Converge vSphere 8 to VMware vSphere Foundation 9.1.x

.

ATTENTION!!

This is a document that was created from a Home Lab.

My Home Lab:

vSphere 8u3i

One vCenter

Two ESXi hosts (Nested)

One NFS datastore (TrueNAS)

Official Documentation

Source Converge a vCenter Instance and ESX Hosts to vSphere Foundation

Verify upgrade path from Product Interoperability Matrix

Requirements

Prepare a temporary IP for vCenter

Prepare five FQDNs and register on DNS (with reverse) for:

1 VCF Operation

3 VCF Management Services

1 VCF License server

And ten IP addresses (minimum) for Management Services

.

UPGRADE STEP

• vCenter Upgrade
• Install VCF Installer
◦ Install VCF Operations
◦ Install VCF Management Services
• Upgrade ESXi
◦ Upgrade ESXi Hosts
◦ Upgrade vDS
◦ Upgrade VMware Tools
◦ Upgrade Virtual HW

.

vCenter Upgrade

You must deploy the new vCenter in the vSphere Cluster that you need to upgrade at VVF. In my test, I deployed the new vCenter in another vSphere infrastructure, and the VCF Installer reports an error.

The vCenter upgrade process is a classic vCenter upgrade.

.

Download vCenter 9.1 from the Broadcom Support Portal

Dedicate a temp IP address and FQDN name (need to register in DNS) for deployment

Mount the downloaded ISO on a bridge PC or Virtual Machine

Start the UI installer

 .

Select upgrade

 .

Start the deployment

.

Deploy the VCF Installer appliance.

I covered this installation in another Post; read this post:

Start a New vSphere Foundation Deployment by Using the VCF Installer Deployment Wizard – BIOLNX

Deploy VCF Operations

Log in to VCF Installer

Download bundles for the VCF Installer appliance (Read this post: Start a New vSphere Foundation Deployment by Using the VCF Installer Deployment Wizard – BIOLNX)

Use VCF Installer to deploy your vSphere Foundation platform.

.

.

Select I have an existing vCenter

Select the network infrastructure for the Management Services and Operations component in my Home Lab. I choose the network where the VM is deployed (otherwise, create a dedicated network; check the firewall configuration in the official documentation)

.

.

Dedicate IP address and FQDN (with reverse)

VVFOPUP.pollaio.lan 192.168.80.110

VVFMNGSUP01.pollaio.lan 192.168.80.111

VVFMNGSUP02.pollaio.lan 192.168.80.112

VVFMNGSUP03.pollaio.lan 192.168.80.113

VVFLICUP01 192.168.80.114

.

.

We enter the FQDN names of the objects; if entered correctly in the DNS (with the reverse), they have a green tick

.

In my case, if the new vCenter is not deployed in the cluster that we want upgrade, we see an error.

.

After vCenter migrating to the vSphere cluster object for the upgrade

.

Save the Password!!!!

Start the VCF Operation appliance installation

.

At the end of VCF operation Installation, we can log in to the VCF Operations UI

Now we can configure the License (See this post)

Register VCF Operations and Your License Server in Connected Mode – BIOLNX

.

Upgrade ESXi

Log in to vCenter and select the Lifecycle Manager

After some time, under Software Depot, the new ESXi version appears

Now we create a new Image; go to Image Library and select Create Image

 

Validate and save

.

Go to Inventory

Select the cluster and after updates

.

Now the upgrade will start if the cluster is correctly configured

Upgrade Virtual Distributed Switch

.

.

Next step

Upgrade VMware Tools

Upgrade Virtual Hardware

.

Converge vSphere 8 to VMware vSphere Foundation 9.1.x

Horizon 2603 is here!

A new version of Omnissa Horizon has just been released, and 2603 is not just another update — it’s an ESB (Extended Service Branch) release and marks an important transition point for many environments.

🔗 Release Notes:
https://docs.omnissa.com/bundle/horizon8-rnV2603/page/Horizon8-ReleaseNotes.html


First things first: end of support for vSphere 7

Let’s start with something critical:

Horizon 2603 ESB no longer supports vSphere 7.x

  • Horizon 2512 was the last release supporting vSphere 7
  • Starting from 2603, vSphere 8 is the required platform

This means one thing:
If you’re planning to move to this ESB, your vSphere upgrade is no longer optional — it’s mandatory

This is a key architectural checkpoint, especially for environments that have been delaying the jump to vSphere 8. (vSphere 7 is end of support)


Event Database + Integrated Authentication (finally!)

Now, let’s talk about one of my favorite new features.

Horizon 2603 introduces the ability to configure the Event Database on Microsoft SQL Server using Active Directory identities (Domain User with Integrated Authentication).

No more SQL authentication.

Why this matters:

  • Eliminates stored SQL credentials
  • Aligns with enterprise security best practices
  • Simplifies credential lifecycle management
  • Improves compliance and auditability

From a design perspective, this is a very welcome step toward a more secure-by-default architecture.

 Final thoughts

This release is not just about new features — it’s about setting a new baseline:

  • ✔️ ESB = long-term stability
  • ✔️ vSphere 8 as the standard
  • ✔️ Stronger security integration

If you were waiting for the “right moment” to modernize your Horizon platform… this is probably it.


 In the next posts, I’ll dive deeper into the other new features and changes introduced in Horizon 2603 — stay tuned 👀


Need help testing or upgrading?

If you’re planning to:

  • Test Horizon 2603
  • Upgrade your existing environment
  • Move from vSphere 7 to vSphere 8 or 9

Feel free to reach out — happy to help with assessments, design, and upgrade strategies.


Have you already started testing Horizon 2603?
Or are you still planning your vSphere 8 migration?

Let’s discuss 

Horizon 2603 is here!

How to Test an NVIDIA Video Card with Omnissa VDI: A How-To Guide

Have you just set up a VDI and want to see if your cool NVIDIA video card is doing its job? Don’t worry, I understand you. There’s nothing more frustrating than spending a fortune on hardware and then finding that the GPU sleeps while the processor does all of it. In this article, I explain in a simple (and fast) way how to test the Nvidia video card within a VDI.

Tested environment

NVIDIA Tesla M10 (not the latest model, but still supported by vSphere and NVIDIA and limited cost for my homelab)

vSphere 8.x (thanks to licenses as vExpert)

Omnissa Horizon 2503 (Thanks to licenses like Omnissa Tech Insider and Omnissa community)

Supermicro as HW

Guest OS Windows 11 2412

NVIDIA drivers installed on ESXi and Windows 11 guest VDI

Configuring the NVIDIA Card: Configuring the Card as Direct Shared

Virtual machine HW: Add the desired cut of the NVIDIA card size

In this link, there are more details on the NVIDIA cards’ size

Virtual GPU Software

First question: But can it be done?

Yes, and it must be done. With modern VDI – we are talking about environments such as those managed with Omnissa (formerly VMware EUC) – it is possible to assign GPUs to virtual machines using technologies such as vGPUs. The problem? It is not always clear if the GPU is really used.

Step 1: Verify that the GPU is mapped

First of all, log in to your VDI (Windows or Linux, little changes) and open the Task Manager or a terminal. In Windows, go to GPU > Performance. If you see “NVIDIA” somewhere, you’re on the right track.

Or use nvidia-smi (yes, it also works in VDI if the drivers are in good shape). It will tell you everything: from the memory used to the temperature, passing through the active processes. It’s like the GPU use.

Step 2: Make the video card work

At this point, test it seriously. What?

  • Open an app that uses graphics acceleration (e.g., a CAD, a 4K video, or even just YouTube at full quality).

A screenshot of a computer AI-generated content may be incorrect.

A screenshot of a computer AI-generated content may be incorrect.

  • On Linux or more closed environments, you can use command-line tools or scripts to make test renders.

During these tests, keep an eye on nvidia-smi or the Task Manager. If the GPU stays at 0%, there’s something wrong (spoiler: it’s often a driver or vGPU assignment issue).

Step 3: Monitor WHIT style

For continuous monitoring, you can install the NVIDIA System Management Interface or use third-party tools built into the Omnissa environment, such as those included in Horizon (Horizon Performance Tracker) or management plug-ins.

Bonus: Don’t forget the logs

Check the host machine and VM logs. Often, there you will find clues to understand if the GPU passage was successful or if there is something blocking everything.

Ultimately?

Testing an Nvidia GPU on a VDI is not complicated, but it takes a method. With the right tools and a keen eye, you can make sure that your graphics assets are really being used, and that the end user (or yourself) doesn’t have to put up with unnecessary lag or jerking.

Want help scripting an automated test? Write. Or… Launch nvidia-smi (with the -l parameter, it goes into automatic refresh) and see if the vGPU wakes up.

 

Some suggestions

 

  • To perform top benchmarks, you have to remove the cap present by default on vSphere for FPS (I would recommend keeping FPS equal to or lower than the Hz value of your monitor, otherwise, we may have a non-optimal fluidity of the images). The cap is deactivated by putting this value in the Advanced settings of the VM’s pciPassthru0.cfg.frame_rate_limiter=0

How to Test an NVIDIA Video Card with Omnissa VDI: A How-To Guide

vSAN ESA and vSAN File Service

Requirements

Enable vSAN File Service

Limitations and Considerations

Limitations and Considerations of vSAN File Service

Networking Considerations for vSAN File Service

After deploying and configuring the vSAN ESA we are ready to enable and configure the vSAN file services.

Enable File Service

A screenshot of a computer

Description automatically generated

A screenshot of a computer service

Description automatically generated

After Enabling the service we will see on the vCenter a new Resource Pool to allocate the File Service Node VM. (One for Each host ESXi)

A screenshot of a computer

Description automatically generated

Configure vSAN File service

Go to vSAN, Services and under File Service click CONFIGURE DOMAIN

A screenshot of a computer

Description automatically generated

A screenshot of a computer

Description automatically generated

A screenshot of a computer

Description automatically generated

We need to configure the Directory Service to enable SMB share and NFS Kerberos Authentication.

The user identity for configuring the directory service must have the correct permission to do a join AD.

A screenshot of a computer

Description automatically generated

A screenshot of a computer

Description automatically generated

A screenshot of a computer

Description automatically generated

After completing the domain configuration we see the computer accounts in the OU select.

A screenshot of a computer

Description automatically generated

Create File Share

Now we can create the file share

A screenshot of a computer

Description automatically generated

Will can create a NFS share with AUTH_SYS or Kerberos Authentication

A screenshot of a computer

Description automatically generated

A screenshot of a computer

Description automatically generated

A screenshot of a computer

Description automatically generated

A screenshot of a computer

Description automatically generated

Will can create an SMB share

A screenshot of a computer

Description automatically generated

A screenshot of a computer

Description automatically generated

Configure ACL permission

SMB SHARE can configure ACL for access use the FSM MMC from a windows OS.

A screenshot of a computer

Description automatically generated

A black background with white text

Description automatically generated

A screenshot of a computer

Description automatically generated

From best practices Microsoft it suggest to user Everyone on Share permission

A screenshot of a computer screen

Description automatically generated

And set the permission on File Level (Security TAB)

A screenshot of a computer screen

Description automatically generated

Mount Share

On every share proprieties, we can find the path to use for mounting the share (The SMB Export Path)

A screenshot of a computer

Description automatically generated

Share quota

The quota control if a specified Share exceed the max space add for it.

A screenshot of a computer

Description automatically generated

We can control the state of all share quotas from the vSphere console.

A screenshot of a computer

Description automatically generated

A screenshot of a computer

Description automatically generated

SMB Export Path -> The path to use for mounting the share

MMC Command -> The command to use for configuring the ACL

A screenshot of a computer

Description automatically generated

vSAN ESA and vSAN File Service

App Volumes 2406 and Unified Access Gateway 2406

All of VMware’s EUC products were continuously updated (in recent years almost always every 3 months) to add new features, fix bugs and mitigate security vulnerabilities.

The move to Broadcom and the subsequent sell of EUC products in Omnissa has brought a few months of stabilization… but I’m happy to announce that versions 2406 of the App Volumes and Unified Access Gateway products are out.

What do we find new?

A logo with text on it

Description automatically generated

App Volumes

Persistent Desktop Support

Expanded Use Cases: New support for classic Windows desktop environments, a significant enhancement to our Apps Everywhere strategy. This new feature extends our efficient one-to-many provisioning model, previously available only for non-persistent desktops, to persistent virtual desktop environments.

And more…

Replicate Application Packages in Specific Stages

We are excited to introduce the Replicate Application Packages in Specific Stages feature, designed to enhance the life cycle management of applications across multiple instances of App Volumes Manager

And more…

Select a specific Package Version when Launching an App (Technology Preview)

Writable Volumes Performance Improvements

Here the Release Notes

A logo of a cloud security system

Description automatically generated

Unified Access Gateway

Added support for Horizon Connection Server’s Home Site Redirection feature (associated with Cloud Pod Architecture)

Added support for Basic and NTLM authentications in outbound proxy configuration.

Added support in PowerShell script to enable/disable monitoring of unrecognized sessions using the new field unrecognizedSessionsMonitoringEnabled.

And more..

Here the Release Notes 

 

The 2406 version of the Connection Server ……..stay tuned!

App Volumes 2406 and Unified Access Gateway 2406

VMware vSphere Foundation for VDI (VVF for VDI)

A blue and white logo

Description automatically generated

A black text on a white background

Description automatically generated

The exit of EUC services from Broadcom (after the acquisition of VMware by the US giant) has brought a situation of uncertainty for all those who have been appreciating for years the features of the VDI/Applications published with Horizon and all the products of the EUC ecosystem that were from VMware.

The birth of Omnissa (effective from the beginning of July) bodes well for the future (more information in this post of mine from a few weeks ago).

Of the many synergies that were natural when vSphere and Horizon were children of the same mother, the first uncertainty was the licensing issue.

VMware gave the possibility, once a specific Horizon license was purchased, to have the vSphere virtualization infrastructure licenses, practically a solution ready to be only implemented. (I remind you that Horizon also goes on other Hypervisors… obviously exploits 10% of the potential… on this issue. I expect news from Omnissa since vSphere and Horizon are no longer brothers). The only limitation of the vSphere license included in Horizon was the need to run on the vSphere platform, licensed with Horizon, only VDI environments and the servers necessary for operation (Connection Server ,,, App Volumes Manager etc ..)

Now that vSphere and Horizon no longer have the same mother, what happens to these licenses? Will I still be able to buy a bundle with Horizon and vSphere together?

This link explains that the best of the matter:

Setting the record straight: EUC to continue to offer Horizon with vSphere and vSAN (omnissa.com)

Where it is indicated that there will be a collaboration between Omnissa and Broadcom to allow the presence of a bundle with Horizon and vSphere.

A green and white logo

Description automatically generated

So it is still possible to purchase one of the following licenses:

  • Horizon Enterprise term
  • Horizon Universal,
  • Horizon Enterprise Plus
  • Horizon Standard Plus
  • Horizon Apps Universal

What is the name of the vSphere package included in Horizon Solutions?

VMware vSphere Foundation for VDI (VVF for VDI)

What does it include?

• vSphere Enterprise Plus

• vCenter Standard

• vSAN Enterprise (100 GB) (licensed per Core)

So how much space have I included in vSAN?

Well, the game is quite simple: for each core of my vSphere cluster on which I host VDI and on which I have the VVF for VDI licenses, just multiply 100GB by the number of CORES. (there are no restrictions on the number of cores)

Let’s focus on the vSAN Enterprise license… what difference do we have from the previous Bundle?

  • vSAN Enterprise includes the same features as vSAN Advanced plus all those of vSAN Enterprise which are:
    • Data-at-rest and data-intransit encryption
    • File services
    • VMware HCI Mesh™2

In this link more information:

VVF_VDI_SPD_July2024.pdf (broadcom.com)

VMware vSphere Foundation for VDI (VVF for VDI)

VMware Horizon takes a long time to provision Desktop virtual machines

VMware Horizon takes a long time to provision the Desktop virtual machines

We detected a strange situation when changing the sizing (number of desktop VMs) or publishing a new image on the Instant clone Desktop Pool.

The highlighted situation is a very long time in creating one or more VMs from the Gold Image. Following investigation we found that the problem is also present when cloning a VM that is present in the same vSphere environment where the instant clone VDIs are allocated.

In our case it was a vSAN environment, having carried out the first routine checks where no network, disk or compatibility problems were found, we went into the details of the logs and in the case of the clone we found this error message in the logs of the VM that was being cloned.

A screenshot of a computer

Description automatically generated

We have found a workaround and a permanent resolution:

Workaround:

Restart the vCenter service

VMware vService Manager

Resolution:

Check this KB https://kb.vmware.com/s/article/96049 where the problem is fixed on vCenter 8.0 U2b.

VMware Horizon takes a long time to provision Desktop virtual machines

VMware Pre Broadcom vs VMware Broadcom – Primi dati reali

Attenzione è una mia valutazione….quindi non sparate sul sistemista

Broadcom ha acquisito VMware, ormai lo sappiamo tutti.
La situazione di incertezza aleggia ovunque soprattutto sul mondo vSphere e sui costi (con tanti competitor che provano a ritagliarsi la loro fetta di mercato togliendole al leader indiscusso di questi anni)


Finalmente in questi giorni incomincio ad avere i primi dati effettivi (Prezzi ecc…) su cui iniziare a fare i primi ragionamenti.
!!Attenzione non voglio dare giudizi ma voglio solo paragonare due offerte fatte allo stesso cliente che abbiamo dovuto rivedere a seguito del nuovo listino (E parliamo di prezzi di listino.. senza eventuali scontistiche)!!

Ragioniamo su un cluster vSphere con 3 nodi da 2 processori ciascuno da 16 core.

Con le precedenti licenze e il vecchio listino nello scenaro ipotizzato dovevamo considerare:

  • Licenza VMWARE VCENTER SERVER 8 STANDARD
  • Licenza VMWARE VSPHERE 8 STANDARD FOR 1 PROCESSOR
  • Support/Subscription
  • Support/Subscription

Con il nuovo listino e le nuove tipologie di licenze invece dobbiamo considerare:

  • VMWARE VSPHERE STANDARD per core (Che comprende la licenza di vCenter)

Entrambe le soluzioni con 5 anni.

Da una prima analisi le prime valutazioni sono:
Con il nuovo listino si viene a pagare circa 30-35% in meno.
Ho una semplificazione nella quotazione (una sola voce rispetto alle 4 precedenti)

Ovviamente:

  • Non abbiamo le licenze perpetue (comunque chi non vuole il supporto sul proprio ambiente di produzione o la possibilità di effettuare aggiornamenti?)
  • é una prima offerta e la quotazione può dipendere da vari fattori e i prezzi potrebbero nuovamente cambiare
  • Le funzionalità all’interno dei bundle possono essere leggermente differenti (il link per vedere le funzionalità presenti nei nuovi bundle VMware vSphere® Product Line Comparison)
  • Posso aver sbagliato i calcoli 🙂
  • Possono avermi dato dei prezzi sbagliati 🙂 spero di no per il cliente 🙂

ma aspettavo di avere due informazioni reali per fare le mie prime considerazioni.

L’unica cosa che posso dire è di valutare con attenzione il cambio …. (io sono il primo che accetta nuove sfide..) ma attenzione a tutti i prezzi nascosti e valutate bene!

P.S. se qualcuno ha delle esperienze in merito … condividiamole.

VMware Pre Broadcom vs VMware Broadcom – Primi dati reali

DRS and HPE SimpliVity

In recent days, a customer reported an anomaly on an HPE SimpliVity cluster hosting instant clone Horizon VDIs. In detail:

  • vSphere with seven hosts present, two were always at 98% CPU utilization and 90% RAM utilization.
  • Continuous vMotion generated by the VM DRS to and from those two HOSTS.

After a careful analysis, we identified that there were no problems at the vSphere infrastructure level.
The issue was due to a Simplivity feature called IWO.

By disabling IWO and keeping DRS active (Full automatic) I have an optimal balance of CPU and RAM load between hosts at the expense of a slight increase in I/O trip times

Scenario – Even VM Load Distribution

I want even VM load across my cluster in terms of CPU and memory. Data locality and I/O performance are not top priorities. Most applications are CPU and memory intensive, and adding 1ms to 2ms to I/O trip times will not impact application performance.

In this scenario, IWO can be disabled thus ensuring no DRS affinity rules are populated into vCenter server. Suppressing DRS affinity rules will allow VMware DRS or allow you to directly distribute VMs across the cluster as desired to ensure all VMs are adequately resourced in terms of CPU and memory. The ‘Data Access Not Optimized’ alarm can be suppressed within vCenter server.

More information:

https://community.hpe.com/t5/around-the-storage-block/how-vm-data-is-managed-within-an-hpe-simplivity-cluster-part-3/ba-p/7033153

DRS and HPE SimpliVity

vSphere Distributed Switch health check

For us VMware systems engineers who every day find ourselves “dialoguing” with those who manage the network ecosystem, we can only find the vSphere Distributed Switch health check function useful.

  1. What these checks allow us to highlight:

These are some of the common configuration errors that health check identifies:

  • Mismatched VLAN trunks between a vSphere distributed switch and a physical switch.
  • Mismatched MTU settings between physical network adapters, distributed switches, and physical switch ports.
  • Mismatched virtual switch teaming policies for the physical switch port-channel settings.

The network health check in vSphere monitors the following three network parameters at regular intervals:

  • VLAN: Checks whether vSphere distributed switch VLAN settings match trunk port configuration on the adjacent physical switch ports.
  • MTU: Checks whether the physical access switch port MTU setting based on per VLAN matches the vSphere distributed switch MTU setting.
  • Network adapter teaming: Checks whether the physical access switch ports EtherChannel setting matches the distributed switch distributed port group IP Hash teaming policy settings.
  1. How to activate:

Access the network section of our vCenter

Select the vDS on which we want to activate health checks

A screenshot of a computer

Description automatically generated

And enable the check that interests us:

A screenshot of a computer

Description automatically generated

  1. Where to check the outcome of the checks?

Wait a few minutes and already first feedback we can have it on ESXi hosts using the vDS in question, where if there are problems the classic red dot will be displayed

A screenshot of a computer

Description automatically generated

For more details, access the network section of our vCenter and select the vDS in question

A screenshot of a computer

Description automatically generated

And we can see that on the vmnic0 and vmnic3 of the first host, there are vLANs of which we have a Portgroup but which are not proposed correctly on all the ports of the switches to which we have attested our hosts. Then we have to have the configuration verified by our colleagues in the network.

  1. How to turn it off:

Repeat the enabling steps but this time select disable.

  1. Risks in activating it (we always consider activating it for a short time)

Depending on the options that you select, the vSphere Distributed Switch Health Check can generate a significant number of MAC addresses for testing teaming policy, MTU size, vLAN configuration, resulting in extra network traffic.
Ensure the number of MAC addresses to be generated by the health check will be less than the size of the physical switch(es) MAC table. Otherwise, there is a risk that the switches will run out of memory, with subsequent network connectivity failures. After you disable vSphere Distributed Switch Health Check, the generated MAC addresses age out of your physical network environment according to your network policy.

More info:

vDS Health Check reports unsupported VLANs for MTU and VLAN (2140503) (vmware.com)

Enabling vSphere Distributed Switch health check in the vSphere Web Client (2032878) (vmware.com)

vSphere Distributed Switch health check