Showing posts with label Cloud. Show all posts
Showing posts with label Cloud. Show all posts

February 25, 2013

Failure of vShield Edge NAT/VPN Traffic Post-5.1 Upgrade

UPDATE: Turns out this is a known issue during the 1.5 > 5.1 VSM upgrade and a fix should be released in an upcoming patch.

That's about the shortest title I could think of to be descriptive of this issue. TLDR is that NAT rules on vShield Edge appliances appear to be causing unexpected behavior on VPN traffic after a vCloud upgrade from 1.5 to 5.1.
Background: We recently upgraded from 1.5 to 5.1. For most of our vDCs, we simply have a single vSE/Routed network that connects a private subnet to a "WAN" network and pulls a public IP from a pool. We forward (NAT) and allow (firewall) selected ports (e.g. 3389 for RDP) to virtual machines. Most of these networks also have a site-to-site VPN tunnel with a physical firewall across the internet. After the upgrade, we went and converted our rules to match on original IP and then enabled "multiple interfaces" - effectively taking them out of compatibility mode. Everything looked good (even for the vSE devices still in compatibility mode)
Issue: We first noticed this when a client reported that they could not access a virtual machine via RDP using it's internal (VSE protected) IP across a VPN tunnel, but could access the VM via RDP using it's public hostname/IP address. We allow all traffic across the VPN (firewall has an any:any rule for VPN traffic). When we logged in to troubleshoot (simply thinking the VPN was down), we found that we could connect to any port on the remote VM across the VPN tunnel except 3389. I could ping from the local subnet to the troubled VM on the vApp network with no problem. I could connect to other ports that were open on the remote VM with no problem. I could not connect to 3389 across the VPN.
We thought it might be isolated, but found the issue on every VSE we have: If there existed a DNAT rule to translate inbound traffic for a particular port, that port would be unresponsive when traffic traversed the VPN tunnel destined for the target of the DNAT rule.

While vCloud Director doesn't show anything strange in the firewall section of vSE configuration, if you log in to vShield Manager and look at the firewall rules there, a "Deny" rule with the private/internal/translated IP is added for any NAT rule that exists:


This, I'm assuming, is for security reasons during the upgrade but it does not show up in vCloud Director (thus our confusion). After taking our appliances out of compatibility mode post-upgrade, the rules were still there.

Solution:  After the vSE is out of compatibility mode (see pg. 49 of the vCD 5.1 Install Guide), re-apply the service configuration (Right-Click vShield Edge Appliance in vCloud Director and select "Re-Apply Service Configuration"). You can also re-deploy the appliance or add an arbitrary rule to the firewall list - both appear to have the same effect.

May 12, 2011

BPOS Offline .... again

*** UPDATE 12:12PM CST ***

From Microsoft Health Dashboard:


The BPOS Operations team is working to resolve service degradation for Exchange Online mail flow for organizations served from this region. Users in affected organizations will experiencing ~40 minute delays when trying to send or receive e-mail using Outlook, OWA, or mobile devices. The BPOS Operations team is actively working to restore service. Next update will be within one hour or when new information is available.


Not sure about anyone else, but ~40 minutes is off by about infinity for me.

----------------------------------------------

Two days in a row now, and if you were watching Twitter it would appear to be affecting a lot of people in the NOAM region. Oddly, the Health dashboard still doesn't show a problem:


Try calling MS support though, it will just hang up on you.

May 10, 2011

Microsoft Exchange Online Outage

**2:20PM CST UPDATE**: Microsoft posted another update to the NOAM Health board:

The BPOS Operations team continues to investigate service degradation issues with Exchange Online mail flow for organizations served from this region. The next service update will be provided within 2 hours if the issue is not resolved.

Hopefully we here something else soon.

------------------------------------------------------------------

Microsoft Exchange Online (and BPOS by extension) are currently having issues with mail flow (read: there isn't any).

From Microsoft as of 11:40am:

The BPOS Operations team is investigating alerts indicating service degradation for Exchange Online mail flow for organizations served from this region. Users in affected organizations may be experiencing delays when trying to send or receive e-mail using Outlook, OWA, or mobile devices. The BPOS Operations team is actively working to determine the root cause and restore service.

When I called in initially, I could hear the service manager yelling in the background as the call queue exploded from a few users to over 60 in a matter of seconds.

Who else is seeing this issue? What have been your impressions of BPOS recently? Anyone on Office 360 having the same problem?

March 20, 2010

Reflections on Google Apps


I just completed our first deployment to Google Apps Premier for a client and a had a great time with it. I've already moved my domain (paulhite.com) over to it and I highly recommend anyone who needs a mail system for their domain to consider it. Here are a couple thoughts on the overall process and results:


November 18, 2009

How I Learned to Stop Worrying and Love the Cloud.

Despite deep-seated childhood fears of all data being consolidated into a single powerful system that touches everything, a little research (and extensive therapy) helped me to develop a healthy relationship with "cloud computing". And by that, I mean that nearly everything I do is contained in the cloud and I am completely dependent on it. Healthy is a relative term.

Red Flags and the Value of Experience

One of the things I hear often said, and something I subscribe to as well, is the idea that a lot of technical knowledge in the world of IT ...