NSX-T Packet Walk
Today I want to show you a quick overview of the path a packet makes when in- or egressing in our lab environment. Overlay networking […]
Daniel Micanek virtual Blog – Like normal Dan, but virtual.
Today I want to show you a quick overview of the path a packet makes when in- or egressing in our lab environment. Overlay networking […]
Did you know we have a free exam voucher promotion for On Demand courses purchased through VMware? With this promotion, students who complete an On Demand course will receive a free exam voucher for the corresponding certification exam. This voucher is valid for one year after course completion.
Synology NFS VAAI Plug-in support for vSphere 8.0
After sharing my recent Synology DS723+ setup for my Homelab, where I initially decided on using iSCSI storage since it had out of the box support for VMware vSphere Storage APIs for Array Integration (VAAI), I had received a number of comments and recommendations to actually stay away from iSCSI and just use NFS due […]
vSphere 8 for SAP NetWeaver and AnyDB is supported and certified since March this year. In August, Lenovo, Pure, Intel, SAP, and VMware have successfully finished the vSphere 8 validation for SAP HANA on 4ht Gen Intel® Xeon® Scalable Processor 2-socket based server systems, codenamed Sapphire […]
When vSphere 8.0 Update 1 was released, I noticed an interesting message about containers being installed while deploying the vCenter Server Appliance (VCSA) … Interesting … while runc has been part of the VCSA for a few releases, it looks like it now launches ws1a-broker container in […]
VMware announced vSAN 8 Update 2 and an exciting new offering, VMware vSAN Max. We welcome Pete Keohler to discuss the details this week on The Virtually Speaking Podcast.
🆕 vSphere 8.0 Update 1c is now available! vSphere 8.0 Update 1c was just released and one of the resolved issues mentioned in the ESXi release notes is the following: […]
VMware is gearing up for a significant update with vSphere 8 Update 2, and it’s set to make waves in the realm of virtualization. Anticipated for release in Q3 2023, this update promises to bring exciting changes that will have a positive impact on the daily routines of VMware administrators.
Security Fixes in Release 4.3(2b)
Defect ID – CSCwf30468
Cisco UCS M5 C-series servers are affected by vulnerabilities identified by the following Common Vulnerability and Exposures (CVE) IDs:
wget https://raw.githubusercontent.com/speed47/spectre-meltdown-checker/master/spectre-meltdown-checker.sh
# sh spectre-meltdown-checker.sh --variant downfall --explain
EVC Intel “Skylake” Generation
CVE-2022-40982 aka 'Downfall, gather data sampling (GDS)'
> STATUS: VULNERABLE (Your microcode doesn't mitigate the vulnerability, and your kernel doesn't support mitigation)
> SUMMARY: CVE-2022-40982:KO
EVC Intel “Broadwell” Generation
CVE-2022-40982 aka 'Downfall, gather data sampling (GDS)'
> STATUS: NOT VULNERABLE (your CPU vendor reported your CPU model as not affected)
> SUMMARY: CVE-2022-40982:OK
Mitigation with an updated kernel
When an update of the microcode is not available via a firmware update package, you may update the Kernel with a version that implements a way to shut off AVX instruction set support. It can be achieved by adding the following kernel command line parameter:
gather_data_sampling=force
When the mitigation is enabled, there is additional latency before results of the gather load can be consumed. Although the performance impact to most workloads is minimal, specific workloads may show performance impacts of up to 50%. Depending on their threat model, customers can decide to opt-out of the mitigation.
There will be an Intel SGX TCB Recovery for those Intel SGX-capable affected processors. This TCB Recovery will only attest as up-to-date when the patch has been FIT-loaded (for example, with an updated BIOS), Intel SGX has been enabled by BIOS, and hyperthreading is disabled. In this configuration, the mitigation will be locked to the enabled state. If Intel SGX is not enabled or if hyperthreading is enabled, the mitigation will not be locked, and system software can choose to enable or disable the GDS mitigation.
The VMware Explore 2023 Las Vegas – Video Library recordings for all on-demand sessions is now available!