Certificate replacement in vCenter HA configuration

Recently I had to change the default certificates of a newly installed vCenter. Nothing unusal with that, if not for the fact that I didn’t think about vCenter HA that I configured before getting the certs. If only I had read that little piece of advice from VMware… ... [Read More]

Passive node down in vCenter HA 6.5

This issue is fixed in vCenter 6.5 update 1. I recently logged on a VCSA 6.5 that had been installed a while back with vCenter High Availability (VCHA) and noticed that the passive node was down. After a few checks, the VM is running, I can... [Read More]

vCenter 6.5 hybrid certificates with Microsoft Standalone CA

The hybrid mode is currently VMware’s recommended deployment model for certificates as it procures a good level of security while not being too cumbersome to implement. In this model only the Machine SSL certificate is signed by the CA and replaced on the vCenter server. The solution user and ESXi... [Read More]

Install the latest PowerCLI on offline systems

If you keep your PowerCLI up to date you may have noticed that since version 6.5.1 you can’t download the installer on the VMware website anymore. This being because VMware moved the distribution of PowerCLI to Powershell Gallery using the cmdlets Install-Module, Uninstall-Module and... [Read More]

All your VMs in RDCManager in 20 seconds

I recently started a new job and just like in my previous one I wanted to have all servers consolidated in one place so I can easily RDP on them if needed. I use the free Microsoft tool Remote Desktop Connection Manager (RDCMan). There are better software out there like... [Read More]

Meltdown & Spectre - Check if your ESXi servers are patched

[Update 20/03/2018] VMware now recommends to apply the patch for Hypervisor-Assisted Guest Mitigation. According to them the performance impact is less than 2%. I haven’t patched yet and I will wait for the feedback of early adopters. The start of the year has been so ridiculous with patches... [Read More]

Metro cluster partial DCI failure

In this article I would like to cover a failure scenario that I recently dealt with and that I suspect is maybe not that common for several reasons. The environment is made of 2 sites in a metro cluster sharing a virtualised storage over a multiplexed fiber. Half of the... [Read More]

Easily run PowerCLI commands as jobs

Overview Start-PowerCLIJobs.ps1 Running commands as jobs is pretty mainstream in Powershell. A simple “Start-Job” or “Invoke-Command -AsJob” will do the trick. However, when PowerCLI is involved it is not as straightforward. If you try to run a command that requires to be connected to a vCenter you will... [Read More]

NSX DFW rule - lost access to vCenter

I was playing with NSX recently and testing the distributed firewall (DFW) that allows for east-west firewalling, aka micro-segmentation. All was going well when I disconnected my brain for a second and added a rule “deny all all” (Yes I know…). Following that moment facepalm I obviously lost access to... [Read More]