Re: Bank Client requires VM Firewall in between subnets

2023-11-20 Thread Daan Hoogland
Bryan, there is a Palo Alto plugin, but I am not sure how advanced it is. As for intrusion detection I would put it in front of the CloudStack installation. The virtual router is one thing you want to protect for instance. I'd need to see the proposed design to give any more judgemental advice.

Re: Documentation on instances live migration with KVM

2023-11-20 Thread Daan Hoogland
For documentation: you - fork/clone https://github.com/apache/cloudstack-documentation/ - create a new branch for your changes - edit the docs in your branch - push your changes to your upstream fork - use https://github.com/apache/cloudstack-documentation/pull/new to create the PR It might requi

Bank Client requires VM Firewall in between subnets

2023-11-20 Thread Bryan Tiang
Hi All, I have a potential client who is a bank, and requires a VPC, 3 Subnets, with each subnet segregated by a firewall. We proposed the idea of using Network ACLs, but they didn’t accept the idea. They want packet filtering, intrusion prevention features etc which are all features of a full

VM Firewalls In Between Subnets

2023-11-20 Thread Bryan Tiang
Hi All, I have a financial client who requires 3 subnets, each filtered by a firewall. They didnt accept the idea of using Network ACLs. They want packet filtering, intrusion prevention systems etc which are all features of a full fledged firewall. Can i install a VM Firewall from Fortinet or

Re: VM serial number change when instance stop/start

2023-11-20 Thread Jithin Raju
Hi Jose, I think currently cloudstack can’t set a fixed serial number on the instance creation on XCP-ng, are you able to set the serial number directly on XCP-ng? if possible you could open an improvement request in github. -Jithin From: José Sánchez Date: Monday, 20 November 2023 at 12:47 P

RE: Swapping Public IP Addresses

2023-11-20 Thread Alex Mattioli
Hi Bryan, Which type of network are you using? From 4.19 it will be possible to change SourceNAT IP. You can change the IP of each network and then decommission the "public" range. To change the IP of the systemVMs you have to disable the zone, destroy the current systemVMs, remove the "public"

Re: Service offerings for root domain visible by other domains

2023-11-20 Thread Jimmy Huybrechts
Hi Pearl, That’s a little bit annoying since you can actually choose the domain root :) Which I guess would mean the same as just leaving it public, but good to know, then I can work around it. :) -- Jimmy Van: Pearl d'Silva Datum: maandag, 20 november 2023 om 17:06 Aan: users@cloudstack.apac

Re: Documentation on instances live migration with KVM

2023-11-20 Thread Jimmy Huybrechts
I actually have never created a PR before ;) Where do I start? -- Jimmy Van: Daan Hoogland Datum: maandag, 20 november 2023 om 16:57 Aan: users@cloudstack.apache.org Onderwerp: Re: Documentation on instances live migration with KVM :D looking forward to your doc PR ;) On Mon, Nov 20, 2023 at 2

Re: Service offerings for root domain visible by other domains

2023-11-20 Thread Pearl d'Silva
Hi Jimmy, An offering that is set to be accessible by ROOT domain, is available to its children too. i.e., since Domain A is a child domain of ROOT, the offering - Admin Test that was created for ROOT domain, would be accessible to Domain A as well. Afaik, there currently is no way to restrict

Re: Documentation on instances live migration with KVM

2023-11-20 Thread Daan Hoogland
:D looking forward to your doc PR ;) On Mon, Nov 20, 2023 at 2:34 PM Jimmy Huybrechts wrote: > > I noticed the documentation on instances is not entirely correct as it it > says: > > (KVM) The Instance must not be using local disk storage. (On XenServer and > VMware, Instance live migration wit

Service offerings for root domain visible by other domains

2023-11-20 Thread Jimmy Huybrechts
Hi, I’m trying to create some offerings now, according to the documentation I can set domains for which it should be visible, so I created one called “Admin Test” and assigned only ROOT to the offering, now logged in with my test account from domain A which is a domain admin for domain A (no ac

Documentation on instances live migration with KVM

2023-11-20 Thread Jimmy Huybrechts
I noticed the documentation on instances is not entirely correct as it it says: (KVM) The Instance must not be using local disk storage. (On XenServer and VMware, Instance live migration with local disk is enabled by CloudStack support for XenMotion and vMotion.) Well, I’m using local storage o

Re: Swapping Public IP Addresses

2023-11-20 Thread Bryan Tiang
Hi Community, Our current Cloudstack is setup with old public IP addresses is assigned to our zone infrastructure. Ongoing next month, we are going to change telco and require re-assigning all our public IP addresses 1. Can CloudStack do public IP migration from old to new in different zones?

Swapping Public IP Addresses

2023-11-20 Thread Bryan Tiang
Hi Community, Our current Cloudstack is setup with old public IP addresses is assigned to our zone infrastructure. Ongoing next month, we are going to change telco and require re-assigning all our public IP addresses. > 1. Can CloudStack do public IP migration from old to new in different zones

Re: Creating a CloudStack AutoScale VM Group with Terraform

2023-11-20 Thread Kiran Chavala
Hi Palash Could you please log a improvement issue here for creating autoscale vm groups via terraform https://github.com/apache/cloudstack-terraform-provider/issues Regards Kiran From: Marco Sinhoreli Date: Monday, 20 November 2023 at 10:48 AM To: users@cloudstack.apache.org Subject: Re: C

VM serial number change when instance stop/start

2023-11-20 Thread José Sánchez
Hi. We use XCP + CloudStack. We have some software installed on VM's that depends on the VM serial number for licensing. When we stop and start the instance the VM serial number changes because the VM is removed from the hypervisor during that action. Is there any way to set a fixed serial numb

RE: Difference between VM Snapshot and Snapshot

2023-11-20 Thread Alex Mattioli
Adding to that, from ACS 4.19 volume snapshots can be copied to other zones (SnapshotsCopy) Regards, Alex -Original Message- From: m...@swen.io Sent: Friday, November 17, 2023 9:58 PM To: users@cloudstack.apache.org Subject: AW: Difference between VM Snapshot and Snapshot One more

CloudStack Collaboration Conference 2023 starts this week!

2023-11-20 Thread Ivet Petrova
Hi All, This is my final reminder that the CloudStack Collaboration Conference 2023 starts this week. On Thursday we will be welcoming all event attendees in Paris. You can also get the full conference experience online through the advanced event platform. Just register here: https://events.hub

Re: KVM clustering with Cloudstack

2023-11-20 Thread Nux
You either do it with Cloudstack or you don't. Using corosync etc is not supported. On 2023-11-20 10:12, Francisco Arencibia Quesada wrote: Good morning guys, What is recommended from your point of view? Create a KVM cluster with corosync and pacemaker, or directly handle the cluster with C

KVM clustering with Cloudstack

2023-11-20 Thread Francisco Arencibia Quesada
Good morning guys, What is recommended from your point of view? Create a KVM cluster with corosync and pacemaker, or directly handle the cluster with CloudStack. Is it fully supported? Kind regards. -- *Francisco Arencibia Quesada.* *DevOps Engineer*

Re: Creating a CloudStack AutoScale VM Group with Terraform

2023-11-20 Thread Marco Sinhoreli
Hi Palash The Autoscale VM group API call is not exposed to the CloudStack Terraform Provider. You can find the complete supported CloudStack resources here: https://registry.terraform.io/providers/cloudstack/cloudstack/latest/docs From: Palash Biswas Date: Tuesday, 14 November 2023 at 16:40

AW: How does Cloudstack limit bandwidth

2023-11-20 Thread me
Hi Marty, what do you mean by "RX pauses"? Are you using xoa as management interface for xcp-ng? You should be able to see speed limits on the nic attached to the VM and the VR. Regards, Swen -Ursprüngliche Nachricht- Von: ma...@gonsource.com Gesendet: Montag, 20. November 2023 05:31 A