Category: Astaro


I got Hyper-v working finally here at my office.  I now have one box hosting 3 virtual mahcines.  VM 1 is my Astaro firewall.  VM 2 is my main AD file/print/authentication server.  VM 3 is my Astaro Command Center which aggregates status and updates from my astaro and my other client installs to me.  This allows me to monitor all of my Astaro easily in one spot without having to constantly individually touch each machine.  My power usage used to idle at nearly 130 watts.  My idle power now hovers around 60 watts.  I now average less than 90 watts which means nearly half of my power budget is now gone.  The host machine is running server 2008 R2 enterprise with Hyper-v.  It has three physical nics.  It also mirrors all functions of the main server except for file serving.

As for resource allocation here is the breakdown:

VM1: 4 vcpus, 2 gigs of ram(static), 3 virtual nics, 80 gigs of dynamic storage on RAID 1, 25% total system cpu ghz reserved with the ability to burst to 50% usage with medium priority.

VM2: 2 vcpus, 2 gigs ram(static), 1 virtual nic, 500 gigs of dynamic storage assigned on it’s own raid 1 array,  0% cpu reservation with burst to 25% cpu with medium priority.

VM3:  4 vcpus, 1 gig ram(static), 1 virtual nic, 120 gigs of dynamic RAID 1 storage, 0% cpu reservation with burst to 25%.

 

Right now the host machine spends most of it’s time at idle.  Considering how little power this draws it will pay for itself in under 1 year.

 

I currently have two virtualization projects going.  One is to convert 3 physical server to hyper-v and one is to convert 3 physical servers to KVM.  Unfortunately p2v on a domain controller is not only not recommended, it doesn’t work well.  Also there is no supported upgrade path from server foundation to anything but standard.  I have foundation and enterprise.  So I am firing up a new enterprise vm and then will manually mount the vhd from foundation backup to grab the files.  It’ll be a permissions nightmare for a bit but i’m used to that..:)  Once i get my AD domain migrated then it is time for Astaro.  Then i decom two boxes saving myself 200 watts of continuous draw.  The draw goes down to about 60 watts.  Keep watching for the KVM conversion.  That one is going to be easier.

I just passed the Astaro Certified Administrator course.  The next one is the Astaro Certified Engineer.  These will help further my status and abilities as an Astaro partner.  These courses I ahve found to be a good use of time and actually add to my knowledge of the Astaro product even though I have been using the Astaro Security Gateway for nearly 10 years…:)

The issue was the licensing server is in Germany and therefore you have to create licenses according to German time..at least that is how it was. They have fixed that issue. The licenses now work as they should..:) There was quite a bit of debate about leaving a local admin account. As usual i’m out on a limb myself…but that’s nothing new..:)

http://www.astaro.org/astaro-gateway-products/hardware-installation-up2date-licensing/37626-my-astaro-horror-story.html

The license itself is borked. I just re-applied my “home” license and it worked fine. I then created an eval license and installed that to “upgrade” the other “home” license…that worked. Installing my new license on top of the eval license borked things..the license is hosed….not looking good for sophos/Astaro..and the anti-sophos folks have more ammo now and depending on what happens tomorrow i may be joining the anti-sophos/Astaro club.

I’ve gone a while before making a first purchase. Right now i’m not sure I’m going to be making another one. I purchased a license for my church recently. At a cost(even with my partner discount) equal to 25% of my entire annual IT budget. The key given to me was not the one i needed to create the license. It took a few days(things being over the memorial day holiday) for the US office to get to me..i don’t fault them on that aspect. I finally get my activation key and my upgrade key. I upgrade the church’s license. I then install the new license to the church’s machine. All hades broke loose then. ALL subscriptions come up as invalid. Also my AD link is severed. I am now at a base license because the Astaro says all of my licenses are invalid or expired. I try a reboot and i am locked out of the webadmin. I NEVER leave the local account active(shouldn’t have to in my book) so i now have a dead astaro. I now have to wait until tomorrow for support to fix this. Meanwhile I get to spend an hour or so tonight rebuilding what was once a perfectly working box. I’m going to loose all of my logs, quarantine and everything else. Luckily i have a backup of my config. This is unacceptable form an “enterprise vendor”. Is this the new norm after the sophos takeover? I hope not. I will post updates as they come in.