<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Api on SneakU</title><link>https://sneaku.com/categories/api/</link><description>Recent content in Api on SneakU</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Tue, 14 Jul 2020 00:00:00 +0000</lastBuildDate><atom:link href="https://sneaku.com/categories/api/index.xml" rel="self" type="application/rss+xml"/><item><title>What's New in NSX-v 6.4.7 - L3port-optimization</title><link>https://sneaku.com/2020/07/14/whats-new-in-nsx-v-6.4.7-l3port-optimization/</link><pubDate>Tue, 14 Jul 2020 00:00:00 +0000</pubDate><guid>https://sneaku.com/2020/07/14/whats-new-in-nsx-v-6.4.7-l3port-optimization/</guid><description>&lt;p&gt;Late last week, the latest version of NSX vSphere, 6.4.7 was released for General Availability (GA). Although it was mainly a maintenance release, there were a couple of items listed in the What&amp;rsquo;s New section of the release notes. I won&amp;rsquo;t list them all here, and instead I will just provide you with a link.&lt;/p&gt;
&lt;p&gt;&lt;a href="https://docs.vmware.com/en/VMware-NSX-Data-Center-for-vSphere/6.4/rn/releasenotes_nsx_vsphere_647.html"&gt;https://docs.vmware.com/en/VMware-NSX-Data-Center-for-vSphere/6.4/rn/releasenotes_nsx_vsphere_647.html&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Once a NSX-v environment has been upgrade to 6.4.7, you may notice there will be a difference in how Distributed Firewall (DFW) rules will look on the dataplane when viewing them using the following command:&lt;/p&gt;</description></item><item><title>Counting Exploded NSX-v DFW Rules</title><link>https://sneaku.com/2020/06/09/counting-exploded-nsx-v-dfw-rules/</link><pubDate>Tue, 09 Jun 2020 00:00:00 +0000</pubDate><guid>https://sneaku.com/2020/06/09/counting-exploded-nsx-v-dfw-rules/</guid><description>&lt;p&gt;When working with a customer recently, there was a question raised about how to calculate the actual number of NSX-v distributed firewall rules configured for a given VM on the dataplane of an ESXi host.&lt;/p&gt;
&lt;p&gt;Whilst the short answer was to jump onto the console of the hypervisor or SSH into the host and look at the rules configured on the filter with the following command:&lt;/p&gt;
&lt;pre tabindex="0"&gt;&lt;code&gt;vsipioctl getrules -f &amp;lt;filtername&amp;gt;
&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;Looks easy enough right? However, It didn&amp;rsquo;t really work in this specific customers environment as SSH and console access to the hypervisors was managed by a 3rd party and hence it was impossible for the customer to run the above command.&lt;/p&gt;</description></item><item><title>How to count DFW rules per ESXi host.</title><link>https://sneaku.com/2020/05/27/how-to-count-dfw-rules-per-esxi-host./</link><pubDate>Wed, 27 May 2020 00:00:00 +0000</pubDate><guid>https://sneaku.com/2020/05/27/how-to-count-dfw-rules-per-esxi-host./</guid><description>&lt;p&gt;If you&amp;rsquo;ve heard me speak at VMworld on NSX Distributed Firewall best practises, you would have heard me speak about the importance of using the Applied To option when configuring DFW rules. One of the metrics using the Applied To option influences is the total number of rules configured per host.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;If you haven&amp;rsquo;t seen the VMworld session, I&amp;rsquo;ve uploaded it to YouTube for easier viewing - &lt;a href="https://youtu.be/fX9pwiIeMps"&gt;https://youtu.be/fX9pwiIeMps&lt;/a&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;As per the published configurations on &lt;a href="https://configmax.vmware.com/"&gt;configmax.vmware.com&lt;/a&gt;, the maximum number of rules supported per host is as follows:&lt;/p&gt;</description></item><item><title>How to sync a dynamic NSX-T group to an external system</title><link>https://sneaku.com/2020/03/02/how-to-sync-a-dynamic-nsx-t-group-to-an-external-system/</link><pubDate>Mon, 02 Mar 2020 00:00:00 +0000</pubDate><guid>https://sneaku.com/2020/03/02/how-to-sync-a-dynamic-nsx-t-group-to-an-external-system/</guid><description>&lt;p&gt;One of the things that makes NSX-T such a flexible platform when it comes to creating security policy is the ability to group membership defined by dynamic criteria, or based on objects such as a logical segment.&lt;/p&gt;
&lt;p&gt;Once a group has been defined in NSX-T based on dynamic criteria, its membership can grow and shrink based on the specified criteria, which is awesome, and allows for virtual workloads to be added/removed from groups based on other attributes (e.g tags, amongst other attributes). But one of the sticking points of this extremely dynamic behaviour is that the groups are only available within the specific NSX-T environment for which they are configured.&lt;/p&gt;</description></item><item><title>NSX-v: Where is my object used that I am trying to delete?</title><link>https://sneaku.com/2017/09/07/nsx-v-where-is-my-object-used-that-i-am-trying-to-delete/</link><pubDate>Thu, 07 Sep 2017 00:00:00 +0000</pubDate><guid>https://sneaku.com/2017/09/07/nsx-v-where-is-my-object-used-that-i-am-trying-to-delete/</guid><description>&lt;p&gt;Over the past few years of working with NSX vSphere, one of the more frustrating things that would happen is that you would try to delete an object of some description (IP Set, Security Group, Service etc) and you would get the annoying message in the UI which says the object is in use, but it doesn&amp;rsquo;t give you any more information or any context of where to even start looking to find out where it is being used.&lt;/p&gt;</description></item></channel></rss>