Security

RSA 7.1 supported under ESX 3.5

René Jorissen on July 23, 2009 7 Comments • Tags: #35 #71 #esx #rsa #support #vmware

More and more people would like to implement OTP (One Time Password) solutions. RSA is one of multiple vendors for OTP solutions. I also notice the wish to implement and support OTP with on-demand tokens, like SMS and e-mail. RSA supports on-demand tokens, but the minimum RSA Authentication Manager version required is 7.1. Not only … Read More

Routing, Switching

Cisco ASA & ESX: strange ARP behavior

René Jorissen on January 12, 2009 10 Comments • Tags: #arp #behavior #esx #icmp #interface #nat #noproxyarp #path #proxy #reverse #reversepath #spoofing #strange #sysopt #verify #vmware

Last week I had a very strange problem with a Cisco ASA firewall. The firewall is configured with multiple interfaces, including a DMZ interface. There are multiple servers in the DMZ. These servers are physical and virtual servers. The virtual servers are VMware servers in a blade environment. I configured the feature ip verify reverse-path … Read More

Security

RSA Authentication Manager 7.1 on VMware

René Jorissen on August 15, 2008 2 Comments • Tags: #61 #71 #authenticate #bad #esx #manager #performance #rsa #slow #vmware

I had to install and configure RSA Authentication Manager 7.1. Looking at the Supported Platforms I couldn’t find VMware ESX as supported platform. VMware ESX was supported for RSA AU6.1. So I thought by myself, let’s give it a try. What I noticed first was the size of the installer. The installation file for RSA … Read More

Other stuff..., Routing

Change ESX host IP address

René Jorissen on June 5, 2008 0 Comments • Tags: #esx #failure #ha #segmentation #vlan

Monday I had to migrate an existing network. I added more VLAN’s to the network for segmentation and breaking the broadcast domain. I introduced a regular VLAN, a VoIP VLAN and a management VLAN. So far no problem. The customer is using Cisco Catalyst 3750G and Cisco Catalyst 3560 switches with PoE. I configured the … Read More

Other stuff..., Switching

Port-channel Cisco vs. VMware ESX

René Jorissen on April 4, 2008 5 Comments • Tags: #balancing #dst #esx #esxtop #etherchannel #ip #lacp #load #loadbalancing #mac #portchannel #src #srcdstip #srcmap

I have had different discussions with different customers about the load-balancing algorithms between a Cisco switch, configured with a port-channel and a VMware ESX server using multiple NICs. Our VMware consultants always choose Route based on IP hashes as load-balancing algorithm. This means that load-balancing happens on layer 3 of the OSI model (source-destination-IP). In … Read More