• Skip to main content
  • Skip to footer

NetworkJutsu

Network Security Consulting | San Francisco Bay Area

  • Blog
  • Services
  • Testimonials
  • About
    • About Us
    • Terms of Use
    • Privacy Policy
  • Contact Us

Blog

VMware ESXi Home Lab [2012]

09/12/2012 By Andrew Roderos 1 Comment

  • Share on Twitter Share on Twitter
  • Share on Facebook Share on Facebook
  • Share on LinkedIn Share on LinkedIn
  • Share on Reddit Share on Reddit
  • Share via Email Share via Email

If you’ve been following my tweets, then you know that I haven’t been doing a lot of CCIE studying. For about three weeks last month, I tried to finish my Openfiler + ESXi (vSphere Hypervisor) home project. Obviously, it wasn’t three straight weeks worth of time – a few hours per day/night. I’ve been very excited about this home project and I’ve already put off another mini-project that I have to do – which is to install my Samsung 128GB SSD drive and drive caddy to replace my optical drive for extra HDD space on my mid-2009 15″ MacBook Pro.

Anyway, if you’ve been researching for whitebox builds then you’ve probably have seen people using Mac Mini as their ESXi host. I’ve considered running ESXi on Apple Mac Mini since others have successfully done it using this guide, but I’ve decided against it. The form factor of Mac Mini is hands down a good feature to have, but there are some limitations to it that may not work for the future growth of my home network and my need to play with different technologies outside Cisco.

There is also Intel NUC as a very attractive ESXi host. However, the older generation of NUCs needs to have a custom ISO so that the NIC would work. With the new Intel NUC (6th generation), the ESXi 6.0 Update 2 works out of the box on these units. I actually talked about it here since I’ve added another ESXi host in my home lab.

Related: VMware ESXi Home Lab – Intel NUC (Frost Canyon)

Before we delve into the ESXi build, let me give you a little bit of background of my old setup. My old server was supposed to be my ESXi since the motherboard is listed here as compatible with ESXi. However, upon building it and really giving a thought it turned out to be not the best solution for what I wanted it to do. I could make it work but as what other people would say just because you can doesn’t mean you should. Having said that, I just built it as a regular Windows box with virtualization software running on top of it to run VMs with different OS (Linux, Unix, and Windows) in them. It worked great and no complaints. However, as a technology enthusiast, there was this voice that kept telling me to run VMware ESXi at home. As you can already tell, the voice won and I’ve decided to buy and build a new home server. Besides, this particular build will be used for VCP studying if ever I decide to really get serious in pursuing it. I do want to get it, but it isn’t my day-to-day job so I am still contemplating. Yes, I am well aware that you need to have instructor-led training first before you can register to take VCP. I am actually currently enrolled in a local community college which is a member of VMware Academy. This is the cheapest route for me so I decided to sign up for the class. I could’ve asked my current employer to pay for the boot camp style VMware vSphere: Install, Configure and Manage class but I’ve decided against it since it really is outside my day-to-day job responsibilities. I am just taking this class just to expand my knowledge outside the Cisco realm.

Anyway, for curious minds out there, here’s my old home server specs:

AMD Phenom II X6 1090T Black Edition
ASUS M4A88TD-V EVO/USB3
2 x G.SKILL Ripjaws 8GB
Dell PERC 5/i
3 x Western Digital Caviar Black 1.5TB
Corsair AX850 PSU

Without further ado, here are the parts of the home server:

Lian Li PC-V351B
Supermicro MBD-X9SCL+-F
Intel Xeon E3-1230 V2 Ivy Bridge
Antec EA-380D Green
2 x Kingston 8GB DDR3 SDRAM ECC Unbuffered Update: It’s 32GB RAM now.
SanDisk Cruzer Blade 4GB USB Flash Drive

This whitebox build is in the high-end range, so if you are looking for just ESXi home lab use then this may not serve your purpose. There are other builds out there that are suitable for inexpensive home lab use, like HP N40L, so choose whatever will work for you. This build will also be used for ESXi home lab (nested ESXi 5.x) and for “production” so I wanted a more powerful host than the N40L and more expandable in the RAM side of things. As already mentioned, I run different OS with different purposes in my home server to provide services for myself, friends, and family. Some of these services are the following but not limited to proxy, FTP, SSH, and etc.

If you were paying attention, the build didn’t have any hard drives in it. This build was designed to run quietly and with low power requirements. I chose to use 4GB USB flash drive to install ESXi on to save power, money, and repurpose the OS hard drive on my old server. Since I do not have CD/DVD-ROM driver either, I searched the web on how to create a USB bootable flash drive and it was pretty straightforward, just follow this guide.

At first, I used Openfiler as my NAS and it worked great. However, I am convinced that the cause for crashing/rebooting of my NAS box was because my RAID controller was overheating. Never really spent a whole lot of time troubleshooting it because this project went over the projected schedule that I wanted to spend my free time on. With that said, I just pulled the trigger and bought Synology DS1812+ as my NAS for CIFS/SMB and NFS shares that my ESXi box will use as its datastore. So far, I love this Synology NAS box and will never go back to Openfiler. Don’t get me wrong, Openfiler is really good but I believe Synology or other NAS manufacturers out there is the way to go. Yes, I could’ve stuck with Openfiler by just buying a new RAID controller to save cost initially, but over time I believe I’ll end up paying more money on energy costs by using a regular PC.

Well, I hope this blog post is a little bit helpful for the people trying to build a whitebox ESXi host. Let me know if you have any questions and I’ll try to answer them as soon as I can. Enjoy!

You might also like to read

VMware ESXi Home Lab [2016]

Disclosure

NetworkJutsu.com is a participant in the Amazon Services LLC Associates Program, an affiliate advertising program designed to provide a means for sites to earn advertising fees by advertising and linking to Amazon.com.

  • Share on Twitter Share on Twitter
  • Share on Facebook Share on Facebook
  • Share on LinkedIn Share on LinkedIn
  • Share on Reddit Share on Reddit
  • Share via Email Share via Email

Filed Under: Virtualization Tagged With: ESXi, Home Lab, VMware

Catalyst 3750 Switch Stack

08/17/2012 By Andrew Roderos 2 Comments

  • Share on Twitter Share on Twitter
  • Share on Facebook Share on Facebook
  • Share on LinkedIn Share on LinkedIn
  • Share on Reddit Share on Reddit
  • Share via Email Share via Email

I like using Catalyst 3750 stack for user access switch. Don’t get me wrong, I’d rather use chassis based switches (Catalyst 4500 or 6500) but as we all know that money is usually a concern. 3750 stack is way less than a dual sup and fully populated 4500 or 6500 so if you’re in a budget then 3750 for user access is the way to go, in my opinion. Yes, you don’t have to get dual sup, but you don’t get the redundancy and it is still more money than a 3750 stack. With the 3750 stack, you get the redundancy since all other switches in the stack can take over as the master switch – equivalent to active switch (VSS) or active sup (dual sup chassis based switch).

3750’s StackWise/StackWise Plus/StackPower, 2960’s FlexStack, and VSS, which was mentioned here, are pretty much the same thing – device pooling/stackable switch technologies. With StackWise/StackWise Plus, you can stack up to nine switches. StackPower and FlexStack allows you to stack up to four switches. The last time I checked, the VSS (Virtual Switching System) allows you to stack only up two chassis based switches. If I remember correctly, VSS used to be a 6500 only technology but now the newer 4500s chassis can support VSS as long as it is equipped with the right supervisor – like Sup 7E.

Stacking Catalyst 3750 does not need any manual configuration. All you have to do is connect the StackWise cables (included when you buy it), boot it up and the stack will automatically form. When you rack and stack nine 3750s with 1U space in between, you’ll need one 3M (~9ft) StackWise cable. The one that comes with the switch is only 50CM (~1ft) which is enough to connect all switches except from the top to the bottom switch with 1U space between switches. If you don’t need the 3M then you can also buy the 1M (~3ft) which is good for 3 – 5 switch stack configuration with 1U space between switches, if I remember correctly. Make sure you plan accordingly when ordering your 3750 stack.

Once all the StackWise cables are connected and the switch powers up, it’ll go through its POST sequence, master election, and etc. What I am concern here is the master election. I like my switch stack to be predictable. As what Jeremy Cioara would say, auto = ought not to use it. Though in QoS video, he admitted liking the AutoQoS. Having said all that, I want to know exactly who should take over as a master when it boots up or when the master fails. As mentioned, the switch stack goes through a master election and is described here. In all the scenarios that I’ve experienced, there are only two things that I need to remember and they are the priority and MAC address.

MAC address is only important when you’re working on a new stack or a stack which has no config in it. The switch with the lowest MAC address wins the master election when the priority is set by default (value of 1). See the example below. The stack below is fresh out of the box.

Switch#show sw
Switch/Stack Mac Address : a493.4cd6.5b80
                                           H/W   Current
Switch#  Role   Mac Address     Priority Version  State
----------------------------------------------------------
 1       Member d867.d990.bb80     1      1       Ready
*2       Master a493.4cd6.5b80     1      1       Ready

As you can tell, I only have two switches in this stack. The switch 2 won the master election since the switch priority is a tie and has a lower MAC address than the switch 1. Switch priority is the first one to be checked when it boots up. That’s not what the Cisco’s documentation says, but again I only consider switch priority and MAC address in the election process. Higher switch priority wins the master election and when all the switches have the same priority then the one with the lowest MAC address wins, as already mentioned.

There maybe some network professionals out there that do not care about who the master is in the stack, but I am not one of them. The scenario in this post is physically laid out as switch 1 being the bottom switch and switch 2 as the top switch. I like my switch stack organized, so whenever I set one up I try to match the logical and physical view of the switch stack. In addition, I like my master to be on the top of the switch stack, physically and logically, so I have to alter my configuration to match the way I want it to look like. The configuration below shows you how to alter the switch stack to match the logical and physical view of the stack.

The first step I do is to configure one of the switches to have a higher priority so I know exactly who the master is on a switch stack. In this scenario, I picked switch 2 to have the highest priority. I don’t have to change the priority on this stack since I know this stack will never grow more than two. However, as best practice, I like to configure the priority value of the switches.

Switch#conf t
Enter configuration commands, one per line.  End with CNTL/Z.
Switch(config)#switch 2 priority 15
Changing the Switch Priority of Switch Number 2 to 15
Do you want to continue?[confirm]
New Priority has been set successfully

If you recall, switch 2 is placed on the top of the stack (physically) and as mentioned earlier I want both physical and logical to match so I have to configure that as well to reflect it. Below is how to configure it to match physical and logical view of the stack.

Switch(config)#switch 2 renumber 1
WARNING: Changing the switch number may result in a configuration change for that switch.
The interface configuration associated with the old switch number will remain as a provisioned configuration.
Do you want to continue?[confirm]
Changing Switch Number 2 to Switch Number 1
New Switch Number will be effective after next reboot

As you may have guessed, you can’t have two switches with the same number so you have to change the remaining switches in the stack. If your stack contains nine switches, then knowing the switch number is important so you can renumber the right switch. To do this easily, you press the mode button of the switch until the stack LED lights up. You’ll now notice that the LED of the port numbers are blinking as well. Take note of those numbers so you can rename the proper switch with the right number. I normally use the top to bottom approach when I number my stack. In this scenario, I only have two switches so it’s easy to do but if you have you nine switches it’ll most likely be jumbled up. Your switch 3 (physically) may be numbered as 9, so make sure to write it down. Anyway, below is to finish what I’ve started.

Switch(config)#switch 1 renumber 2
WARNING: Changing the switch number may result in a configuration change for that switch.
The interface configuration associated with the old switch number will remain as a provisioned configuration.
Do you want to continue?[confirm]
Changing Switch Number 1 to Switch Number 2
New Switch Number will be effective after next reboot

Since I only have two switches and I know that this stack is not going to get another switch, I didn’t change the switch priority on the other one. I normally change the priorities of all the switches in the stack whenever I configure a stack from scratch except for the bottom switch. This way, I know which switch will be the next master switch when the original master fails. Obviously, this is a matter of preference so you don’t have to follow my method.

Once everything has been renumbered, it’s time to reboot the stack. When the stack is fully booted, verify the switch stack to make sure that everything is what you desire it to be.

Switch>sho switch
Switch/Stack Mac Address : a493.4cd6.5b80
                                           H/W   Current
Switch#  Role   Mac Address     Priority Version  State
----------------------------------------------------------
*1       Master a493.4cd6.5b80     15     1       Ready
 2       Member d867.d990.bb80     1      1       Ready

If you compare the previous show switch output earlier, the switch with a493.4cd6.5b80 is now showing up as switch 1 and has a priority of 15. With the priority set to 15, this helps determine who will be the master of the switch during election. Again, this does not guarantee that it’ll always be the master, however, since when there’s a tie in priority the next one to check is the MAC address.

Hope this has been helpful and thank you for reading!

Disclosure

NetworkJutsu.com is a participant in the Amazon Services LLC Associates Program, an affiliate advertising program designed to provide a means for sites to earn advertising fees by advertising and linking to Amazon.com.

  • Share on Twitter Share on Twitter
  • Share on Facebook Share on Facebook
  • Share on LinkedIn Share on LinkedIn
  • Share on Reddit Share on Reddit
  • Share via Email Share via Email

Filed Under: Switching Tagged With: Cisco, IOS, Switch

System Time And Log Time

08/07/2012 By Andrew Roderos Leave a Comment

  • Share on Twitter Share on Twitter
  • Share on Facebook Share on Facebook
  • Share on LinkedIn Share on LinkedIn
  • Share on Reddit Share on Reddit
  • Share via Email Share via Email

As pointed out in my previous blog post, I don’t like seeing wrong time. I especially do not like seeing two different time on show log and show clock output. I’ve seen this happened several times on Cisco routers and switches and it really annoys me whenever I need to know when a specific event happened and also how long ago it happened. Having said that, I try to create a config template for every router and switches I deploy. Also, I try to go back to all the routers and switches already deployed so everything is standardized. If you have thousands of routers and switches, it’ll be a pain in the neck to do it manually so tools such as AlterPoint Device Authority or SolarWinds’ Network Configuration Manager are there to help. These products also keep backups of all your configurations also so it’s a great tool to have in an enterprise.

Below is to show an example of a router with NTP and timezone properly configured but log timestamp doesn’t match the system time.

Router#sho clock
10:39:06.730 PST Tue Jul 31 2012
Router#conf t
Router (config)#int f0/0
Router (config-if)#no shut
Jul 31 15:52:39:  %SYS-5-CONFIG_I: Configured from console by networkjutsu on console
Jul 31 15:52:39:  %LINK-3-UPDOWN: Interface FastEthernet0/0, changed state to up
Jul 31 15:53:39:  %LINEPROTO-5-UPDOWN: Line protocol on Interface FastEthernet0/0, changed state to up

To fix this, issue the command below.

Router(config)# service timestamps log datetime localtime msec
Router#show clock
10:40:30.360 PST Tue Jul 31 2012
Router#conf t
Router (config)#int f0/0
Router (config-if)#shut
Jul 31 10:39:53.280: %SYS-5-CONFIG_I: Configured from networkjutsu by console
Jul 31 10:39:54.280: %LINK-5-CHANGED: Interface FastEthernet0/0, changed state to administratively down
Jul 31 10:39:54.580: %LINEPROTO-5-UPDOWN: Line protocol on Interface FastEthernet0/0, changed state to down

As you can see above, the log timestamp is now synchronized with the system time clock. Now, it’s time for you to send this config to all routers and switches in your network.

Hope this has been helpful and thank you for reading!

Disclosure

NetworkJutsu.com is a participant in the Amazon Services LLC Associates Program, an affiliate advertising program designed to provide a means for sites to earn advertising fees by advertising and linking to Amazon.com.

  • Share on Twitter Share on Twitter
  • Share on Facebook Share on Facebook
  • Share on LinkedIn Share on LinkedIn
  • Share on Reddit Share on Reddit
  • Share via Email Share via Email

Filed Under: General Tagged With: Cisco, IOS

Cisco router and/or switch timezone

07/18/2012 By Andrew Roderos Leave a Comment

  • Share on Twitter Share on Twitter
  • Share on Facebook Share on Facebook
  • Share on LinkedIn Share on LinkedIn
  • Share on Reddit Share on Reddit
  • Share via Email Share via Email

I don’t know about you but I like having the right time in my Cisco routers and/or switches. Having the right time is important especially when you need to find time sensitive information like when did a certain interface went down or did the router’s ACL block a certain traffic at a specific time. A lot of organizations have NTP servers that are stratum 1. Companies such as EndRun Technologies sell stratum 1 NTP servers which are normally synchronized over GPS, CDMA, or WWV. That being said, take advantage of that NTP server and point all of your nodes that are capable of running NTP to that server.

The issue that I have with Cisco routers/switches is that they default to UTC and even if you have a stratum 1 NTP server, when you issue show clock it will still show you the UTC time. I may be wrong to assume that not a lot of people know their UTC offset value for their timezone so when they see that UTC time, they’ll most likely go to Google and do a search. Fortunately, Cisco routers and switches have the capability of changing the UTC offset value. Now, you do not have to “google” the UTC equivalent for your timezone. Without further ado, here are the commands that you need to issue to change your Cisco router/switch’s timezone.

Router#sho clock
23:32:28.465 UTC Wed Jul 1 2012
Router#conf t
Enter configuration commands, one per line. End with CNTL/Z.
Router (config)#clock timezone PST -8
Router (config)#do show clock
15:33:06.549 PST Wed Jul 1 2012
Router (config)#clock summer-time PST recurring 2 Sun Mar 2:00 1 Sun Nov 2:00
Router (config)#do sho clock
16:34:15.462 PST Wed Jul 1 2012

Since my timezone is Pacific Standard Time (PST), I used -8 for my UTC offset value. Obviously, you need to change the offset value that is equivalent to your area’s timezone. The second command below is for countries that observe Daylight Savings Time (DST) rule. The new DST rule (2007 changes) observed here in the USA is that it begins at 2:00 a.m. on the second Sunday of March and ends at 2:00 a.m. on the first Sunday of November.

Now that you know how to change the timezone in Cisco IOS, it’s time for you to send out the changes to all of your routers and switches.

Disclosure

NetworkJutsu.com is a participant in the Amazon Services LLC Associates Program, an affiliate advertising program designed to provide a means for sites to earn advertising fees by advertising and linking to Amazon.com.

  • Share on Twitter Share on Twitter
  • Share on Facebook Share on Facebook
  • Share on LinkedIn Share on LinkedIn
  • Share on Reddit Share on Reddit
  • Share via Email Share via Email

Filed Under: General Tagged With: Cisco, IOS

LAN Design

05/26/2012 By Andrew Roderos Leave a Comment

  • Share on Twitter Share on Twitter
  • Share on Facebook Share on Facebook
  • Share on LinkedIn Share on LinkedIn
  • Share on Reddit Share on Reddit
  • Share via Email Share via Email

A question about LAN design came up and I decided to write a blog post about it. This blog post, however, is not going to cover every LAN design possibilities out there since there are other blogs that covers it – such designs talk about TRILL, FabricPath, SPB, vPC, and etc. I will, however, cover some LAN designs that I’ve seen in production and were mentioned in CCDP ARCH book. For people who are still in the CCNA level, the LAN design in this blog post will be covered in CCNP/CCDP books so keep on studying. Hopefully, this blog post will serve a good introduction to the topic.

The picture on the left side is called Layer 2 looped design, per CCDP ARCH FLG (Foundation Learning Guide) book. This is one of the common LAN designs, in a medium sized environment if your access layer switch is only Layer 2 capable. For simplicity sake, I did not include the core layer switches in the diagram. However, this design can be used as well as core/distribution switch, this is called collapsed-core LAN design. Collapsed-core design is mostly found in a small/medium sized network where it doesn’t need a core layer.

As the name implies, this design has a Layer 2 loop. Of course, this is only true if the switches are not running STP. With this design, one of the links is in blocking mode which means the other link won’t be used if you’re running the IEEE 802.1D standard, also known as Common Spanning Tree (CST) or just STP. With Cisco switches, at least the ones I’ve used, run PVST+, by default, which means you can take advantage of the other link to do some load balancing across two links. Though, in reality it is not really balanced since traffic in two VLANs are not normally identical. Books will tell you load balancing but I agree with Brian Dennis where he mentioned in one of the INE videos that it is actually load sharing. Load sharing is accomplished by configuring the STP parameters per VLAN and First Hop Redundancy Protocol (FHRP), like HSRP, VRRP, and GLBP.

One disadvantage of this design is that you can span VLANs across multiple switches, which means the broadcast domain is extended. If a broadcast was sent from a host connected to Access-1, that broadcast will propagate across all the switches in the LAN who has that VLAN configured. Another disadvantage is the STP convergence – if there is a failure in the topology, the network needs to reconverge first before forwarding any traffic. While implementing IEEE 802.1w, also known as RSTP, can help with the reconvergence of the network, there is still a period of time that the traffic is not forwarding.

The design on the right is called Layer 2 loop-free, per CCDP ARCH FLG. As the name implies, the design does not have Layer 2 loop which means STP has been avoided – meaning no more waiting for STP to reconverge and no more blocked ports. However, this design does not avoid the network reconvergence. When there’s a failure in the topology, FHRP will still need to release its duties as a primary traffic forwarder for the other switch to take over. The load sharing is simpler than the first one since there will be no STP configurations on top of the FHRP. While this design is a better choice than the first one, at least in my opinion, it needs to be said that spanning VLANs across multiple switches is not recommended. Make sure that spanning VLANs across other switches is not needed before picking this design. If, for whatever reason, the network needs to span VLANs across other switches, the design can be converted to the Layer 2 looped design by changing the port channel between the distribution switches to Layer 2 link.

This design is called Layer 3 routed, sometimes called routed access. Out of the three diagrams, this is the best design since there’s no STP and FHRP needed which allows equal cost load balancing (again, sharing) and no need to wait for the network to reconverge when topology changes. The diagram depicts that the VLANs are different on each switches but it does not need to be different. The advantage of making it different VLANs on each switches is when the requirement needs to be changed to Layer 2 looped design.

Unfortunately, I do not know the official name for this design since these were not covered in CCDP ARCH or CCNP BCMSN material. Let’s just call it single chassis with dual supervisor Layer 2 loop free. These two are very similar to the first two design presented earlier but without the redundancy of the second chassis. These designs, however, still has some redundancy built into it – dual sup. The obvious advantage of this design is the cost savings, since the design does not require to buy another chassis and line cards. While chassis failure can happen, it is very rare so this is an attractive design to deploy in some environments. The dual sup has some similarities with the HSRP active and standby concept. However, in supervisor redundancy it is called active (primary) and hot (standby or secondary), as shown here.

This design allows you to combine two switches and present it to other switches in the network as one logical switch. With this design, the STP has been eliminated since the downstream switches will see it only as a single logical switch. The downstream switches will run Multichassis EtherChannel (MEC), also known as Multichassis Link Aggregation (MLAG), and the distribution switches will run VSS (Virtual Switching System). I believe this is not very common LAN design in a user environment since this is an expensive solution. I will make an assumption that this is a design that can be deployed in a data center environment. While this can work in a data center environment, there are other designs out there that I consider better than this. Besides, if you’re going to be designing a data center environment you may want to look at other switches offered by other vendors or if your environment is a Cisco shop, then you feel free to look at the Nexus line. Per Ethan Banks, Catalyst 6500 may not be the right choice for a data center environment moving forward.

Running VSS and MEC/MLAG comes with a caveat, the split-brain issue – this has been covered by Ivan Pepelnjak in his blog post. While I have not encountered it in production, I’ve heard stories about it happening in a production environment. While I am familiar with the technology, I’ve never really configured one. Though, I will be configuring it pretty soon during Cisco Live.

I hope this blog post serves a good introduction to LAN design.

Reference

Designing Cisco Network Service Architectures (ARCH) Foundation Learning Guide

Disclosure

NetworkJutsu.com is a participant in the Amazon Services LLC Associates Program, an affiliate advertising program designed to provide a means for sites to earn advertising fees by advertising and linking to Amazon.com.

  • Share on Twitter Share on Twitter
  • Share on Facebook Share on Facebook
  • Share on LinkedIn Share on LinkedIn
  • Share on Reddit Share on Reddit
  • Share via Email Share via Email

Filed Under: Design, Switching

  • « Go to Previous Page
  • Page 1
  • Interim pages omitted …
  • Page 9
  • Page 10
  • Page 11
  • Page 12
  • Page 13
  • Interim pages omitted …
  • Page 18
  • Go to Next Page »

Footer

WORK WITH US

Schedule a free consultation now!

LET’S TALK

Copyright © 2011–2026 · NetworkJutsu · All Rights Reserved · Privacy Policy · Terms of Use