Re: ALARM - ACS reboots host servers!!!

2014-03-03 Thread France
I believe this is a bug too, because VMs not running on the storage, get 
destroyed too:


Issue has been around for a long time, like with all others I reported. 
They do not get fixed:

https://issues.apache.org/jira/browse/CLOUDSTACK-3367

We even lost assignee today.

Regards,
F.

On 3/3/14 6:55 AM, Koushik Das wrote:

The primary storage needs to be put in maintenance before doing any 
upgrade/reboot as mentioned in the previous mails.

-Koushik

On 03-Mar-2014, at 6:07 AM, Marcus shadow...@gmail.com wrote:


Also, please note that in the bug you referenced it doesn't have a
problem with the reboot being triggered, but with the fact that reboot
never completes due to hanging NFS mount (which is why the reboot
occurs, inaccessible primary storage).

On Sun, Mar 2, 2014 at 5:26 PM, Marcus shadow...@gmail.com wrote:

Or do you mean you have multiple primary storages and this one was not
in use and put into maintenance?

On Sun, Mar 2, 2014 at 5:25 PM, Marcus shadow...@gmail.com wrote:

I'm not sure I understand. How do you expect to reboot your primary
storage while vms are running?  It sounds like the host is being
fenced since it cannot contact the resources it depends on.

On Sun, Mar 2, 2014 at 3:24 PM, Nux! n...@li.nux.ro wrote:

On 02.03.2014 21:17, Andrei Mikhailovsky wrote:

Hello guys,


I've recently came across the bug CLOUDSTACK-5429 which has rebooted
all of my host servers without properly shutting down the guest vms.
I've simply upgraded and rebooted one of the nfs primary storage
servers and a few minutes later, to my horror, i've found out that all
of my host servers have been rebooted. Is it just me thinking so, or
is this bug should be fixed ASAP and should be a blocker for any new
ACS release. I mean not only does it cause downtime, but also possible
data loss and server corruption.


Hi Andrei,

Do you have HA enabled and did you put that primary storage in maintenance
mode before rebooting it?
It's my understanding that ACS relies on the shared storage to perform HA so
if the storage goes it's expected to go berserk. I've noticed similar
behaviour in Xenserver pools without ACS.
I'd imagine a cure for this would be to use network distributed
filesystems like GlusterFS or CEPH.

Lucian

--
Sent from the Delta quadrant using Borg technology!

Nux!
www.nux.ro




Suitable solution for HW

2014-03-03 Thread Pääkkönen Pekka
Hi,

I am planning to install virtualization or cloud solution to a rack server with 
the following spec:

Dell PowerEdge R820
+ 4 processors (Intel Xeon E5-4620), 8 cores/processor
+ 512 GB RAM
+ 8 HDD, 1 TB/disk
+ 2*1Gb, 2*10Gb network cards

A similar server would also be available.

One use case for the rack server would be serve as a cluster of database nodes 
with write-intensive workloads.

Would CloudStack be an appropriate solution for this kind of HW?
Or would a virtualization solution (for example Xen) be a better choice?


Regards,
Pekka Pääkkönen


Re: Suitable solution for HW

2014-03-03 Thread Daan Hoogland
On Mon, Mar 3, 2014 at 11:24 AM, Pääkkönen Pekka pekka.paakko...@vtt.fi wrote:
 Or would a virtualization solution (for example Xen) be a better choice?


I don't understand your question or you don't understand cloudstack,
Pekka. Using cloudstack you would still need a virtualization server
like Xen. If you are on;ly using one and don't foresee any migration
of running VMs go with that. If you have uptime requirements that span
beyond the livetime of your hardware, use cloudstack.

-- 
Daan


RE: Suitable solution for HW

2014-03-03 Thread Pääkkönen Pekka
Hi Daan,

Maybe I should have been clearer.
I was wondering about the implications for performance. 
Would performance in a database clustering use case be better with plain Xen 
(or other virtualization solution), when compared to CloudStack with Xen?
Or is this an unnecessary concern?

Also, is CloudStack aimed for clusters consisting of tens/hundreds of such rack 
servers, or is it suitable also for smaller deployments?

Pekka  


-Original Message-
From: Daan Hoogland [mailto:daan.hoogl...@gmail.com] 
Sent: 3. maaliskuuta 2014 12:28
To: users@cloudstack.apache.org
Subject: Re: Suitable solution for HW

On Mon, Mar 3, 2014 at 11:24 AM, Pääkkönen Pekka pekka.paakko...@vtt.fi wrote:
 Or would a virtualization solution (for example Xen) be a better choice?


I don't understand your question or you don't understand cloudstack, Pekka. 
Using cloudstack you would still need a virtualization server like Xen. If you 
are on;ly using one and don't foresee any migration of running VMs go with 
that. If you have uptime requirements that span beyond the livetime of your 
hardware, use cloudstack.

--
Daan


RE: Suitable solution for HW

2014-03-03 Thread Nux!

On 03.03.2014 11:22, Pääkkönen Pekka wrote:

Hi Daan,

Maybe I should have been clearer.
I was wondering about the implications for performance.
Would performance in a database clustering use case be better with
plain Xen (or other virtualization solution), when compared to
CloudStack with Xen?
Or is this an unnecessary concern?

Also, is CloudStack aimed for clusters consisting of tens/hundreds of
such rack servers, or is it suitable also for smaller deployments?


Cloudstack can grow from 1 to many servers.
Re hypervisor, if you want to run databases then IO will be your main 
concern. At some point the hypervisor will not matter, your disks will 
matter. I'd look at investing in SSDs.
You can also look at conainer technology such as openvz and LXC which 
usually have better IO (since they access the hardware directly).


--
Sent from the Delta quadrant using Borg technology!

Nux!
www.nux.ro


Re: Suitable solution for HW

2014-03-03 Thread Geoff Higginbottom
Hi Daan.

As Nux has already highlighted, disk IO is the critical factor for high 
performance database applications.

Using local storage within the Hypervisor will only provide very limited IOPS, 
even with 15k SAS disks.

We have been doing a lot of work with SolidFire storage recently. In my opinion 
they are simply the best storage option available for CloudStack, and have a 
plugin which integrates it directly with CloudStack.

Regards

Geoff Higginbottom
CTO / Cloud Architect

D: +44 20 3603 0542tel:+442036030542 | S: +44 20 3603 0540tel:+442036030540 
| M: +447968161581tel:+447968161581

geoff.higginbot...@shapeblue.commailto:geoff.higginbot...@shapeblue.com | 
www.shapeblue.comhtp://www.shapeblue.com/ | 
Twitter:@cloudstackguruhttps://twitter.com/#!/cloudstackguru

ShapeBlue Ltd, 53 Chandos Place, Covent Garden, London, WC2N 
4HSx-apple-data-detectors://5


On 3 Mar 2014, at 11:43, Nux! n...@li.nux.romailto:n...@li.nux.ro wrote:

On 03.03.2014 11:22, P??kk?nen Pekka wrote:
Hi Daan,
Maybe I should have been clearer.
I was wondering about the implications for performance.
Would performance in a database clustering use case be better with
plain Xen (or other virtualization solution), when compared to
CloudStack with Xen?
Or is this an unnecessary concern?
Also, is CloudStack aimed for clusters consisting of tens/hundreds of
such rack servers, or is it suitable also for smaller deployments?

Cloudstack can grow from 1 to many servers.
Re hypervisor, if you want to run databases then IO will be your main concern. 
At some point the hypervisor will not matter, your disks will matter. I'd look 
at investing in SSDs.
You can also look at conainer technology such as openvz and LXC which usually 
have better IO (since they access the hardware directly).

--
Sent from the Delta quadrant using Borg technology!

Nux!
www.nux.rohttp://www.nux.ro
Need Enterprise Grade Support for Apache CloudStack?
Our CloudStack Infrastructure 
Supporthttp://shapeblue.com/cloudstack-infrastructure-support/ offers the 
best 24/7 SLA for CloudStack Environments.

Apache CloudStack Bootcamp training courses

**NEW!** CloudStack 4.2.1 traininghttp://shapeblue.com/cloudstack-training/
18th-19th February 2014, Brazil. 
Classroomhttp://shapeblue.com/cloudstack-training/
17th-23rd March 2014, Region A. Instructor led, 
On-linehttp://shapeblue.com/cloudstack-training/
24th-28th March 2014, Region B. Instructor led, 
On-linehttp://shapeblue.com/cloudstack-training/
16th-20th June 2014, Region A. Instructor led, 
On-linehttp://shapeblue.com/cloudstack-training/
23rd-27th June 2014, Region B. Instructor led, 
On-linehttp://shapeblue.com/cloudstack-training/

This email and any attachments to it may be confidential and are intended 
solely for the use of the individual to whom it is addressed. Any views or 
opinions expressed are solely those of the author and do not necessarily 
represent those of Shape Blue Ltd or related companies. If you are not the 
intended recipient of this email, you must neither take any action based upon 
its contents, nor copy or show it to anyone. Please contact the sender if you 
believe you have received this email in error. Shape Blue Ltd is a company 
incorporated in England  Wales. ShapeBlue Services India LLP is a company 
incorporated in India and is operated under license from Shape Blue Ltd. Shape 
Blue Brasil Consultoria Ltda is a company incorporated in Brasil and is 
operated under license from Shape Blue Ltd. ShapeBlue is a registered trademark.


Re: ALARM - ACS reboots host servers!!!

2014-03-03 Thread Amin Samir
Hello,

This link addresses your issue.
https://issues.apache.org/jira/browse/CLOUDSTACK-3367

Amin

Sent from my iPad

 On Mar 3, 2014, at 1:56 PM, Koushik Das koushik@citrix.com wrote:
 
 The primary storage needs to be put in maintenance before doing any 
 upgrade/reboot as mentioned in the previous mails.
 
 -Koushik
 
 On 03-Mar-2014, at 6:07 AM, Marcus shadow...@gmail.com wrote:
 
 Also, please note that in the bug you referenced it doesn't have a
 problem with the reboot being triggered, but with the fact that reboot
 never completes due to hanging NFS mount (which is why the reboot
 occurs, inaccessible primary storage).
 
 On Sun, Mar 2, 2014 at 5:26 PM, Marcus shadow...@gmail.com wrote:
 Or do you mean you have multiple primary storages and this one was not
 in use and put into maintenance?
 
 On Sun, Mar 2, 2014 at 5:25 PM, Marcus shadow...@gmail.com wrote:
 I'm not sure I understand. How do you expect to reboot your primary
 storage while vms are running?  It sounds like the host is being
 fenced since it cannot contact the resources it depends on.
 
 On Sun, Mar 2, 2014 at 3:24 PM, Nux! n...@li.nux.ro wrote:
 On 02.03.2014 21:17, Andrei Mikhailovsky wrote:
 
 Hello guys,
 
 
 I've recently came across the bug CLOUDSTACK-5429 which has rebooted
 all of my host servers without properly shutting down the guest vms.
 I've simply upgraded and rebooted one of the nfs primary storage
 servers and a few minutes later, to my horror, i've found out that all
 of my host servers have been rebooted. Is it just me thinking so, or
 is this bug should be fixed ASAP and should be a blocker for any new
 ACS release. I mean not only does it cause downtime, but also possible
 data loss and server corruption.
 
 
 Hi Andrei,
 
 Do you have HA enabled and did you put that primary storage in maintenance
 mode before rebooting it?
 It's my understanding that ACS relies on the shared storage to perform HA 
 so
 if the storage goes it's expected to go berserk. I've noticed similar
 behaviour in Xenserver pools without ACS.
 I'd imagine a cure for this would be to use network distributed
 filesystems like GlusterFS or CEPH.
 
 Lucian
 
 --
 Sent from the Delta quadrant using Borg technology!
 
 Nux!
 www.nux.ro
 


CS mgm. inside XenServer

2014-03-03 Thread Dubravko Sever
Hi,

I have unsupported configuration,and tying to run cs mgm,. inside XenServer 
Hypervisor that I'm managing .  So is there any workarounf that allows me to 
manually register existing VM-s indide CS database, to avoid shutt down by 
agent.
This is testing enviromend, but In feture I would like to migrate existing 
instances (indise XenServer cluster) to be managed my CS?

Thanks

Dubravkoi



-- 
Dubravko Sever
Sektor za računalne sustave
Sveučilište u Zagrebu, Sveučilišni računski centar (Srce), www.srce.unizg.hr
dubravko.se...@srce.hr, tel: +385 1 616 5807, fax: +385 1 616 5559




Re: ALARM - ACS reboots host servers!!!

2014-03-03 Thread Andrei Mikhailovsky
Pretty poor, I agree. 


IMHO the ACS agent should not be allowed to reboot the host server. This is not 
the type of things you would like to automate as you will eventually end up 
with broken volumes and data loss. 


And you are right of course, like what happened in my case. I currently have 
two vms which used that NFS server for volumes and the rest 50+ vms use ceph. 
As a result of the nfs server reboot all host servers have rebooted causing 50+ 
vms to reset without being properly shutdown. 


I am using ACS 4.2.1 with KVM, so this issue seems to be present on KVM + 
XenServer. 


Andrei 
- Original Message -

From: France mailingli...@isg.si 
To: users@cloudstack.apache.org 
Cc: d...@cloudstack.apache.org 
Sent: Monday, 3 March, 2014 8:49:28 AM 
Subject: Re: ALARM - ACS reboots host servers!!! 

I believe this is a bug too, because VMs not running on the storage, get 
destroyed too: 

Issue has been around for a long time, like with all others I reported. 
They do not get fixed: 
https://issues.apache.org/jira/browse/CLOUDSTACK-3367 

We even lost assignee today. 

Regards, 
F. 

On 3/3/14 6:55 AM, Koushik Das wrote: 
 The primary storage needs to be put in maintenance before doing any 
 upgrade/reboot as mentioned in the previous mails. 
 
 -Koushik 
 
 On 03-Mar-2014, at 6:07 AM, Marcus shadow...@gmail.com wrote: 
 
 Also, please note that in the bug you referenced it doesn't have a 
 problem with the reboot being triggered, but with the fact that reboot 
 never completes due to hanging NFS mount (which is why the reboot 
 occurs, inaccessible primary storage). 
 
 On Sun, Mar 2, 2014 at 5:26 PM, Marcus shadow...@gmail.com wrote: 
 Or do you mean you have multiple primary storages and this one was not 
 in use and put into maintenance? 
 
 On Sun, Mar 2, 2014 at 5:25 PM, Marcus shadow...@gmail.com wrote: 
 I'm not sure I understand. How do you expect to reboot your primary 
 storage while vms are running? It sounds like the host is being 
 fenced since it cannot contact the resources it depends on. 
 
 On Sun, Mar 2, 2014 at 3:24 PM, Nux! n...@li.nux.ro wrote: 
 On 02.03.2014 21:17, Andrei Mikhailovsky wrote: 
 Hello guys, 
 
 
 I've recently came across the bug CLOUDSTACK-5429 which has rebooted 
 all of my host servers without properly shutting down the guest vms. 
 I've simply upgraded and rebooted one of the nfs primary storage 
 servers and a few minutes later, to my horror, i've found out that all 
 of my host servers have been rebooted. Is it just me thinking so, or 
 is this bug should be fixed ASAP and should be a blocker for any new 
 ACS release. I mean not only does it cause downtime, but also possible 
 data loss and server corruption. 
 
 Hi Andrei, 
 
 Do you have HA enabled and did you put that primary storage in 
 maintenance 
 mode before rebooting it? 
 It's my understanding that ACS relies on the shared storage to perform HA 
 so 
 if the storage goes it's expected to go berserk. I've noticed similar 
 behaviour in Xenserver pools without ACS. 
 I'd imagine a cure for this would be to use network distributed 
 filesystems like GlusterFS or CEPH. 
 
 Lucian 
 
 -- 
 Sent from the Delta quadrant using Borg technology! 
 
 Nux! 
 www.nux.ro 




Re: ALARM - ACS reboots host servers!!!

2014-03-03 Thread Andrei Mikhailovsky

Koushik, I understand that and I will put the storage into the maintenance mode 
next time. However, things happen and servers crash from time to time, which is 
not the reason to reboot all host servers, even those which do not have any 
running vms with volumes on the nfs storage. The bloody agent just rebooted 
every single host server regardless if they were running vms with volumes on 
the rebooted nfs server. 95% of my vms are running from ceph and those should 
have never been effected in the first place. 
- Original Message -

From: Koushik Das koushik@citrix.com 
To: users@cloudstack.apache.org users@cloudstack.apache.org 
Cc: d...@cloudstack.apache.org 
Sent: Monday, 3 March, 2014 5:55:34 AM 
Subject: Re: ALARM - ACS reboots host servers!!! 

The primary storage needs to be put in maintenance before doing any 
upgrade/reboot as mentioned in the previous mails. 

-Koushik 

On 03-Mar-2014, at 6:07 AM, Marcus shadow...@gmail.com wrote: 

 Also, please note that in the bug you referenced it doesn't have a 
 problem with the reboot being triggered, but with the fact that reboot 
 never completes due to hanging NFS mount (which is why the reboot 
 occurs, inaccessible primary storage). 
 
 On Sun, Mar 2, 2014 at 5:26 PM, Marcus shadow...@gmail.com wrote: 
 Or do you mean you have multiple primary storages and this one was not 
 in use and put into maintenance? 
 
 On Sun, Mar 2, 2014 at 5:25 PM, Marcus shadow...@gmail.com wrote: 
 I'm not sure I understand. How do you expect to reboot your primary 
 storage while vms are running? It sounds like the host is being 
 fenced since it cannot contact the resources it depends on. 
 
 On Sun, Mar 2, 2014 at 3:24 PM, Nux! n...@li.nux.ro wrote: 
 On 02.03.2014 21:17, Andrei Mikhailovsky wrote: 
 
 Hello guys, 
 
 
 I've recently came across the bug CLOUDSTACK-5429 which has rebooted 
 all of my host servers without properly shutting down the guest vms. 
 I've simply upgraded and rebooted one of the nfs primary storage 
 servers and a few minutes later, to my horror, i've found out that all 
 of my host servers have been rebooted. Is it just me thinking so, or 
 is this bug should be fixed ASAP and should be a blocker for any new 
 ACS release. I mean not only does it cause downtime, but also possible 
 data loss and server corruption. 
 
 
 Hi Andrei, 
 
 Do you have HA enabled and did you put that primary storage in maintenance 
 mode before rebooting it? 
 It's my understanding that ACS relies on the shared storage to perform HA 
 so 
 if the storage goes it's expected to go berserk. I've noticed similar 
 behaviour in Xenserver pools without ACS. 
 I'd imagine a cure for this would be to use network distributed 
 filesystems like GlusterFS or CEPH. 
 
 Lucian 
 
 -- 
 Sent from the Delta quadrant using Borg technology! 
 
 Nux! 
 www.nux.ro 




Re: ALARM - ACS reboots host servers!!!

2014-03-03 Thread Nux!

On 03.03.2014 12:24, Andrei Mikhailovsky wrote:

I am using HA for about 30% of the guest vms, but my testing showed
that HA is not working reliably with KVM. It works pretty well if you
initiate a vm shutdown inside a guest without using the ACS GUI.
However, when the host goes down for whatever reason (power failure,
init 6/0, network failure, etc.) the HA fails to kick in and restart
the vms.


This shuld be submitted as a bug. Which version are you on?




Regarding the nfs storage, I did not put the nfs server in the
maintenance mode. Would this solve the problem with reboots? I will
try it next time when I am doing maintenance on the nfs, but I do
recall that i've previously restarted the nfs server in the past and
I've not seen the hosts rebooting themselves. Is there a timeout which
causes the hosts to reboot?


Not sure what the timeout is, I'd be interested in finding out as well.

To the best of my knowledge, when you put primary storage in m-mode ACS 
will shut down the VMs on it.
Otherwise the shared storage is used by ACS to maintain HA (so your HA 
is as good as your shared storage ...), if link to the shared storage is 
down the host assumes something is wrong and shuts down (fences itself), 
this is the correct and expected behaviour. Maybe your network has 
segmented etc.






In any case, I think it is not safe to do an automated host server
reboot and if it was up to me I would disable this feature from the
agent. IMHO this should be down to system administrator and acs agent
should send an alert email if something goes wrong instead of
rebooting the host servers.


Not sure what to tell you, HA is a sensitive and complex subject. For 
now I'm ok with this behaviour and I see it implemented similarly in 
Xenserver, too.





I am using ceph for my primary storage for guest vms data and root
disks. The NFS is used as a backup disk offering for the guest.


Andrei




--
Sent from the Delta quadrant using Borg technology!

Nux!
www.nux.ro


Re: ALARM - ACS reboots host servers!!!

2014-03-03 Thread Nux!

On 03.03.2014 12:37, Andrei Mikhailovsky wrote:

Koushik, I understand that and I will put the storage into the
maintenance mode next time. However, things happen and servers crash
from time to time, which is not the reason to reboot all host servers,
even those which do not have any running vms with volumes on the nfs
storage. The bloody agent just rebooted every single host server
regardless if they were running vms with volumes on the rebooted nfs
server. 95% of my vms are running from ceph and those should have
never been effected in the first place.


It sounds like ACS need to become more aware of multiple primary 
storages..


--
Sent from the Delta quadrant using Borg technology!

Nux!
www.nux.ro


Re: A shared network: State = Setup :(

2014-03-03 Thread Erik Weber
That should be correct.

From:
https://cwiki.apache.org/confluence/display/CLOUDSTACK/CloudStack+objects+states

Setup - Indicates the network configuration is setup with Vlan from the
moment it was created. Happens when vlan is passed in to the createNetwork
call, so its immutable for the network for its entire lifecycle. Happens
for Shared networks.

*Remark - the difference between Implemented and Setup state. When vlanId
is passed in to createNetwork call, the newly created network is marked
with Setup state - meaning that its never gonna release the vlan till the
network is destroyed.*

*-- *
*Erik*


On Mon, Mar 3, 2014 at 2:17 PM, Vladimir Melnik v.mel...@uplink.ua wrote:

 Dear colleagues,

 I'm trying to add a shared network, but it doesn't become Implemented, it
 remains in the Setup state. I tried to restart it, the virtual router
 has started, it works, I can ping it from the Internet, but it doesn't
 change the state of that shared network.

 Can you help me to realize, where did it go wrong? What should I check?

 Thank you very much!

 --
 With best regards and wishes,
 Vladimir Melnik




Re: UI customizations

2014-03-03 Thread Nux!

On 03.03.2014 18:37, Michael Phillips wrote:

1. Can the UI of CS be totally customized?
2. If the answer to #1 is yes, does anyone know of any companies that
offers this?


Michael,

Everything the UI does is call APIs; you can get any web developer (in 
any language) to build a custom interface and use the Cloudstack APIs.

https://cloudstack.apache.org/docs/api/

HTH
Lucian

--
Sent from the Delta quadrant using Borg technology!

Nux!
www.nux.ro


Re: no VM statistics

2014-03-03 Thread Hollman Enciso R.
Thanks a lot Madan and Geoff


Re: CS 4.2.1 VPN connection failed

2014-03-03 Thread Geoff Higginbottom
Motty,

What is the CIDR of the remote network ?

Regards

Geoff Higginbottom
CTO / Cloud Architect

D: +44 20 3603 0542tel:+442036030542 | S: +44 20 3603 0540tel:+442036030540 
| M: +447968161581tel:+447968161581

geoff.higginbot...@shapeblue.commailto:geoff.higginbot...@shapeblue.com | 
www.shapeblue.comhtp://www.shapeblue.com/ | 
Twitter:@cloudstackguruhttps://twitter.com/#!/cloudstackguru

ShapeBlue Ltd, 53 Chandos Place, Covent Garden, London, WC2N 
4HSx-apple-data-detectors://5


On 3 Mar 2014, at 18:17, motty cruz 
motty.c...@gmail.commailto:motty.c...@gmail.com wrote:

Hello All,
I'm having issues with a site-to-site VPN connection on Cloudstack Advance
Network.

vpc-1 CIDR 10.99.0.0/16

vpc-tier-1 10.99.1.0/24

customer gateway match client settings,

in Virtual Router I see connections coming from client IP but no route
back.
If I log in to VR, I am able to pint client's IP. The outisde firewall not
filtering outgoing traffic, and incoming traffic from client's IP is allow
all.

any idea or suggestions?

Thanks,
Need Enterprise Grade Support for Apache CloudStack?
Our CloudStack Infrastructure 
Supporthttp://shapeblue.com/cloudstack-infrastructure-support/ offers the 
best 24/7 SLA for CloudStack Environments.

Apache CloudStack Bootcamp training courses

**NEW!** CloudStack 4.2.1 traininghttp://shapeblue.com/cloudstack-training/
18th-19th February 2014, Brazil. 
Classroomhttp://shapeblue.com/cloudstack-training/
17th-23rd March 2014, Region A. Instructor led, 
On-linehttp://shapeblue.com/cloudstack-training/
24th-28th March 2014, Region B. Instructor led, 
On-linehttp://shapeblue.com/cloudstack-training/
16th-20th June 2014, Region A. Instructor led, 
On-linehttp://shapeblue.com/cloudstack-training/
23rd-27th June 2014, Region B. Instructor led, 
On-linehttp://shapeblue.com/cloudstack-training/

This email and any attachments to it may be confidential and are intended 
solely for the use of the individual to whom it is addressed. Any views or 
opinions expressed are solely those of the author and do not necessarily 
represent those of Shape Blue Ltd or related companies. If you are not the 
intended recipient of this email, you must neither take any action based upon 
its contents, nor copy or show it to anyone. Please contact the sender if you 
believe you have received this email in error. Shape Blue Ltd is a company 
incorporated in England  Wales. ShapeBlue Services India LLP is a company 
incorporated in India and is operated under license from Shape Blue Ltd. Shape 
Blue Brasil Consultoria Ltda is a company incorporated in Brasil and is 
operated under license from Shape Blue Ltd. ShapeBlue is a registered trademark.


Re: KVM

2014-03-03 Thread María Noelia Gil
I forgot to add the following line:

2014-03-03 20:24:07,964 WARN  [kvm.resource.LibvirtComputingResource] 
(main:null) LibVirt version 0.9.10 required for guest cpu mode, but version 
0.9.8 detected, so it will be disabled

El 03/03/2014, a las 01:09, Marcus shadow...@gmail.com escribió:

 It doesn't look like you've enabled debug, you're only getting WARN
 and INFO messages. Please enable debug.
 
 On Sun, Mar 2, 2014 at 4:40 PM, María Noelia Gil marianoelia@um.es 
 wrote:
 When I run CloudStack-setup-agent shows the following:
 
 Starting to configure your system:
 Configure Apparmor ...[OK]
 Configure Network ... [OK]
 Configure Libvirt ...
 [OK]
 Configure Firewall ...
 [OK]
 Configure Nfs ... [OK]
 Configure cloudAgent ...
 [OK]
 CloudStack Agent setup is done!
 
 The log file displays the following.
 
 2014-03-03 00:32:44,320 INFO  [cloud.agent.AgentShell] (main:null) Agent 
 started
 2014-03-03 00:32:44,321 INFO  [cloud.agent.AgentShell] (main:null) 
 Implementation Version is 4.2.1
 2014-03-03 00:32:44,322 INFO  [cloud.agent.AgentShell] (main:null) 
 agent.properties found at /etc/cloudstack/agent/agent.properties
 2014-03-03 00:32:44,323 INFO  [cloud.agent.AgentShell] (main:null) 
 Defaulting to using properties file for storage
 2014-03-03 00:32:44,324 INFO  [cloud.agent.AgentShell] (main:null) 
 Defaulting to the constant time backoff algorithm
 2014-03-03 00:32:44,326 INFO  [cloud.utils.LogUtils] (main:null) log4j 
 configuration found at /etc/cloudstack/agent/log4j-cloud.xml
 2014-03-03 00:32:44,384 INFO  [cloud.agent.Agent] (main:null) id is 0
 2014-03-03 00:32:44,396 INFO  
 [resource.virtualnetwork.VirtualRoutingResource] (main:null) 
 VirtualRoutingResource _scriptDir to use: scripts/network/domr/kvm
 2014-03-03 00:32:45,020 WARN  [kvm.resource.LibvirtComputingResource] 
 (main:null) LibVirt version 0.9.10 required for guest cpu mode, but version 
 0.9.8 detected, so it will be disabled
 2014-03-03 00:32:45,114 INFO  [kvm.resource.LibvirtComputingResource] 
 (main:null) No libvirt.vif.driver specified. Defaults to BridgeVifDriver.
 2014-03-03 00:32:45,145 INFO  [cloud.agent.Agent] (main:null) Agent [id = 0 
 : type = LibvirtComputingResource : zone = default : pod = default : workers 
 = 5 : host = localhost : port = 8250
 2014-03-03 00:32:45,154 INFO  [utils.nio.NioClient] (Agent-Selector:null) 
 Connecting to localhost:8250
 2014-03-03 00:32:45,333 INFO  [utils.nio.NioClient] (Agent-Selector:null) 
 SSL: Handshake done
 2014-03-03 00:32:45,334 INFO  [utils.nio.NioClient] (Agent-Selector:null) 
 Connected to localhost:8250
 2014-03-03 00:32:45,662 INFO  [cloud.serializer.GsonHelper] 
 (Agent-Handler-1:null) Default Builder inited.
 2014-03-03 00:32:45,733 INFO  [cloud.agent.Agent] (Agent-Handler-2:null) 
 Proccess agent startup answer, agent id = 0
 2014-03-03 00:32:45,733 INFO  [cloud.agent.Agent] (Agent-Handler-2:null) Set 
 agent id 0
 2014-03-03 00:32:45,737 INFO  [cloud.agent.Agent] (AgentShutdownThread:null) 
 Stopping the agent: Reason = sig.kill
 2014-03-03 00:32:45,738 INFO  [cloud.agent.Agent] (Agent-Handler-2:null) 
 Startup Response Received: agent id = 0
 
 I do not get to fix the error.
 
 Thanks.
 
 El 02/03/2014, a las 00:25, Marcus shadow...@gmail.com escribió:
 
 changing
 



Re: CS 4.2.1 VPN connection failed

2014-03-03 Thread motty cruz
Hi Geoff,

the CIDR of the remote network is 192.168.0.0/24

IKE policy : 3des-md5
ESP policy 3des-md5
IKE lifetiem : 86400
ESP lifetime 3600
dead peer detection yes
state Error

Status: Resource[Site2SiteVpnConnection:31]is unreachable: Failed to apply
site-to-site VPN

That is the error i'm getting,

In /var/log/message :
Mar  3 20:59:23 r-171-VM cloud: ipsectunnel.sh: done ipsec tunnel entry for
right peer=client_public_ip  right networks=192.168.0.0/24
Mar  3 20:59:23 r-171-VM cloud: ipsectunnel.sh: checking connection
status...
Mar  3 20:59:24 r-171-VM cloud: ipsectunnel.sh: checking connection
status...
Mar  3 20:59:25 r-171-VM cloud: ipsectunnel.sh: checking connection
status...
Mar  3 20:59:26 r-171-VM cloud: ipsectunnel.sh: checking connection
status...
Mar  3 20:59:27 r-171-VM cloud: ipsectunnel.sh: checking connection
status...
Mar  3 20:59:28 r-171-VM cloud: ipsectunnel.sh: fail to connect to remote,
status code: 11
Mar  3 20:59:28 r-171-VM cloud: ipsectunnel.sh: would stop site-to-site VPN
connection
Mar  3 20:59:28 r-171-VM cloud: ipsectunnel.sh: removing configuration for
ipsec tunnel to client_public_ip



On Mon, Mar 3, 2014 at 12:27 PM, Geoff Higginbottom 
geoff.higginbot...@shapeblue.com wrote:

 Motty,

 What is the CIDR of the remote network ?

 Regards

 Geoff Higginbottom
 CTO / Cloud Architect

 D: +44 20 3603 0542tel:+442036030542 | S: +44 20 3603 0540tel:
 +442036030540 | M: +447968161581tel:+447968161581

 geoff.higginbot...@shapeblue.commailto:geoff.higginbot...@shapeblue.com
 | www.shapeblue.comhtp://www.shapeblue.com/ | Twitter:@cloudstackguru
 https://twitter.com/#!/cloudstackguru

 ShapeBlue Ltd, 53 Chandos Place, Covent Garden, London, WC2N
 4HSx-apple-data-detectors://5


 On 3 Mar 2014, at 18:17, motty cruz motty.c...@gmail.commailto:
 motty.c...@gmail.com wrote:

 Hello All,
 I'm having issues with a site-to-site VPN connection on Cloudstack Advance
 Network.

 vpc-1 CIDR 10.99.0.0/16

 vpc-tier-1 10.99.1.0/24

 customer gateway match client settings,

 in Virtual Router I see connections coming from client IP but no route
 back.
 If I log in to VR, I am able to pint client's IP. The outisde firewall not
 filtering outgoing traffic, and incoming traffic from client's IP is allow
 all.

 any idea or suggestions?

 Thanks,
 Need Enterprise Grade Support for Apache CloudStack?
 Our CloudStack Infrastructure Support
 http://shapeblue.com/cloudstack-infrastructure-support/ offers the best
 24/7 SLA for CloudStack Environments.

 Apache CloudStack Bootcamp training courses

 **NEW!** CloudStack 4.2.1 training
 http://shapeblue.com/cloudstack-training/
 18th-19th February 2014, Brazil. Classroom
 http://shapeblue.com/cloudstack-training/
 17th-23rd March 2014, Region A. Instructor led, On-line
 http://shapeblue.com/cloudstack-training/
 24th-28th March 2014, Region B. Instructor led, On-line
 http://shapeblue.com/cloudstack-training/
 16th-20th June 2014, Region A. Instructor led, On-line
 http://shapeblue.com/cloudstack-training/
 23rd-27th June 2014, Region B. Instructor led, On-line
 http://shapeblue.com/cloudstack-training/

 This email and any attachments to it may be confidential and are intended
 solely for the use of the individual to whom it is addressed. Any views or
 opinions expressed are solely those of the author and do not necessarily
 represent those of Shape Blue Ltd or related companies. If you are not the
 intended recipient of this email, you must neither take any action based
 upon its contents, nor copy or show it to anyone. Please contact the sender
 if you believe you have received this email in error. Shape Blue Ltd is a
 company incorporated in England  Wales. ShapeBlue Services India LLP is a
 company incorporated in India and is operated under license from Shape Blue
 Ltd. Shape Blue Brasil Consultoria Ltda is a company incorporated in Brasil
 and is operated under license from Shape Blue Ltd. ShapeBlue is a
 registered trademark.



Re: CS 4.2.1 VPN connection failed

2014-03-03 Thread motty cruz
Thanks for your reply Geoff,

in CS
Network - VPC - vpc1 - Router - Network ACL Lists

I see two default_allow and default_deny, I am unable to change or remove
this ACLs

Thanks,
Celso


On Mon, Mar 3, 2014 at 1:45 PM, Geoff Higginbottom 
geoff.higginbot...@shapeblue.com wrote:

 Do you am have a default allow or default deny on the VPC Tier?

 Regards

 Geoff Higginbottom
 CTO / Cloud Architect

 D: +44 20 3603 0542tel:+442036030542 | S: +44 20 3603 0540tel:
 +442036030540 | M: +447968161581tel:+447968161581

 geoff.higginbot...@shapeblue.commailto:geoff.higginbot...@shapeblue.com
 | www.shapeblue.comhtp://www.shapeblue.com/ | Twitter:@cloudstackguru
 https://twitter.com/#!/cloudstackguru

 ShapeBlue Ltd, 53 Chandos Place, Covent Garden, London, WC2N
 4HSx-apple-data-detectors://5


 On 3 Mar 2014, at 21:09, motty cruz motty.c...@gmail.commailto:
 motty.c...@gmail.com wrote:

 Hi Geoff,

 the CIDR of the remote network is 192.168.0.0/24

 IKE policy : 3des-md5
 ESP policy 3des-md5
 IKE lifetiem : 86400
 ESP lifetime 3600
 dead peer detection yes
 state Error

 Status: Resource[Site2SiteVpnConnection:31]is unreachable: Failed to apply
 site-to-site VPN

 That is the error i'm getting,

 In /var/log/message :
 Mar  3 20:59:23 r-171-VM cloud: ipsectunnel.sh: done ipsec tunnel entry for
 right peer=client_public_ip  right networks=192.168.0.0/24
 Mar  3 20:59:23 r-171-VM cloud: ipsectunnel.sh: checking connection
 status...
 Mar  3 20:59:24 r-171-VM cloud: ipsectunnel.sh: checking connection
 status...
 Mar  3 20:59:25 r-171-VM cloud: ipsectunnel.sh: checking connection
 status...
 Mar  3 20:59:26 r-171-VM cloud: ipsectunnel.sh: checking connection
 status...
 Mar  3 20:59:27 r-171-VM cloud: ipsectunnel.sh: checking connection
 status...
 Mar  3 20:59:28 r-171-VM cloud: ipsectunnel.sh: fail to connect to remote,
 status code: 11
 Mar  3 20:59:28 r-171-VM cloud: ipsectunnel.sh: would stop site-to-site VPN
 connection
 Mar  3 20:59:28 r-171-VM cloud: ipsectunnel.sh: removing configuration for
 ipsec tunnel to client_public_ip



 On Mon, Mar 3, 2014 at 12:27 PM, Geoff Higginbottom 
 geoff.higginbot...@shapeblue.commailto:geoff.higginbot...@shapeblue.com
 wrote:

 Motty,

 What is the CIDR of the remote network ?

 Regards

 Geoff Higginbottom
 CTO / Cloud Architect

 D: +44 20 3603 0542tel:+442036030542 | S: +44 20 3603 0540tel:
 +442036030540 | M: +447968161581tel:+447968161581

 geoff.higginbot...@shapeblue.commailto:geoff.higginbot...@shapeblue.com
 mailto:geoff.higginbot...@shapeblue.com
 | www.shapeblue.comhttp://www.shapeblue.comhtp://www.shapeblue.com/ |
 Twitter:@cloudstackguru
 https://twitter.com/#!/cloudstackguru

 ShapeBlue Ltd, 53 Chandos Place, Covent Garden, London, WC2N
 4HSx-apple-data-detectors://5


 On 3 Mar 2014, at 18:17, motty cruz motty.c...@gmail.commailto:
 motty.c...@gmail.commailto:
 motty.c...@gmail.commailto:motty.c...@gmail.com wrote:

 Hello All,
 I'm having issues with a site-to-site VPN connection on Cloudstack Advance
 Network.

 vpc-1 CIDR 10.99.0.0/16

 vpc-tier-1 10.99.1.0/24

 customer gateway match client settings,

 in Virtual Router I see connections coming from client IP but no route
 back.
 If I log in to VR, I am able to pint client's IP. The outisde firewall not
 filtering outgoing traffic, and incoming traffic from client's IP is allow
 all.

 any idea or suggestions?

 Thanks,
 Need Enterprise Grade Support for Apache CloudStack?
 Our CloudStack Infrastructure Support
 http://shapeblue.com/cloudstack-infrastructure-support/ offers the best
 24/7 SLA for CloudStack Environments.

 Apache CloudStack Bootcamp training courses

 **NEW!** CloudStack 4.2.1 training
 http://shapeblue.com/cloudstack-training/
 18th-19th February 2014, Brazil. Classroom
 http://shapeblue.com/cloudstack-training/
 17th-23rd March 2014, Region A. Instructor led, On-line
 http://shapeblue.com/cloudstack-training/
 24th-28th March 2014, Region B. Instructor led, On-line
 http://shapeblue.com/cloudstack-training/
 16th-20th June 2014, Region A. Instructor led, On-line
 http://shapeblue.com/cloudstack-training/
 23rd-27th June 2014, Region B. Instructor led, On-line
 http://shapeblue.com/cloudstack-training/

 This email and any attachments to it may be confidential and are intended
 solely for the use of the individual to whom it is addressed. Any views or
 opinions expressed are solely those of the author and do not necessarily
 represent those of Shape Blue Ltd or related companies. If you are not the
 intended recipient of this email, you must neither take any action based
 upon its contents, nor copy or show it to anyone. Please contact the sender
 if you believe you have received this email in error. Shape Blue Ltd is a
 company incorporated in England  Wales. ShapeBlue Services India LLP is a
 company incorporated in India and is operated under license from Shape Blue
 Ltd. Shape Blue Brasil Consultoria Ltda is a company incorporated in Brasil
 and is operated under license from Shape 

Re: CS 4.2.1 VPN connection failed

2014-03-03 Thread Geoff Higginbottom
Celso,

You should be able to create new ACL lists and also change which one is applied 
to the Tier.

For the VPN return traffic you need to ensure that you have an ACL rule 
allowing the traffic.

You could simply add an allow all rule for the CIDR of the remote network in 
the appropriate ACL List.

Regards

Geoff Higginbottom
CTO / Cloud Architect

D: +44 20 3603 0542tel:+442036030542 | S: +44 20 3603 0540tel:+442036030540 
| M: +447968161581tel:+447968161581

geoff.higginbot...@shapeblue.commailto:geoff.higginbot...@shapeblue.com | 
www.shapeblue.comhtp://www.shapeblue.com/ | 
Twitter:@cloudstackguruhttps://twitter.com/#!/cloudstackguru

ShapeBlue Ltd, 53 Chandos Place, Covent Garden, London, WC2N 
4HSx-apple-data-detectors://5


On 3 Mar 2014, at 22:05, motty cruz 
motty.c...@gmail.commailto:motty.c...@gmail.com wrote:

Thanks for your reply Geoff,

in CS
Network - VPC - vpc1 - Router - Network ACL Lists

I see two default_allow and default_deny, I am unable to change or remove
this ACLs

Thanks,
Celso


On Mon, Mar 3, 2014 at 1:45 PM, Geoff Higginbottom 
geoff.higginbot...@shapeblue.commailto:geoff.higginbot...@shapeblue.com 
wrote:

Do you am have a default allow or default deny on the VPC Tier?

Regards

Geoff Higginbottom
CTO / Cloud Architect

D: +44 20 3603 0542tel:+442036030542 | S: +44 20 3603 0540tel:
+442036030540 | M: +447968161581tel:+447968161581

geoff.higginbot...@shapeblue.commailto:geoff.higginbot...@shapeblue.commailto:geoff.higginbot...@shapeblue.com
| www.shapeblue.comhttp://www.shapeblue.comhtp://www.shapeblue.com/ | 
Twitter:@cloudstackguru
https://twitter.com/#!/cloudstackguru

ShapeBlue Ltd, 53 Chandos Place, Covent Garden, London, WC2N
4HSx-apple-data-detectors://5


On 3 Mar 2014, at 21:09, motty cruz 
motty.c...@gmail.commailto:motty.c...@gmail.commailto:
motty.c...@gmail.commailto:motty.c...@gmail.com wrote:

Hi Geoff,

the CIDR of the remote network is 192.168.0.0/24

IKE policy : 3des-md5
ESP policy 3des-md5
IKE lifetiem : 86400
ESP lifetime 3600
dead peer detection yes
state Error

Status: Resource[Site2SiteVpnConnection:31]is unreachable: Failed to apply
site-to-site VPN

That is the error i'm getting,

In /var/log/message :
Mar  3 20:59:23 r-171-VM cloud: ipsectunnel.sh: done ipsec tunnel entry for
right peer=client_public_ip  right networks=192.168.0.0/24
Mar  3 20:59:23 r-171-VM cloud: ipsectunnel.sh: checking connection
status...
Mar  3 20:59:24 r-171-VM cloud: ipsectunnel.sh: checking connection
status...
Mar  3 20:59:25 r-171-VM cloud: ipsectunnel.sh: checking connection
status...
Mar  3 20:59:26 r-171-VM cloud: ipsectunnel.sh: checking connection
status...
Mar  3 20:59:27 r-171-VM cloud: ipsectunnel.sh: checking connection
status...
Mar  3 20:59:28 r-171-VM cloud: ipsectunnel.sh: fail to connect to remote,
status code: 11
Mar  3 20:59:28 r-171-VM cloud: ipsectunnel.sh: would stop site-to-site VPN
connection
Mar  3 20:59:28 r-171-VM cloud: ipsectunnel.sh: removing configuration for
ipsec tunnel to client_public_ip



On Mon, Mar 3, 2014 at 12:27 PM, Geoff Higginbottom 
geoff.higginbot...@shapeblue.commailto:geoff.higginbot...@shapeblue.commailto:geoff.higginbot...@shapeblue.com
wrote:

Motty,

What is the CIDR of the remote network ?

Regards

Geoff Higginbottom
CTO / Cloud Architect

D: +44 20 3603 0542tel:+442036030542 | S: +44 20 3603 0540tel:
+442036030540 | M: +447968161581tel:+447968161581

geoff.higginbot...@shapeblue.commailto:geoff.higginbot...@shapeblue.commailto:geoff.higginbot...@shapeblue.com
mailto:geoff.higginbot...@shapeblue.com
| 
www.shapeblue.comhttp://www.shapeblue.comhttp://www.shapeblue.comhtp://www.shapeblue.com/
 |
Twitter:@cloudstackguru
https://twitter.com/#!/cloudstackguru

ShapeBlue Ltd, 53 Chandos Place, Covent Garden, London, WC2N
4HSx-apple-data-detectors://5


On 3 Mar 2014, at 18:17, motty cruz 
motty.c...@gmail.commailto:motty.c...@gmail.commailto:
motty.c...@gmail.commailto:motty.c...@gmail.commailto:
motty.c...@gmail.commailto:motty.c...@gmail.commailto:motty.c...@gmail.com
 wrote:

Hello All,
I'm having issues with a site-to-site VPN connection on Cloudstack Advance
Network.

vpc-1 CIDR 10.99.0.0/16

vpc-tier-1 10.99.1.0/24

customer gateway match client settings,

in Virtual Router I see connections coming from client IP but no route
back.
If I log in to VR, I am able to pint client's IP. The outisde firewall not
filtering outgoing traffic, and incoming traffic from client's IP is allow
all.

any idea or suggestions?

Thanks,
Need Enterprise Grade Support for Apache CloudStack?
Our CloudStack Infrastructure Support
http://shapeblue.com/cloudstack-infrastructure-support/ offers the best
24/7 SLA for CloudStack Environments.

Apache CloudStack Bootcamp training courses

**NEW!** CloudStack 4.2.1 training
http://shapeblue.com/cloudstack-training/
18th-19th February 2014, Brazil. Classroom
http://shapeblue.com/cloudstack-training/
17th-23rd March 2014, Region A. Instructor led, On-line
http://shapeblue.com/cloudstack-training/

Re: CS 4.2.1 VPN connection failed

2014-03-03 Thread motty cruz
Thanks Geoff,
the problem was in CS I had to create a VPC with /16 mask and once that was
created I created network with mask /24 - to connect to client I was using
/24 but once we used mask 16, connection was successful.

thanks for your help!


On Mon, Mar 3, 2014 at 2:44 PM, Geoff Higginbottom 
geoff.higginbot...@shapeblue.com wrote:

 Celso,

 You should be able to create new ACL lists and also change which one is
 applied to the Tier.

 For the VPN return traffic you need to ensure that you have an ACL rule
 allowing the traffic.

 You could simply add an allow all rule for the CIDR of the remote network
 in the appropriate ACL List.

 Regards

 Geoff Higginbottom
 CTO / Cloud Architect

 D: +44 20 3603 0542tel:+442036030542 | S: +44 20 3603 0540tel:
 +442036030540 | M: +447968161581tel:+447968161581

 geoff.higginbot...@shapeblue.commailto:geoff.higginbot...@shapeblue.com
 | www.shapeblue.comhtp://www.shapeblue.com/ | Twitter:@cloudstackguru
 https://twitter.com/#!/cloudstackguru

 ShapeBlue Ltd, 53 Chandos Place, Covent Garden, London, WC2N
 4HSx-apple-data-detectors://5


 On 3 Mar 2014, at 22:05, motty cruz motty.c...@gmail.commailto:
 motty.c...@gmail.com wrote:

 Thanks for your reply Geoff,

 in CS
 Network - VPC - vpc1 - Router - Network ACL Lists

 I see two default_allow and default_deny, I am unable to change or remove
 this ACLs

 Thanks,
 Celso


 On Mon, Mar 3, 2014 at 1:45 PM, Geoff Higginbottom 
 geoff.higginbot...@shapeblue.commailto:geoff.higginbot...@shapeblue.com
 wrote:

 Do you am have a default allow or default deny on the VPC Tier?

 Regards

 Geoff Higginbottom
 CTO / Cloud Architect

 D: +44 20 3603 0542tel:+442036030542 | S: +44 20 3603 0540tel:
 +442036030540 | M: +447968161581tel:+447968161581

 geoff.higginbot...@shapeblue.commailto:geoff.higginbot...@shapeblue.com
 mailto:geoff.higginbot...@shapeblue.com
 | www.shapeblue.comhttp://www.shapeblue.comhtp://www.shapeblue.com/ |
 Twitter:@cloudstackguru
 https://twitter.com/#!/cloudstackguru

 ShapeBlue Ltd, 53 Chandos Place, Covent Garden, London, WC2N
 4HSx-apple-data-detectors://5


 On 3 Mar 2014, at 21:09, motty cruz motty.c...@gmail.commailto:
 motty.c...@gmail.commailto:
 motty.c...@gmail.commailto:motty.c...@gmail.com wrote:

 Hi Geoff,

 the CIDR of the remote network is 192.168.0.0/24

 IKE policy : 3des-md5
 ESP policy 3des-md5
 IKE lifetiem : 86400
 ESP lifetime 3600
 dead peer detection yes
 state Error

 Status: Resource[Site2SiteVpnConnection:31]is unreachable: Failed to apply
 site-to-site VPN

 That is the error i'm getting,

 In /var/log/message :
 Mar  3 20:59:23 r-171-VM cloud: ipsectunnel.sh: done ipsec tunnel entry for
 right peer=client_public_ip  right networks=192.168.0.0/24
 Mar  3 20:59:23 r-171-VM cloud: ipsectunnel.sh: checking connection
 status...
 Mar  3 20:59:24 r-171-VM cloud: ipsectunnel.sh: checking connection
 status...
 Mar  3 20:59:25 r-171-VM cloud: ipsectunnel.sh: checking connection
 status...
 Mar  3 20:59:26 r-171-VM cloud: ipsectunnel.sh: checking connection
 status...
 Mar  3 20:59:27 r-171-VM cloud: ipsectunnel.sh: checking connection
 status...
 Mar  3 20:59:28 r-171-VM cloud: ipsectunnel.sh: fail to connect to remote,
 status code: 11
 Mar  3 20:59:28 r-171-VM cloud: ipsectunnel.sh: would stop site-to-site VPN
 connection
 Mar  3 20:59:28 r-171-VM cloud: ipsectunnel.sh: removing configuration for
 ipsec tunnel to client_public_ip



 On Mon, Mar 3, 2014 at 12:27 PM, Geoff Higginbottom 
 geoff.higginbot...@shapeblue.commailto:geoff.higginbot...@shapeblue.com
 mailto:geoff.higginbot...@shapeblue.com
 wrote:

 Motty,

 What is the CIDR of the remote network ?

 Regards

 Geoff Higginbottom
 CTO / Cloud Architect

 D: +44 20 3603 0542tel:+442036030542 | S: +44 20 3603 0540tel:
 +442036030540 | M: +447968161581tel:+447968161581

 geoff.higginbot...@shapeblue.commailto:geoff.higginbot...@shapeblue.com
 mailto:geoff.higginbot...@shapeblue.com
 mailto:geoff.higginbot...@shapeblue.com
 | www.shapeblue.comhttp://www.shapeblue.comhttp://www.shapeblue.com
 htp://www.shapeblue.com/ |
 Twitter:@cloudstackguru
 https://twitter.com/#!/cloudstackguru

 ShapeBlue Ltd, 53 Chandos Place, Covent Garden, London, WC2N
 4HSx-apple-data-detectors://5


 On 3 Mar 2014, at 18:17, motty cruz motty.c...@gmail.commailto:
 motty.c...@gmail.commailto:
 motty.c...@gmail.commailto:motty.c...@gmail.commailto:
 motty.c...@gmail.commailto:motty.c...@gmail.commailto:
 motty.c...@gmail.com wrote:

 Hello All,
 I'm having issues with a site-to-site VPN connection on Cloudstack Advance
 Network.

 vpc-1 CIDR 10.99.0.0/16

 vpc-tier-1 10.99.1.0/24

 customer gateway match client settings,

 in Virtual Router I see connections coming from client IP but no route
 back.
 If I log in to VR, I am able to pint client's IP. The outisde firewall not
 filtering outgoing traffic, and incoming traffic from client's IP is allow
 all.

 any idea or suggestions?

 Thanks,
 Need Enterprise Grade Support for Apache CloudStack?
 Our 

RE: Suitable solution for HW

2014-03-03 Thread Pääkkönen Pekka
Hi,

Yes. Thanks a lot for your answers.

Regards,
-Pekka

-Original Message-
From: Daan Hoogland [mailto:daan.hoogl...@gmail.com] 
Sent: 3. maaliskuuta 2014 16:15
To: users@cloudstack.apache.org
Subject: Re: Suitable solution for HW

Well Pekka,

:) Do you find an answer to your question in here?
My answer(s) would have been;
no
and yes it is unnecessary. Cloudstack will orchestrate, provision and leave the 
stuff alone from there on in.

regards,

On Mon, Mar 3, 2014 at 1:19 PM, Geoff Higginbottom 
geoff.higginbot...@shapeblue.com wrote:
 Hi Daan.

 As Nux has already highlighted, disk IO is the critical factor for high 
 performance database applications.

 Using local storage within the Hypervisor will only provide very limited 
 IOPS, even with 15k SAS disks.

 We have been doing a lot of work with SolidFire storage recently. In my 
 opinion they are simply the best storage option available for CloudStack, and 
 have a plugin which integrates it directly with CloudStack.

 Regards

 Geoff Higginbottom
 CTO / Cloud Architect

 D: +44 20 3603 0542tel:+442036030542 | S: +44 20 3603 
 0540tel:+442036030540 | M: +447968161581tel:+447968161581

 geoff.higginbot...@shapeblue.commailto:geoff.higginbottom@shapeblue.c
 om | www.shapeblue.comhtp://www.shapeblue.com/ | 
 Twitter:@cloudstackguruhttps://twitter.com/#!/cloudstackguru

 ShapeBlue Ltd, 53 Chandos Place, Covent Garden, London, WC2N 
 4HSx-apple-data-detectors://5


 On 3 Mar 2014, at 11:43, Nux! n...@li.nux.romailto:n...@li.nux.ro wrote:

 On 03.03.2014 11:22, P??kk?nen Pekka wrote:
 Hi Daan,
 Maybe I should have been clearer.
 I was wondering about the implications for performance.
 Would performance in a database clustering use case be better with 
 plain Xen (or other virtualization solution), when compared to 
 CloudStack with Xen?
 Or is this an unnecessary concern?
 Also, is CloudStack aimed for clusters consisting of tens/hundreds of 
 such rack servers, or is it suitable also for smaller deployments?

 Cloudstack can grow from 1 to many servers.
 Re hypervisor, if you want to run databases then IO will be your main 
 concern. At some point the hypervisor will not matter, your disks will 
 matter. I'd look at investing in SSDs.
 You can also look at conainer technology such as openvz and LXC which usually 
 have better IO (since they access the hardware directly).

 --
 Sent from the Delta quadrant using Borg technology!

 Nux!
 www.nux.rohttp://www.nux.ro
 Need Enterprise Grade Support for Apache CloudStack?
 Our CloudStack Infrastructure 
 Supporthttp://shapeblue.com/cloudstack-infrastructure-support/ offers the 
 best 24/7 SLA for CloudStack Environments.

 Apache CloudStack Bootcamp training courses

 **NEW!** CloudStack 4.2.1 
 traininghttp://shapeblue.com/cloudstack-training/
 18th-19th February 2014, Brazil. 
 Classroomhttp://shapeblue.com/cloudstack-training/
 17th-23rd March 2014, Region A. Instructor led, 
 On-linehttp://shapeblue.com/cloudstack-training/
 24th-28th March 2014, Region B. Instructor led, 
 On-linehttp://shapeblue.com/cloudstack-training/
 16th-20th June 2014, Region A. Instructor led, 
 On-linehttp://shapeblue.com/cloudstack-training/
 23rd-27th June 2014, Region B. Instructor led, 
 On-linehttp://shapeblue.com/cloudstack-training/

 This email and any attachments to it may be confidential and are intended 
 solely for the use of the individual to whom it is addressed. Any views or 
 opinions expressed are solely those of the author and do not necessarily 
 represent those of Shape Blue Ltd or related companies. If you are not the 
 intended recipient of this email, you must neither take any action based upon 
 its contents, nor copy or show it to anyone. Please contact the sender if you 
 believe you have received this email in error. Shape Blue Ltd is a company 
 incorporated in England  Wales. ShapeBlue Services India LLP is a company 
 incorporated in India and is operated under license from Shape Blue Ltd. 
 Shape Blue Brasil Consultoria Ltda is a company incorporated in Brasil and is 
 operated under license from Shape Blue Ltd. ShapeBlue is a registered 
 trademark.



--
Daan