Showing posts with label Rick Rohne. Show all posts
Showing posts with label Rick Rohne. Show all posts

Monday, September 6, 2010

Pre-Logon Client Choices in Access Gateway Enterprise

By: Rick Rohne

This is an update to a previous article that I wrote about adding a pull-down menu with connection type choices on the logon page for Access Gateway Enterprise Edition. By default Access Gateway Enterprise Edition uses group extraction and EPA scans to determine what kind of connection a user can make. Access Gateway Enterprise also has a client choices screen after authentication that can provide end user selections. These policies may not always offer the best solution for your organization. Therefore configuring a pre-logon client choice may be the best option.

Background

The following are some reasons why you would give users a selection box before authentication:
1. Give users a choice to access their appliacations, desktops, or VPN sessions
2. Allow users to access Sharepoint, OWA, and other clientless web applications using the same url.
3. Allows users to have more control, reducing support calls.
4. Get more out of Access Gateway Enterprise.
I created this video to give you an idea on how this can be used:




Procedure


NOTE: The index.html file mentioned on this article is found under /netscaler/ns_gui/vpn

First create a cookie on the user's workstation

This procedure creates a cookie on the user's workstation which will be evaluated by the session policy. The name of the cookie is NSCookie

1. Download index.html to your workstation.
2. Open the file for editing with your preferred document editor software.
3. Locate the following section:

4. Add the following on the next available line


5. The next line should read:

6. Add storeValues(this);" so that it reads:


Next create the actual pull-down menu


1. On the same index.html page locate the line that reads:

 
2. Add the following code.



(Note: you can add as many OPTIONS as you wish. The Value’s m(x) will be used to match up against a session policy)


3. Save the changes and copy the file to the /netscaler/ns_gui/vpn directory
Note: make sure to backup the original file.


Create a procedure to allow the custom page to survive a reboot


1. Connect to the appliance using an SSH client such as PuTTY.
2. Type shell.
3. Make a directory on the hard drive to hold the custom file.
mkdir /var/customizations
4. Copy the modified page to the new directory.

cp /netscaler/ns_gui/vpn/index.html /var/customizations/


5. Create a startup script file called rc.netscaler under /nsconfig (if one is not already present).
cd /nsconfig
touch rc.netscaler

6. Copy the copy command into rc.netscaler.
echo cp /var/customizations/index.html /netscaler/ns_gui/vpn/index.html >> /nsconfig/rc.netscaler
Next you must modify the session policies to be based on the presence of the cookie instead of the default "true value".

The expression syntax would look similar to that shown in the screen shot below:

add vpn sessionPolicy xMyDT-pol "REQ.HTTP.HEADER Cookie CONTAINS MyDT" XD_ONLY


More Information



The user will then be given a drop down menu on the default logon page. The cookie will be placed on their workstation and evaluated by the session policies. MyDT is the default which should always match the users Default connection while others will match other session policies.



More information on Access Gateway Enterprise

Read more!

Saturday, April 24, 2010

SCCM on XENDesktop or PVS Standard Target Devices

By:Rick Rohne
Have you ever tried to manage your XENDesktop or PVS target devices using SCCM? In some ways, managing the devices using SCCM is irrelevant due to the nature of how PVS works, but low and behold, I've run into a few companies that insist on using SCCM for inventory management and application installation. The SCCM client, however, does not work well in a streamed OS environment. If you've ever tried installing the SCCM client on a PVS image, you will notice that SCCM shows new machines with the same name in its collections every time a PVS target device reboots in standard mode. This is because the SCCM client changes the GUID when an imageis pushed to new hardware. SCCM uses the GUID to keep track of Physical Hardware devices.

Overview how SCCM works
To give you an idea how it works, SMS uses the GUID of the computers to associate the Computer and OS with the SMS object. This GUID is stored in the c:\windows\SMSCFG.ini file.

The GUID can be read from this file, also by querying WMI using this vb script.
----------------------------------------------------------------------------------------------------------------------------------
strComputer = "."
strNameSpace = "root\ccm" strClass = "CCM_Client=@" Set objClass = getObject("Winmgmts:{impersonationlevel=impersonate}!\\" & strComputer & "\" & strNameSpace & ":" & strClass)
strGUID = objClass.ClientID
Wscript.Echo strGUID
Set objClass = Nothing
-------------------------------------------------------------------------------------------------------------
The problem we see is in a Citrix Provisioned desktop, this file comes up with a duplicate GUID each time. This causes the SCCM client t re-generate theGUID and create a new file on every boot.
You can find this information here http://support.microsoft.com/kb/837374

The Fix
In order to persist the computers GUID, you must be using “cache to targets hard drive” when you place your systems in standard mode. We use the hard drive to save the SCCMCFG.ini file after each reboot.
This also means that "cache to RAM" or "cache to Server" will not be sufficient because the cache will be purged on every reboot.

Step 1.
To resolve this, first, you have to run a script when switching from private mode to standard mode. This is done by the XENDesktop Admin after he modifies the default image…
This script stops the SCCM service and deletes the c:\windows\SCCMCFG.ini file.
'--------------------------- SCCM Cleanup.vbs--------------------------------------
'Stop SCCM client strServiceName = "CCMExec"
Set objWMIService = GetObject("winmgmts:{impersonationLevel=impersonate}!\\.\root\cimv2")
Set colListOfServices = objWMIService.ExecQuery("Select * from Win32_Service Where Name ='" & strServiceName & "'")
For Each objService in colListOfServices objService.StopService() Next ' Cleanup SCCM Set fso = CreateObject("Scripting.FileSystemObject") Set aFile = fso.GetFile("c:\windows\SMSCFG.ini") aFile.Delete
----------------------------------------------------------------------------------------
Step 2.
Now, you have to run a shutdown script and startup script that basically places the c:\windows\SCCMCFG.ini file on the Cache drive on shut down. When the computer boots up, it will check to see if the file exists on the cache drive. If it does not, the SCCM client will register itself to the SCCM server and create a new c:\windows\SCCMCFG.ini file. Upon shutdown, the c:\windows\SCCMCFG.ini file is copied to the cache drive.

This is a simple batch file script that can be loaded into active directory as a computer startup script for the OU where XENDesktop computers reside.

Startup Script
IF EXIST G:\SMSCFG.ini COPY G:\SMSCFG.ini C:\Windows\SMSCFG.ini /y > c:\smserror.txt

Shutdown Script
COPY c:\windows\SMSCFG.ini G:\SMSCFG.ini /y > g:\smserror.txt

Now computers that are manged by SCCM will show up as unique entries in the SCCM database.
NOTE: This was tested with SCCM 2007 R2, PVS 5.1, and XENDesktop 4


More information on Provisioning Server

Read more!

Symantec Endpoint Protection on XENDesktop and PVS target devices

By:Rick Rohne
I’ve recently come across a couple of companies trying to install Symantec Endpoint Protection on their XENDesktop PC’s, and finding a very annoying outcome. First of all, the SEP client does not update completely or not at all, the SEP client blue screens during the installation, and/or the SEP manager display multiple entries in the database for the same host. There are a few root problems when installing the SEP client to a PXE booted shared image, and I was determined to find the answers…


Problem


After installing Symantec on a base image in XENDesktop, the client computers appear more than once in the Symantec console. This continues to happen after every boot. Alternatively, if you try to install Symantec SEP while booted to the network, you may receive a blue screen after the first reboot.
Solution
Boot your VM using Microsoft Hyper-V or perform a reverse image when performing Symantec Endpoint Protection Installation.  This is required because SEP modifies the NIC drivers during installation.  Next, Clean up the registry after the first boot as to allow the image to re-register with a unique Hardware ID for each Virtual Desktop.

Step by Step

1. Import your XENDesktop OU
To ensure that your Virtual Desktops get the policies that are assigned, I recommend using the Symantec Endpoint Protection Manager Active Directory Import tool to import the OU for your XENDesktop computers. This will allow the OU to have custom policies and that will tailor to the XENDesktop farm.
Once you have the XENDesktop OU imported, you will see existing clients, and you can have the option to scan for new clients as they are added. The main reason for creating this OU is to ensure that the clients get a specific policy.

2. Configure your policies
I found that the High performance policy Template gives you the best policy for your Virtual Desktops. After duplicating the policy, you can modify the new policy with a few additional settings.

  • In the File System Auto Protect, change the default settings of “Load Auto-Protect” to Symantec Endpoint Protection Start.

  • Exclude the .vdiskcache file if you are performing the write cache on the computer’s hard disk.
  • Since these Virtual desktops will always come up with the default image, you can exclude any scheduled scans. This will ensure that your virtual desktops have the best performance possible.

3. Next, assign the policy to the new XENDesktop Group:


Using the SEP Manager Tool, you can right click on the policy and assign it to your XENDesktop group.

4. Prepare your image
NOW you are ready to boot the client and install the SEP client software.

First, boot the client using Microsoft Hyper-V. (For information on how to use Hyper-V to update offline vDisks, see http://www.thegenerationv.com/2010/02/using-hyper-v-for-pvs-vdisk-offline.html

5. Deploy the client to your Virtual PC
Perform the client deployment manually, ensure that the client deployment is visible to the end user as to ensure that you do not shut down before the client is finished installing.

Once installed, perform a reboot and allow the client to come back online. Then you must manually delete the unique registry keys and xml files that associate this computer name to Symantec SEP Manager.

6. Perform Registry and file system cleanup
  • Install the Symantec Endpoint Protection Client after all of the other installations are complete.
  • Before you save the image, start the "Registry Editor."
  • Locate and delete the following registry key:
          HKLM\SOFTWARE\Symantec\Symantec Endpoint Protection\SMC\SYLINK\SyLink\HardwareID
Reference:
http://service1.symantec.com/support/on-technology.nsf/854fa02b4f5013678825731a007d06af/0e2c1c8989fe2a268825748a004a565c?OpenDocument











  • Exit the "Registry Editor."
  • Delete the C:\program Files\Common Files\Symantec Shared\HWID\sephwid.xml file
  • Shut down the VM and publish the vDisk as a standard image.
  • Create a batch file for your XENDesktop PC’s that will delete these entries. You can publish this batch file as a shut down script to ensure that the PC removes these entries every time the machine is shut down. Alternatively, you can just run these scripts when you are running in private mode before transitioning to standard mode.
  • You will most likely see new entries show up for the Virtual Desktops in the Endpoint Protection Manager. This is because the hardware is virtual and will continue to change after every reboot. Therefore, it is important for you to perform a Desktop Group Sync when you are running reports. If this is completely un-manageable for your organization, you can also setup personalities for each of your virtual desktops that include the same hardware ID. This process will require you to run a script to import the Hardware ID into the registry on each boot.

 
 
 
 
 
 
 
 
 
 
 
 
 
 

7. Verify Functionality
After you perform these procedures, you should see that all updates take place and that the correct policies are assigned to the desktops



 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
Reference:
http://service1.symantec.com/support/ent-security.nsf/854fa02b4f5013678825731a007d06af/7c87b2b11e0d18c48025765000518741?OpenDocument

http://service1.symantec.com/SUPPORT/ent-security.nsf/docid/2007110510364248

SEP Registration Process




More information on Provisioning Server


Read more!

Monday, February 8, 2010

Using Hyper-V for PVS VDisk Offline Maintenance

By:Rick Rohne

I’ve recently been toying with the idea of using Microsoft Hyper-V to perform offline maintenance of my Provisioning Server VDisks. Furthermore, I’ve discovered that it is very possible to install the Hyper-V role directly on the PVS server or servers in your production environment.

While this may not be the best solution for all deployments, I have found that installing the hyper-V role directly on the PVS server saves a lot of time when having to perform tasks such as updating PVS target device software, Anti-Virus software that modifies the network stack, or updating physical computer network drivers.
This blog hosted on the Citrix Blog site shows exactly how to use Hyper-V to update your Vdisk images. Be sure to follow these instructions to the “T”.. Using Hyper-V to update Offline vDisks , and since the best way to get super performance out of your PVS server is to run it on a Windows Server 2008 x64 box, it just makes sense to use the same server to run the hyper-v role.

If you choose to do this, I strongly suggest adding a new directory outside of your PVS store to perform the offline maintenance. You may also choose to keep the Hyper-V services stopped when you are not using them, and finally, create a dedicated network on the Hyper-V host (maybe your management network) to assign your external network to your VM’s. Although these steps are not necessary, it will ensure that your hyper-V services never interfere with your PVS services.

I would like to know if anyone else is doing this, I currently have one production deployment and my own lab running this scenario and it really does seem to work great.

Read more!

Wednesday, January 13, 2010

Agentless backup for Citrix XenServer VM's

By:Rick Rohne
One of the great things about Virtualization is the ability to take quick snapshots of your XENServer VM’s so that you have a restore point to go back to at any time; however, keeping snapshots in your XENServer Storage Repositories is not always the answer to a good solid disaster recovery plan.
Take a look at this product which performs automated online snapshots and archives of your XenServer VM's.

There is always a free way for everything

You can use the XENAPI to perform automated snapshots and even schedule this on a Windows Server, you can even go so far as to archive these images off using SSH etc. But anytime scripting is involved, you have to take into account the changes, additions, and deletions of VM’s in your environment. You can learn more about automating XENServer backups using the XENAPI on the Citrix XENServer Codeshare site http://community.citrix.com/cdn/xs/codeshare.

Alike (Agentless Snapshots) http://www.quorumsoft.com/

I’ve been using Alike to perform automated snapshots and backups of the VM’s in my lab since it first came out of BETA. Alike is a Citrix Ready product that can perform an agentless snapshot and download of your XenServer VM’s to the servers Disk. This may seem trivial, however, Alike actually performs De-duplication of the snapshots and provides an easy to use interface that allows you to schedule a backup job and perform restores without any downtime.
Take a look at some of the key features of Alike:
  • Data Deduplication - Performs block-level data deduplication across all VMs backed up
  • Friendly UI - This easy-to-use User Interface will get you backing up quickly
  • XenServer Integration - Leverages XenServer snapshots to capture guest VM state. Recomended XenServer 5.5
  • Pool Support - Alike is pool-aware and can back up guests deployed to a XenServer storage pool
  • Quiesce Support - Quiesced snapshots are supported in XenServer 5.5
  • Supported Storage Repositories (SRs) - Alike Supports any SR in XenServer 5.5
  • Point-in-time restore - Versions each snapshot that is backed up
  • Syslog integration - Logging can be sent to a syslog server email/paging notifications
  • Flexible Scheduling - Jobs can be scheduled daily, weekly, or monthly; may be configured for multiple runs per day
How Alike Works
1. The Alike scheduler service launches a Job and connects to the appropriate XenServer host.
2. A snapshot of the Virtual Machine (with or without Quiescence) is created.
3. The snapshot image is exported to the temporary work area in an XVA format.
4. Guest image white space is eliminated, then downloaded and processed (deduplicated, compressed and encrypted).
5. Only delta data is vaulted to the storage repository for permanent storage.
6. The backup is now complete and resides safely on disk.

Now if that’s not enough, here’s an excellent video that pretty much tells you the rest of my story:


Keep in mind, however, that even if you are taking snapshots of your VM’s, it is still a good practice to also perform a nightly agent backup of the data that is within the VM. By using both technologies, you can perform an easy restore of your XenServer VM’s so that all the applications and server settings are restored as well as get all the data since the last daily or hourly backup.

My experiences
1. It's much faster than scripting.
2. Works with Citrix Storagelink technology (Netapp storage).
3. New VM's can be automatically added to the Backups.
4. You can even clean up the old snapshots.
5. It would be nice if it worked with XenServer Tags to automate scheduling.
6. I'm hoping it works with Hyper-V and other Virtualization software soon.


For more information on Alike and to get updated pricing, visit their website at http://www.quorumsoft.com/


Read about other products that work with XenServer


Read more!

Saturday, December 12, 2009

Citrix Command Center Basics with Netscaler

By:Rick Rohne

If you have been working with Citrix Netscaler, VPX, Access Gateway Enterprise, Application Firewall, or Brach Repeater you are probably interested in ways to collect statistics, reports, and alerts for all your Application Networking devices… Citrix Command Center is just the tool to use, and when configured right, you can get a deep understanding of how your devices are operating in the field. Here, I’m going to go over some of the basic Command Center setup tasks to get you on your way to total knowledge of your Application Networking Infrastructure.


Citrix Command Center is an SSH and SNMP monitoring station that also triples as Config Archiving and mission control center for all of Citrix’s Application Networking gear (both physical and virtual). You can use it to build graphs and receive alerts on system usage and individual entity usage. You can also use it to upload batched commands or transfer configs from development to production. Best of all, it’s included with your purchase of Netscaler Enterprise, Application Firewall, Access Gateway Enterprise, or Branch Repeater.


Who should use Command Center?
• Anyone that has two or more Branch Repeaters, Netscalers, Netscaler VPX, or Application Firewalls.
• Any time you will be transferring your configs from test to development
• When you are using Application Firewall
• When you want to be alerted on up/down events (i.e. when a Service fails and recovers such as the Citrix XML service or your e-commerce web site).
• When you want to keep historic trends of your ANG Infrastructure (i.e. Authentications, VServer hits, Packets received and transmitted, or http requests per second to your Web Sites etc.).
• If you will be writing policies and actions based on traffic usage i.e. Sure Connect or MAX client.


Installation


When setting up Command Center (CCC) for the first time, it’s probably a good idea to have a beefy server and a database that can hold plenty of gathered statistics. It supports a MYSQL, Microsoft SQL, or Oracle datastore and it will generally get pretty big (depending on how much information you gather and how long you keep it. Here is a link to the installation guide (It supports both Windows and Linux installations) Citrix Command Center Installation Guide 3.3 .

After you have it setup, you can choose to run CCC manually or as a Windows Service. If you want to run it as a service, simply run the "C:\Program Files\Citrix\Citrix Command Center\bin\InstallCCAsService.bat" file. This will set the service to start automatically and also install an Apache service on TCP port 9090 (unsecure) or 8443 (secure). It’s managed using a web browser pointed at the Server IP with the port specified during setup. The default username is root with the password of public.


First Steps


The first thing you will want to do is go to the Admin tab to setup some default settings for your CCC installation. Here you can:
• Change the Authentication and authorization settings to Local User accounts or central Directory accounts.
• Configure Log rotations and how long to keep logs around
• Configure your email server default settings
• Configure Inventory settings (Such as whether certificates are backed up etc.


After you have your default settings configured, you will want to create a MAP (Under Citrix Network). A Map is a collection of similar devices with similar roles (Such as an HA pair or a quad of devices in a GSLB configuration). Once you setup your map with all the default information, you can then add devices to the map individually or by running a discovery with an IP range (see below).


Provided that you have not locked down the snmp managers in your ANG devices, Command Center will automatically configure the SNMP community and Trap destinations. It is a good idea to later lock down the SNMP manager hosts to just the devices that will be enabled for management.

NOTE: If an SNMP manager or SNMP manager Network is defined, the automatic configuration will fail. Simply delete all SNMP managers and run the discovery again, or manually configure the SNMP settings.

Once the MAP has been defined, you will start collecting Alarms, however, you must still do some manual configuration if you want to receive alerts or build custom graphs.


Alarms


Alarms can be found under the Fault tab. The Alarms section shows Active Alarms and the status of the Alarm. Not all alarms are enabled by default, Citrix Netscaler comes with some basic alarms that are already configured such as Entity up/down status, Config Changes, Login Failures, HA failover etc.. If you would like to get alarms for typical tasks such as CPU, memory, or Disk usage you will have to configure the alarm thresholds on each device (Or batch a command to configure all the devices from Command Center).


If you would like to setup email alerts, you will want to configure Alarm Triggers. With Alarm triggers you can select what emails addresses receive information on what alarms. You can target specific categories or failure objects and you can use Wild Cards for matching similar failure objects.
NOTE: if you want Command Center to alert on part of a service name for multiple services called SVC_Email_01 and SVC_Email_02, you can add *Email* in the failure object.



Graphing and Reporting statistics


Reporting is one of my favorite features of Command Center because it allows you to know exactly what is going on with your Application Infrastructure and web applications such as:
• CPU, Disk and memory usage over time
• How much traffic is being received and at what are the peak times
• How many SSL VPN connections are occurring
• Authentication Successes and failures
• Reporting also helps you identify if you are using the right size device

The first thing you must do when configuring reporting is configure your Polled Counters… You can configure Counters under the Performance tab of Command Center. Some counters are configured by default; however, you should go in and disable counters that you will not use as well as select counters that are important to your organization.

NOTE: The more counters that are selected, the more processing the Command Center will have to do. Also, Counters with a Plus sign next to them will require additional processing by the appliances. These counters provide the most detailed information such as service and Vserver hit counts, packet rates, etc.


Once you have your counters selected, wait about 5 – 10 minutes and run a quick report or setup a custom report… Custom reports are reports that can be re-used and scheduled and sent to an email distribution. To start, select quick report or Add Custom report from its view.

Select the devices and the counters that you would like to see in your report, and select finish.



Here you can see the counters in the view of your choice.


Central Configuration


The Configuration gives you a single place to execute common tasks for your devices. You can Update Certificates, or Generate Certificates from a central location. You can also use Custom tasks to Batch configurations from Test to Production. You can read more about the custom tasks in a previous blog that I wrote about creating Template configurations for Application Firewall Application Firewall goes Commando


This is just the beginning


There are many other things you can do with Command Center, if you are running any of Citrix’s application networking products in production, I encourage you to download this and give it a try…. Although there is not a whole lot of documentation on Command Center, you can get some useful information from the Admin and User Guides found at http://support.citrix.com/product/nscc/v3.3


More information on Netscaler


Read more!

Friday, December 11, 2009

Netscaler's Application Firewall goes Commando!

By:Rick Rohne

Application Firewall is a relatively complex feature of the Netscaler using complex policies and profiles to identify un-wanted traffic that is flowing to and from an organization’s extranet. Building the policies the first time can be a challenging task alone, but when it comes to duplicating and transporting the policies, well we will just say it’s NO picnic.

Let's take a look at how Citrix Command Center can be used to easily "create" and "transport" Application Firewall Template profiles from Development into Production without having to go deep into the cli.

First of all, if you haven’t heard of Citrix Command Center, you are definetly missing out. Citrix CC is a great tool that can alert and track historic trends of Citrix Netscaler, Application Firewall, Access Gateway Enterprise, and Branch Repeater. It can also be used to transport commands from development to production with just a few simple steps. I’ll be posting more information about Command Center in a later blog, but for now, let me give you a little teaser by making AppFW Profiles portable.

Let’s start by creating a simple Application Firewall Profile (and Policy) Template. vThis template will be a starting point for all your Vservers, and it will give you practice on how to export and import the profiles and policies using Command Center…
First, go in and create a simple AppFW policy and profile that can be re-used by all sites. i.e. no host header matching and no learned data. Call the Policy Template_Pol and the Profile Template_Prof.


Once you have your profile created and configured, you will want to save the config by clicking the little Save button on the Top right.
NOTE: if you don’t save your config, you will not be able to read the commands that were entered using the cat command.
Open a Secure Shell client and login to your Netscaler and type Shell to drop to FreeBSD. You can then use the CLI to grep the commands into a Template File that you can later copy out and re-use any time:


After your Template file is created, simply download the file using an SFTP client to your Computer. (WinSCP does a great job here because you can use it’s built in text editor that works well with Citrix Netscaler Config files). You will find this file under the "/Var" directory on the Netscaler.


Next make a copy of the file on your PC and rename it to something that is a little meaningful… Something like “AppFW_Website_00001”... Then open the new file and do a Find all occurrences of “Template_” and replace with “Website_00001”.



Now you are ready to import this new policy and profile using Citrix Command Center. Open Command Center; go to Configuration / Custom Task / Add Custom Task. Use the Import from command line to browse to your newly created file and select next. The Custom Task wizard will capture the contents of the file and place them in sequential commands that can be fed into the Netscaler.
NOTE: Make sure you remove any task variables at the bottom of the page. Citrix Command center reads some of the commands and misinterprets Deny-URL’s as Task Variables..




Finally, go back to the Netscaler Configuration utility and refresh the screen. You will see that you have a complete copy of the original Profile and Policy (with a new name) ready to begin learning mode on a new Web Application….




Ok, since you have the basic concepts, let’s take this one step further… Since it is relatively risky to place the App Firewall Rules in learning mode while facing the public Internet, you can use Netscaler VPX to create your initial profiles and policies and build all the learned and deployed data in a development environment. Once you are finished deploying all the rules, save the configuration and perform the same steps, only this time deploy rules to the production Netscalers and bind them to the production Vservers.




Read more!

Monday, December 7, 2009

How XENDesktop recovers from a XENServer failed pool master

By:Rick Rohne
According to Citrix Article CTX122458 you can configure a XENDesktop DDC to communicate with two or more XENServers in a Farm with HA configured.  In the case of a failure, the DDC simply goes through the list until it finds the new XENServer master. This got me thinking… It goes through the list???  What happens when you have a large farm?   Does this mean that XENDesktop will not be able to control Virtual Machines for the duration of the outage?  Time to get some Network traces to find out what is going on under the covers…

The Basics
The basis of the article shows that you can add multiple XENServers to the options tab of the XENDesktop DDC configuration as seen here:


1. Create a desktop group as normal using the XENDesktop Setup Wizard or manually in the Delivery Center Console by selecting Citrix Xen VM infrastructure (included with XenDesktop) as the host infrastructure. Specify the address of a single XenServer in the Address field.

2. Select Options and enter:
Addresses=[http://xenserver1.pool1.citrix.com,http://xenserver2.pool1.citrix.com,...][http://xenserver1.pool2.citrix.com,http://xenserver2.pool2.citrix.com,...]...

Does Every Server have to be entered?
Citrix states that you do not have to add all of the XENServers in the Farm to the DDC configuration. I was a little weary about this, so I had to do some testing to see what happens when you don’t list all the servers and one of the “Un-listed” servers becomes the Pool Master.
To my surprise, the answer was definitely NO (You don't have to list all the Pool Members)! When and if the Pool Master fails, the DDC just needs to be able to communicate with one other Member Server in the XENServer Pool. The DDC then performs the Authentication Request and if the authentication succeeds, the Member Server will tell the DDC the IP address of the Pool Master. If no Pool Master is elected, the DDC continues to poll the XENServers until the election has taken place.
The Proof is in the Trace
When the Pool Master experiences a failure; the DDC senses the failure and begins to go down its list of listed XENServers in the list.


The First XENServer that responds may be a Pool Member, however, the Member accepts the authentication request and awaits commands.


The DDC then issues a command to get all records


The XENServer Member recognizes and accepts the command but informs the DDC of the Pool Master IP address in the response.


The DDC then connects to the New Pool Master (Even if it is not listed in the options)



As you can see, you don't have to enter all of the servers in the XENServer farm. I would probably recommend adding at least 4 XENServers in each farm to allow for some flexibility for server reboots and server maintenance...


More on XENDesktop


Read more!

Saturday, October 31, 2009

There’s an APPSENSE for that!

By:Rick Rohne

Having trouble getting acceptance with your VDI Profile Management? There’s an APPSENSE for that!
Do your User profiles get corrupt leaving you to resetting your user profiles? There’s an AppSense for that!
Do your users complain about logon times? There’s an AppSense for that!
Having trouble with silo servers overwriting User profiles? There’s an AppSense for that!
Do Executables take up all the CPU or Memory on your servers or desktops? There’s an AppSense for that!
Do you have multiple VDI images due to application compliance and security? There’s an AppSense for that!

I recently spent a few days with the US AppSense team to learn the new features of AppSense Management Suite 8 and to learn how AMS8 applies to todays technology, especially on the VDI and Application Virtualization front. Here are some of my key take aways from my time with AppSense.

Who is AppSense

AppSense has been around for over ten years helping Admins manage the end user experience on PC's and Server Based Computing Solutions... Environment Manager, Application Manager, and Performance Manager are the three core products that make up the AppSense Management Suite, each component compliments an SBC and VDI environment in its own unique way.

Profile/Personality Management

AppSense Environment Manager ‘EM’ stores User Application Preferences in a database, not a file system, and it only stores changes to the profile. This has many advantages.
First of all, User Preferences are tracked by a central management engine. This allows the users’ personality for an application to be streamed at application launch and application close events. (Not at logon and log off events). The idea behind this is to ensure that the user logon times are optimized and that only personality settings that are needed are transferred. This configuration alone can reduce your logon times exponentially.

EM also stores and streams only the personality 'changes' in files and the registry. This reduces the application launch time because the personality settings (delta’s) are merged into the local profile or mandatory profile stored on the server or vdi (not the Network). Plus, since it only get’s streamed at application launch, logon times are not affected.

Due to the architecture of EM, an administrator no longer has to store profiles for different PC’s, Terminal Servers, VDI’s, or silo’s on different file shares (even if the operating systems are different). Environment Manager stores user personalities in a central intelligent database, so you can store all the users’ settings by “user” not by system Role. This can be taken one step further by using AppSense to aid in the migration of users’ settings from Windows XP to Windows 7 without causing any corruption.
EM also has a scripting engine, that allows an administrator to map drives, printers, Environmental Variables, and set registry values based on events such as application startup, application shut down, RDP and ICA connect, reconnect and disconnect. The Script engine has location awareness and is not limited to just logon and logoff events. Of course, there are so many other things you can do with Environment Manager, but I don’t have the time or the space to cover all of them.

Managing VDI and SBC performance

Performance Manager is a part of the suite that has been around for a long time and is very popular in the Citrix XENApp environments. Well known for Multi-User Environments, the PM engine runs at the kernel level and manipulates the cpu scheduler so that all users on a system get equal time to the processor. This can easily be observed in a multi user environment when a single user launches a complex task that overwhelms the system and spikes the CPU to 100%. All Users on that system have to wait until the process completes before their processes are executed. These concepts can also be introduced in a VDI environment to control CPU, Disk, and memory utilization on the physical Server allowing a better end user experience across the board.
System Resource Entitlement ensures that a consistent experience is delivered to end users during process start and throughout the entire execution of the process. System Resource Entitlement can be considered the QoS of a VDI and MU environment. These QoS features can be applied to Network, Memory, and Disk utilization and applied by user, group or application across the entire enterprise.
Managing Application Compliance & Security

With Application Manager ‘AM’, Apps can be controlled without the management overhead of GPO's, file system permissions, or complex scripts...
In a VDI or published Desktop environment, Admins might be tempted to install all of the Applications that are used by the company on a single image, and then manage the applications by modifying the file permissions of the executables. This can be very time consuming, and can easily become a maintenance nightmare due to the complexities of most organizations. Admins might also decide to have a core image for every type of user in an organization. While this solves compliance issues, it introduces many new challenges in the way of updating core images and preventing image sprawl. Application Manager solves this by managing accessible or prohibited resources based on user or device criteria. Admins can release one image to an entire organization, while controlling application access centrally.

Traditional Application authorization lists are generally based on executable names, which can easily be compromised by copying and renaming the executable. AM Trusted Ownership removes this risk by only allowing executables to run that trusted owners or administrators have installed. If an executable is launched that was not installed by a trusted owner, the executable simply won’t run. One very common discussion that I find myself in is "how to manage Anti-Virus Updates in a VDI environment". Obviously, every time a ghost VDI is provisioned, it must update its anti-virus from a parent server, thus causing extra startup processing and network utilization. By using Application Entitlement and Trusted Ownership you can reduce the dependency for Anti-Virus Software in a VDI environment by locking down the systems to only execute trusted processes. I know I'm going to see a lot of flack on this, but take a test drive, and you will see what I'm talking about.

Using Application Manager, you can have a single VDI or Terminal Server image with All Applications Installed, while ensuring that compliance and security are maintained.

The Run Down

So, If AppSense has been around all this time, what is so special about their products now? The short answer is, AppSense has had 10 years of practice for what is about to be the event of a lifetime! Let's face it, VDI is the big buzz word of the year(s), and everyone wants a piece of the vdi-pie. Some of the key issues that seems to be slowing the VDI rollout's revolve around "User Experience", "Profile Management", and of course, "The overall management" of the Infrastructure. AppSense can help you roll out and manage your VDI environment, while also applying to your existing PC and SBC environment.


Looking for more information on AppSense



Read more!
Microsoft Virtualization, Citrix, XENServer, Storage, iscsi, Exchange, Virtual Desktops, XENDesktop, APPSense, Netscaler, Virtual Storage, VM, Unified Comminications, Cisco, Server Virtualization, Thin client, Server Based Computing, SBC, Application Delivery controllers, System Center, SCCM, SCVMM, SCOM, VMware, VSphere, Virtual Storage, Cloud Computing, Provisioning Server, Hypervisor, Client Hypervisor.