ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    Food for thought: Fixing an over-engineered environment

    Scheduled Pinned Locked Moved IT Discussion
    designserver consolidationvirtualizationhyper-vstoragebackup
    91 Posts 9 Posters 10.0k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • EddieJenningsE
      EddieJennings @scottalanmiller
      last edited by

      @scottalanmiller said in Food for thought: Fixing an over-engineered environment:

      @coliver said in Food for thought: Fixing an over-engineered environment:

      @eddiejennings said in Food for thought: Fixing an over-engineered environment:

      I'd configure two Virtual switches on the Hyper-V host. One external and one private. Each VM would have two vNIC, one connected to each virtual switch. Private switch would be for traffic between the VMs, and external switch for Internet access.

      This seems unnecessarily complex for your environment. Any reason for doing this and not just a single virtual switch?

      I agree. What’s the benefit here?

      From the data that New Relic shows me, it looks like there isn't any. I guess I could make an argument that the SQL Server VM and the REDIS VM shouldn't have Internet access. The problem with that is two fold.

      1. I'd add the complexity of having WSUS or something to be able to feed those VMs Windows updates.
      2. It seems like having a way to RDP into those machines would be overly complex.
      1 Reply Last reply Reply Quote 0
      • coliverC
        coliver @EddieJennings
        last edited by

        @eddiejennings said in Food for thought: Fixing an over-engineered environment:

        Since my thought is to turn everything into a VM, it would be better performing to create a virtual private switch just for that VM-to-VM traffic rather than configure something that still utilizes the physical switch for such traffic. However, from what I'm seeing it doesn't look like separating that traffic onto its own private switch is necessary.

        I'm confused as to how you would see better performance? You're going to have more then one host correct? Unless you are planning on setting up an independent physical switch for host-to-host/vm-to-vm communication then everything would be going over the physical switch regardless. VLANs aren't for performance purposes they are for security purposes.

        1 Reply Last reply Reply Quote 0
        • DashrenderD
          Dashrender @EddieJennings
          last edited by

          @eddiejennings said in Food for thought: Fixing an over-engineered environment:

          Since my thought is to turn everything into a VM, it would be better performing to create a virtual private switch just for that VM-to-VM traffic rather than configure something that still utilizes the physical switch for such traffic. However, from what I'm seeing it doesn't look like separating that traffic onto its own private switch is necessary.

          The idea might have some credibility in the real world, but in a single host, where the traffic is all on vswitches, this won't really make any difference.
          Each VM with only one a single vswitch connection, all inter VM traffic will stay inside the hypervisor, never touching the physical switches. You team several 1 GB or upgrade to a 10GB NIC in the server (and a 10 GB port on the switch) and you shouldn't see that be a bottle neck at all.

          1 Reply Last reply Reply Quote 1
          • EddieJenningsE
            EddieJennings
            last edited by

            @coliver
            Right now, I'm planning on one host with multiple VMs. So if I had this separate, internal network, methinks performance would be better on a virtual private switch, rather than using virtual external switches bound to a physical NIC that is a part of a separate VLAN on the physical switch.

            On performance, you're right about VLANs, they're designed for security. I guess you could argue you'd reducing potential broadcast traffic, but in this situation that wouldn't matter, as the number of devices is the same. It looks more and more like the separate-network-for-server-to-server communication is unnecessary.

            @Dashrender
            You're right. The only time VM traffic would be going over a 1 GB link would be when that traffic has to travel over the physical NIC to the physical switch. Even if the virtual switch was an external switch, the VM to VM traffic would be going over the 10 GB virtual switch link.

            coliverC J 3 Replies Last reply Reply Quote 1
            • coliverC
              coliver @EddieJennings
              last edited by

              @eddiejennings said in Food for thought: Fixing an over-engineered environment:

              Right now, I'm planning on one host with multiple VMs. So if I had this separate, internal network, methinks performance would be better on a virtual private switch, rather than using virtual external switches bound to a physical NIC that is a part of a separate VLAN on the physical switch.

              Probably not. But you're talking yourself out of it now so I don't need to say anything else.

              EddieJenningsE 1 Reply Last reply Reply Quote 1
              • EddieJenningsE
                EddieJennings @coliver
                last edited by

                @coliver said in Food for thought: Fixing an over-engineered environment:

                @eddiejennings said in Food for thought: Fixing an over-engineered environment:

                Right now, I'm planning on one host with multiple VMs. So if I had this separate, internal network, methinks performance would be better on a virtual private switch, rather than using virtual external switches bound to a physical NIC that is a part of a separate VLAN on the physical switch.

                Probably not. But you're talking yourself out of it now so I don't need to say anything else.

                πŸ˜„ Yeah, during this thought process, I'll likely be talking myself out of most things that would be just a virtualized version of current architecture.

                DashrenderD coliverC 2 Replies Last reply Reply Quote 0
                • DashrenderD
                  Dashrender @EddieJennings
                  last edited by

                  @eddiejennings said in Food for thought: Fixing an over-engineered environment:

                  @coliver said in Food for thought: Fixing an over-engineered environment:

                  @eddiejennings said in Food for thought: Fixing an over-engineered environment:

                  Right now, I'm planning on one host with multiple VMs. So if I had this separate, internal network, methinks performance would be better on a virtual private switch, rather than using virtual external switches bound to a physical NIC that is a part of a separate VLAN on the physical switch.

                  Probably not. But you're talking yourself out of it now so I don't need to say anything else.

                  πŸ˜„ Yeah, during this thought process, I'll likely be talking myself out of most things that would be just a virtualized version of current architecture.

                  Definitely a hard thing to get over at times.

                  1 Reply Last reply Reply Quote 0
                  • coliverC
                    coliver @EddieJennings
                    last edited by

                    @eddiejennings said in Food for thought: Fixing an over-engineered environment:

                    @coliver said in Food for thought: Fixing an over-engineered environment:

                    @eddiejennings said in Food for thought: Fixing an over-engineered environment:

                    Right now, I'm planning on one host with multiple VMs. So if I had this separate, internal network, methinks performance would be better on a virtual private switch, rather than using virtual external switches bound to a physical NIC that is a part of a separate VLAN on the physical switch.

                    Probably not. But you're talking yourself out of it now so I don't need to say anything else.

                    πŸ˜„ Yeah, during this thought process, I'll likely be talking myself out of most things that would be just a virtualized version of current architecture.

                    So green field it. Ignore current infrastructure for a bit. How would you make this work in an ideal environment. Then look at where what you have now differs from that ideal. Are those differences necessary? Would moving them toward ideal adversely effect users?

                    1 Reply Last reply Reply Quote 5
                    • J
                      Jimmy9008 @EddieJennings
                      last edited by

                      @eddiejennings said in Food for thought: Fixing an over-engineered environment:

                      @coliver
                      Right now, I'm planning on one host with multiple VMs. So if I had this separate, internal network, methinks performance would be better on a virtual private switch, rather than using virtual external switches bound to a physical NIC that is a part of a separate VLAN on the physical switch.

                      If the VMs are on the same host no need to give them internal and external virtual NICs. They will communicate over the external virtual switch, but the traffic wont go to the physical NIC/out to the LAN.

                      You only want internal switch between VMs where they are only supposed to talk with each other/not be on a LAN.

                      1 Reply Last reply Reply Quote 1
                      • J
                        Jimmy9008 @EddieJennings
                        last edited by

                        @eddiejennings said in Food for thought: Fixing an over-engineered environment:

                        @coliver

                        On performance, you're right about VLANs, they're designed for security. I guess you could argue you'd reducing potential broadcast traffic, but in this situation that wouldn't matter, as the number of devices is the same. It looks more and more like the separate-network-for-server-to-server communication is unnecessary.

                        I didn't think they were for security...

                        I thought VLANs were purely for segregation of traffic to make quality of service/planning better. Yeah sure, something on VLAN1 wont interact with VLAN2... but its the same switch/hardware/cables. So I presume if I can get access to that kit with Wireshark or something id be able to get the traffic regardless of VLANs, and the fact they are VLANs wouldn't matter... Could be wrong here though (probably am)...

                        scottalanmillerS 2 Replies Last reply Reply Quote 1
                        • scottalanmillerS
                          scottalanmiller @Jimmy9008
                          last edited by

                          @jimmy9008 said in Food for thought: Fixing an over-engineered environment:

                          @eddiejennings said in Food for thought: Fixing an over-engineered environment:

                          @coliver

                          On performance, you're right about VLANs, they're designed for security. I guess you could argue you'd reducing potential broadcast traffic, but in this situation that wouldn't matter, as the number of devices is the same. It looks more and more like the separate-network-for-server-to-server communication is unnecessary.

                          I didn't think they were for security...

                          I thought VLANs were purely for segregation of traffic to make quality of service/planning better.

                          No that's the myth. They actually make those things worse. They make planning harder and confuse people about QoS. They add overhead and bottlenecks so you have to plan more and do more QoS just ot overcome the VLAN problems. VLANs are for security in some limited cases and for management on a massive scale.

                          1 Reply Last reply Reply Quote 0
                          • scottalanmillerS
                            scottalanmiller @Jimmy9008
                            last edited by

                            @jimmy9008 said in Food for thought: Fixing an over-engineered environment:

                            but its the same switch/hardware/cables. So I presume if I can get access to that kit with Wireshark or something id be able to get the traffic regardless of VLANs, and the fact they are VLANs wouldn't matter... Could be wrong here though (probably am)...

                            That's subnets that you are thinking of. If you can do that with a VLAN, it's not a VLAN πŸ˜‰ The definition of a VLAN means that that can't be done.

                            1 Reply Last reply Reply Quote 0
                            • scottalanmillerS
                              scottalanmiller
                              last edited by

                              Okay, I've not read everything but starting from the top...

                              Networking - VLANs are gone. You describe very clearly in the OP that they serve no purpose, don't talk about them again. Gone. Done. Over. One Big Flat Network, OBFN.

                              Servers - Definitely no need for more than one. Going down to just one will significantly improve your performance and your reliability. Right now your apps depend on the separate database server which depends on your SAN. That's an inverted pyramid with another tier. So instead of the normal three tiers of risk, you have five! Collapsing that down to one will make you so much more reliable. Hyper-V is fine. So is KVM.

                              Storage - This is easy, local disks. Either all SSD or one SSD pool and one spinner pool. That's all.

                              1 Reply Last reply Reply Quote 2
                              • scottalanmillerS
                                scottalanmiller
                                last edited by

                                REDIS should be on Linux, REDIS on Windows is crazy. It's expensive and slow.

                                EddieJenningsE 1 Reply Last reply Reply Quote 3
                                • EddieJenningsE
                                  EddieJennings @scottalanmiller
                                  last edited by

                                  @scottalanmiller said in Food for thought: Fixing an over-engineered environment:

                                  REDIS should be on Linux, REDIS on Windows is crazy. It's expensive and slow.

                                  I just finished reading a little on REDIS yesterday, and when I asked myself why we're running it on Windows, the answer came to me. Previous and most of current regime (I'm the exception) = if there's a way to do X with Microsoft, use Microsoft.

                                  travisdh1T scottalanmillerS 2 Replies Last reply Reply Quote 0
                                  • travisdh1T
                                    travisdh1 @EddieJennings
                                    last edited by

                                    @eddiejennings said in Food for thought: Fixing an over-engineered environment:

                                    @scottalanmiller said in Food for thought: Fixing an over-engineered environment:

                                    REDIS should be on Linux, REDIS on Windows is crazy. It's expensive and slow.

                                    I just finished reading a little on REDIS yesterday, and when I asked myself why we're running it on Windows, the answer came to me. Previous and most of current regime (I'm the exception) = if there's a way to do X with Microsoft, use Microsoft.

                                    sigh

                                    I'd have the same reaction to anyone that just defaulted to = if there's a way to do X with CentoOS, use CentOS mentality.

                                    coliverC scottalanmillerS 2 Replies Last reply Reply Quote 0
                                    • coliverC
                                      coliver @travisdh1
                                      last edited by

                                      @travisdh1 said in Food for thought: Fixing an over-engineered environment:

                                      @eddiejennings said in Food for thought: Fixing an over-engineered environment:

                                      @scottalanmiller said in Food for thought: Fixing an over-engineered environment:

                                      REDIS should be on Linux, REDIS on Windows is crazy. It's expensive and slow.

                                      I just finished reading a little on REDIS yesterday, and when I asked myself why we're running it on Windows, the answer came to me. Previous and most of current regime (I'm the exception) = if there's a way to do X with Microsoft, use Microsoft.

                                      sigh

                                      I'd have the same reaction to anyone that just defaulted to = if there's a way to do X with CentoOS, use CentOS mentality.

                                      Except one is saving the company money the other is costing them? Not sure if that's a direct corollary.

                                      1 Reply Last reply Reply Quote 0
                                      • scottalanmillerS
                                        scottalanmiller @EddieJennings
                                        last edited by

                                        @eddiejennings said in Food for thought: Fixing an over-engineered environment:

                                        @scottalanmiller said in Food for thought: Fixing an over-engineered environment:

                                        REDIS should be on Linux, REDIS on Windows is crazy. It's expensive and slow.

                                        I just finished reading a little on REDIS yesterday, and when I asked myself why we're running it on Windows, the answer came to me. Previous and most of current regime (I'm the exception) = if there's a way to do X with Microsoft, use Microsoft.

                                        Don't ask why not Microsoft, put it in dollars and ask why spending so much and not able to maintain the latest versions. Don't mention the tech, that's not how IT communicates. Make them see business terms, make them make business decisions.

                                        1 Reply Last reply Reply Quote 1
                                        • scottalanmillerS
                                          scottalanmiller @travisdh1
                                          last edited by

                                          @travisdh1 said in Food for thought: Fixing an over-engineered environment:

                                          @eddiejennings said in Food for thought: Fixing an over-engineered environment:

                                          @scottalanmiller said in Food for thought: Fixing an over-engineered environment:

                                          REDIS should be on Linux, REDIS on Windows is crazy. It's expensive and slow.

                                          I just finished reading a little on REDIS yesterday, and when I asked myself why we're running it on Windows, the answer came to me. Previous and most of current regime (I'm the exception) = if there's a way to do X with Microsoft, use Microsoft.

                                          sigh

                                          I'd have the same reaction to anyone that just defaulted to = if there's a way to do X with CentoOS, use CentOS mentality.

                                          Right, the reaction is "tech over business".

                                          1 Reply Last reply Reply Quote 1
                                          • EddieJenningsE
                                            EddieJennings
                                            last edited by EddieJennings

                                            I agree with the idea of thinking in terms of greenfield and using the hardware I have, rather than looking at how stuff is structure now and simply trying to replicate that but with VMs.

                                            Here's my current thought process about what VMs to make and storage.

                                            Current Server 2 becomes the new Hyper-V Host

                                            • This server has the best processor and most RAM of the other two.
                                            • Combine the Intel S3500 SSDs from the other two and create a RAID 5 array of the six 300 GB disks to have 1.5 TB of usable storage. This would leave two unused drive bays.
                                              • Between all of the servers right now 971 GB of storage is used. Perhaps RAID 6 with 1.2 TB of usable storage makes more sense.
                                            • Have five VM guests: IIS Server, SQL Server, REDIS, PostFix server, VM for what will become our backup solution

                                            For the REDIS, PostFix, and other VM, I plan on giving them each one VHD. I'm curious about your folks' opinions on storage for IIS and SQL Server.

                                            Current storage for the physical SQL Server:

                                            • Two SSDs in RAID 1 presenting a disk where the OS and SQL Server application are installed
                                            • Four SSDs in RAID 10 present a disk where it appears the actual database files are stores, as well as SQL Server's backups.

                                            Current storage for the physical IIS Server:

                                            • Two SSDs in RAID 1 presenting a disk where the OS and applications are installed
                                            • Four Winchester disks in RAID 10 presenting a disk where the files used by our web application / IIS are stored.

                                            For a virtualized SQL server and IIS , does it make sense to have separate VHDs for the OS / application and actual database files / virtual folders? Or would it be better to have a single VHD with separate partitions? Perhaps the greater question is there any advantage having such separation?

                                            scottalanmillerS 2 Replies Last reply Reply Quote 1
                                            • 1
                                            • 2
                                            • 3
                                            • 4
                                            • 5
                                            • 2 / 5
                                            • First post
                                              Last post