VMware Cloud Community
rampeter
Enthusiast
Enthusiast

Template Server - Do's and Don't

Hi All,

How to prepare a best template server ,What are recommendations steps which needs to be carried out.Kindly suggest.

0 Kudos
8 Replies
1an3
Enthusiast
Enthusiast

I have mine kept very generic.

I do not join our domain.

I install latest windows updates. I install latest VM Tools.

I have the template at a minimum hardware spec.

I have a customization template that maintains a DHCP address, and joins the domain, setting the hostname to the VM Name.

So when I deploy a new server from the template, I provide a VM name. Once the customization has completed, I need to change the VLAN/IP Address, change and record the local admin password and adjust the spec as required.

0 Kudos
rampeter
Enthusiast
Enthusiast

Is joining the server in domain will cause any problem ?

0 Kudos
TomHowarth
Leadership
Leadership

this of it this way, when a machine is joined to the domain it creates a GUID SID for the AD Domain it is joined to.  when you create a template this will be duplicated in each machine you build, delivering to capability to potentially cripple your AD.

Do not join a template server to the domain.

Keep them as generic as you can, and regularly fire them up as a VM to update your OS patches

Tom Howarth VCP / VCAP / vExpert
VMware Communities User Moderator
Blog: http://www.planetvm.net
Contributing author on VMware vSphere and Virtual Infrastructure Security: Securing ESX and the Virtual Environment
Contributing author on VCP VMware Certified Professional on VSphere 4 Study Guide: Exam VCP-410
0 Kudos
rampeter
Enthusiast
Enthusiast

Can anyway it can be reviewed in servers of the duplication?

0 Kudos
1an3
Enthusiast
Enthusiast

If you customize the new VM when you deploy it you have the option to generate a new SID

0 Kudos
TomHowarth
Leadership
Leadership

As an Active Directory cannot have duplicate GUIDS in a domain, you will find machines dropping of the network.  Seriously it would just be better to restart your template machine as a VM, return it to Template mode (if a windows machine, Run SYSPrep to and remove it from the domain and then remove and rejoin all the machines that have been created from the original template.

A Local SID is not an issue in an AD environment as it is not used for communication (this is not the case in a WorkGroup)

Tom Howarth VCP / VCAP / vExpert
VMware Communities User Moderator
Blog: http://www.planetvm.net
Contributing author on VMware vSphere and Virtual Infrastructure Security: Securing ESX and the Virtual Environment
Contributing author on VCP VMware Certified Professional on VSphere 4 Study Guide: Exam VCP-410
0 Kudos
rampeter
Enthusiast
Enthusiast

Tom- I have my template server joined in domain only but i don't find any issues in VM (windows and linux)more than 300 vm's

0 Kudos
rampeter
Enthusiast
Enthusiast

Any more suggestions ?

0 Kudos