
Configuring security groups for instances in an ESX cluster
Security group functionality is provided by VMware vCNS, and not by the security group rules
configurable from the CloudSystem Portal. To enable the security groups feature in an ESX
environment, the following must be true.
• VMware vShield Manager virtual appliance must be installed and configured for each managed
vCenter Server, as a single vShield Manager can serve only a single vCenter Server
environment.
• vShield App virtual appliance must be intalled from vShield Manager on each ESX host in the
cluster that is managed from the managed vCenter Server.
• CloudSystem Foundation requires that all vShield Manager certificate names match compute
host names.
To learn how to configure security groups using vShield Manager and vShield App, refer to the
vShield Administration Guide at VMware.
Configuring iSCSI on ESX compute hosts
If you plan to attach iSCSI volumes created in the HP 3PAR storage system to instances hosted on
VMware ESX servers, then you must configure an iSCSI adapter on the ESX compute hosts.
Configuring networking for the VMkernel
A single VMkernel adapter is required to support iSCSI. The VMkernel runs services for iSCSI
storage and must be connected to a physical network adapter.
Prerequisites
• SAN storage hardware is using HP 3PAR firmware version 3.1.2
Procedure 51 Configuring networking for the VMkernel
1. Log in to the vSphere Client hosting your vCenter Server and select a compute host from the
Inventory panel.
2. Select the Configuration→Networking tab.
3. From the vSphere Standard Switch view, select Add Networking.
4. Select VMkernel and click Next.
5. To create a new standard switch, select Create a vSphere standard switch.
6. Select the NIC to use for iSCSI traffic and click Next.
7. Enter a network label and click Next.
The label helps you easily identify the VMkernel adapter.
8. Specify the IP settings and click Next.
9. Review the information and click Finish.
After configuring the VMkernel networking, you need to bind the iSCSI adapter with the VMkernel
adapter. You can find a list of available storage adapters in the Hardware tab under Storage
Adapters. When the VMkernel adapter is bound with the iSCSI adapter, you see a network
connection on the list of VMkernel port bindings for the iSCSI adapter.
Setting the discovery address and target name of the storage system
The iSCSI adapter uses the target discovery address to determine which storage resources on the
network are available for access.
Dynamic discovery
When using dynamic discovery, a SendTagets request is sent to the iSCSI server every time the
initiator contacts the server. To use this type of discovery, you must associate your storage adapter
with an iSCSI initiator, and set that initiator to use dynamic discovery. Each time the host sends
out the request for targets, the Static Discovery list is populated with newly discovered targets.
98 Compute node creation
Commenti su questo manuale