Professional Documents
Culture Documents
Vmware Vcloud
Vmware Vcloud
CopyrightlTrademark
Copyright © 2013 VMware, Inc. All rights reserved. This manual and its accompanying
materials are protected by U.S. and international copyright and intellectual property laws.
VMware products are covered by one or more patents listed at http://www.vmware.com/go/
patents. VMware is a registered trademark or trademark of VMware, Inc. in the United States
and/or other jurisdictions. All other marks and names mentioned herein may be trademarks
of their respective companies.
The training material is provided "as is,' and all express or implied conditions,
representations, and warranties, including any implied warranty of merchantability, fitness for
a particular purpose or noninfringement, are disclaimed, even if VMware, Inc., has been
advised of the possibility of such claims. This training material is designed to support an
instructor-led training course and is intended to be used for reference purposes in
conjunction with the instructor-led training course. The training material is not a standalone
training tool. Use of the training material for self-study without class attendance is not
recommended .
These materials and the computer programs to which it relates are the property of, and
embody trade secrets and confidential information proprietary to, VMware, Inc. , and may not
be reproduced, copied , disclosed, transferred, adapted or modified without the express
written approval of VMware, Inc.
Course development: Daniel Crider, Rob Nendel
Technical review: Carla Gavalakis, Tom Thomas, Mike Sutton, Steve Schwarze, Jerry
Ozbun, Lizann Dunegan, Phil Cohen , Andy Cary, John Krueger, David Johnston, Jerry Davis
Technical editing: James Brook
Production and publishing: Ron Morton
WWIN. vmware.com/education
TABLE OF CONTENTS
Lab 1: Configuring VMware vCloud Director Networking .. . ....... ... . .. .. . ... . .... 1
Lab 2: Configuring YMware vCloud Director Network Pools . . ... . . .. .. .. . ... . . ... . .... 7
Lab 3: Creating Provider Virtual Datacenters . . . . . . . . . . . . . . . . . . . .................. . 11
Lab 4: Organizations . . . . . . . . . . . . . . . . . . . . . . . . . . . .. . .......... . .... . .... . ........ 17
Lab 5: Creating VMware vCloud Director vApp Templates .......... . . . . .. . . . . ....... . ... 31
Lab 6: Building and Publishing YMware vCloud Director vApps . . ..... . ... . . . ....... . ... 41
Lab 7: Deploying YMware vCloud Director vApps . . . . . . . . . . .............. . . ....... 51
Lab 8.' YMware vSphere vApp Networking ......................... . .. . ..... . .... . ... 61
Lab 9: Hosting Inbound Services ............. . .. . ................ . . . . .............. 69
Lab 10: Managing Custom Security Roles .................. .. . . . .......... . ... 79
Lab 11: Integrating LDAP and Active Directory ..... . ... . ... . .. .. .. .... ....... .... . .. .. 83
Lab 12: Managing Cloud Resources .............. . .. . . . . . .. . .. . .. . .. . . . . . . . ..... .... 89
Lab 13: Managing Organization Resources ......... .. .. . . .. .. .. . .. . . . . .. . . . .. . . . . . . .. .95
Lab 14: Managing VMware vSphere Resources ..... . ... . . .. . .. .. . ... . ........ . ..... . . 103
Lab 15: Monitoring Cloud Components. . . .... . . . . . .. ... . . .. . ................... . . 111
Lab 16: Organization Users . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .119
Lab 17: Installing VMware vCloud Director .. .. . . . . . .... . ... ..... . .. 127
1. Install licenses.
2. Configure resource cluster network settings for vCloud Director external networks.
3. Create a vCloud Director external network.
Username administrator
Password vmware I !
3. On the ControlCenter desktop, double-click the Web-Console shortcut and click the Continue
to tbis website (not recommended) link.
4. Log in to the vSphere Web Client console using the following credentials.
User ID administrator
Password vmwarel!
Setting Action
Name Type Production and click Next.
5. Click Next.
6. Click Finish.
1. In Internet Explorer, open a new browser tab and type the URL of the vCloud Director server:
http://vcd.vcd-ad.vclass.local
2. Click the Continue to this Website (not recommended) link and log in to the vCloud Director
console, using the following credentials.
Username administrator
Password vmware 1 !
Setting Action
Gateway address Type 172 .20 . 11.10.
8. Click OK
9. Click Next.
10. Under Name this External Network, in the Network name text box, type Production and
click Next.
11 . Under Ready to Complete, click Finish.
2. In the left pane, right-click vCloud Datacenter and select New Distributed Switch.
3. In the New Distributed Switch wizard, perform the following actions.
Setting Action
Name Type dvs-VLAN-Pool and click Next.
Default port group Deselect the check box and click Next.
4, Click Finish.
5. When the dvs-VLAN-Pool switch appears in the left pane, right-click dvs-VLAN-Pool and
select Add and Manage Hosts.
6. In the Add and Manage Hosts wizard, leave Add Hosts selected and click Next.
7. Click the Add New Hosts icon, which appears as a green plus (+) sign.
8, In the Select new hosts panel, select the esxi01.vcd-ad.vc1ass.1ocal and esx02.vcd
ad.vc1ass.1ocal check boxes, and click OK
IU.iii
If you are not already logged in to the vCloud Director console, open a new Internet Explorer
tab and log in to the vCloud Director console using the information in "Preparing for the lab."
2. In the vCloud Director console, click 4 Create a network pool.
3. In the Create Network Pool wizard, leave VLAN-backed selected and click Next.
4. Under Configure VLAN-backed Pool, in the VLAND ID range text box, type 200 - 2 9 9 and
click Add.
5. In the vCenter list, select vCenterServer.
6. In the vDS list, select dvs-VLAN-Pool.
7. Click Next.
8. Under Name this Network Pool, type ORG-VLAN-Pool in Name and click Next.
9. Under Ready to Complete, click Finish.
Remain logged in to the vSphere Web Client and vCloud Director consoles.
1. On the Control Center desktop, double-click the Web-Console shortcut and click the Continue
to this website (not recommended) link.
2. Log in using the user ID of administrator and the password of vmware I!.
3. In the left pane, click Home.
4. Click the VM Storage Profiles icon.
5. Click the Enable Storage Profiles icon.
6. Select the vCloud-Resource-Cluster cluster. The pane should report that the VM Storage
Profile Status for vCloud-Resource-Cluster is set to Enabled.
7. Click the Close button.
8. Click the Create a New VM Storage Profile icon.
Setting Action
Name Type Gold.
Setting Action
Name Type High-Performance-Pool.
Setting Action
Name Type Generic-Pool.
9. Click OK.
Username administrator
Password vrnwarel!
Setting Action
Name this Provider VDC Type Generic .
Prepare Hosts Select One credential for all hosts. Type root for
the root server name. Type vmwarel! for the
password. Click Next. Click Finish.
Setting Action
Name tbis Provider VDC Type High-Performance.
Add Storage Select Gold. Click Add. Select Silver. Click Add.
Click Next.
4. Click Finish.
Leave the vCloud Director console open for the next lab.
Lab 4 Organizations 17
Perfonn this lab as teams of two students. Each team will manage a VMware® cloud. Students will
be identified as student A and student B. Some items in the lab must be done by both students. But
most tasks will be done by one student while the other student checks the work. Students will take
turns so that both students in the team gain experience with the command and the ill.
Username administrator
Password VDlwarel!
Setting Action
Organization name Type QA.
As you type the organization name, the organization's URL dynamically changes to show what
you are typing and finishes with http://vcd/cloud/orglQAI.
18 Lab 4 Organizations
3. Click Next.
4. Under LDAP options, leave Do not use LDAP selected and click Next.
5. Under Add Local Users, click the Add button.
6. In the New User wizard, perfonn the following actions.
Setting Action
User name Type qa_ admin.
7. Click OK.
8. Click the Add button and perfonn the following actions to configure a second user.
Setting Action
User name Type qa_userl .
9. Click OK.
Lab 4 Organizations 19
10. Click Next.
11. Under Catalog Publishing, select Allow publishing catalogs to aU organizations and click
Next.
12. Under Email Preferences.click Next.
13. Under Policies, perfonn the following actions.
Setting Action
vApp Leases: Click the first drop-down menu and select Never Expires.
Maximum runtime lease
vApp Leases: Click the first drop-down menu and select Never Expires.
Maximum storage lease
vApp template lease: Click the first drop-down menu and select Never Expires.
Maximum storage lease
·H·Ii)
The percentage of available resources for each provider is displayed. External networks,
available to each provider virtual datacenter, appear after a provider vDC is selected.
4. Under Select Allocation Model, select Pay-As-You-Go and click Next.
5. Under Configure Pay-As-You-Go Model, keep all the default settings and click Next.
20 Lab 4 Organizations
6. Under Allocate Storage, perform. the following actions.
Setting Action
Storage Profiles Select Gold and click Add. Select Silver and click Add.
Storage Limit For the Gold and Silver storage profiles, select the
Unlimited radio button.
7. Click Next.
8. Under Select Network Pool & Services, select ORG-VLAN-Pool from the Network pool
drop-down menu.
9. In the Quota for this organization text box, type so.
10. Click Next.
11 . Under Configure Edge Gateway, select the Create a new edge gateway check box and
perform the following actions.
Setting Action
Edge Gateway name Type QA Ga teway.
Lab 4 Organizations 21
16. In the Change IP Assignment wizard, select Manual from the 1P Assignment drop-down
menu.
17. In the 1P Assignment text box, type 172.20.11.200.
The manual address assigned to an organization edge gateway must be within the range
allocated in the external network. In this case, the IP address must be in the range
172.20.11.200-172.20.11.254.
18. Click OK to close the Change IP Assignment wizard.
19. Click Next.
20. Under Create Organization VDC Network, select the Create a network for tbis virtual
datacenter check box and perform the following actions.
Setting Action
Network name Type QA External.
22 Lab 4 Organizations
Configure organization networking
1. Click the Manage & Monitor tab.
2. In the left pane, click Edge Gateways.
3. In the right pane, monitor the QA Gateway status. Wait until the status changes to Ready before
continuing.
4. Right-click QA Gateway and select Edge Gateway Services.
5. In the Configure Services: QA Gateway panel, under the DHCP tab, select the Enable DHCP
check box and click the Add button.
6. In the Add DHCP Pool panel, perform the following actions.
Setting Action
Enable pool Leave selected.
Lab 4 Organizations 23
Task 2: Create and configure the RD organization
In this task, you will create the RD organization in vCloud Director. You will also allocate resources
to the organization, configure networking and create a catalog. Student B will do this task. Student
A will check the settings.
This task has the following subtasks:
• Create the organization.
• Allocate resources to the organization.
• Configure organization networking.
• Add a catalog to the organization.
Setting Action
Organization name Type RD.
As you type the organization name, the organization's URL dynamically changes to show what
you are typing and finishes with http://vcdlcloudiorgIRD/.
3. Click Next.
4. Under LDAP options, leave Do not use LDAP selected and click Next.
5. Under Add Local Users, click the Add button.
6. In the New User wizard, perform the following actions.
Setting Action
User name Type rd_ admin.
24 Lab 4 Organizations
Setting Action
Confirm password Type vmwarel!.
7. Click OK
8. Click the Add button and perform the following actions to configure a second user.
Setting Action
User name Type rd_ userl.
9. Click OK
10. Click Next.
11. Under Catalog Publishing, select Allow publishing catalogs to all organizations and click
Next.
12. Under Email Preferences.click Next.
Lab 4 Organizations 25
13. Under Policies, perform the following actions.
Setting Action
vApp leases: From the first drop-down menu, select Never Expires.
Maximum runtime lease
vApp leases: From the first drop-down menu, select Never Expires.
Maximum storage lease
vApp template lease: From the first drop-down menu, select Never Expires.
Maximum storage lease
Limits Select the radio button to enable input. In the text box,
Number of resource intensive type 5.
operations per user
Limits Select the radio button to enable input. In the text box,
Number of resource intensive type 50 .
operations per organization
Limits Select the radio button to enable input. In the text box,
Number of simultaneous type 10.
connections per VM
26 Lab 4 Organizations
6. Under Allocate Storage, perform the following actions.
Setting Action
Storage Profiles Select Bronze and click Add.
Storage Limit For the Bronze storage profile, select the Unlimited
radio button.
7. Click Next.
8. Under Select Network Pool & Services, select ORG-VLAN-Pool from the Network pool
drop-down menu.
9. In the Quota for this organization text box, type 50 •
Setting Action
Edge Gateway name Type RD Ga teway.
Lab 4 Organizations 27
16. In the Change IP Assignment wizard, select Manual from the IP Assignment drop-down
menu.
17. In the IP Assignment text box, type 172 .20 . 11. 201.
The manual address assigned to an organization edge gateway must be within the range
allocated in the external network. In this case, the IP address must be in the range
172.20.11.200-172.20.11.254.
Setting Action
Network name Type RD External.
28 Lab 4 Organizations
25. Click Next.
26. Under Name this Organization VDC, type RD VDC in the Name text box.
27. Click Next.
28. Under Ready to Complete, click Finish.
Setting Action
Enable pool Leave selected.
Lab 4 Organizations 29
Add a catalog to the organization
1. Click the Home tab and click 7 Add a catalog to an organization.
2. In the New Catalog wizard, select RD and click Next.
3. Under Name this Catalog, type RD Catalog in the Name text box and click Next.
4. Under Publish this Catalog, select Publish to all organizations and click Next.
5. Under Ready to complete, click Finish.
30 Lab 4 Organizations
LabS
Creating VMware vCloud Director vApp
Templates
I . '
I
II
4. When prompted, click Run . You are prompted to click Run twice.
5. Close the Internet Explorer window and click Retry. AJI browser windows must be closed
before the plug-in can be installed.
Cancel
6. In the VMware Client Integration Plug-in 5.1.0 installation wizard, click Next.
7. Under End-User License Agreement, click I accept the terms of the .Iicense agreement and
click Next.
8. Under Destination Folder, click Next.
9. Under Ready to Install tbe Plug-in, click Install.
This website wants to run the following add-on: 'VMware Remote Console Plug-in' from 'VMware, Inc,',
User ID administrator
Password vmware 1!
2. In the left pane, select vCenter > Hosts and Clusters > vCloud Datacenter.
4. When prompted to allow plug-in access to the local operating system, click AJlow.
Protocol: https:
Hostname: webcliertsrv.vcd-ad.\
Port: 9443
The VMware Oert Int~atIon PIuo-In wII rIVe web appIcations and remote VMs access
to your operating system. Otiy aIow stes you trust.
5. In the Deploy OVF Template wizard, select Local file and click Browse.
6. In the Open file window, if necessary, go to My Documents > d o wn l o ads > v App s >
SU SE- VM.
If you do not see the Select a resource step in the wizard, it is because you selected a different
starting point in the hierarchy specified in step 2. The Deploy OVF Template wizard options are
contextual to the selected node. Do not cancel the wizard. Continue with the lab. In step 18 you
will be asked to select the vCloud-Resource-Cluster cluster. You will likely find that the cluster
is already selected.
12. Under Select storage, select datastore1 .
13. From the Select virtual disk format drop-down menu, select Thin Provision.
("-liut·UI
You must select the datastore flfst and then select Thin Provisioning. Selection of a datastore
will reset the Select virtual disk format drop-down menu to Thick Provisioned Lazy Zeroed
each time. Because the classroom envirorunent has limited resources, Thin Provisioning must
be selected. If you accidentally select Thick Provisioning, you will run out of storage resources
before being able to complete labs.
14. Click Next.
15. Under Setup networks, keep the default destination network ofVM Network and click Next.
16. Under Ready to complete, click Finish.
17. Monitor the task status in the Recent Tasks pane. Wait for the OVF deployment to complete
before continuing.
18. In the left pane, select vCloud-Resource-Cluster.
19. In the right pane, click the Related Objects tab.
20. Click the Top Level Objects tab.
~ .~ ~ I - Actions ...
NarTl~ .-· r " I r.. _. Ii
I ,. ,A,ction s ....
~
Nam' r- r-, 1 r r . _ --I
a . Right-click the Pop-Up Blocked message and select AJways AJlow Pop-ups from This
Site.
b. When prompted, click Yes.
c. If prompted to display the Web page again, click Retry.
d. If the console window does not open, select SUSE-VM again and click the Open Virtual
Machine Console icon.
5. In the virtual machine console window, click the Continue to this website (not recommended)
link.
6 . When the virtual machine has fmished booting, log in using the following credentials.
User ID root
Password vmwarel!
Username administrator
Password vrnwarel!
~
/-lam"!
1.1 ~___o___
Imp_rt fr-o--s-
m v-p-h--e_
e r- .._. lish ... I_I
Setting Action
vCenter Keep the default vCenterServer.
VM Select SUSE_VM.
9. Click OK.
10. Monitor the SUSE-Base status. Wait until the status changes to Ready before continuing. The
import operation will take a few minutes to complete.
7. If prompted with a security warning, select the Always trust content from this publisher
check box, click Yes, and click Run.
L l I ..
Actions: No Selections
Gold Mas.
Upload
Imp( Imp ort from vSphere .
1% :::J Launerl Uploads and [Io"vvnloads Progress \"'\.lindol./Il
Uploading OVF packages directly into vCloud Director enables various types of organization
users to import vApp templates without the assistance of a system administrator to deploy an
OVF template in vSphere.
17. When the transfer is complete, close the Transfer Progress window.
18. Monitor the Win2k3-Base status. Wait until the status changes to Ready before continuing.
Remain logged in to the vCloud Director console for the next lab.
URL http://vcd.vcd-ad.vclass.local
Username administrator
Password vmwarel!
~ vApps
+
Build New' vApp .. .
Setting Action
Name Type RD-vAppl.
Win2k3-Base RDI-Win2k3-A
17. Leave the Bronze storage profile selected for each virtual machine and click Next.
18. Under Configure Virtual Machines, use the following table to change the Computer Name
for each virtual machine.
RDI-Win2k3-A RDI-VM2
Setting Action
Gateway address Type 172 • 3 0 . 11 0 . 1.
21 . Click Next.
22. Under General, type RD1-Loca1 in the Network name text box and click Next.
23. Click Finish.
24. For the RDI-Win2k3-A virtual machine, select RDl-Local from the Network drop-down
menu.
25. For both virtual machines, select DHCP from the IP assignment drop-down menu.
26. Click Next.
27. Under Configure Networking, for the RDI-Local network, select RD-External from the
Connection drop-down menu.
28. Click Next.
29. Under Ready to Complete, click Finish.
30. Monitor the RD-vAppl status. Wait until the status changes to Stopped before continuing.
31 . Right-click RD-v Appl and select Open.
32. In the right pane, click the vApp Diagram tab.
C ( ~ J
.! RD1·LoclIl
- -- ----
RDExternal
Changing the NAT type to port forwarding with IP masquerading enabled provides a many-to
one NAT configuration.
41 . Click OK
42. Under the networks list, click Apply. Wait for the configuration change to complete before
continuing.
43. In the left pane, click vApps.
44. In the right pane, right-click RD-vAppl and select Add to Catalog.
Setting Action
Name Keep the default name.
46. Click OK
47. Monitor the RD-vAppl status. Wait until the status changes to Stopped before continuing.
00 vApps
+
Build [\Jew v.Cl.pp ...
Setting Action
Name Type QA-vAppl.
9. Click Next.
10. Under Add Virtual Machines, select Win2k3-Base and click the Add button.
11 . Click Next.
12. Under Configure Resources, use the following table to change the virtual machine names.
16. For the QAI-Win2k3-A virtual machine, select Add Network from the Network drop-down
menu.
Setting Action
Gateway address Type 172 . 30 . 210 . 1.
QA1-Wln2k3-A
.f. OA1-Local
OAExternal
Setting Action
Name Keep the default name.
42 . Click OK
43. Monitor the vApp status. Wait until the status changes to Stopped before continuing.
Remain logged in to the vCloud Director console for the next lab.
As you perform this lab, notice differences when adding the copied VMware vSphere® VAppSTM to
your respective My Cloud containers. One vApp was published with customization specified.
Another was published with the identical copy option selected. As these vApps are copied to
different catalogs and then added to a My Cloud container, the configuration options available and
the steps necessary are significantly different.
Username administrator
Password vmwarel!
Setting Action
Name Type vApp-From-QA.
12. Click OK
13. In the left pane, select My Organization's Catalogs.
14. In the right pane, monitor the vApp-From-QA status. Wait until the status changes to Ready
before continuing.
15. Right-click vApp-From-QA and select Add to My Cloud.
16. In the Add to My Cloud wizard, perform the following actions.
Setting Action
Name Type RD-vApp2.
17. Click OK
18. Click the My Cloud tab.
19. In the left pane, click vApps.
20. In the right pane, monitor the RD-vApp2 status. Wait until the status changes to Stopped before
continuing.
21. Right-click RD-vApp2 and select Open.
Setting Action
Name Type vApp-From-RD.
RD1-SUSE-A QA2-SUSE-A
18. For each virtual machine, select Silver from the Storage profile drop-down menu.
19. Click Next.
20. Under Configure Networking, change the computer names using the following table.
QA2-Win2k3-A QA2-VM2
21 . For the QA2-Win2k3-A virtual machine, select Add Network from the NIC 0 drop-down
menu.
Setting Action
Gateway address Type 172.30.220.1.
Perform this lab as teams of two students. Each team will manage a VMware® cloud. Students win
be identified as student A and student B. Some items in the lab must be done by both students. But
most tasks will be done by one student while the other student checks the work. Students will take
turns so that both students in the team gain experience with the command and the VI.
1. In Internet Explorer, open a new browser tab and log in to the RD administrator console using
the following information.
Username rd admin
Password vmwarel!
Login administrator
Password vmwarel!
10. On the virtual machine desktop, double-click the Command Prompt shortcut.
14. Try to ping the local network gateway by typing ping 172.30. 11 0 . 1. The ping command
will not receive a response.
15. Press Ctrl+C to stop the ping command.
The local gateway at 172.30.110.1 is attached to the same subnet as the virtual machine. What
might be interfering with network traffic in this context?
~ Enable IP Masquerade
20. Click the Firewall tab, deselect the Enable firewall check box, and click OK.
21. Click Apply. Wait for the configuration update to complete.
22. Go to the Pop out Console window.
23. In the Command Prompt window, try to ping the local gateway by typing ping
172.30.110.1.
The ping command will receive a response. The gateway firewall device was blocking the
ping response.
25. Try to ping the RD organization gateway by typing ping 172.30.1.1. The ping command
will not receive a response.
26. Press Ctrl+C to stop the ping command.
The IF address of the RD organization gateway is 172.30.1.1, which is on the same subnet as
the external interface of the RDI-Local gateway. You can ping the external interface of the
RDI-Local gateway but not the IF address of the organization gateway. What might the root
cause be?
The ping command will receive a response because the gateway fIrewall is no longer blocking
traffic. You might need to wait a few moments for the gateway to reconfigure and allow traffic
to pass.
1. In Internet Explorer, open a new browser tab and log in to the QA administrator console using
the following information.
URL http://vcd.vcd-ad.vclass.local/cloudlorg/QA
Username
Password vmwarel!
Setting Action
Name Type Ping.
Setting Action
Name Type Ping.
Login administrator
Password vmwarel!
32. On the virtual machine desktop, double-click the Command Prompt shortcut.
33. In the Command Prompt window, run the following commands.
Command Description
ping 172 . 30.210.1 The local network gateway
ping 172.30 . 11.100 The IP address assigned to QA-vAppl. Replace the IP address
with the value that recorded in step 24.
Each ping command should receive a response. If any command fails to receive a response,
repeat steps 5-32 steps to verify ftrewall and network configurations.
Username administrator
Password vmwarel!
7, Click the Add Network icon, which appears as a green plus (+) sign.
8, In the New Organization VDC Network wizard, select Connect directly to an external
network.
g, Select Production and click Next.
10, Under Name this Organization vDC Network, type RD Services Network in the Name
text box.
11, ClickNext.
URL ht1p:llvcd.vcd-ad.vclass.local/cloudlorg/RD
Username rd admin
Password vmwarel!
~ vApps
-+-~- o
Build New vApp ...
17. In the New vApp wizard, under Name this vApp, perform the following actions.
Setting Action
Name Type RD- Services .
36. Right-click the RDS-SUSE-A virtual machine and select Popout Console.
37. If necessary, click the Continue to this website (not recommended) link.
,a·iii
The virtual machine will reboot because of guest customization steps taken by vCloud Director.
38. Wait for the virtual machine to start and reboot. This process might take a few minutes. You
will experience a noticeable delay before the reboot occurs, while the SUSE login prompt
continues to be displayed.
39. When the virtual machine has rebooted and you are prompted to log in, close the Popout
Console window.
40. Minimize the Internet Explorer window.
41. On the ControlCenter desktop, double-click the Putty shortcut.
42. In the PuTIY window, type the external IP address of the RDS-SUSE-A virtual machine that
you recorded in step 32 and click Open.
43. When prompted, click Yes to confmn the PuITY security alert.
1. In Internet Explorer, click the system administrator console tab and log in using the following
credentials.
Username Administrator
Password vmwarel!
Only the System Administrator role can create suballocated IP pools on organization gateways.
URL http://vcd.vcd-ad.vclass.local/c1oud/orglQA
Username
Password vmwarel!
Setting Action
Gateway address Type 172.30.100.1.
The suballocated IP range provided by the system administrator is used in the services network
NAT configuration to expose internal virtual machines to the production network.
Setting Action
Name Type Any TCP.
Setting Action
Applied on Select Production.
88 vApps
+ o
Build (\Jew vApp ...
36. In the New vApp wizard, under Name tbis vApp, perform the following actions.
Setting Action
Name Type QA- Services.
38. Under Add Virtual Macbines, select Public Catalogs from the Look In drop-down menu.
39. In the virtual machine list, select the SUSE-Base virtual machine and click Add. You might
need to use the scroll bar or page controls to fmd the SUSE-Base entry.
40. Click Next.
41. Under Configure Resources, change the virtual machine name to QAS-SUSE-A.
42. From the Storage profLle drop-down menu, select Gold.
43. Click Next.
44. Under Configure Virtual Machines, change the computer name to QAS-VM 1.
45. From the Network drop-down menu, select QA Services Network.
46. From the IP Assignment drop-down menu, select Static - Manual.
47. In the IP address text box, type 172.30.100.14 O.
48. Click Next.
49. Under Configure networking, click Next. Do not select Fence vApp.
The virtual machine will reboot because of guest customization steps taken by vCloud Director.
56. Wait for the virtual machine to start up and reboot. This process might take a few minutes. You
will experience a noticeable delay before the reboot occurs, while the SUSE login continues to
be displayed.
57. When the virtual machine has rebooted and you are prompted to log in, close the Popout
Console window.
58. Minimize the Internet Explorer window.
59. On the ControlCenter desktop, double-click the Putty shortcut.
60. In the PuTIY window, type the external IP address of the DNAT rule and click Open. The
external address is 172.20.11.240.
61. When prompted, click Yes to confirm the PuTIY security alert.
62. Log in to the virtual machine with a user name of root and password ofvmwarel!.
63. Close the PuTIY window.
64. Close the QA administrator console tab.
Remain logged in to the vCloud Director console for the next lab.
Username administrator
Password vmwarel!
Setting Action
Name Type CustomRole.
Catalog Expand Catalog rights. Select View Private and Shared Catalogs.
8. Click OK
Leave the vCloud Director console open for the next task.
Task 2: Create a vCloud Director user and test the custom security
role
In this task, you will add a vCloud Director user and use the user to test the new custom security
role. This task should be done by student B, with student A checking the settings.
1. If you are not logged in to the vCloud Director console, open Internet Explorer and log in to the
vCloud Director server using the following information.
Username rd admin
Password vmwarel!
2. Log in to vCloud Director with a user ID of rd_ admin and a password of vmware I!.
3. Click the Administration tab.
4. Click Users in the left panel.
5. Click the plus (+) icon to add a user.
6. Type Francis_Dalton in the User name text box.
7. Type vmwarel1 in the Password text box.
8. From the Roles available to this user drop-down menu, select CustomRoJe.
9. Click OK
10. Click Logout.
11. Log in with the user ID of Francis_Dalton and a password ofvmwarel!.
Server 172.20.10.93
Port 389
UseSSL Deselect.
Password vmwarell
These setting should all already be the default settings for a standard Active Directory LDAP.
Different settings would be required for nonstandard schemas and for OpenLDAP.
Surname sn
Email mail
Telephone telephoneNumber
Group membership dn
identifier
These setting should all already be the default settings for a standard Active Directory LDAP.
Different settings would be required for nonstandard schemas and for OpenLDAP.
Name en
Membership member
Group membership dn
identifier
IH.iij
Some systems might initially be unable to connect. If you see a connection error, wait two
minutes and try to connect again.
0 ~m.j,
0 (jfI,O-rto~m o
0 ;um. rr. 6 ,n
0 To' ~tto-m;~
16. In the LDAP Setting Test Results window, type the user name MHanuner.
17. Click Test. All green check marks and all fields should contain values.
18. Click OK.
19. Click Synchronize LDAP.
20. Close the Internet Explorer tab for the vCloud Director console.
Wait five minutes to give the vCloud Director system time to synchronize for the next task.
7. Click Search.
8. Select SSpade.
9. Click Add.
10. Click OK
11. In the left panel, click Groups.
17. Click OK
18. Click Logout.
1. Use the Internet Explorer browser console for the RD organization at https://vcd.vclass.locall
cloudiorgIRD/.
2. Try to log in with the following user names and passwords. Click Logout after each successful
login.
URL http://vcd.vcd-ad.vclass.local
Username administrator
Password vmwarel!
Setting Action
SMTP server name Type vcd. vcd- ad. vclass . local.
The vcd.vcd-ad.vclass.locaI system has been configured as a simple postfix email system. The
email system has been configured so that all email messages are forwarded to the johndoe
mailbox.
13. Type cat /var/mail/johndoe.
14. At the end of the file, you should see a test message similar to the following example:
From administrator@vcd-ad.vclass.local Wed Oct 10 14:47:062012
Return-Path: <administrator@vcd-ad.vclass.locaI>
X-Original-To: administrator@vcd-ad.vclass.local
Delivered-To: johndoe@vcd-ad.vclass.local
Received: from vcd.vcd-ad.vclass.local (vcd.vcd-ad.vclass.local [172.20.1 0.91])
by vcd.vcd-ad.vclass.local (Postfix) with ESMTP id 87562EC5B2
for <administrator@vcd-ad.vclass.local>; Wed, 10 Oct 2012 14:47:06 -0500 (CDT)
Date: Wed, 10 Oct 2012 14:47:06 -0500 (CDT)
From: "administrator@vcd-ad.vclass.locaI" <administrator@vcd-ad.vclass.local>
To: "administrator@vcd-ad.vclass.local" <administrator@vcd-ad.vclass.local>
Message-ID: <1200280528.1.1349898426515.1avaMail.vcloud@vcd.vcd-ad.vclass.local>
Subject: VCD Notification VMware vCloud Director Email Test
In addition to creating provider virtual datacenters and organization vDCs, the system
administrator can change existing vDC configurations.
Setting Action
CPU resources guaranteed Type 10.
5. Under the Network Pool & Services tab, change the number of networks provisioned to the
organization by typing 60 in the text box.
6. Click OK Wait for the configuration update to complete before continuing.
5. In the Allocated IP Addresses list, click the Edge Gateway column header to sort the list by
edge gateway assignment.
6. Find the IP addresses allocated to QA gateway and answer the following questions by
comparing the listed allocations to the suballocation range you recorded in step 3.
External interface of the QA gateway: _ _ _ _ _ _ _ _ _ _ _ __
The system administrator can disable specific networks here, change network characteristics, or
delete networks.
1. In Internet Explorer, open a new tab and log in to the QA administrator page using the
following information.
Username
Password vmwarel!
Organization administrators have full control over lease, default quota, and password lockout
settings. Organization administrators cannot change limits imposed by the system administrator.
Setting Action
vApp leases: From the second drop-down menu, select Days. From the
Maximum runtime lease first drop-down menu, select 14.
vApp leases: From the second drop-down menu, select Days. From the
Maximum storage lease flfSt drop-down menu, select 30.
Users
+
1.
IH·iii
Notifications sent in this context can be addressed to all users in the organization., or to all
organization administrators.
8. In the Notify Users panel, select Organization Administrators from the To drop-down menu.
9. In the Subject text box, type Policy Changes.
10. In the Message text box, type vApp runtime and storage leases have been
reduced to 14 and 30 days respectively.
IU·iii
Notifications sent in this context are automatically addressed to any user with items in the
organization virtual datacenter. Relevant items are vApp templates, vApps, Media, and any
other object that a user might have attached or created as a resource.
18. Click Cancel.
External IP allocations have an associated category that is useful for identifYing which
addresses are used by which devices and how those addresses are being used. In the displayed
IP allocations list, you will see at least one IP allocated with a category of VSE and at least one
IP allocated with a category of NAT. The VSE category identifies which IP addresses have been
allocated for use by the organization network devices, such as an edge gateway interface, and
which IP addresses have been allocated for NAT translation.
4. Using the IP allocation table, record the IP addresses for each of the following connections:
The following steps require that you performed the "Hosting Inbound Services" lab. If you did
not complete that lab, do not perform the ping steps below, but do perform all other steps.
6. On the Control Center computer, select Start> All Programs> Accessories> Command
Prompt.
7. In the Command Prompt window, begin a continuous ping by typing ping 172.20.11.240
-to
iU·iii
You will see very little effect on network throughput as a result of reapplying the edge gateway
service configuration. Monitor the response times and watch for time-out conditions in the
continuous ping operation.
11 . When the reapply of gateway service configuration is complete, return to the QA administrator
console. Leave the continuous ping running.
12. Right-click QA Gateway and select Re-deploy.
13. When prompted, click Yes.
14. In the Command Prompt window, observe network throughput as the VMware vShield Edge
device is redeployed.
iU.iii
The redeployment will take a few minutes to complete. During redeployment, you will see the
ping reply times increase. In general, network connectivity is not cut off for long periods of
time. During the redeployment, you will see one or two periods in which full network
interruption occurs.
15. When the redeployment is complete, close the Command Prompt window.
16. In the QA administrator console, click the Org VDC Networks tab.
17. Right-click QA Services Network and select Properties
18. In the Network Properties panel, click the Network Specification tab.
Organization administrators can modify or add IP pool ranges for any given organization
network that is not directly connected to an external network defmed by a system administrator.
19. In the static IP pool range text box, type 172.30.100.160 -172 .30.100.170 and click
Add.
20. Click OK Wait for the configuration update to complete before continuing.
lu·ni
The IP allocations that are listed apply only to the organization network. Each IP allocation
specifies a virtual machine and a VMware vSphere® VAppTM. One of the IP addresses is listed
as being assigned to a VMware® vShield Edge™ (internal) virtual machine. In this case, the
vShield Edge (internal) virtual machine is the QA gateway and the IF address listed is the
address assigned to its internal interface.
3. In the right pane, click the gear icon and select New User.
4. In the New User wizard, perform the following actions.
Setting Action
User name Type qa_user2.
5. Click OK.
Username administrator
Password vmwarel!
veentelS
I~O=-_ : ~
~ .t..ttach New vCenter
7. Click Cancel.
8. Complete the following information for the vCenter Server system:
Name
Status
vCenter Server
Port Number
Version
vShield Manager
vCenter Proxy
You might see a Pop-Up Blocked warning message at the top of the browser window. Disable
the pop-up blocker and click Open in vSphere Web Client.
17. Click Continue to this website (not recommended).
18. Log in to vCenter Server, using the foUowing credentials.
Password vmwarel!
19. Minimize the vSphere Web Client window and return to the vCloud Director console.
Username administrator
Password vmwarel!
• Datastore
• Type (
• Connected
• Capacity (Usedffotal)
• % Used
Based on this information, which datastore has the highest free-space capacity?
7. Click OK
Leave the vCloud Director console connected for the next task.
5. Click Cancel.
Leave vCloud Director console logged in for the next task.
4. Click the Port Groups tab. You should see all currently assigned port groups.
5. In the upper right of the browser window, type vApp (case-sensitive) and press Enter. You
should now see all port groups that are associated with cloud networks that have "v App" in the
network name.
Username administrator
Password vmwarel!
IU-iiil
In some cases, a provider vDC might be shared by many organization vDCs. In the class
environment, your provider vDCs back single organization vDCs, so resource use is the same
for each pair.
11. In the far-right column header, click the Customize Columns control.
ResolJrce Pools
12. In the Customize Columns panel, select Used Network Count and vApps, then click OK.
Expand the columns so that the column headings are visible and answer the following
questions:
3. In the Tasks list, sort the list by clicking the Owner column heading until the system-owned
tasks appear at the top of the list.
4. Examine the first two pages of tasks and answer the following question:
5. Click the Owner column heading until administrator-owned tasks are listed first.
6. Examine the first two pages of tasks and answer the following question:
Task 3: Enable and verify Syslog logging for vCloud Director networks
In this task, you will configure Syslog settings for network operations, synchronize logging between
the system and an edge gateway, and test firewall rule logging. Student B will do this task. Student
A will check the settings.
You must have completed the "Hosting Inbound Services" lab before beginning this task.
1. In the \\vcs.vcd-ad.vclass.local Windows Explorer window, click the Back button so that the IP
named folders are displayed.
Are there any folders named with an IP address in the range of 172.20.11.200-172.20.11.254?
25. In the \\vcs.vcd-ad.vclass.local Windows Explorer window, press F5 to refresh the view.
Answer the following question:
You will see a new folder named witb an IP address in the range of 172.20.11.200
172.20.11.254. This IP address is the external address of the QA gateway. All firewall rules
configured with logging enabled result in events being logged from the external address of the
edge gateway, even if tbe target of the rule is an external NAT IP address.
27. In Notepad, search for "icmp." The search should take you to the end of the file.
28. Examine the log entry and close Notepad.
29. Close the \\vcs.vcd-ad.vclass.local Windows Explorer window.
30. Close the Command Prompt window.
Remain logged in to the vCloud Director console for the next lab.
Perform this lab as teams of two students. Each team will manage a VMware® cloud. Students will
be identified as student A and student B. Some items in the lab must be done by both students. But
most tasks will be done by one student while the other student checks the work. Students will take
turns so that both students in the team gain experience with the command and the ill.
1. If you are currently logged in to the vCloud Director console, click the Logout link in the
upper-right corner of the browser page. You must log out of the vCloud Director console before
continuing.
2. Log in to the QA organization page using the following information.
URL http://vcd.vcd-ad.vclass.local/cloudlorg/QA
Username
Password vmwarel!
3. Click the My Cloud tab. No vApps are listed as being accessible or owned by the qa_userl
account.
4. In the upper-right comer of the page, click the Logout link.
Username
Password vrnwarel!
Username
Password vrnwarel!
As the system administrator, you created a catalog for the QA organization lab 4. Later, as the
QA organization administrator, you interacted with that catalog. However, using the
nonadministrative qa_ userl account, you have no access to the catalog. Organization catalogs
are not automatically shared to all organization users.
3. In the upper-right comer of the page, click the Logout link.
4. Log in to the QA organization page, using the following credentials.
Username
Password vrnwarel!
Na me 1 ~ Shar" oj
(§ QA Catalog
13. In the upper-right comer of the page, click the Logout link.
Username
Password vmwarel!
15. Click the Catalogs tab. In the right pane, the QA catalog appears and can be accessed.
Username
Password vmwarel!
Username
Password vmwarel!
Perform this lab as teams of two students. Each team will manage a VMware® cloud. Students will
be identified as student A and student B. Some items in the lab must be done by both students. But
most tasks wiH be done by one student while the other student checks the work. Students will take
turns so that both students in the team gain experience with the command and the UI.
The vSpbere DRSNMware vSphere® High Availability configuration used in this lab is specific to
this lab environment. In most production environments, the best practice is to enable features like
vSphere HA, EVC, and Power Management. The configuration that you should use in production
environments depends on individual requirements. vCloud Director requires vSphere DRS to be
enabled. vCloud Director does not require vSpbere HA features.
1. If you are not logged in to the vSphere Web Client, do the following :
a. Double-click the vSphere Web Client shortcut.
b. Log in using the user ID of administrator and the password of vmware 1'.
2. Verify that you have a datacenter and vSphere DRS cluster properly configured:
a. Click Home.
b. In the Home pane, click the Hosts and Clusters icon.
c. Verify that you have a datacenter named vCloud Datacenter.
d. Verify that a vSphere DRS cluster is under the datacenter. In this lab, the vSphere DRS
cluster is named vCloud-Resource-Cluster.
e . Verify that VMware ESXi™ hosts esxiOl.vcd-ad.vclass.local and esxi02.vcd
ad.vclass.local are members of the cluster.
f. Click the vSphere DRS cluster vCloud-Resource-Cluster in the left inventory panel.
g. Click the Manage tab in the vCloud-Resource-Cluster pane.
h. Click the Settings subtab.
i. Click vSphere DRS under Services.
o DRS Automation should be selected and set to Fully Automated.
o Power Management should be set to OfT.
o Advanced Options should be set to None.
j. Click vSphere HA under Services. vSphere HA should be turned off.
• dvs-IP-Storage
• dvs-Production
• dvs-vMotion
3. Select the dvs-IP-Storage switch.
4. Click the Manage tab.
5. Click the Settings subtab under Manage.
6. Expand the VMkemel ports under IP-Storage. You should see two vmkl ports conftgured at IP
addresses 172.20.13.51 and 172.20.13.52.
7. Expand the dvs-IP-Storage-DVUplinks on.
The dvs-IP-Storage switch should be correctly conftgured so that it can be bound to the
VMware vSphere® Virtual iSCSI Adapter. There should only be a single uplink (with two NIC
adapters) for this switch. The uplink is named dvUplinkl. One NIC adapter should be
connected to vmnic3 on esxiOl.vcd-ad.vclass.local. The other NIC adapter should be connected
to vrnnic3 on esxi02.vcd-ad.vclass.local.
I"Jiii[.]~1
If the distributed switch used by IP storage is not limited to a single uplink (one NIC per host) it
will not be possible for the vSphere virtual iSCSI adapter to bind to the VMkemel port. By
default, distributed network switches are created with four potential uplinks.
9. Use the Networking view in vSphere Web Client to confmn that the following VMkemel ports
exist with the proper network configuration.
Remain logged in to the vCenter Server system and leave the vSphere Web Client open.
Cilnce l
In this lab environment, the iSCSI storage array validates the iSCSI name of the storage
requester. In a production system, consult with your storage administrator to determine the
authentication requirements of the local storage arrays.
13. Click the Targets tab under Adapter Details.
14. Click the Dynamic Discovery tab.
15. Click the Add button.
16. In the iSCSI Server text box, type 172 . 20.13.14 .
17. Keep the default port of 3260.
18. Leave Inherit settings from parent selected.
19. Click OK.
20. Click the Network Port Binding tab_
storage Adapters
!iii ~ C ~ ... t- ~=
24. Click the icon to rescan the host for new storage devices or new VMware vSphere® VMFS
volumes. Allow the scan for new storage devices and for new VMFS volumes. Click OK
storage Adapters
25. Click the Devices tab under Adapter Details. You should see four iSCSI disk devices.
26. Click the Related Objects tab at the top of the pane.
27. Click the Datastores tab. You should now see the following datastores:
• Fast-Datastore-I
• Fast-Datastore-2
• Medium-Datastore--I
• Slow-Datastore-I
Either a datastore 1 or a datastore2 will be present.
Remain logged in to the vCenter Server and leave the vSphere Web Client open.
User-defined storage
Datastore capability Description
Medium-Datastore-l Silver-Level Medium speed and cost
storage
Remain logged in to the vCenter Server system and leave the vSphere Web Client open.
~el ; 5
. Enable VM Storage Profiles per Compute
Re sou r ce
rjiJ e 6\
NV H ' · • ~E
Create a new VM Sto rage Profile
8. Create the following storage profIles and connect them to the specifIed user-defmed storage
capability.
User-defined storage
Storage profile capability
Gold Gold-Level
Silver Silver-Level
Bronze Bronze-Level
Remain logged in to the vCenter Server system and leave the vSphere Web Client open.
5. Run the nslookup command to confirm that the DNS host can resolve the vCloud Director
host name. Type nslookup vcd.
Name: vcd.vcd-ad.vclass.local
Address: 172.20.10.91
7. Run the nslookup command to confIrm that the DNS host can resolve the Address Resolution
Protocol (ARP) address of the IP address for the vCloud Director HITP service. Type
nslookup 172.20.10.91.
8. Run the nslookup command to confIrm that the DNS host can resolve the ARP address of the
IP address for the vCloud Director console proxy service. Type nslookup 172.20.10.92.
10. Type the command service ntpd status to verify that the NTP daemon is running.
11. lfthe NTP service daemon is not running, type the command service ntpd start. lfthe
service fails to start, ask your instructor for assistance.
Leave your PuTTY SSH session connected to vcd.vcd-ad.vclass.local for the next task.
1. Use the PuTTY SSH utility on the ControlCenter desktop to connect to vcd.vcd-ad.vclass.local
if you are not still connected from task 8.
2. Use the cd command to change directories to the /root/downloads directory where the
vCloud Director software binary is stored.
# cd /root/downloads
3. Type 1 s -1 to determine the exact filename of the vCloud Director software binary. In the
screenshot, the filename is vmware -vcloud-director- 5.1.0 - 810718 . bin. Your
filename will be similar.
[rootBvcd downloads] # Is -1
total 2816H
-rw-r--r-- 1 root root 288115734 Sep 23 15:00 vmware-vcloud-director-5.1.0-81071
3.bin
[rootBvcd downloads]# chmod a+x '.bin
[rootBvcd downloads] # Is -1
total 281644
-rwxr-xr-x 1 root root 288115734 Sep 23 15:00 vl'm.Y6re-vcloud-director-5.1.0-810718.hin
•
4. Run the binary by typing . / in front of the filename. Type the filename correctly: It is case
sensitive. Use the correct filename shown in your system, not the filename in the example.
# ./vmware-vcloud-director-S.l.0-810718.bin
5. Type n in response to Would you like to run the script now (yin)?
Leave the PuTTY SSH session connected to vcd.vcd-ad.vclass.local for the next task.
Type the command correctly, with correct filenames and paths. In the example, the command
ends with the number 1.
4. Type /usr/sbin/al ternatives - -config key tool. The command returns how many
versions of keytool are installed on this system and allows you to set the default version that the
system will use. Select the Java Runtime Envirorunent version 6 keytool.
Selection Command
Leave the PuTTY SSH session to vcd.vcd-ad.vclass.local connected for the next task.
Task 11: Prepare the vCloud Director SSL keystore and create self
signed certificates
In this task, you will prepare the vCloud Director server SSL keystore and create self-signed
certificates. This task should be performed by student A, with student B checking the work.
1. Use the PuTTY SSH utility on the ControlCenter desktop to connect to vcd.vcd-ad.vclass.local
if you are not still connected from task 10.
2. Create a directory for the certificates with the mkdir command:
# mkdir /opt/certificates
4. Run the keytool command to create a certificates keys tore file and an alias for the HTTP
certificate. Use a password ofvmwarel!.
5. After you run the key tool command, you will be prompted with several questions. Use the
following answers.
Correct? yes
Password for HfTP? Press the Enter key to use the default password ofvmwarel!.
[root~vc c1 ctovnload!!lj# Itc.ytool -Ic.eV3t.or e c er~ifice.te~.)r(!!I -!!It.oreql'pe JCEKS -=I1:orep~~ vrn.,arel' -genkey -keyalQ RSA -al::l.e.!!I htt.p
~hat 1!!1 your tlr!lt and la!!t n~i
[Unknown): vcd.vcd-ad.vcla33.1ocal
What. 13 ttle n&tle: at yOllE:' ot:'qanlzatlonal uTIle 'I
( Unkno~nJ: Cloud. Actmlnl!1ttac 10n
What 13 the name or youe ot:Q'anlzatlont
[Unlcnovn]: Cloud Con'l'p Ut i OiWI
What 1:1 ttLe name ot your Clty or Locsl1tyi
(Unkno\iln): fort Worth
What 13 the name ot your: State or PrOvince?
(Unknown]: Texa!!
Whae 1!!1 the t\llD-letter countc'.' code tor ctllS unit 7
( Unknown}: US
I!I CN·vCd.vcd-ad.vCla~!!.local, OU'"'Cloud ltdU'llnl!1{'ce.r;ton, (I-C lOud Compu t l n Q, l.-fot:t Worth, S r-Te x e.~, CeUS C'orrec{' ?
(no] : ye~
6. Run the keytool command to create an alias for the console proxy certificate. Use the
keys tore password of vmware 1!.
# key tool -keystore certificates.ks -storetype JCEKS -storepass
vmwarel! -genkey -keyalg RSA -alias consoleproxy
You can press the up arrow key to copy the last command. You can edit the copied command.
Correct? yes
Password for console proxy? Press the Enter key to use the default
password ofvmwarel!.
9. Use the chmod command to make the directory and files readable by all users.
# chmod -R a+r /opt/certificates
Leave your PuITY SSH session connected to vcd.vcd-ad.vclass.local for the next task.
5. Type exi t to close the PuTTY SSH session. Wait for at least two minutes for the vmware-vcd
service to completely restart before proceeding to the next task.
Leave the vCloud Director console open for the next task.
13. Click Edit on the right side level with Lookup Service.
19. Click Edit on the right side level with vCenter Server.
20. Type vc s . vcd - ad. vc las s . local for the vCenter Server name.
21 . Type administra tor for the administrator user name.
8 · Datacenters
B·· vCloud Datacenter
B" vCloud-Resource-Cluster
esxiOl, vcd-ad .vclass ,local
esxi02 .vcd-ad .vclass .Iocal
33. Close the Internet Explorer tab that is connected to the VMware Security Manager server.
Task 16: Attach the vCenter Server system and vShield Manager
In this task, you will attach the vCenter Server system and vSbield Manager to the vCloud Director
cell. This task should be done by student A and checked by student B.
1. Use the Internet Explorer browser on the ControlCenter console to open a new tab. Leave the
tabs with the vCloud Director console and the vSphere Web client running.
2. Go to bttp:llvcd.vcd-ad.vclass.local.
3. Click Continue to this website (not recommended) to ignore the security warning.
4. Click Attach a vCenter.
5. Type vcs. vcd-ad. vclass .local for the vCenter Server system host name.
6. Keep the default port number of 443.
148 Lab 17 Installing VMware vCloud Director
7. Type administrator for the vCenter Server system user ID.
8. Type vmwarell for the vCenter Server administrator password.
9. Type vCen terServer as a vCenter Server name.
10. Type vCenter Server - Resource Cluster in the Description text box.
11. Select Use the following URL.
12. Type https: / /vcs. vcd-ad.vclass .local: 9443 for the URL.
13. Click Next.
14. Type vcns. vcd- ad. vclass .local for the vShield Manager host name.
15. Type admin for the vShield Manager administrator name.
16. Type vmwarell for the vShield Manager administrator password.
17. Click Next.
18. Click Finish.
19. A green check mark should appear next to item 1 on the menu, and the item should change to
Attach anotber vCenter.