cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
958
Views
2
Helpful
2
Replies

VEM installation locations/options question

RAMAN AZIZIAN
Level 1
Level 1

Fellow Engineers,

I know my question will be redundant, and I have done all I can to search the community, but I am very new to the 1000V deployment, and I would greatly appreciate any feedback/information in regard to the questions that i have.

We recently installed a pair of 1010's. We have allocated so far 3 VSB/VSM on the 1010's.

My main question is as follow;

VEM upgrade:

To upgrade the VEM software, does the ESX host need to point to the VSM repository to pull down the software, or can it be fetched from:

VUM

Manual

vcenter

VEM addition to the ESX

If there is a new ESX host being installed, and it does not have the VEM image, what options/locations can the ESX server point to, to pull down the VEM software:

VUM

Manual

Web site

vcenter

VSM

One of the issues that we are dealing with is the ACL we apply on each 1010 appliance and the VSM/VSB module for management. Our customer requires a specific ACL's to be applied to allow certain host to have access to the each component (1010, VSM, etc) to perform management tasks. There was a question about Software upgrade and fetching VEM software to a new ESX host.

The question was in regard to adding the ESX host IP address to the ACL list. With this method, we would have to add each host (ESX Server) to the Management ACL list, and I know this can cause problems due to errors or just sheer amount of work that will be required.

I hope my questions make sense, and I will be glad to provide any additional information that you may have.

Thanks for taking the time to provide me feedback.

Raman Azizian

2 Replies 2

Robert Burns
Cisco Employee
Cisco Employee

Raman,

Answers inline.

Regards,

Robert

VEM upgrade:

To upgrade the VEM software, does the ESX host need to point to the VSM repository to pull down the software, or can it be fetched from:

VUM

Manual

vcenter

[Rob] The VSM does not push any VEM software to the ESX hosts.  It's pushed by vCenter VUM or installed manually with vCLI, vihostupdate or vMA.  When VUM is installed there's a Cisco specific respository added which contains all the posted versions of VEM software.  Assuming VUM is correctly setup, it will push the appropriate software to the host when it has been added to the 1000v vDS.  Alternately you can manually install the .vib using one of the host update or command line utilities.  The VEM software .vib files are bundles with each VSM and accessble from http://<VSM-IP-Address>.  If the required .vib version is not present you can download the latest from either CCO or VMware's website.  This is all documented in the upgrade guides:

http://www.cisco.com/en/US/docs/switches/datacenter/nexus1000/sw/4_2_1_s_v_1_4_a/upgrade/software/guide/n1000v_upgrade_software.html

http://www.cisco.com/en/US/docs/switches/datacenter/nexus1000/sw/4_2_1_s_v_1_4_a/install/vem/guide/n1000v_vem_install.html

VEM addition to the ESX

If there is a new ESX host being installed, and it does not have the VEM image, what options/locations can the ESX server point to, to pull down the VEM software:

VUM

Manual

Web site

vcenter

VSM

[Rob] See previous comment. 

One of the issues that we are dealing with is the ACL we apply on each 1010 appliance and the VSM/VSB module for management. Our customer requires a specific ACL's to be applied to allow certain host to have access to the each component (1010, VSM, etc) to perform management tasks. There was a question about Software upgrade and fetching VEM software to a new ESX host.

The question was in regard to adding the ESX host IP address to the ACL list. With this method, we would have to add each host (ESX Server) to the Management ACL list, and I know this can cause problems due to errors or just sheer amount of work that will be required.

[Rob] All software updates are normally performed by VUM and therefore use the same TCP ports for accessing vCenter.  Hosts do not pull software from the VSM directly.  For required Firewall ports to be opened concerning the 1000v, please see my other post here:

https://supportforums.cisco.com/thread/2070391

Robert,

I appreciate you quick response.

I have a better understanding now in regard to the Upgrade/Addition of VEM software.

Best Regards,

-raman

Review Cisco Networking for a $25 gift card