Download presentation
Presentation is loading. Please wait.
Published byKelly Potter Modified over 9 years ago
1
Patch Management Module 13
2
Module 2-421 You Are Here VMware vSphere 4.1: Install, Configure, Manage – Revision A Operations vSphere Environment Introduction to VMware Virtualization VMware ESX and ESXi VMware vCenter Server Networking Storage Virtual Machines Access Control Resource Monitoring Data Protection Scalability Installing VMware ESX and ESXi High Availability Patch Management
3
Module 2-422 Importance VMware vSphere 4.1: Install, Configure, Manage – Revision A Over time, your VMware vSphere™ environment might undergo change in its hardware or software configuration, or in the form of software updates or patches. From a manageability and scalability perspective, you should implement changes to your vSphere environment in an orderly, controlled, and systematic fashion.
4
Module 2-423 Module Objectives VMware vSphere 4.1: Install, Configure, Manage – Revision A Describe VMware vCenter™ Update Manager List the steps to install Update Manager Use Update Manager: Create and attach a baseline Scan an inventory object Remediate an inventory object
5
Module 2-424 Update Manager VMware vSphere 4.1: Install, Configure, Manage – Revision A Update Manager enables centralized, automated patch and version management for VMware® ESX™/ESXi hosts, virtual machines, and virtual appliances. Update Manager reduces security risks. Keeping systems up to date reduces the number of vulnerabilities. Many security breaches exploit older vulnerabilities. Reducing the diversity of systems in an environment: Makes management easier Reduces security risks
6
Module 2-425 Update Manager Capabilities VMware vSphere 4.1: Install, Configure, Manage – Revision A Automated patch downloading: Begins with information-only downloading Is scheduled at regular configurable intervals Contacts the following sources: For ESX/ESXi patching: https://hostupdate.vmware.com For Windows and Linux virtual machines and applications: https://www.shavlik.com For third-party patches: URL of third-party source Creation of baselines and baseline groups Scanning: Inventory systems are scanned for baseline compliance. Remediation: Inventory systems that are not current can be automatically patched.
7
Module 2-426 Update Manager Components VMware vSphere 4.1: Install, Configure, Manage – Revision A Shavlik patch source vCenter Server system Update Manager server database server vCenter Server database patch database VMware patch source Update Manager agents are installed into virtual machines. hosts optional download server VMware vSphere Client with Update Manager plug-in Internet patch database A A A A A A A A A third-party patch source
8
Module 2-427 Installing Update Manager VMware vSphere 4.1: Install, Configure, Manage – Revision A Update Manager must be installed on a 64-bit machine. To install, start the VMware vCenter Installer and click vCenter Update Manager. Information needed during the installation: vCenter Server host name, user name, and password Choice of database: use default or existing database Update Manager port settings: Host name, ports, proxy settings (if necessary) Destination folder and location for downloading patches To install the Update Manager client: Install the Update Manager Extension plug-in into the vSphere Client.
9
Module 2-428 Configuring Update Manager Settings VMware vSphere 4.1: Install, Configure, Manage – Revision A Modify Update Manager configuration properties. By default, all patch sources are enabled. Add third-party patch sources if necessary.
10
Module 2-429 Baseline and Baseline Groups VMware vSphere 4.1: Install, Configure, Manage – Revision A A baseline consists of one or more patches, extensions, or upgrades. There are five types of baselines: Host patch Host extension Host upgrade Virtual machine patch Virtual appliance upgrade Update Manager includes a number of default baselines. A baseline group consists of multiple baselines: Can contain one upgrade baseline per type and one or more patch and extension baselines example of default baselines for hosts
11
Module 2-430 Creating a Baseline VMware vSphere 4.1: Install, Configure, Manage – Revision A To create a baseline: 1.Click Create. 2.Specify name and description. 3.Choose a baseline type. 4.For a patch baseline, select a patch option: Fixed or Dynamic. 5.Select patches to add to the baseline. A host patch is added to this baseline.
12
Module 2-431 Attaching a Baseline VMware vSphere 4.1: Install, Configure, Manage – Revision A To view compliance information and remediate inventory objects, first attach a baseline or baseline group to an object. For improved efficiency, attach a baseline to a container object instead of to an individual object.
13
Module 2-432 Scanning for Updates VMware vSphere 4.1: Install, Configure, Manage – Revision A Scanning evaluates the inventory object against the baseline or baseline group. A scan can be performed manually or automatically, using a scheduled task. manual scan scheduled scan
14
Module 2-433 Viewing Compliancy VMware vSphere 4.1: Install, Configure, Manage – Revision A In this example, the scan found two noncompliant hosts. After the scan, a host object can be staged and then remediated.
15
Module 2-434 Remediating Objects VMware vSphere 4.1: Install, Configure, Manage – Revision A You can remediate virtual machines, templates, virtual appliances, and hosts. You can perform the remediation immediately or schedule it for a later date.
16
Module 2-435 Remediation Options for a Cluster VMware vSphere 4.1: Install, Configure, Manage – Revision A When remediating hosts in a cluster, you must temporarily disable certain cluster features: VMware DPM, VMware HA, FT. You can generate a report that identifies problems before remediation occurs.
17
Module 2-436 Patch Recall Notification VMware vSphere 4.1: Install, Configure, Manage – Revision A At regular intervals, Update Manager contacts VMware to download notifications about patch recalls, new fixes, and alerts. Notification Check Schedule is selected by default. On receiving patch recall notifications, Update Manager: Generates a notification in the notification tab No longer applies the recalled patch to any host: Patch is flagged as recalled in the database. Deletes the patch binaries from its patch repository Does not uninstall recalled patches from ESX hosts: Instead, it waits for a newer patch and applies that to make a host compliant.
18
Module 2-437 Remediation Enabled for DRS VMware vSphere 4.1: Install, Configure, Manage – Revision A Eliminate downtime for virtual machines when patching ESX/ESXi hosts: 1. Update Manager puts host in maintenance mode. 2. DRS moves virtual machines to available host. 3. Update Manager patches host and then exits maintenance mode. 4. DRS moves virtual machines back per rule. maintenance mode UM + DRS !
19
Module 2-438 Lab 27 VMware vSphere 4.1: Install, Configure, Manage – Revision A In this lab, you will install, configure, and use Update Manager. 1. Install Update Manager. 2. Modify cluster settings. 3. Install and enable the Update Manager plug-in. 4. Configure Update Manager. 5. Create a patch baseline. 6. Attach a baseline and scan for updates. 7. Stage patches and remediate ESXi hosts.
20
Module 2-439 Module Summary VMware vSphere 4.1: Install, Configure, Manage – Revision A Describe Update Manager List the steps to install Update Manager Use Update Manager: Create and attach a baseline Scan an inventory object Remediate an inventory object
21
Module 2-440 Key Points VMware vSphere 4.1: Install, Configure, Manage – Revision A Update Manager patches and updates ESX/ESXi hosts, virtual machines, templates, and virtual appliances. Update Manager reduces security vulnerabilities by keeping systems up to date and by reducing the diversity of systems in an environment.
Similar presentations
© 2024 SlidePlayer.com Inc.
All rights reserved.