<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>mrstorey303 Tracker</title>
    <link>https://communities.vmware.com/wbsdv95928/tracker</link>
    <description>mrstorey303 Tracker</description>
    <pubDate>Thu, 23 Nov 2023 17:03:57 GMT</pubDate>
    <dc:date>2023-11-23T17:03:57Z</dc:date>
    <item>
      <title>Re: vSAN shutdown cluster Powercli function</title>
      <link>https://communities.vmware.com/t5/VMware-vSAN-Discussions/vSAN-shutdown-cluster-Powercli-function/m-p/2986875#M15618</link>
      <description>&lt;P&gt;+1 to this - we actually have a support case open with VMware because we can't find what permissions are required to use the 'shutdown vsan' and 'restart / startup vsan' cluster other than top level / &lt;A href="mailto:administrator@vsphere.local" target="_blank"&gt;administrator@vsphere.local&lt;/A&gt;&amp;nbsp;privs.&lt;/P&gt;&lt;P&gt;We need to scope a role for tenants within our shared vcenter to do this - but it doesn't seem to be documented anywhere.&amp;nbsp; lmk if you have any insight!&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Fri, 15 Sep 2023 08:29:29 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/VMware-vSAN-Discussions/vSAN-shutdown-cluster-Powercli-function/m-p/2986875#M15618</guid>
      <dc:creator>mrstorey303</dc:creator>
      <dc:date>2023-09-15T08:29:29Z</dc:date>
    </item>
    <item>
      <title>Re: NSX Application Platform Automation</title>
      <link>https://communities.vmware.com/t5/VMware-NSX-Discussions/NSX-Application-Platform-Automation/m-p/2985376#M16882</link>
      <description>&lt;P&gt;Fwiw I heard back from VMware about this.&lt;/P&gt;&lt;P&gt;In my case, this is because I'm using a very recent (8.1+) version of vcenter, which deprecates tkg release 1.21.6, which causes an issue for 0.2.x versions of the appliance.&lt;/P&gt;&lt;P&gt;As I suspected, there is a new release of the automation appliance coming out soon which will address this.&lt;/P&gt;</description>
      <pubDate>Tue, 05 Sep 2023 10:38:34 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/VMware-NSX-Discussions/NSX-Application-Platform-Automation/m-p/2985376#M16882</guid>
      <dc:creator>mrstorey303</dc:creator>
      <dc:date>2023-09-05T10:38:34Z</dc:date>
    </item>
    <item>
      <title>Re: NSX Application Platform Automation</title>
      <link>https://communities.vmware.com/t5/VMware-NSX-Discussions/NSX-Application-Platform-Automation/m-p/2985325#M16881</link>
      <description>&lt;P&gt;+1 - I'm getting the same here.&lt;/P&gt;&lt;P&gt;To me this reads like the automation appliance is pre-loaded with whatever yaml deploys tkg clusters, and it's trying to deploy a deprecated version.&lt;/P&gt;&lt;P&gt;Basically, we prob need a new version of the OVA.&lt;/P&gt;&lt;P&gt;Will reach out to support + account team unless you have heard anything?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 04 Sep 2023 16:07:07 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/VMware-NSX-Discussions/NSX-Application-Platform-Automation/m-p/2985325#M16881</guid>
      <dc:creator>mrstorey303</dc:creator>
      <dc:date>2023-09-04T16:07:07Z</dc:date>
    </item>
    <item>
      <title>NSX-T Identity Firewall Event Log Scraping - Large Environments</title>
      <link>https://communities.vmware.com/t5/VMware-NSX-Discussions/NSX-T-Identity-Firewall-Event-Log-Scraping-Large-Environments/m-p/2950560#M15985</link>
      <description>&lt;P class=""&gt;Is it possible to configure Identity Firewall Event Log Scraping to servers that hold subscribed events? Or do event log servers in the id firewall configuration *have* to be domain controllers, because there's no way of telling NSX to look in an event log other than the security log?&lt;/P&gt;&lt;P class=""&gt;We have a pretty large environment - NSX-T 3.2.2, multiple domains, many sites, many domain controllers. Since domain controllers only hold events for logon attempts against that particular domain controller, we'd end up having to configure a lot of event log servers in NSX.&lt;/P&gt;&lt;P class=""&gt;With other user ID solutions we've been able to configure event log forwarding on a box, which acts as an aggregation point for these types of events, and we point the solution at that. Is it wishful thinking I can get NSX-T to do that?&lt;/P&gt;&lt;P class=""&gt;Thanks in advance&lt;/P&gt;</description>
      <pubDate>Wed, 25 Jan 2023 00:07:58 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/VMware-NSX-Discussions/NSX-T-Identity-Firewall-Event-Log-Scraping-Large-Environments/m-p/2950560#M15985</guid>
      <dc:creator>mrstorey303</dc:creator>
      <dc:date>2023-01-25T00:07:58Z</dc:date>
    </item>
    <item>
      <title>NSX Application Platform Without Tanzu?</title>
      <link>https://communities.vmware.com/t5/VMware-NSX-Discussions/NSX-Application-Platform-Without-Tanzu/m-p/2928467#M15415</link>
      <description>&lt;P&gt;Has anyone has success deploying the NSX Application Platform on a k8s platform that *is not* Tanzu?&lt;/P&gt;&lt;P&gt;Documentation says that it's supported on&amp;nbsp;1.17 - 1.21 upstream k8s compliant cluster:&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.vmware.com/en/VMware-NSX-T-Data-Center/3.2/nsx-application-platform/GUID-D54C1B87-8EF3-45B3-AB27-EFE90A154DD3.html" target="_blank"&gt;https://docs.vmware.com/en/VMware-NSX-T-Data-Center/3.2/nsx-application-platform/GUID-D54C1B87-8EF3-45B3-AB27-EFE90A154DD3.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Ideally we'd like to deploy NAPP on a managed k8s instance, such as EKS or GKE, but to us so far, it seems extremely difficult to deploy on anything that is not Tanzu..&lt;/P&gt;&lt;P&gt;Deploying on EKS for example, will throw an error saying there aren't enough control nodes for advanced deployments (ie requires 3, but EKS doesn't expose control node counts because the mgmt plane is a managed service).&lt;/P&gt;</description>
      <pubDate>Mon, 12 Sep 2022 17:56:34 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/VMware-NSX-Discussions/NSX-Application-Platform-Without-Tanzu/m-p/2928467#M15415</guid>
      <dc:creator>mrstorey303</dc:creator>
      <dc:date>2022-09-12T17:56:34Z</dc:date>
    </item>
    <item>
      <title>NSX Application Platform Deployment Failed - 'Registration Failed'</title>
      <link>https://communities.vmware.com/t5/VMware-NSX-Discussions/NSX-Application-Platform-Deployment-Failed-Registration-Failed/m-p/2918309#M14953</link>
      <description>&lt;P class=""&gt;I’m struggling to deploy the NSX Application Platform in our environment.&amp;nbsp; &amp;nbsp;The deployment prechecks all pass, but the deployment consistently fails at the ‘Registering Platform’ step.&lt;SPAN class=""&gt;&amp;nbsp; &lt;/SPAN&gt;Admittedly I am a newbie when it comes to Tanzu and k8s, but hoping someone can point me in the right direction.&lt;/P&gt;&lt;P class=""&gt;I have deployed a Tanzu CE cluster, 3 control plane nodes and 3 worker nodes.&lt;SPAN class=""&gt;&amp;nbsp; &lt;/SPAN&gt;All meeting the spec required to deploy NSX intelligence (16CPUs, 64GB RAM, 1TB Disk).&lt;SPAN class=""&gt;&amp;nbsp; &lt;/SPAN&gt;Kube VIP + antrea is used for networking.&lt;/P&gt;&lt;P class=""&gt;MetalLB has been configured to provide an entry point for the service name / fqdn.&lt;SPAN class=""&gt;&amp;nbsp; &lt;/SPAN&gt;It has been given a pool of 15 addresses, and I have configured 2 A records to point to the first two addresses from this range:&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;Service name - &lt;A href="http://nsx-application-platform.domain.com" target="_blank" rel="noopener"&gt;nsx-application-platform.domain.com&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;Messaging Service Name - &lt;A href="http://nsx-application-platform-msn.domain.com" target="_blank" rel="noopener"&gt;nsx-application-platform-msn.domain.com&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;(&lt;EM&gt;To be honest, I’m not exactly clear what the ‘messaging service name’ is - it seems new with nsx 3.2.x - I’m also just taking it on faith that the deployment will somehow assign the correct IPs from the metallb pool, to correspond with the A records I have created…..&lt;/EM&gt;)&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;For context, I’ve been using this chap’s guide, and found it very helpful - &lt;A href="https://lumberjackwizard.com/2022/03/09/deploying-nsx-application-platform-part-six-metallb/" target="_blank" rel="noopener"&gt;https://lumberjackwizard.com/2022/03/09/deploying-nsx-application-platform-part-six-metallb/&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;Aside from the obvious symptom / error of ‘NSX Application Platform Registration failed’ during deployment, the only other errors I can see are these, which occur on the metallb speaker pods&lt;/P&gt;&lt;P class=""&gt;Events:&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;&amp;nbsp; &lt;/SPAN&gt;Type &lt;SPAN class=""&gt;&amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;Reason &lt;SPAN class=""&gt;&amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;Age &lt;SPAN class=""&gt;&amp;nbsp; &lt;/SPAN&gt;From &lt;SPAN class=""&gt;&amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;Message&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;&amp;nbsp; &lt;/SPAN&gt;---- &lt;SPAN class=""&gt;&amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;------ &lt;SPAN class=""&gt;&amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;----&lt;SPAN class=""&gt;&amp;nbsp; &lt;/SPAN&gt;---- &lt;SPAN class=""&gt;&amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;-------&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;&amp;nbsp; &lt;/SPAN&gt;Warning&lt;SPAN class=""&gt;&amp;nbsp; &lt;/SPAN&gt;Unhealthy&lt;SPAN class=""&gt;&amp;nbsp; &lt;/SPAN&gt;45m &lt;SPAN class=""&gt;&amp;nbsp; &lt;/SPAN&gt;kubelet&lt;SPAN class=""&gt;&amp;nbsp; &lt;/SPAN&gt;Liveness probe failed: Get "&lt;A href="http://10.50.16.169:7472/metrics" target="_blank" rel="noopener"&gt;http://10.50.16.169:7472/metrics&lt;/A&gt;": context deadline exceeded (Client.Timeout exceeded while awaiting headers)&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;&amp;nbsp; &lt;/SPAN&gt;Warning&lt;SPAN class=""&gt;&amp;nbsp; &lt;/SPAN&gt;Unhealthy&lt;SPAN class=""&gt;&amp;nbsp; &lt;/SPAN&gt;45m &lt;SPAN class=""&gt;&amp;nbsp; &lt;/SPAN&gt;kubelet&lt;SPAN class=""&gt;&amp;nbsp; &lt;/SPAN&gt;Readiness probe failed: Get "&lt;A href="http://10.50.16.169:7472/metrics" target="_blank" rel="noopener"&gt;http://10.50.16.169:7472/metrics&lt;/A&gt;": context deadline exceeded (Client.Timeout exceeded while awaiting headers)&lt;/P&gt;&lt;P class=""&gt;That said, all the pods in the metallb namespace look like they are running ok:&lt;/P&gt;&lt;P class=""&gt;&amp;gt;kubectl get pods -n metallb-system&lt;/P&gt;&lt;P class=""&gt;NAME&lt;SPAN class=""&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;READY &lt;SPAN class=""&gt;&amp;nbsp; &lt;/SPAN&gt;STATUS&lt;SPAN class=""&gt;&amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;RESTARTS &lt;SPAN class=""&gt;&amp;nbsp; &lt;/SPAN&gt;AGE&lt;/P&gt;&lt;P class=""&gt;controller-66445f859d-589zw &lt;SPAN class=""&gt;&amp;nbsp; &lt;/SPAN&gt;1/1 &lt;SPAN class=""&gt;&amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;Running &lt;SPAN class=""&gt;&amp;nbsp; &lt;/SPAN&gt;0&lt;SPAN class=""&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;20h&lt;/P&gt;&lt;P class=""&gt;speaker-c6gqt &lt;SPAN class=""&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;1/1 &lt;SPAN class=""&gt;&amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;Running &lt;SPAN class=""&gt;&amp;nbsp; &lt;/SPAN&gt;0&lt;SPAN class=""&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;20h&lt;/P&gt;&lt;P class=""&gt;speaker-dnrbh &lt;SPAN class=""&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;1/1 &lt;SPAN class=""&gt;&amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;Running &lt;SPAN class=""&gt;&amp;nbsp; &lt;/SPAN&gt;0&lt;SPAN class=""&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;20h&lt;/P&gt;&lt;P class=""&gt;speaker-ncpcl &lt;SPAN class=""&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;1/1 &lt;SPAN class=""&gt;&amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;Running &lt;SPAN class=""&gt;&amp;nbsp; &lt;/SPAN&gt;0&lt;SPAN class=""&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;20h&lt;/P&gt;&lt;P class=""&gt;speaker-qg6zz &lt;SPAN class=""&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;1/1 &lt;SPAN class=""&gt;&amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;Running &lt;SPAN class=""&gt;&amp;nbsp; &lt;/SPAN&gt;0&lt;SPAN class=""&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;20h&lt;/P&gt;&lt;P class=""&gt;speaker-qt7mw &lt;SPAN class=""&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;1/1 &lt;SPAN class=""&gt;&amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;Running &lt;SPAN class=""&gt;&amp;nbsp; &lt;/SPAN&gt;0&lt;SPAN class=""&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;20h&lt;/P&gt;&lt;P class=""&gt;speaker-r6kgs &lt;SPAN class=""&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;1/1 &lt;SPAN class=""&gt;&amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;Running &lt;SPAN class=""&gt;&amp;nbsp; &lt;/SPAN&gt;0&lt;SPAN class=""&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;20h&lt;/P&gt;&lt;P class=""&gt;I appreciate these scenarios are very difficult to diagnose and troubleshoot - but I’d really appreciate any pointers you could throw my way!&lt;/P&gt;&lt;P class=""&gt;Thanks in advance&lt;/P&gt;</description>
      <pubDate>Tue, 12 Jul 2022 10:32:52 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/VMware-NSX-Discussions/NSX-Application-Platform-Deployment-Failed-Registration-Failed/m-p/2918309#M14953</guid>
      <dc:creator>mrstorey303</dc:creator>
      <dc:date>2022-07-12T10:32:52Z</dc:date>
    </item>
    <item>
      <title>vLCM &amp; Auto Deploy - Stateful Install to Remote / SAN Disk</title>
      <link>https://communities.vmware.com/t5/VMware-vSphere-Discussions/vLCM-amp-Auto-Deploy-Stateful-Install-to-Remote-SAN-Disk/m-p/2869485#M40326</link>
      <description>&lt;P&gt;I'm trying to use auto deploy to perform stateful installs on diskless ESXi hosts to an FC SAN disk on our Flasharray (using the 'remote' disk argument).&lt;/P&gt;&lt;P&gt;This works fine unless I configure auto deploy to build the host into a vLCM enabled cluster (which annoyingly is what I want...)&lt;/P&gt;&lt;P&gt;When using a vLCM cluster, auto deploy always fails with 'install --firstdisk specified, but no suitable disk is found' during install.&amp;nbsp; It seems that regardless of what disk arguments you set in the host profile associated with the vLCM cluster, auto deploy insists on using 'firstdisk' - when I want it to use 'remote'.&lt;/P&gt;&lt;P&gt;It works fine if I deploy the host outside the cluster - so, I guess I have a workaround (I could just move the hosts into the cluster after they are deployed), but it feels like this is an undocumented feature / limitation of vLCM and auto deploy, unless I'm missing something.&lt;/P&gt;&lt;P&gt;Anyone with similar experiences?&lt;/P&gt;</description>
      <pubDate>Thu, 30 Sep 2021 09:22:05 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/VMware-vSphere-Discussions/vLCM-amp-Auto-Deploy-Stateful-Install-to-Remote-SAN-Disk/m-p/2869485#M40326</guid>
      <dc:creator>mrstorey303</dc:creator>
      <dc:date>2021-09-30T09:22:05Z</dc:date>
    </item>
    <item>
      <title>Re: Horizon 8.2 / F5 iApp + Connection Server HTML5 Tunnelling</title>
      <link>https://communities.vmware.com/t5/Horizon-Desktops-and-Apps/Horizon-8-2-F5-iApp-Connection-Server-HTML5-Tunnelling/m-p/2865942#M94773</link>
      <description>&lt;P&gt;To further this - we're also finding that having x-forwarded-for enabled on the our F5 also prevents DEM smart policies from being able to detect the gateway location (ie internal / external).&lt;/P&gt;&lt;P&gt;This is preventing policy based cut / paste operations from working, ie we want 'internal' users to have inbound+outbound cut and paste, and disabled for external.&lt;/P&gt;&lt;P&gt;Anyone else seeing this?&lt;/P&gt;</description>
      <pubDate>Wed, 08 Sep 2021 16:08:57 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/Horizon-Desktops-and-Apps/Horizon-8-2-F5-iApp-Connection-Server-HTML5-Tunnelling/m-p/2865942#M94773</guid>
      <dc:creator>mrstorey303</dc:creator>
      <dc:date>2021-09-08T16:08:57Z</dc:date>
    </item>
    <item>
      <title>Re: Horizon 8.2 / F5 iApp + Connection Server HTML5 Tunnelling</title>
      <link>https://communities.vmware.com/t5/Horizon-Desktops-and-Apps/Horizon-8-2-F5-iApp-Connection-Server-HTML5-Tunnelling/m-p/2862019#M94641</link>
      <description>&lt;P&gt;Reply from F5 support:&lt;/P&gt;&lt;P&gt;re: x-forwarded-for:&lt;/P&gt;&lt;P&gt;&lt;EM&gt;- This is an application requirement and depends on the application itself. The BigIP unit only inserts the client's IP address as a header for the application to be aware of source of connectivity and requests.&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;re: why would disabling x-forward-for make a difference anyway?&lt;/P&gt;&lt;P&gt;&lt;EM&gt;- This is something that VMWare team will have to explain. Browsers identify themselves with "agent data", so application should have no problems identifying them as such.&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;re: are F5 going to fix / update the iApp&lt;/P&gt;&lt;P&gt;&lt;EM&gt;- If there is an issue with new Horizon version that needs to be fixed, VMWare will provide a fix/patch/workaround.&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;a href="https://communities.vmware.com/t5/user/viewprofilepage/user-id/3090293"&gt;@wing523&lt;/a&gt;&amp;nbsp;- do you have any detail on why disabling x-forwarded-for is actually required for selective tunnelling to work on recent horizon versions?&amp;nbsp; Appears there is a bit of finger-pointed regarding why the issue occurs, and who's responsibility it is to fix.&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Fri, 13 Aug 2021 17:03:52 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/Horizon-Desktops-and-Apps/Horizon-8-2-F5-iApp-Connection-Server-HTML5-Tunnelling/m-p/2862019#M94641</guid>
      <dc:creator>mrstorey303</dc:creator>
      <dc:date>2021-08-13T17:03:52Z</dc:date>
    </item>
    <item>
      <title>Re: Horizon 8.2 / F5 iApp + Connection Server HTML5 Tunnelling</title>
      <link>https://communities.vmware.com/t5/Horizon-Desktops-and-Apps/Horizon-8-2-F5-iApp-Connection-Server-HTML5-Tunnelling/m-p/2861315#M94614</link>
      <description>&lt;P&gt;Reopening this for discussion if possible - while I follow up with F5 re: iApp configuration - anyone know from within VMware why disabling this feature would allow the connection servers to start correctly / selectively tunnelling for html5 again?&amp;nbsp; And why this is a change in Horizon 8.x ?&lt;/P&gt;&lt;P&gt;Not an expert, but I all I thought x-forwarded-for did was just send the client IP to the web server, for logging / auditing purposes etc.&amp;nbsp; Why would the connection servers break tunnelling if F5 sent this info?&lt;/P&gt;</description>
      <pubDate>Mon, 09 Aug 2021 14:55:38 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/Horizon-Desktops-and-Apps/Horizon-8-2-F5-iApp-Connection-Server-HTML5-Tunnelling/m-p/2861315#M94614</guid>
      <dc:creator>mrstorey303</dc:creator>
      <dc:date>2021-08-09T14:55:38Z</dc:date>
    </item>
    <item>
      <title>Re: Horizon 8.2 / F5 iApp + Connection Server HTML5 Tunnelling</title>
      <link>https://communities.vmware.com/t5/Horizon-Desktops-and-Apps/Horizon-8-2-F5-iApp-Connection-Server-HTML5-Tunnelling/m-p/2860486#M94579</link>
      <description>&lt;P&gt;My bad! &amp;nbsp;Looks like someone disabled tunnelling on one of the connection servers in the pair in between testing.&lt;/P&gt;&lt;P&gt;Just went back to double check the config and it works!&lt;/P&gt;&lt;P&gt;Thanks to all involved. &amp;nbsp;Will reach out to F5 to see if they'll consider updating their iApp to reflect these changes - doesn't look like it's been updated in a while.&lt;/P&gt;</description>
      <pubDate>Tue, 03 Aug 2021 07:39:36 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/Horizon-Desktops-and-Apps/Horizon-8-2-F5-iApp-Connection-Server-HTML5-Tunnelling/m-p/2860486#M94579</guid>
      <dc:creator>mrstorey303</dc:creator>
      <dc:date>2021-08-03T07:39:36Z</dc:date>
    </item>
    <item>
      <title>Re: Horizon 8.2 / F5 iApp + Connection Server HTML5 Tunnelling</title>
      <link>https://communities.vmware.com/t5/Horizon-Desktops-and-Apps/Horizon-8-2-F5-iApp-Connection-Server-HTML5-Tunnelling/m-p/2860310#M94570</link>
      <description>&lt;P&gt;Sorry for the delay with this - I retried disabling this on the http client profile (the one the iApp creates), and also setting the client profile to 'none' on the LTM, but I still get the cert warnings.&lt;/P&gt;&lt;P&gt;Trying to follow up with F5 support now - will report back if I find anything useful.&lt;/P&gt;</description>
      <pubDate>Mon, 02 Aug 2021 09:55:51 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/Horizon-Desktops-and-Apps/Horizon-8-2-F5-iApp-Connection-Server-HTML5-Tunnelling/m-p/2860310#M94570</guid>
      <dc:creator>mrstorey303</dc:creator>
      <dc:date>2021-08-02T09:55:51Z</dc:date>
    </item>
    <item>
      <title>Re: Horizon 8.2 / F5 iApp + Connection Server HTML5 Tunnelling</title>
      <link>https://communities.vmware.com/t5/Horizon-Desktops-and-Apps/Horizon-8-2-F5-iApp-Connection-Server-HTML5-Tunnelling/m-p/2855869#M94358</link>
      <description>&lt;P&gt;Thanks for your reply - I'm aware of the KB but that config is something I'd like to avoid - using wildcard certificates for desktops and configuring view to access agents via DNS name isn't really palatable - I'd just like to get 8.2 to behave in the same way 7.12 was in terms of connection server html5 tunnelling and F5 LTMs.&lt;/P&gt;&lt;P&gt;I saw the release notes, and admittedly reading &lt;EM&gt;'the forwarding rules for HTTP requests.....have changed..'&lt;/EM&gt; certainly seems relevant, but the frontServiceWhitelist config just disables the admin console on a connection server, it doesn't seem related to html5 blast tunnelling.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jul 2021 16:20:44 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/Horizon-Desktops-and-Apps/Horizon-8-2-F5-iApp-Connection-Server-HTML5-Tunnelling/m-p/2855869#M94358</guid>
      <dc:creator>mrstorey303</dc:creator>
      <dc:date>2021-07-05T16:20:44Z</dc:date>
    </item>
    <item>
      <title>Horizon 8.2 / F5 iApp + Connection Server HTML5 Tunnelling</title>
      <link>https://communities.vmware.com/t5/Horizon-Desktops-and-Apps/Horizon-8-2-F5-iApp-Connection-Server-HTML5-Tunnelling/m-p/2855858#M94355</link>
      <description>&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;Anyone out there using the Horizon F5 iApp to front multiple connection servers?&lt;/P&gt;&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;Since upgrading from Horizon 7.12 to Horizon 8.2 our F5’s don’t seem to work with selective tunnelling to HTML5 clients anymore, so this naturally throws a cert warning because the URL offered is that of the remote desktop IP rather than the blast external URL (so, basically not tunnelled).&lt;/P&gt;&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;We’re running the v1.5.9 of the Horizon iApp, and we have “Use Blast Secure Gateway for only HTML Access Connections to machine” set on the connection servers. The iApp has ‘No, Blast connections should not go through the BIG-IP system’. But I’ve also tried with ‘Yes - blast should go through BIG-IP + Yes, Blast proxied by UAGs’ which has the same non-tunnelling result.&lt;/P&gt;&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;External HTML5 client connections via a UAG work fine (and associated F5 LTM), Not sure what’s changed since the upgrade re: selective HTML5 tunnelling for load balanced connection servers.&lt;/P&gt;&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;Anyone with similar setups experienced this?&lt;/P&gt;&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;Thanks in advance&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jul 2021 13:52:57 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/Horizon-Desktops-and-Apps/Horizon-8-2-F5-iApp-Connection-Server-HTML5-Tunnelling/m-p/2855858#M94355</guid>
      <dc:creator>mrstorey303</dc:creator>
      <dc:date>2021-07-05T13:52:57Z</dc:date>
    </item>
    <item>
      <title>Large Linked Mode Environments - Backup, Recovery, Operations</title>
      <link>https://communities.vmware.com/t5/VMware-vCenter-Discussions/Large-Linked-Mode-Environments-Backup-Recovery-Operations/m-p/2315173#M35300</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Its looking like I need to break up our centralised, multi-tenant vCenter model up into a individual vCenters per tenant, pretty much because of the limitations of NSX - ie not able to scope access for distributed firewall admins to 'per tenant' ESX hosts (I want to prevent a tenant from pushing firewall rules to other tenant's esxi nodes).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Splitting up the vcenters I'm fine with - in many ways it'd make my life simpler.&amp;nbsp; But I'm getting pressure internally to consider deploying all of them into a single SSO domain - and given my recent (bad) vCenter upgrade experiences, and the rollback / DR prep you need to do in order to recover from a failed upgrade when using linked mode, it fills me with dread.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I guess you're all aware - the only supported rollback method (outside of recovering from file based vcsa backups) is to:&lt;/P&gt;&lt;P&gt;- Power down ALL vcenters in the SSO domain (or at least stop services on all)&lt;/P&gt;&lt;P&gt;- Snap, power back up.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This makes sense, because it allows for a clean recovery point across the domain, avoiding the obvious issues you'll run into re: PSC replication.&amp;nbsp; But, it's pretty inconvenient.&amp;nbsp; If you have a failed upgrade on one vcenter, be prepared to roll them all back.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The potential scenario I'm looking at is a 9 x VCSA, single SSO deployment.&amp;nbsp; (3 x tenants, 3&amp;nbsp; datacenters).&amp;nbsp; To me, this spells bad news.&amp;nbsp; Yes, I want centralised auth, I want global object searching....but I don't think I have enough confidence in VMware's directory service, nor do I think there's enough expertise out there to support this appropriately.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Interested to know if anyone here has a large linked mode environment and how this impacts routine patching an upgrades?&amp;nbsp; It's crazy right?&amp;nbsp; Someone convince me otherwise!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 28 Sep 2020 10:51:02 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/VMware-vCenter-Discussions/Large-Linked-Mode-Environments-Backup-Recovery-Operations/m-p/2315173#M35300</guid>
      <dc:creator>mrstorey303</dc:creator>
      <dc:date>2020-09-28T10:51:02Z</dc:date>
    </item>
    <item>
      <title>Re: Configure SAML auth / SSO with Skyline Advisor?</title>
      <link>https://communities.vmware.com/t5/Skyline-Community-Discussions/Configure-SAML-auth-SSO-with-Skyline-Advisor/m-p/1838972#M1534</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks - unfortunately there's no appetite to deploy another IDP - we're heavily invested in Okta so we'd like to use this really.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It looks entirely possible to do - I just could use some advice with what values to set for the login redirect URIs on both sides / the SP and the IDP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a ticket open with VMware support but I think this is uncharted territory for them - they're asking re: 'What errors are you getting' etc.&amp;nbsp; I'm not really at that point - I could guess some values to generate errors, but not sure if that's a sensible way to progress the conversation! &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://communities.vmware.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'll keep hacking away, but if there's any bright spark out there who's done this, I'd appreciate talking to them!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 Jul 2020 09:32:43 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/Skyline-Community-Discussions/Configure-SAML-auth-SSO-with-Skyline-Advisor/m-p/1838972#M1534</guid>
      <dc:creator>mrstorey303</dc:creator>
      <dc:date>2020-07-08T09:32:43Z</dc:date>
    </item>
    <item>
      <title>Re: Scheduled Findings / Recommendations Reports</title>
      <link>https://communities.vmware.com/t5/Skyline-Community-Discussions/Scheduled-Findings-Recommendations-Reports/m-p/2302335#M2439</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Excellent, thank you.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 25 Jun 2020 07:33:00 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/Skyline-Community-Discussions/Scheduled-Findings-Recommendations-Reports/m-p/2302335#M2439</guid>
      <dc:creator>mrstorey303</dc:creator>
      <dc:date>2020-06-25T07:33:00Z</dc:date>
    </item>
    <item>
      <title>Re: Configure SAML auth / SSO with Skyline Advisor?</title>
      <link>https://communities.vmware.com/t5/Skyline-Community-Discussions/Configure-SAML-auth-SSO-with-Skyline-Advisor/m-p/1838970#M1532</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Perfect!&amp;nbsp; many thanks - forgive my ignorance, but these guides are specifically for Velocloud / VMware's SD-WAN products - presumably they're provided here because both Velocloud and Skyline are services which run in the same cloud service, and are therefore subject to the same authentication options?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 23 Jun 2020 10:11:45 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/Skyline-Community-Discussions/Configure-SAML-auth-SSO-with-Skyline-Advisor/m-p/1838970#M1532</guid>
      <dc:creator>mrstorey303</dc:creator>
      <dc:date>2020-06-23T10:11:45Z</dc:date>
    </item>
    <item>
      <title>Re: UAG Blast Tunnelling for HTML Connections Only?</title>
      <link>https://communities.vmware.com/t5/Horizon-Desktops-and-Apps/UAG-Blast-Tunnelling-for-HTML-Connections-Only/m-p/1834522#M84947</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;OK thanks, this is what I figured.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In which case, I guess my options are for internal TrueSSO are:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Enable tunnelling - both thick clients and HTML5 clients are tunnelled regardless.&lt;/P&gt;&lt;P&gt;- Disable tunnelling, but configure the connection servers to return a DNS name rather than IP address, so that direct HTML5 connections do not throw a cert warning.&amp;nbsp; (Not entirely happy to do this, because it'd introduce a significant dependancy on accurate DNS queries for instant clones / highly ephemeral environments.&amp;nbsp; I could see an issue where users are brokered out to different machines to what the connection server allocated!)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I should probably throw in a feature request for the UAG product team.&amp;nbsp; Just as a side, I've always wondered why these cert warnings only throw for brokered, direct HTML5 connections, and not brokered direct connections from the thick client?&amp;nbsp; Maybe a question for another thread!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 22 Jun 2020 08:44:06 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/Horizon-Desktops-and-Apps/UAG-Blast-Tunnelling-for-HTML-Connections-Only/m-p/1834522#M84947</guid>
      <dc:creator>mrstorey303</dc:creator>
      <dc:date>2020-06-22T08:44:06Z</dc:date>
    </item>
    <item>
      <title>Scheduled Findings / Recommendations Reports</title>
      <link>https://communities.vmware.com/t5/Skyline-Community-Discussions/Scheduled-Findings-Recommendations-Reports/m-p/2302333#M2437</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is it possible to configure Skyline advisor to set emails out on a schedule?&amp;nbsp; ie - Send me a weekly schedule of all critical + moderate severity findings in my environment to x email addresses?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The only config option I see is a simple toggle switch 'Email New Critical Findings', which is great - I'd want this to continue, but I see some value in having regular reports, almost to nag our engineers into resolving or acknowledging existing findings / recommendations.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Likewise, are there any plans to offer an API to query Skyline via internal automation?&amp;nbsp; Feel there could be come value in exposing / feeding Skyline data to internal monitoring tools.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm trying to develop a process for our engineers to regularly review Skyline - scheduled emails and API access would help here I think.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 20 Jun 2020 05:04:45 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/Skyline-Community-Discussions/Scheduled-Findings-Recommendations-Reports/m-p/2302333#M2437</guid>
      <dc:creator>mrstorey303</dc:creator>
      <dc:date>2020-06-20T05:04:45Z</dc:date>
    </item>
  </channel>
</rss>

