console Configuration 23
vNetwork Standard Switch Properties 26
4 Basic Networking with vNetwork Distributed Switches 29
vNetwork Distributed Switch Architecture 30
Configuring a vNetwork Distributed Switch 31
dvPort Groups 34
dvPorts 35
Private VLANs 36
Configuring vNetwork Distributed Switch Network Adapters 38
Configuring Virtual Machine Networking on a vNetwork Distributed Switch 42
Network I/O Control 43
5 Advanced Networking 45
Internet Protocol Version 6 45
VLAN Configuration 46
Networking Policies 46
Change the DNS and Routing Configuration 62
MAC Addresses 63
TCP Segmentation Offload and Jumbo Frames 64
NetQueue and Networking Performance 67
VMDirectPath I/O 68
VMware, Inc.
3
ESX Configuration Guide
6 Networking Best Practices, Scenarios, and Troubleshooting 69
Networking Best Practices 69
Mounting NFS Volumes 70
Networking Configuration for Software iSCSI and Dependent Hardware iSCSI 71
Configuring Networking on Blade Servers 74
Troubleshooting 76
Storage
7 Introduction to Storage 81
About ESX Storage 81
Types of Physical Storage 82
Supported Storage Adapters 83
Target and Device Representations 83
About ESX Datastores 85
Comparing Types of Storage 88
Displaying Storage Adapters 89
Viewing Storage Devices 90
Displaying Datastores 91
8 Configuring ESX Storage 93
Local SCSI Storage 93
Fibre Channel Storage 94
iSCSI Storage 94
Datastore Refresh and Storage Rescan Operations 108
Create VMFS Datastores 109
Network Attached Storage 110
Creating a Diagnostic Partition 112
9 Managing Storage 115
Managing Datastores 115
Changing VMFS Datastore Properties 117
Managing Duplicate VMFS Datastores 119
Using Multipathing with ESX 121
Storage Hardware Acceleration 129
Thin Provisioning 130
Turn off vCenter Server Storage Filters 133
10 Raw Device Mapping 135
About Raw Device Mapping 135
Raw Device Mapping Characteristics 138
Managing Mapped LUNs 140
Security
4
VMware, Inc.
Contents
11 Security for ESX Systems 145
ESX Architecture and Security Features 145
Security Resources and Information 153
12 Securing an ESX Configuration 155
Securing the Network with Firewalls 155
Securing Virtual Machines with VLANs 164
Securing Virtual Switch Ports 169
Internet Protocol Security 171
Securing iSCSI Storage 174
13 Authentication and User Management 177
Securing ESX Through Authentication and Permissions 177
About Users, Groups, Permissions, and Roles 178
Working with Users and Groups on ESX Hosts 182
Encryption and Security Certificates for ESX 187
14 Service Console Security 195
General Security Recommendations 196
Log In to the Service Console 196
Service Console Firewall Configuration 197
Password Restrictions 200
Cipher Strength 206
setuid and setgid Flags 206
SSH Security 208
Security Patches and Security Vulnerability Scanning Software 209
15 Security Best Practices and Scenarios 211
Security Approaches for Common ESX Deployments 211
Virtual Machine Recommendations 215
Host Profiles
16 Managing Host Profiles 223
Host Profiles Usage Model 223
Access Host Profiles View 224
Creating a Host Profile 224
Export a Host Profile 225
Import a Host Profile 225
Edit a Host Profile 226
Manage Profiles 227
Checking Compliance 231
Appendixes
A ESX Technical Support Commands 235
VMware, Inc.
5
Zgłoś jeśli naruszono regulamin