| Windows Server 2012 Version | Physical Memory Limit |
| Foundation | 32GB |
| Essentials | 64GB |
| Standard | 4TB |
| Datacenter | 4TB |
| Storage Server 2012 Workgroup | 32GB |
| Storage Server 2012 Standard | 4TB |
| Hyper-V Server 2012 | 4TB |
Nuffnang
Tuesday, December 3, 2013
Microsoft Windows Server 2012 Memory Limits
Monday, November 18, 2013
Block Youtube flash videos in Squid
Steps to block all youtube flash videos in Squid proxy server.
Add the below configurations to squid.conf file.
[root@server ~#]vi /etc/squid/squid.conf#1: Create an acl for flash video contents
acl flash rep_mime_type video/x-flv
#2: Deny flash videos by denying the above acl
http_reply_access deny flash
#Save the squid.conf file
#3: Reload squid service to take effect changes
[root@server ~#]service squid reloadTuesday, November 5, 2013
Block https sites in squid (eg: block https://www.facebook.com)
Step1: Create a new acl with facebook.com (Dont forget to add a dot (".") before facebook.com)
acl badsites dstdomain .facebook.com
Step2: Deny the above domain to connect via ssl connection (https)
http_access deny CONNECT badsites
Friday, October 18, 2013
OpenStack Havana
On October 17, OpenStack's Havana, the eighth release of this IaaS for
public, private, and hybrid clouds, brings its enterprise
customers several new improvements.
In the real world, OpenStack sees these features playing out in the following ways:
Application Driven Capabilities: OpenStack Orchestration is a template driven service for describing and automating the deployment of compute, storage and networking resources for an application. The new global clusters feature for Object Storage enables you to cut costs and improve performance by replicating and delivering data around the world, and the new QoS capability across Block Storage drivers allows you to guarantee performance requirements for an application. Docker support was also added to speed application deployment using virtualization containers.
Improved Operational Experience: The Dashboard user interface (UI) has also been improved. OpenStack Metering now provides managers with a single source of usage data across OpenStack services for activities like enterprise chargebacks and feeding systems monitoring tools.
In the real world, OpenStack sees these features playing out in the following ways:
Application Driven Capabilities: OpenStack Orchestration is a template driven service for describing and automating the deployment of compute, storage and networking resources for an application. The new global clusters feature for Object Storage enables you to cut costs and improve performance by replicating and delivering data around the world, and the new QoS capability across Block Storage drivers allows you to guarantee performance requirements for an application. Docker support was also added to speed application deployment using virtualization containers.
Improved Operational Experience: The Dashboard user interface (UI) has also been improved. OpenStack Metering now provides managers with a single source of usage data across OpenStack services for activities like enterprise chargebacks and feeding systems monitoring tools.
More Enterprise Features: OpenStack
continues to mature and support enterprise driven features such as
end-to-end encryption across all Block Storage drivers, Secure Socket
Layer (SSL) support across all service application programming
interfaces (APIs), new virtual private network (VPN) and
Firewall-as-a-Service (FaaS) capabilities. All users will be happy to
see better support for rolling upgrades and boot from volume, which
provides the foundation for live migration. Last, but not least, popular
storage and networking providers continue to improve and write new
plug-ins for OpenStack, making it easier for enterprises to work with
their trusted vendors and take advantage of existing infrastructure.
Saturday, October 5, 2013
How to create an encrypted zip file on Linux
The zip command line tool provides an encryption option. The encryption algorithm used by zip command is PKZIP stream cipher. The PKZIP algorithm is known to be insecure. Also, the fact that the password is typed and shown in plain text makes it even more vulnerable.
To create an encrypted zip file with zip:
To create an encrypted zip file with zip:
$ zip --password MY_SECRET secure.zip doc.pdf doc2.pdf doc3.pdf
To uncompress a zip file that is encrypted with zip command:
$ unzip secure.zip
Archive: secure.zip [secure.zip] doc.pdf password:
Sunday, September 22, 2013
vSphere 5.5 : Technical Details
Improved Security
There's no longer a dependency on a shared root account when using the ESXi Shell. Local users who are assigned administrative privileges automatically have full shell access—there's no need to "su" to run commands as the root user.
Extensive Logging and Auditing
vSphere 5.5 logs all user activity from both the Shell and the Direct Console User Interface under the user's account. This logging ensures user accountability and makes it easy to audit user activity.
Enhanced vMotion
Live virtual machine migration allows you to combine vMotion and Storage vMotion into a single operation. For small virtual infrastructure implementations, combined vMotion migration means that the entire virtual machine (memory, CPU and disk) moves from one host to another. In larger environments, enhanced vMotion means that you can live-migrate entire virtual machines from one cluster to another, even if those clusters don't share storage.
New Virtual Hardware
vSphere 5.5 introduces a new generation of virtual hardware with virtual machine hardware version 9, which includes the following features:
Virtual machines can now support up to 64 virtual CPUs.
Virtual machines can support up to 1 TB of RAM.
New Advanced Host Controller Interface (AHCI) supports up to 120 devices per virtual machine.
Maximum VMDK size increased to 62TB.
Guest OS Storage Reclamation returns disk space to the storage pool when it's de-allocated from within the guest OS.
Improved CPU virtualization by exposing more information about the host CPU architecture to virtual machines. This improved CPU exposure allows for better debugging, tuning and troubleshooting of operating systems and applications within the virtual machine.
Active Directory Integration
You can join vSphere hosts to your Active Directory domain. Once added, Active Directory handles user authentication and removes the need to create user accounts on each host.
Centralized Management of Host Image and Configuration via Auto Deploy
Combining the features of host profiles, Image Builder and PXE, vSphere Auto Deploy simplifies host installation and upgrade. The Auto Deploy library centrally stores all vSphere host images. Administrators can automatically provision new hosts based on user-defined rules and host rebuilds are as simple as a reboot.
Stateless Firewall
vSphere ESXi now features a service-oriented and stateless firewall, which you can configure using the vSphere client or at the command line with ESXCLI. The new firewall engine eliminates the use of IPTABLES and allows administrators to define port rules for services. Additionally, you can specify IP ranges or individual IP addresses that can connect to host services.
Saturday, September 14, 2013
Protect DNS
Best practice protection approaches for DNS software are as follows:
• Running the latest version of name server software, or an earlier version with appropriate patches
• Running name server software with restricted privileges
• Isolating name server software
• Setting up a dedicated name server instance for each function
• Removing name server software from nondesignated hosts
• Creating a topological and geographic dispersion of authoritative name servers for fault tolerance
• Limiting IT resource information exposure through two different zone files in the same physical name server (termed as split DNS) or through separate name servers for different client classes.
• Running the latest version of name server software, or an earlier version with appropriate patches
• Running name server software with restricted privileges
• Isolating name server software
• Setting up a dedicated name server instance for each function
• Removing name server software from nondesignated hosts
• Creating a topological and geographic dispersion of authoritative name servers for fault tolerance
• Limiting IT resource information exposure through two different zone files in the same physical name server (termed as split DNS) or through separate name servers for different client classes.
Subscribe to:
Posts (Atom)