Aug 2008 MAR

August 25th, 2008

Completed audit of vlans on each trunk port versus the configuration of the vswitches on each of the ESX servers in Hill. Corrected problems found which had or may have impacted the production environment.

Closed the SWE for implementing a Samba server within VUMC. After trying to work through multiple problems and incompatibilities with integrating Samba and AD, the end user decided to switch to a windows solution for their new file server. This may be revisited later, but was ended due to time constraints with the start of the school year.

Worked with the NOC to implement LDAP authentication on the SmartCDUs used in the data centers. Received approval and setup an ftp repository for firmware updates to simplify updating the SmartCDUs to the supported revision. Demonstrated a working proof-of-concept to the Data Center Manager and provided instructions for installation and configuration of the solution.

Upgraded the ‘Flash’ server to the latest revision. This update was performed by request in order to provide expanded capabilities to end users of the service.

Continued to make progress on the Virtual Desktop project. Recently upgraded the Sun Global Desktop server software to the latest revision. This upgrade moves the server to more modern versions of apache and tomcat as well as provides additional functionality needed for the project.

Continued working with the project manager for the Ultraseek replacement project. Currently working with vendors to implement ‘pilots’ of their services over a subset of our web environment for testing and evaluation.

Signed up for the first ESX training class which will be held the first week of December in Nashville.

Jul 2008 MAR

July 29th, 2008

Completed VUNETID replacement project. Minor issues with unknown applications were found after moving to production, but were all rectified in concert with Frank in iDev.

Samba integration into AD/LDAP is nearly complete for the Med Centre server PHM1. Host has been joined to the domain and appears to be properly authenticating with AD/LDAP security. Local admin still needs to create the dual data shares which are to be shared within the AD directory tree.

Provided support in getting the application for monitoring connectivity/latency between the university and gmail running on noc-apps.its.

Handled most all web environment oriented Magic tickets while Peter was on vacation and in training. Obtained an honorary promotion to the position of “Peter Junior”, with a later threat of being further promoted to a “Full Peter.”

Attempted to perform upgrade on flash.its from Flash Media Server (FMS) version 2 to version 3. Incorrect license key was provided for use in the upgrade. New key has been obtained and the upgrade is being rescheduled with the Streaming Media team.

Worked with Cindy Frank and other members of the group working on the ITS website redesign project. Was able to implement all requirements put forth including merger of the production site with the test site, configuring LDAP authentication, separation and security on the SSL implementation, inline email integration, etc.

Resolved a problem with interface bonding which appeared to be occurring on its-hclnbu03. Final testing was performed by Derek and Mark who verified proper operation. Not known why the problem was not seen until recently.

Helix project is still on hold awaiting upgrade of the WRVU server.

OSSEC project is still on hold awaiting further testing or instruction.

CSM monitoring project is still on hold awaiting time to work with Peter on snmptrap handling.

Jun 2008 MAR

June 26th, 2008

Attended the Red Hat class in Atlanta. Received an RHCT certification. I’ll get the RHCE next time..

Worked with Frank Kyle on the replacement VUNETID project. Bluestem has now been heavily modified from the base installation to run from a single directory tree. This allows the application to run with SELinux enabled and enforcing, as well as making it much easier to port to a new machine later on. Documentation is now in the directory tree along with the installation which explains the modified structure and locations of important files. We have been awaiting the correct ColdFusionMX7 license and clearance from ITS Security in order to move the replacement to a public IP address for pre-production testing.

Worked with Chris Marshall, ND&E, and the NOC to migrate a couple machines to the ITS Test Network.

Identified a problem with the .115 network while working on the bluestem replacement. The machine was a VM and the root problem was discovered to be inconsistent configuration on the switch ports which the VM host was attached. After reporting the issue I was directed to evaluate the entire ESX environment for this same type of problem. Only one other production problem was found and corrected, all others are non-production and will be resolved during normal maintenance for each affected host.

Performed upgrade of Helix Server for streaming media to version 12. Initial report from John in Streaming Media was that everything appeared to be working and the upgrade was a success. A compatibility issue was identified by John the next morning for encoding from the WRVU server. The upgrade had to be reverted to version 11 to enable encoding/streaming for WRVU until their server software can be upgraded to a compatible version.

Coordinated a migration from single 1Gb fiber to etherchannel (dual) 2Gb fiber for several production vlans in two of the Hill 148 High Density racks. Dan Raymer handled migrating VMs, Roland Serman handled MSSQL failover, and Barry McCurry performed reconfiguration of the Hill_Router and Hill_6513 for this change.

Awaiting coordination with the windows team to re-install the OSSEC client on a couple of their test machines to move forward with evaluation. The two SharePoint servers previously being used have been rebuilt and are no longer available for testing. OSSEC has been successfully reconfigured to utilize a mySQL backend for log aggregation, though local logs are still maintained for the WebUI.

The SWE for CSM monitoring is still on hold until an snmptrap handling solution has been installed and configured for the Nagios host.

May 2008 MAR

May 26th, 2008

Completed installation and configuration of two storage nodes for Kenon. Learned how to setup bonding. Found work-around for problem with bonding Intel + Broadcom NICs. Worked with Barry McCurry in ND&E to configure the network ports and test initial connectivity.

Assisted Joy Saunders and Scott Hogan in locating hardware and documenting information for asset tracking. Submitted updated information to the NOC to update their inventory tracking database.

Worked with ND&E, Peter Woods, and Guy Sheppard to categorize the impact of migrating an old uplink for the High Density racks in Hill 148. Documented the impact analysis and submitted a change request for the proposal which was approved for implementation.

Worked with Kiran from the iDev team and Peter Woods to migrate the Iolan IP/Serial appliance to the .41 network and reconfigure Jtest1 to utilize the device. Made needed firewall updates to host-based firewall and submitted needed changes to ITS Security for the managed firewalls.

Worked with Chris Marshall to help plan and implement a new Apphosting Test Network. Worked with Kenny Elmore and Victor Herbert in ND&E to push the new vlan to all needed ports/switches, as well as Terry Cavender with ITS Security to get the firewall rules in place.

Migrated the OSIS-DEV server to the new AppHosting Test Network. Worked with Rick Williams and members of the iDev team to reconfigure firewall rules and permissions set for use.

Worked with other Apphosting Admins and iDev staff to migrate needed hosts to the new Apphosting Test Network. Coordinated cabling, firewall configuration, hardware relocation, and

Aided Lee Brewer from iDev with testing of the new IDM application servers. Reported findings to Peter Woods who acted on them to properly configure services to run within the needed guidelines for the project.

Found and corrected an issue with time discrepancies that was reported by Lee Brewer. When Selinux permissions were incorrectly set on the configuration file, and was therefore being denied access by the ntpd daemon. Reported findings to Peter Woods who checked other problem hosts for the same problem.

Verified communication from the HILLCSM to nagios.its for SNMPTraps being sent by the CSM module for monitoring. Awaiting time with Peter (probably after the IDM roll-out) to configure the server to monitor the incoming traps.

Implemented a test for an OSSEC server, 2 linux agents, and 2 windows agents for testing. Have been utilizing a book on OSSEC as well as the online wiki to tweak and configure the test setup. Testing is still ongoing.

Apr 2008 MAR

April 25th, 2008

Primarily getting accustomed to the transfer from the NOC to the Unix Team by reading online documentation on policies and procedures and exploring the use of online tools available.

I have been granted access to more and more machines I’ve been trying to somewhat familiarize myself with the services, etc on each.

Assisted Roland with anti-virus integration to the new epolicy server by creating and setting up access for a test repository on the Linux back end.