Infront released a new management pack, a while ago, for FREE, to the community via System Center Central.
http://www.systemcentercentral.com/tabid/143/indexid/94055/default.aspx?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+systemcentercentral%2Fblogs+%28Blogs+at+System+Center+Central%29
This management pack will give you a deeper insight into your virtual machines including recognising which platform (Hyper-V, VMware & Citrix), which hosts they're located on, if VM Tools are installed and the version.
(footnote. I actually wrote this post the day they released it, but forgot to post it /facepalm)
Showing posts with label Citrix. Show all posts
Showing posts with label Citrix. Show all posts
Thursday, 15 November 2012
Thursday, 10 May 2012
Building the TESG Private Cloud Customer Experience Centre - Part 1
Every year my employer holds an event for customers (and potential new customers) to show case what we do and give customers a chance to meet our partner vendors.
This year, nicely coinciding with just after the System Center 2012 release, I landed the brilliant job of setting up something to demonstrate our System Center and Desktop expertise.
And so the concept of the Private Cloud and Optimised Desktop Customer Experience Centre was born.
The goal?
Over a couple of blog posts I'll aim to share some of the planning, thoughts and tips & tricks that went into building it.
What I'll not be doing is guides on how to install the different components as there are plenty of them out there, but I will post links to some relevant good guides.
My original test lab was made up of a couple of HP Proliant DL380 G7's with some shared space pinched off the corporate SAN, but as this was going to need to host a lot more and it would need to be "slightly" portable for attending events like the T360 it was time to purchase some upgrades.
So far this has spread out across 34 VM's and there's still more to come...
This is a quick example diagram that I drew up to show the Hyper-V layout
Once all the hardware components were installed and racked then Hyper-V was the first thing to tackle and all I can say is thank god for Aidan Finn and his blog: http://www.aidanfinn.com/
Lots of useful posts, for example: http://www.aidanfinn.com/?p=10311
I'm going to leave the rest for the next post, but I just want to mention something that came to light when I installed the first System Center component, Virtual Machine Manager.
This is a logical first place to start if you've got the chance to build a private cloud from scratch like I have as you can implement Service Templates for deploying your VM's to help structure the environment and provide servicing and scale out options.
However, I hit a problem almost straight away, I struggled to get it to see my storage provider.
Originally I was ordering a Dell Equalogic iSCSI SAN for the environment, but due to certain disks not being available and increased costs for alternatives I was suggested to look at a DotHill AssuredSAN 2332.
The first thing I did was ask/check it supported SMI-S protocol, which it did as this is what VMM requires for the new features.
However when trying to set it up in VMM, it soon came to light that it only supported SMI-S 1.3 whereas VMM requires version 1.5.
So lesson learnt, make sure that when checking specifications, especially SAN's that you check in detail, right down to the version number!
There is a useful table (I found this afterwards!) that details the supported arrays:
http://technet.microsoft.com/en-us/library/gg610600.aspx
Part 4 - Partner Solutions & Extensions
This year, nicely coinciding with just after the System Center 2012 release, I landed the brilliant job of setting up something to demonstrate our System Center and Desktop expertise.
And so the concept of the Private Cloud and Optimised Desktop Customer Experience Centre was born.
The goal?
- To showcase the full System Center 2012 suite
- To showcase the interactions of each component and how they drive efficiencies
- To showcase an elastic and easily scalable datacentre that can flex into the Public Cloud
- To showcase the dynamic desktop with OS, Data, User and Application layers abstracted
- To showcase BYOD and specifically desktop/application access on tablet devices
Over a couple of blog posts I'll aim to share some of the planning, thoughts and tips & tricks that went into building it.
What I'll not be doing is guides on how to install the different components as there are plenty of them out there, but I will post links to some relevant good guides.
My original test lab was made up of a couple of HP Proliant DL380 G7's with some shared space pinched off the corporate SAN, but as this was going to need to host a lot more and it would need to be "slightly" portable for attending events like the T360 it was time to purchase some upgrades.
- More memory. Upgrade from 64Gb per host to 128Gb
- Dedicated Storage. iSCSI SAN that would also allow me to show some of the VMM storage management features (N.B. More details on this later, plus some pitfalls to watch out for!)
- Dedicated Switches. To show SCOM network management & keep the environment self contained.
- More NIC's. The original environment only had 4 onboard NICs, not good enough.
- Flight case to rack it all in to make it portable (kind of!)
- Active Directory
- Virtual Machine Manager
- Operations Manager
- Service Manager
- Configuration Manager
- Data Protection Manager
- Orchestrator
- App Controller
- SQL 2008 R2 Server
- SharePoint Enterprise Server
- Exchange
- Lync
- ForeFront UAG
- ForeFront TMG
- File Servers
- XenDesktop Mgt Server
- XenDesktop VDI Desktops
- XenApp Mgt Server
- XenApp App Servers
- Remote Desktop Session Hosts
- Remote Desktop Broker/Gateway/Licensing
- RDS/Hyper-V VDI Desktops
- Dedicated Win 7 Admin Workstations
- Citrix NetScaler VM Appliance
- App-V Sequencer Workstations
So far this has spread out across 34 VM's and there's still more to come...
This is a quick example diagram that I drew up to show the Hyper-V layout
Once all the hardware components were installed and racked then Hyper-V was the first thing to tackle and all I can say is thank god for Aidan Finn and his blog: http://www.aidanfinn.com/
Lots of useful posts, for example: http://www.aidanfinn.com/?p=10311
I'm going to leave the rest for the next post, but I just want to mention something that came to light when I installed the first System Center component, Virtual Machine Manager.
This is a logical first place to start if you've got the chance to build a private cloud from scratch like I have as you can implement Service Templates for deploying your VM's to help structure the environment and provide servicing and scale out options.
However, I hit a problem almost straight away, I struggled to get it to see my storage provider.
Originally I was ordering a Dell Equalogic iSCSI SAN for the environment, but due to certain disks not being available and increased costs for alternatives I was suggested to look at a DotHill AssuredSAN 2332.
The first thing I did was ask/check it supported SMI-S protocol, which it did as this is what VMM requires for the new features.
However when trying to set it up in VMM, it soon came to light that it only supported SMI-S 1.3 whereas VMM requires version 1.5.
So lesson learnt, make sure that when checking specifications, especially SAN's that you check in detail, right down to the version number!
There is a useful table (I found this afterwards!) that details the supported arrays:
http://technet.microsoft.com/en-us/library/gg610600.aspx
Part 1 - Building the TESG Private Cloud Customer Experience Centre
Part 3 - Installation Guide LinksPart 4 - Partner Solutions & Extensions
Labels:
2012,
App Controller,
App-V,
Citrix,
ConfigMgr,
DPM,
Dynamic Desktop,
Hyper-V,
Operations Manager,
Planning,
Private Cloud,
SCCM,
SCOM,
SCORCH,
SCSM,
SCVMM,
Service Manager,
System Center,
Virtualisation
Friday, 30 March 2012
User Centricity and Licensing
The world of IT is changing. There is a strong push to move to a much more User Centric approach for software delivery and that means using technology such as delivering an application through RDS or a Citrix Presentation session. This brings so much simplification in terms of centralised management of the application and updates as well easily controlling user access by groups for example and as long as the number of users the application is available to matches the number of licenses owned for the application then everything is fine... isn't it?
Wrong…
This has to be the top licensing misconception and often comes up in discussions I have with customers.
When an application such as Office, Visio or Project is delivered in this manner then controlling access either via Active Directory groups, or Group Policies etc is not sufficient. This is due to these applications being licensed “per device”. With this license model it means that every device that the user can potentially access (or does access) the remote session with the application in requires a license.
For example;
Parking the whole logging in remotely scenario for now as that’s an even bigger amount of possible devices, Fred has the ability to use any device within the organisation to access his remote desktop. Each one of these devices would require licensing for the per device licensed application.
This isn’t just limited to Terminal Services, Remote Desktop Services and Citrix (I know the underlying tech is the same!) scenarios.
This same license model also applies to VDI, you could potentially access a VDI desktop from any device as that’s the benefit. It also applies to app streaming solutions like XenApp and application virtualisation such as App-V and AppWave.
Basically, all the technologies that really push User Centricity and targeting applications at users rather than devices (System Center 2012 Configuration Manager heavily focuses on this).
So really since applications can be delivered to any client device, a per device application license must be obtained for every device the delivery mechanism server has the ability to deliver an application to, not just the person using the desktop application.
One solution to this is AppSense Application Control. While this solution allows you to claw back some control and compliance and is recognised by Microsoft as an official way to control licensing it does have some draw backs.
AppSense Application Control allows you to define the devices that are allowed to run the per device licensed software and block it from running on non-licensed devices, giving you the flexibility of centrally managing and delivering software like MS Project from RDS/XenApp/VDI/App-V methods, but at the same time removes the flexibility that targeting the user and flexible working should bring.
One area that this is vitally important in, in my opinion, though is blocking access to applications licensed in this model when logging in from outside of the corporate network when any device could be used and “in theory” thousands/millions of licenses should be required and you only have your corporate devices covered fully by an Enterprise Agreement for example.
So what can you do? Well it all depends on the application, the vendor and the licensing model. There are some agreements and special licensing models that can be potentially useful but they all take some analysis of numbers required, benefits and costs etc.
All I can really advise is:
Wrong…
This has to be the top licensing misconception and often comes up in discussions I have with customers.
When an application such as Office, Visio or Project is delivered in this manner then controlling access either via Active Directory groups, or Group Policies etc is not sufficient. This is due to these applications being licensed “per device”. With this license model it means that every device that the user can potentially access (or does access) the remote session with the application in requires a license.
For example;
- Fred usually uses the Thin Client on his desktop. That’s license number 1 required.
- He pops into a branch office in the afternoon and logs into a PC and connects to his remote session through a portal. That’s license number 2 needed.
- He then disappears home early and logs in from home using his iPad. That’s license number 3.
Parking the whole logging in remotely scenario for now as that’s an even bigger amount of possible devices, Fred has the ability to use any device within the organisation to access his remote desktop. Each one of these devices would require licensing for the per device licensed application.
This isn’t just limited to Terminal Services, Remote Desktop Services and Citrix (I know the underlying tech is the same!) scenarios.
This same license model also applies to VDI, you could potentially access a VDI desktop from any device as that’s the benefit. It also applies to app streaming solutions like XenApp and application virtualisation such as App-V and AppWave.
Basically, all the technologies that really push User Centricity and targeting applications at users rather than devices (System Center 2012 Configuration Manager heavily focuses on this).
So really since applications can be delivered to any client device, a per device application license must be obtained for every device the delivery mechanism server has the ability to deliver an application to, not just the person using the desktop application.
One solution to this is AppSense Application Control. While this solution allows you to claw back some control and compliance and is recognised by Microsoft as an official way to control licensing it does have some draw backs.
AppSense Application Control allows you to define the devices that are allowed to run the per device licensed software and block it from running on non-licensed devices, giving you the flexibility of centrally managing and delivering software like MS Project from RDS/XenApp/VDI/App-V methods, but at the same time removes the flexibility that targeting the user and flexible working should bring.
One area that this is vitally important in, in my opinion, though is blocking access to applications licensed in this model when logging in from outside of the corporate network when any device could be used and “in theory” thousands/millions of licenses should be required and you only have your corporate devices covered fully by an Enterprise Agreement for example.
So what can you do? Well it all depends on the application, the vendor and the licensing model. There are some agreements and special licensing models that can be potentially useful but they all take some analysis of numbers required, benefits and costs etc.
All I can really advise is:
- Make sure every application you aim to deliver remotely has it's licensing properly checked before you take the plunge and do it to ensure you avoid any costly compliance challenges.
- If in doubt, speak to someone who knows. All application vendors/suppliers will have specialists, check with your account manager to see what they can do to help.
Subscribe to:
Posts (Atom)


