Friday, July 23, 2010

NFS, CIFS, and Zones


NFS, CIFS, and Zones

For years, users could not share NFS mounts from a Zone in Solaris. This may be about to change!

With PSARC/2010/280, there is a chance that we will see the ability to share NFS from a Zone, but I can only hope that we will be able to see overlapping shares, so we can share those same Zones shared from a Global Zone, simultaneously.

I hope we will be able to share the root zones via NFS from the global zone as well as directories separately from each individual zone. This is a great feature for hop-off servers.

Yes, the DMZ implementations do matter.

Tuesday, July 13, 2010

Solaris Crossbow Virtual Wire: Network in a Box



Solaris Crossbow Virtual Wire: Network in a Box

Abstract:

For 8 years, Sun has been re-developing the TCP/IP stack under Solaris. Nicolas Droux is involved as one of the core architects in Solaris in the process of re-architecting the TCP/IP stack. At the 23'rd Large Installation System Administration Conference (LISA-09), Nicolas presented over a short session describing the new features in Solaris TCP/IP from Project Crossbow.

Problems
  • Host Virtualilzation
  • Service Virtualization
Key Issues to Solve
  • Virtualizing Hardware NIC's
  • Zones Sharing a NIC
  • Maintain Performance
  • The desire is to allow the virtualized network stack to use as much of the hardware as possible.
  • Allow the Virtual Machines to understand how much bandwidth they are allowed to use, to keep zones from stepping on one another.
  • Management integrated into the stack itself, to avoid users having to look at multiple man pages.
  • Security to ensure badly behaved applications are not injecting bad packets on a shared network
8 Years of Development
  • Old code based upon Steams of solutions to resolve
  • closer integration of IP to TCP layers
  • data link, mac to IP
  • new interface to device drivers (Project Nemo)
  • IP QoS integrated, simplified, and made more efficient
  • Crossbow integrated at MAC layer
  • Requested more modern NIC features from hardware more hardware rings buffers, DMA Channels, and rich classifiers... building new features into the TCP/IP stack
Enablers & Key Opportunities
  • Server and Network Consolidation
  • Open Networking
  • Cloud Computing
Features
  • Hardware Lanes, to assign traffic to virtual NIC's, buffers, kernel threads, interrupts, the CPU threads, Zones, and/or Virtual Machines!
  • Stack adjusts flow based upon server load or traffic load, with ability to adjust interrupts, so large chains of packets can be pulled from the NIC without an interrupt per packet penalty
  • Virtual NIC's, pseudo-MAC instances, can be configured with bandwidth, priorities, and link aggregation, and assign V-NIC's on top
  • Bind: VLAN and Priority Flow Control to a V-NIC; hardware lan to a Switch
  • Virtual switch built automatically whenever 2 VNIC's are assigned to a Data Link
  • Virtual Switch can be built on EtherStubs, isolated from real hardware
  • Assigning a CPU Pool to a VNIC is coming
Implications to Hardware
  • Zones can replace real machines in a model in a Solaris model on a laptop
  • Virtual Switches can replace real switches in a Solaris model on a laptop
  • Virtual Routers can replace real routers in a Solaris model on a laptop
  • The configuration can be deployed in a production data center
Implications to Services: Crossbow Flows
  • Flows describes a type of traffic moving through a network
  • Flows can be described by: Services, Transport, Port Number, etc.
  • Properties can be attached to flows: Bandwidth, CPU, Priorities, etc.
  • Flows can be created on NIC's an V-NIC's
Question & Answers
  • Bandwidth can be assigned to a NIC, Bandwidth Guarantees to allow bursting was on the roadmap in 2009.

Monday, July 5, 2010

Political Posturing Holding Up Solaris, But Coming!


Political Posturing Holding Up Solaris, But Coming!

Mika Borner, leader of the Switzerland OpenSolaris User Group, which is sponsored by the Advocacy Community Group, recently had a NDA discussion with Dan Roberts (Director of Solaris Product Management.) His impressions of the future of Solaris have been recorded for all to see:
Oracle is still working out, how Solaris/Solaris Next/OpenSolaris will play together. As I understood, this is the main reason why OpenSolaris 2010H? is delayed.
New Solaris and/or SPARC releases on the way.
I can't tell you about the future of Solaris, but I see it quite rosy. The promises Oracle has made about Solaris/SPARC have/will more or less be fulfilled. There will be some interesting announcements ;-)
...

My personal opinion is, that Oracle will invest more into (Open)Solaris
than they will in Oracle Unbreakable Linux. In the former Oracle has full control, while the latter has to follow RHEL development closely.

The biggest question at the moment is, will OpenSolaris 2010H? come out
at all, and if yes, when... Honestly I don't know, but Oracle Open World could be a good time to release it.


New Solaris Releases During OpenWorld?

The question seems to be WHEN and HOW will the latest releases be conducted, not necessarily IF. Speculation seems to point around Oracle Open World 2010 in September. How this seems to it in could be tied into the various agenda items.
Oracle and Fujitsu Keynote Addresses, for SPARC Solaris communities.
Oracle and Intel Keynote Addresses, for Intel Solaris (and Linux & Microsoft) communities.
While never attending an Oracle Open World in the past, one would certainly be interested attending the next one virtually!


New UltraSPARC T3 Release During OpenWorld?

What the SPARC community is waiting for, with much anticipation, is the arrival of UltraSPARC T3 processor. This processor will help the SPARC community jump ahead of the competition in the central processor community for the next few years again.

The UltraSPARC T2, while still competitive from an aggregate socket performance perspective, is a little weak on cost competitiveness. With the doubling of cores on the T3, cost competitiveness should be increased.

Friday, June 25, 2010

Thin Clients: Partnering With IBM or Sun/Oracle



Introduction:
IBM basically invented the idea of the mainframe and terminals. Over the years, the rise of the mid-range gave an affordable alternative to mainframes and terminals. The Personal Computer, made popular in businesses by IBM, was originally considered a more flexible terminal, but started to become heavier with the advent of client-server computing, eventually eating away at the mid-range market. The technical workstation, designed to bring more powerful computing power for the desktop in an open architecture, was eventually replaced by the Personal Computer and Thin Client. With more computing infrastructure becoming virtualized, there is a heavy movement toward Thin Clients, but IBM is having difficulty partnering fairly.


Devon IT and IBM:
IBM partnered with Devon IT to provide a Thin Client solution for their blade servers. After IBM provided inflated numbers on two occasions to Devon IT, requested Devon IT for money in conjunction with development resources, Devon IT borrowed cash from a third-party two times to supply the cash with development, and IBM canned the project somewhere in the middle - the failed joint effort resulted in a lawsuit.


IBM iDataPlex, ClientPlex, and Devon TC5:
IBM is the RICO Defendant in this case. The case goes on, reading like a conspiracy in a modern history encyclopedia, but Line 67 is really difficult to get past, if true:
67. The RICO Defendants solicited and accepted a wire transfer payment of
$3,000,000 from Devon on March 1, 2008 under the iDataPlex Agreement after the Blade Project had been cancelled but before Devon was advised of the cancellation. Upon information and belief, the RICO Defendants did not advise Devon of the cancellation of the Blade Project until April, 2008 to ensure that the RICO Defendants and STG would receive the $3,000,000 development payment in March, 2008.

iDataPlex Agreement Restructure:
After Devon was abused by the previous agreement, Devon started the process of trying to get their money back through an IBM suggested restructuring:
101. ...According to Meyerson, expected sales would be at least 100,000 planars per quarter with a likelihood of more than 500,000 planar sales per quarter. Additionally, Meyerson represented that the part numbers would be readily available world-wide.
102. Ultimately, Meyerson agreed that IBM would pay Devon AD $100 per planar
sold through the second quarter of 2010, and $10 per planar thereafter until 2013 with certain specified caps that would set the total royalty at $9,100,000 through the second quarter of 2010 and at $14,700,000 through the fourth quarter of 2013. See Exhibit “G” at § 19.1.
103. Meyerson explained that the royalty stream of $100 per planar through the second quarter of 2010 was intended to return to Devon the $8 million that had been invested in the iDataPlex Project, plus reasonable interest. Meyerson characterized the revenue stream from the proposed restructuring of the iDataPlex Agreement as an “underhand pitch.” Upon information and belief, Meyerson agreed that IBM would return the $8 million owed to Devon with the restructuring of the iDataPlex Agreement as part of the unlawful accounting scheme identified and described in Paragraphs 1 - 6, 69 - 72.
104. On information and belief, Meyerson knew at the time of the negotiation of the
Restructured Agreements that Devon would not receive the IBM part numbers he had promised, that the information and estimates he provided regarding future royalties were inaccurate, and that Devon would not have agreed to the Restructured Agreements if he had truthfully disclosed the situation.

IBM iDataPlex Agreement Addendum:
IBM and Devon had an agreement that IBM would not market another Thin Client. After taking Devon's money, IBM went ahead and broke that agreement, as well.
106. Importantly, pursuant to the Addenda, STG, IBM’s hardware division, is
expressly prohibited until December 31, 2010 from, among other things, proactively enabling thin client hardware products which are “similar or reasonably equivalent in function to Devon’s TC-5 and/or TC-2 product…” See Exhibit “H” at § 2.0; Exhibit “I” at § 2.0.
107. Following the execution of the Addenda, upon information and belief, STG began
proactively enabling a very similar thin client hardware product developed by Wyse Technology (“Wyse”) in clear breach of STG’s obligations under the Addenda. STG’s breach and improper marketing of Wyse’s thin client terminal has undermined the competitive edge the Addenda were intended to give Devon’s TC5 and TC2 products.

Devon Co-Opted to Fund IBM Marketing Wyse:
What is even more unbelievable, IBM took money for marketing Devon products to promote a competitor's product, in breech of contract!
112. As further evidence of the depth of the IBM’s betrayal, in late August and early
September of 2009, Guevarez attended the VMWorld conference at the Moscone Center in San Francisco, California to promote Devon’s thin-client product. Devon incurred all the costs for Guevarez to attend this event on its behalf. However, instead of promoting Devon’s interests and products at the conference, Guevarez secretly created a marketing video with Maryam Alexandrian-Adams (“Adams”), Senior Vice President Worldwide Sales and Channels for Wyse, actively promoting Wyse’s partnership with the STG division and, more importantly, marketing and proactively enabling Wyse’s thin-client product, all in breach of IBM’s contracts with
Devon. The video is posted at http://www.youtube.com/watch?v=HYCwr27pko4 .

Agreement Restructure with IBM Unilateral Cancellation:
IBM promised the assignment of an OEM part number with royalties and promptly canceled the product upon agreement signature.
116. During the negotiations surrounding the Restructured Agreements, specifically
throughout June of 2008, Meyerson and other IBM employees continued to assure Devon that Devon’s TC5 thin client terminal would be assigned an IBM OEM part number. By having an IBM part number assigned to Devon IT’s thin client, the thin client would be released as a standard product from IBM and would have immediate name recognition and credibility in the market place by virtue of its association with IBM.
117. It was critical to the business of Devon IT that IBM follow through on its
assurance to OEM the TC5, and Devon relied on the representations that IBM would do so in entering into the Restructured Agreements.
118. However, promptly after Devon entered into the Restructured Agreements with
IBM and without consulting Devon, the RICO Defendants advised Devon that it had cancelled plans to assign the TC5 an OEM number

IBM Offers & Breaks Another Thin-Client Agreement:
After breaking the OEM Thin Client agreement, IBM agreed to market the Thin Client under a different program to make it more price competitive, but broke that agreement as well.
119. Instead of assigning the TC5 an OEM part number as originally promised,
Meyerson advised Devon that the TC5 instead would be marketed through IBM’s vlh program. According to Meyerson, Devon would enjoy greater monetary benefits through the vlh program than had IBM assigned TC5 an OEM part number because IBM would only mark up the sale price of the TC5 by only 5 - 10%, a much lower mark up than the mark up that would be made if the TC5 were assigned an OEM part number.
...
122. However, despite the representations from Meyerson that Devon’s TC5 would be marketed at a competitive price, the RICO Defendants proceeded to mark up the TC5’s sale price by a substantially higher amount than the 5 – 10% than had been represented, thereby making it exceedingly expensive and less appealing to customers.
123. Upon information and belief, had the RICO Defendants assigned an OEM part
number to the TC5 as originally promised, Devon would have likely garnered $900 million from the OEM program.

A Well Established Alternative for Thin Clients:

While IBM had been extracting funding from Thin Client manufacturers to defraud stock investors regarding financial performance and demonstrating very little commitment to the Thin Client market, there has been another vendor who has heavily invested in the Thin Client community: Sun and Oracle.

While IBM was working to put Thin Client vendors out of business by allegedly defrauding them of their money, there are many success stories with SunRay Thin Clients.


Thin-Client Sampling from Sun & Oracle:

There were many thin clients which were made available from Sun, some manufactured by different companies. A sampling from each generations follows:


Sun had produced Thin Clients for internal and external use for over 10 years. The very first SunRay 1 client is still compatible with the existing framework, even though it is over 10 years old. What made this client so attractive was the ability to plug in existing desktop components and give the user the ability to just throw out the PC.


There was also an all-in-one first generation SunRay 170 that was available. Very sleek and stylish. Keep the old keyboard with mouse and dump the monitor and PC.


The second generation SunRay 2 thin client offered additional capabilities such as encryption with the additional horse power on-board while being half the size with half the power consumption.


An ergonomic and slim all-in-one SunRay 270 was also made available.


New to the family was a SunRay 2N laptop! Yes, if it is stolen, there is no fear regarding loss of data. Use it from home, office, or StarBucks with no fears.


After Sun was purchased by Oracle, there was ripe speculation in the industry concerning what would happen to the hardware business in Sun. This was put promptly to rest with the new SunRay 3. This client is incredibly robust, supporting Fiber or Copper networking, with extremely robust dual-DVI monitor support of "up to 2560 x 1600 resolution for a single display or 5120 x 1600 for two displays".


Robust Thin Client Community:
Wikipedia offers a nice summary of the SunRay systems. A robust Thin Client community surrounds Sun and Oracle. The mailing list for a Sun-Ray Users Group is active, with an open mail archive. Sun Ray laptops like the Comet15 were produced by third-party vendors such as Tadpole. Other vendors such as General Dynamics make entire lines of mobile or desktop thin clients.

Network Management:
We always try to take the reader back to the point... what does this have to do with Network Management?

When building out help desks and network operation centers, the sensible way to manage these facilities is leveraging thin clients. Low paid help desk workers should never have the ability to take intellectual property home from a PC using simple disks, usb sticks, or email. High paid network operation center workers have access to critical data regarding a companies operations and this type of data should also be protected. In both of these environments, the crash or virus on a PC means a loss in productivity, which can be avoided through a simple thin client hardware swap.

There is no better way to build out a secure Network Operations Center than to leverage SunRay Thin Clients.

Conclusion:
As virtualization continues to increase and move powerful clients appear in the market desiring to access data on the internet, Thin Client usage will continue to grow. The SunRay is a stable environment to grow upon, holding an excellent track record for over a decade.

Tuesday, June 15, 2010

Finding Spares and Information and for a Test Lab?


Finding Spares and Information for a Test Lab?

When one is not in need of hardware or software support, eBay is a great place to go.
There are some nice on-line system handbook entries for the older systems, if you don't have a service contract.

Of course, if you need some documents, this is a great place to go.

Don't forget the system news, for Solaris & SPARC news information not isolated to Oracle!

Wednesday, June 9, 2010

Finding Firefox for Solaris

Looking for a recent version of FireFox for Solaris?

Solaris ships with a fairly old version, so that is not the place to go.

There is always sunfreeware.com - the authoritative place to find SVR4 packages of reasonably recent software for all modern versions of Solaris. Steven M. Christensen provides a level of continuity that Sun (and now Oracle) do not afford to provide. You can find packages dating back to Solaris 2.5 - providing support for systems over a decade and a half old.

If you are interested in the latest & greatest - you can go to Mozilla firefox release repository.
[DIR] 3.0.18/                   16-Feb-2010 20:18    -  
[DIR] 3.0.19-real-real/ 15-Mar-2010 20:52 -
[DIR] 3.5.8/ 03-Feb-2010 12:23 -
[DIR] 3.5.9/ 17-Mar-2010 12:17 -
[DIR] 3.6.2/ 30-Mar-2010 11:27 -
[DIR] 3.6.3/ 05-Apr-2010 13:13 -
[DIR] devpreview/ 19-May-2010 10:41 -
[DIR] latest-3.0/ 15-Mar-2010 20:52 -
[DIR] latest-3.5/ 17-Mar-2010 12:17 -
[DIR] latest-3.6/ 05-Apr-2010 13:13 -
[DIR] latest/ 05-Apr-2010 13:13 -

Looking in the "latest" tree - where are the Solaris packages?
[DIR] contrib-localized/ 01-Apr-2010 14:16 -
[DIR] contrib/ 02-Apr-2010 22:41 -
[DIR] linux-i686/ 01-Apr-2010 12:36 -
[DIR] mac/ 01-Apr-2010 12:15 -
[DIR] source/ 02-Apr-2010 14:04 -
[DIR] update/ 01-Apr-2010 15:46 -
[DIR] win32-EUBallot/ 01-Apr-2010 15:16 -
[DIR] win32/ 01-Apr-2010 14:09 -

The Solaris packages are unfortunately contributed under "contrib"...
[DIR] solaris_pkgadd/ 02-Apr-2010 22:41 -
[DIR] solaris_tarball/ 02-Apr-2010 23:19 -

The Solaris packages are unfortunately contributed under "contrib"...

Creating a home directory for root in Solaris 10

Abstract: In Solaris 10, '/' is the default home folder for root. While effective, it's also messy, allowing root's personal files and directories to intermix with the system files. The following explains how to clean up the '/' directory and is easiest if done immediately after installing Solaris. Before starting: you'll need root access to complete the following and you should decide on the new root folder location.
Recommended root folder locations:
/root (the one used later in this post)
/export/home/root (consistent with other user home directories on the system)

Login: non-root account
(Create one with the useradd command as root if necessary.)

$ su
Password: root-password
# usermod -d /root -m root
# exit


What just happened:

su assumed super user role

usermod -d /root -m root modified the root account with these options:

-d /root root's new directory is /root

-m makes(creates) the new directory

root user account that is modified

exit some changes can't be made while the user is logged in

Now to move root's personal files to the new home folder.

# ls -al /
# mv root-personal-files
# cp possible personal files

Examine the 'ls -al /' results. Leave everything owned by 'sys' in the / directory.
Directories: most directories in /, especially large ones with lots of sub-directories, stay in /. If you think but aren't sure that a directory belongs in the new home directory, leave a copy in / and put a copy the new home directory.
Individual files: especially .files like .profile probably belong in your folder.