Written by Stephen Elliot
With its ability to reduce costs and optimize the IT infrastructure by abstracting resources, virtualization has become an increasingly popular tactic for enterprises having to compete in an ever more challenging global economy. According to a recent study CA conducted with 300 CIOs and top IT executives, 64 percent of respondents say they've already invested in virtualization, and the other 36 percent reported that they plan to invest in virtualization.
You don't have to look very hard to find the biggest reasons for virtualization's widespread adoption: cost savings and IT agility improvements. Because of the current global economic crisis, CIOs are being asked not only to do more with less, but also to do it with lower headcount while delivering higher IT service levels. By wringing out more performance without adding huge IT infrastructure line items to the budget, virtualization provides the more-bang-for-less-buck solution that organizations are looking for. Increasingly, enterprise IT organizations want to host more critical workloads on virtual machines; however the management risks must be reduced.
Respondents to CA's study stated they are also implementing virtualization for technical reasons like easier provisioning and software deployment. But although virtualization brings a tremendous opportunity for IT organizations to compress the processes and cycle times between production and application development teams, drive out more agility in the infrastructure and automate more processes, it brings a lot of complexity to the expertise needed to run the software and the management processes that must be tweaked and adjusted.
The Challenges Facing Virtual Infrastructure Management
One major technical issue facing organizations looking to add virtualization to their IT infrastructure is the limitations of system platform tools. As the virtual machine count begins to creep up, platform tools can't provide the amount of granular performance data necessary to give the IT staff a complete picture of what's going on.
Couple that with the heterogeneous mix of virtualization platforms companies are using and management challenges begin to have an impact on IT's ability to accelerate the deployment of virtual machines. The bottom line is that both platform management and enterprise management solutions are required to deliver an integrated business service view of both physical and virtual environments.
Similarly, organizations need the ability to integrate the physical infrastructure with its virtual counterpart in order to automate configuration changes, patch management, server provisioning and resource allocation. The key business service outcomes of this are lower operations costs, improved ROI from virtualization deployments, and an end-to-end view of an IT service.
CIOs are also looking at virtualization for more than just cost savings. They're looking for a management solution that will transform their IT organizations and demonstrate success via measurable metrics and key performance indicators, whether they're business processes such as inventory churn and increasing margins, or technical metrics like server-to-admin ratio (or virtual-machine-to-admin ratios), or even a reduction in the number of trouble tickets sent to the service desk. The goal is to deliver business transformation in an ongoing, measurable manner to mitigate the business risk of a growing virtualization deployment.
The Solution: Virtualization as Strategy, Not Just Tactic
All of these challenges point to a common solution that transforms the deployment of virtualization from being an ad hoc cost-savings tactic to a more strategic enterprise platform. Rather than merely increasing the number of virtual machines, IT can take the opportunity to think about how it can get the most out of decompressing the processes between teams, increasing the workflow automation, reducing handoff times, reducing configuration check times and increasing compliance. These are the foundational steps that lead to IT transformation and successful business service outcomes. Without these capabilities, the failure rate of projects and associated costs substantially increase.
Where Virtual Infrastructure Management Is Headed
Another reason that viewing virtualization as an enterprise platform is becoming crucial to organizations is that virtual machines are taking on different forms as virtual technology transforms. The management of desktop virtualization is becoming increasingly important as the technology increases in popularity. One particular challenge is the number of different architectures that needs to be taken into consideration for any desktop virtualization solution.
Likewise, a growing number of organizations are investigating network virtualization. In particular, Cisco's new virtual switch technology, which includes embedded software from VMware, has been making ripples across the IT world.
Having an enterprise platform in place makes such new developments in virtualization easier to implement and manage. The better an organization plans for the management, processes and chargeback opportunities virtualization offers, the more IT can lead the business outcome discussion and drive out measurable success.
While virtualization has already helped transform data centers, drive consolidation efforts and reduce power and cooling costs, we've just scratched the surface. There's a lot more to go.
Friday, March 13, 2009
Virtual Infrastructure Management
Posted by Roy Zafar at 7:19 AM 0 comments
Labels: Data Center, Virtualization
Wednesday, March 11, 2009
Desktop Virtualization – Has it hit your desk yet?
Written by David Ting
The discussion on desktop virtualization, or hosted virtual desktop, is heating up. Some view it as futuristic. Others say it is throwback to the world of mainframe computing. With economic concerns forcing businesses to take a hard look at expenses across the enterprise, however, there are many reasons this is such a hot topic.
In our current cost conscious world, the potential to reduce IT costs are obvious: virtualization significantly reduces the need for idle computing hardware and drastically lowers power consumption - especially in mission critical environments like healthcare where machines need to be on 24 hours a day. Lower power consumption comes from reducing the need to run lightly loaded but high powered CPUs at each desktop and delivering desktop sessions for multiple users from a server that can be heavily loaded. Most importantly, virtualization frees up IT from having to maintain large numbers of desktop systems that are largely user managed. It also eliminates the need to constantly re-image machines that have degraded through common usage. Imagine how many fewer head aches we would have if we could have a new copy of the OS Image everyday - and not have to suffer through the "plaque" build up that slowly kills performance.
This all sounds good. But, before diving headfirst into the virtualization pool, it's important to realize that the benefits of desktop virtualization also lead to a new security challenges - especially around managing user identities, strong authentication and enforcement of access policies.
With user identities being relevant in multiple points within the virtual desktop , coordinating and enforcing access policies becomes far more difficult and error prone as all the systems have to be in sync. Since one of the advantages of having virtual desktops is the ability to dynamically create desktops specific to the user's role within the organization, having a centralized way to manage user identities, roles and access (or desktop) policies is critical in this new virtualized environment. Allowing users to only access tailored desktops specific to their role or access location can be tremendously valuable in controlling access to computing resources. Being able to leverage a single location for authenticating users, obtaining desktop access rights and auditing session related information is equally important, if not more so, than what we have in a conventional desktop environment.
While it is still some time out before adoption becomes common - security capabilities and limitations present a barrier to adoption - we're beginning to see customers who need to address these issues - connecting the user identity with authentication and policy link all the way from the client to the virtualized session and even to the virtualized application.
Desktop virtualization has tremendous promise - however, until we can replicate the user's current experience --and more importantly--make it easier to set and enforce authentication and policy in this environment, there's still work to be done.
Posted by Roy Zafar at 7:50 AM 0 comments
Labels: Data Center, Virtualization
Friday, January 30, 2009
Windows Vista Virtualization: What You Need To Know To Get Started
By Danielle Ruest and Nelson Ruest
Microsoft's release of Windows Vista and its Service Pack 1 coincides with one of the greatest revolutions in the IT industry: the coming of virtualization technologies. VMware, Oracle, Citrix, Symantec, Sun Microsystems, Thinstall, Microsoft, and others have entered the fray to release products that are oriented towards virtualization.
(click image for larger view) Running Windows Vista through desktop virtualization. |
These products fall into two main categories.
- Machine virtualization lets you run complete operating systems within a virtualized layer on top of physical hardware, making better use of hardware resources. This level of virtualization is proving to be a boon to organizations at many levels seeking server consolidation, desktop virtualization, disaster recovery planning, and more.
- Application virtualization lets you "sandbox" applications so that they do not affect the operating system or other applications when deployed to a system. Application virtualization, or AppV, will make it much easier to manage application lifecycles because applications are no longer "installed" on systems, but rather, copied to systems.
Both of these technologies have a significant impact on Vista adoption. Overall, it is a good thing most organizations haven't moved to adopt Vista yet because they will be able to take advantage of virtualization in their deployment. Here's how.
A major barrier to Vista adoption is the hardware required to make the most of its feature set. While the base hardware requirements for Vista are not too unusual, considering the type of hardware that is available now, they are still important. Hardware refreshes are expensive, so whether you have 10 computers or 10,000, you need to plan and budget for hardware refreshes.
The table below outlines two sets of requirements for Vista: Vista Capable and Vista Premium PC configurations. The first allows you to run the base-level Vista editions and the second lets you take advantage of all of Vista's features.
| Vista Capable PC | Vista Premium PC | |
|---|---|---|
| Processor | At least 800 MHz | 32-bit: 1 GHz x86; 64-bit: 1 GHz x64 |
| Minimum Memory | 512 Mbytes | 1 Gbyte |
| Graphics Processor | Must be DirectX 9 capable | Support for DirectX 9 with a WDDM driver, 128 Mbytes of graphics memory*, Pixel Shader 2.0 and 32 bits per pixel |
| Drives | DVD-ROM drive | |
| Accessories | Audio output | |
| Connectivity | Internet access | |
| * If the graphics processing unit (GPU) shares system memory, then no additional memory is required. If it uses dedicated memory, at least 128 Mbytes is required. | ||
If you want to plan for the future, you should really opt for a Vista Premium PC. But what if you didn't have to be too concerned about hardware upgrades and could still have access to Vista's features? That is what machine virtualization can do. In fact, the common term for this process is desktop virtualization.
(click image for larger view) A virtual machine is really just a series of files in a folder. |
With desktop virtualization, you run Windows Vista inside a machine virtualization engine on a central server. Then you give users access to a virtual version of Vista through a remote connection. Users can continue to run older Windows operating systems on their actual desktops, but, through the remote session, access and use the new Vista feature set.
It is fairly easy to do this and you don't necessarily need a server to host the virtual Vista instance. Lots of manufacturers now offer machine virtualization technologies. What is even better is that many of these technologies are completely free! For example, Microsoft offers Virtual PC and Virtual Server 2005, VMware offers VMware Server, and Citrix offers XenServer Express, all for free. Others such as Oracle and Sun both offer free virtual machine engines -- Oracle offers Oracle VM and Sun offers xVM -- but their engines are not optimized for Windows operating systems, so you won't gain by using them for this purpose.
Of the three that do run Windows properly, the best choice might be Citrix XenServer Express since it is an operating system in and of itself. With the Microsoft and VMware offerings, you need to first load a supported OS on the host system, then load the virtualization engine. With XenServer, you just load XenServer, then create the virtual instances of the operating systems you need.
This arrangement can offer the best of all worlds. Here's why:
- When you run Windows Vista on a system, server, or PC, you need a license. All retail Vista licenses only allow one single instance of the operating system to run for each license. The Enterprise Edition, however, offers up to four virtual instances of Windows Vista for each license you own. Note that the only way to acquire the Enterprise license is through a Software Assurance program. This is often out of reach for small to medium businesses.
- If you use the Microsoft or VMware virtualization engines, you'll need a license for the OS running on the actual hardware system if you choose the Windows version. Then you'll need a license for each instance of Vista you want to run in a virtual instance.
- With VMware Server, you can choose the Linux version and run a "free" operating system on the hardware system. Microsoft does not offer a Linux version of its virtualization products.
- If you use XenServer Express, then you just need to load it onto a hardware platform. From then on you can create any instance of Windows Vista. Of course, each instance of Vista will require a license.
Whichever solution you choose, you'll gain lots of advantages by running Vista in a virtual machine. First, if you run it from a server, you can provide central backup and control of each machine. Second, because a virtual machine is really nothing but a series of files in a folder, it becomes really easy to create multiple machines; just copy the files and you have a new machine. Third, it becomes so much easier to protect machines because each machine is contained within itself. For example, if a virus attacks a virtual machine and corrupts it, just throw the virtual machine away and restore it from a backup. Voila! You're back to a working machine in no time. And finally, because the resources required to run the virtual machine are on the server or host machine, you don't need powerful resources at the endpoint to run Vista.
There is no doubt that machine, or rather desktop, virtualization is an attractive solution for a Vista migration. It might even be an attractive solution for the home user since you can use it to "sandbox" each Vista session and therefore protect all others. However, this is only really viable for the experienced home user.
You'll also need to keep in mind that the license for Windows Vista Home and Home Premium does not allow home users to run them in virtual machines. If you intend to use Vista in a virtual machine, it must be one of Business, Ultimate, or Enterprise and obviously, the latter wouldn't be available to home users.
A second major barrier to Vista adoption is application compatibility. Microsoft has modified several core components of the Windows code with Vista and, in many cases, this breaks applications. (See How to Manage Windows Vista Application Compatibility.)
If you decide that you don't want to centralize all your desktops and intend to deploy Vista on each one of your endpoints, then perhaps you need to take a really close look at application virtualization (AppV). AppV is much like machine virtualization, but instead of capturing an entire operating system installation, it captures each and every application you deploy on your systems. Basically, you "sandbox" each application so that it does not make any actual modifications at all when it runs on a system. This is all done through the use of an application virtualization agent that resides either within the application itself or on the operating system.
The single most powerful advantage AppV gives you is that, once an application is virtualized, it will run on any Windows operating system. Just think of it. Each time you move from one OS to another, you have to test all your applications, repackage them to meet target OS requirements, and then deploy them.
With AppV all that goes away since, once the application is virtualized, it will run on any Windows OS. And, because there are no changes to the target OS, you do not need to install the application, but rather simply copy it to the system. That's because AppV does not capture the application installation process like other systems do, it captures the running state of the application. That's powerful and may even warrant the adoption of AppV even if you don't migrate to Vista.
Like machine virtualization, several vendors have released AppV engines. Microsoft offers Application Virtualization 4.5. Symantec offers Software Virtualization Solution (SVS) through its Altiris division. Citrix offers AppV through Citrix XenApp (formerly Presentation Server 4.5). Thinstall offers ThinstallVS. Of these, only Symantec offers a free or personal edition of its AppV engine. This personal edition of SVS is fully functional and can be run on up to 10 PCs. What's even better is that the download site also includes over 40 pre-virtualized applications.
In many ways, application virtualization is even easier to use than machine virtualization. With AppV, the only thing you need to change is the model you use for application management. Home users can virtualize anything from Internet Explorer to full versions of Microsoft Office. Don't like what a recent Web site visit has done to your browser? Just reset the application and you're back to what you had before. This might just be the answer to what your kids need on the home PC.
Imagine, since Symantec's SVS is free for personal use, home computer manufacturers could pre-load it on their systems. Then, you could carry your applications around with you on a USB keychain. Want to do a bit of browsing, just plug in your USB and launch your favorite applications. Not that's something everyone can get their teeth around.
In the office, AppV is even more powerful. We've worked on a ton of migration and deployment projects and we know for a fact that the most time-consuming effort in any such project is application preparation. With AppV, you completely change the dynamics of any deployment project and put all of the application woes behind you. That's a powerful operating model.
There you have it: two different models that can let you move to Windows Vista at your own pace and on your own terms. Now there's no reason to delay. Move to one of the virtualization models first, then you can move to Vista once you've mastered these new IT operating models.
- For more information on migrating to Windows Vista, download the free eBook The Definitive Guide to Vista Migration by Ruest and Ruest.
- VMware Server
- Citrix XenServer Express
- Microsoft Virtual Server
- Microsoft Virtual PC
- Oracle VM
- Sun xVM
- Microsoft Application Virtualization
- Citrix XenApp (formerly Citrix Presentation Server)
- ThinstallVS
- Symantec Software Virtualization Solution
- SVS Downloads for Symantec SVS
- Windows Vista Licensing and Virtual Machines
Posted by Roy Zafar at 8:34 AM 0 comments
Labels: Computer Tips, Virtualization, Windows
Thursday, January 29, 2009
Virtualization Security: A Solution Looking For A Problem?
By Mike Fratto
One of the themes coming from RSA and from vendors in the last few months is the notion that virtual servers, whether running on a hypervisor or not, are somehow more at risk that physical servers. I don't buy it entirely because servers and applications that are virtualized tend to be in tightly controlled data centers. If your data center is secure, so are your servers. Why treat virtualized servers special?
The type of security, by the way, isn't ensuring separation of data and resources within the hypervisor, rather the security problem is that traditional network security functions like firewall, IDS/IPS, and content filtering are difficult to achieve within the virtual switch itself -- interserver server communications that never cross the wire. After expressing my skepticism to a few vendors at the show, the product pitches carried a hint of desperation or aggravation (I couldn't tell which), trying to convince my why security in the hypervisor is important.
The common statement and leading questions are:
- Well, having security near the servers is important, right? Yes, but that’s a leading question. What am I going to say, no, security near the servers is a bad idea? Thing is, a data center is unlike the rest of the network. It's a controlled environment where you should know what is happening, you don't have random users connecting to the wire, and server-to-server communications are contained within the data center. Communications passing beyond the data center perimeter can be controlled at the choke point.
- Which leads to the statement that the reason why there is often little internal security in the data center is the cost to deploy targeted security inside the data center and the relatively high-capacity requirements, which is often multi-GB to 10 GB or more. The bang for the buck is low. However, putting security functions in the hypervisor is less expensive than hardware. Not free, just less expensive, so the cost of license fees has to be accounted for and, of course, the performance hit within the virtualized environment.
- Virtulalization features like VMWares VMotion that allows a running VM to be moved seamlessly between hypervisors creates a far more dynamic environment than with standalone physical computers. Granted, the environment can be more dynamic, but if a company loses control of its virtualized servers, it has big problems anyway.
- Finally, initiatives using virtualized servers to create like virtualized desktops for users is an interesting use of virtualization, but do you really want to intermingle your users with your data center? That's like plugging your access switches directly into the data center. Virtual desktops should be partitioned off from the data center and treated like any other desktop.
All of this is great in theory and I could very well be missing the threats to virtualized servers, but I really don't see any difference in risk or threats between a server or application running on bare iron versus running on a hypervisor. If your data center has good controls and is following good management processes already, those processes will apply to all servers.
Granted, there are some considerations specific to virtualization, like preventing resource starvation, ensuring the hypervisor is properly hardened, ensuring that there are effective controls to make sure that VM resources such as memory, disk, CPU instructions, etc., within the same hypervisor are partitioned.
Like anything regarding security, you need to first determine what the threat vectors are to a resource, the who and how, first, and then develop controls to mitigate the successful exploitation of the threat. Once the controls are identified, you have to determine where to employ them in a virtualized environment. Interserver communication in an n-tier application may be controlled within the network if you can guarantee that various servers will always communicate through the physical network. That is an architectural process issue. However, if interserver communications occur between servers on the same hypervisor, then a hypervisor-based integrated product may be necessary and there are several vendors like Reflex Security or Montego Networks that have products to suit and I am sure there are others. Of course, there also are host-based solutions that can be used on servers real or virtualized. Just don't get caught up in the virtualization hype. A computer is a computer and good management practices are your only patch to success.
Posted by Roy Zafar at 8:00 AM 0 comments
Labels: Data Center, Virtualization