Solved

How to remediate ESXi (v5) host on the end of VPN without shutting down guest VMs

Posted on 2015-01-13
16
334 Views
Last Modified: 2015-02-02
I have a vCenter server installation with around 15 ESXi 5.5 hosts all located at different offices. I regularly remediate the hosts to keep them all up-to-date, using vCenter Update Manager.

However, one of the hosts is at a remote location connected by a VPN client which runs on a VM on that host.  When the VM running the VPN client is running it allows vCenter to talk to the host to perform all the usual vCenter functions, and this works perfectly well 24/7/365.  However, to remediate that host it normally has to shutdown or vMotion off all VMs so the host can enter maintenance mode.  If I shutdown the VM running the VPN client then vCenter Update Manager can no longer communicate with the host to complete the remediation.  It is a single host at the location so vMotion is not an option.

Is there any way I can remediate the host without shutting down the VPN client VM which needs to run on it for the remediation to complete?

Thanks
0
Comment
Question by:Paul Huxham
  • 8
  • 5
  • 2
16 Comments
 
LVL 117
ID: 40546316
Is it possible to use a physical client you can connect to, using Teamviwer etc
0
 

Author Comment

by:Paul Huxham
ID: 40546323
Not really.  There's one other physical server at that site, but that's on the LAN side at the remote site so also becomes inaccessible when the VPN client is down.
0
 
LVL 117
ID: 40546355
and not accessible via Teamviewer, and Internet, we use Teamviewer, as a fallback, because our VPN server is virtual!
0
 

Author Comment

by:Paul Huxham
ID: 40546373
No, once the VPN is down, everything on the LAN is isolated completely.  The VM running the VPN is also the firewall, so when it's down there's no access to anything (including the Internet), so TeamViewer isn't really an option.
0
 
LVL 117
ID: 40546377
So maybe time to consider a hardware VPN appliance.

if the host was down, how would you power it back up?
0
 

Author Comment

by:Paul Huxham
ID: 40546388
The host is located in a managed datacenter so we can get the local support to power-off/on as necessary but they have no access to what's running on the host.  Yes, time for a hardware VPN perhaps!
0
 
LVL 117
ID: 40546393
If you just need to update the host, it can be done using the Offline Package, SCP the offline package to the host, execute the commands on the SSH remote console, and reboot! (update done!).

If you want to use Update Manager, then you will need a hardware VPN, of different VPN end point, which is not on the Host you are updating.
0
Better Security Awareness With Threat Intelligence

See how one of the leading financial services organizations uses Recorded Future as part of a holistic threat intelligence program to promote security awareness and proactively and efficiently identify threats.

 
LVL 11

Expert Comment

by:Mr Tortur
ID: 40546600
Hi,
and if you go with the offline package as described by Andrew Hancock don't forget to enable your VM startup option on your esx host (select esx in vsphere client / config tab / software / vm startup options), in order for your vpn VM to automatically boot after your host boot.
0
 

Author Comment

by:Paul Huxham
ID: 40546603
Thanks Mr Tortur, but that's already set!
0
 
LVL 11

Expert Comment

by:Mr Tortur
ID: 40546736
Ok. Then there is no other option than the one already given by Andrew Hancock.
Or add another esx, or set your vpn/firewall on a physical machine..
0
 

Accepted Solution

by:
Paul Huxham earned 0 total points
ID: 40574770
So, for the benefit of anybody reading this thread, with the same question, there does not appear to be any way in this scenario to remediate a remote host while it has a running VM.  It is necessary for the host being remediated to shutdown all running VMs (and restart), so if you are relying on one of those VMs for connection between the host and vCenter, you won't be able to remediate the host remotely.

Alternatives, are to remediate the host locally from another device from the command line, or install a second host at the remote location to run the VM.
0
 

Author Comment

by:Paul Huxham
ID: 40574787
I've requested that this question be closed as follows:

Accepted answer: 0 points for huxham's comment #a40574770

for the following reason:

There isn't a solution to this problem, this summarizes the workarounds.
0
 
LVL 117
ID: 40574788
Solutions, have been provided, they may not be to your liking!
0
 

Author Comment

by:Paul Huxham
ID: 40576638
There are no solutions provided.  There are workarounds provided, but the question I asked is not achievable.  That's why I clearly summaries the workarounds in my final post (http://#a40574770) before I closed the question, for the benefit of anybody reading the thread at a later date.
0
 

Author Closing Comment

by:Paul Huxham
ID: 40583575
There are no solutions provided.  There are workarounds provided, but the question I asked is not achievable.  That's why I clearly summaries the workarounds in my final post (http:#a40574770) before I closed the question, for the benefit of anybody reading the thread at a later date.
0

Featured Post

Complete VMware vSphere® ESX(i) & Hyper-V Backup

Capture your entire system, including the host, with patented disk imaging integrated with VMware VADP / Microsoft VSS and RCT. RTOs is as low as 15 seconds with Acronis Active Restore™. You can enjoy unlimited P2V/V2V migrations from any source (even from a different hypervisor)

Join & Write a Comment

Suggested Solutions

#Citrix #Citrix Netscaler #HTTP Compression #Load Balance
It Is not possible to enable LLDP in vSwitch(at least is not supported by VMware), so in this article we will enable this, and also go trough how to enabled CDP and how to get this information in vSwitches and also in vDS.
Teach the user how to delpoy the vCenter Server Appliance and how to configure its network settings Deploy OVF: Open VM console and configure networking:
How to install and configure Citrix XenApp 6.5 - Part 1. In this video tutorial we have explained step by step installation of Citrix XenApp 6.5 Server on Windows Server 2008 R2 is explained in this video. We have explained the difference between…

707 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

15 Experts available now in Live!

Get 1:1 Help Now