linescanner Posted May 12, 2009 Posted May 12, 2009 And we all know how much everyone loves the D-Trace graphs! I'm off to have a play with the 7410, cheers guys! Boys and their toys 1
Duke Posted May 12, 2009 Author Posted May 12, 2009 Boys and their toys Funny cos it's true! To all - If any of you reading this are thinking about getting a Sun S7000 box, I can tell you it's absolutely awesome. Thanks to Rick and teejay I've just got a proof-of-concept working with user accounts and it really flies! Have a go with the Sun S7000 Simulator and check out D-Trace, being able to actually see exactly which clients and files are using up your bandwidth is brilliant. Big thanks to Andy and Rick at Cutter Project and Phil at Sun - give them a shout if you're thinking about buying one of these things. Cheers, Chris 4
teejay Posted May 12, 2009 Posted May 12, 2009 @Duke Yes, finding it really impressive on the user accounts, got just short of 1,200 pupil accounts on one 7110 at the moment, with around 550 desktops logging on:D 1
Hebdenlad Posted May 12, 2009 Posted May 12, 2009 Funny cos it's true! To all - If any of you reading this are thinking about getting a Sun S7000 box, I can tell you it's absolutely awesome. Thanks to Rick and teejay I've just got a proof-of-concept working with user accounts and it really flies! Have a go with the Sun S7000 Simulator and check out D-Trace, being able to actually see exactly which clients and files are using up your bandwidth is brilliant. Big thanks to Andy and Rick at Cutter Project and Phil at Sun - give them a shout if you're thinking about buying one of these things. Cheers, Chris AAw, I'm blushing now.
torledo Posted May 12, 2009 Posted May 12, 2009 Hi torledo, thanks for your reply. The plan is eventually to get another 7410 and mirror them across the site. As the 7410 has four Ethernet sockets and can easily be expanded to more (the FAS2020 is just a single controller unfortunately, couldn't afford a dual one), plus has the performance boost from the Flash accelerators and is 22TB rather than just 4TB, I think it makes the most sense for it to be our primary storage unit. Cheers, Chris i know what you mean about the cost implications of going with dual controllers. It's not just the additional controller price but most of the added cost feature options have a bump in price for licensing for two controllers. madness. infact, i've been expecting an array like the S7000 for sun for some time. Ever since i read about the little spat between netapp and sun, which i believe involved netapp bringing an action against sun claiming zfs violated wafl patents. hebdenland would be aware of that...not sure if it's still ongoing. I new then zfs plus sun hardware all packaged up could be a game changer....although i suspect it's a little bit too early and netapp and emc still have considerable market share . although perhaps netapp are using storevault to compete on the price-performance end vs sun. but surely the 7140 is a level above the storvault range. @hebdenland - is vtl functionality on the road map for the s7000. I know you have your prime and plus products for doing vtl at a higher price point, but it might be an interesting idea to give the s7000 a vtl personality option.....i've gone a bit cold on the idea of vtl thinking ata based backup is just fine, but it could help to bring vtl down to the small market....any thoughts ? 1
Duke Posted May 13, 2009 Author Posted May 13, 2009 Ever since i read about the little spat between netapp and sun, which i believe involved netapp bringing an action against sun claiming zfs violated wafl patents. hebdenland would be aware of that...not sure if it's still ongoing. Funny you should mention that. Our NetApp dealer actually mentioned it as a reason to stay with NetApp and avoid Sun. It all depends which side of the argument you believe - I figure either NetApp are extremely confident or they're really getting desperate for ways to compete with Sun and the S7000's. As I've mentioned, I still think of NetApp as top-tier (just look at the market share and the people who use them, it's hard to argue with), but at their prices and with the products Sun are coming up with I think the gap is getting smaller all the time... Cheers, Chris 1
jvelador Posted October 16, 2009 Posted October 16, 2009 We evaluated a 7310 with 4 aggregated gE interfaces and were immediately impressed with the performance. The company now has a 7410 that was recently configured. One thing I noticed in the evaluation was that unlike the NetApp 6070 it may replace, there is no host-based security. At least, nothing I've found in the documentation/admin guide or in the BUI itself alludes to that ability. The shares have to be read-write for obvious reasons. There is nothing preventing a user with root privileges on some Linux box to mount the share, create a local user with the same UID/GID as the systems that write the data and wreak havoc. Short of separating the 7410 to another VLAN, has anyone found a way to secure by host? I asked a Sun engineer during the configuration and he admitted there was no way to do this in the 7410 itself. Hopefully, someone has run across this?
apaton Posted October 17, 2009 Posted October 17, 2009 There is nothing preventing a user with root privileges on some Linux box to mount the share, create a local user with the same UID/GID as the systems that write the data and wreak havoc. ............... Short of separating the 7410 to another VLAN, has anyone found a way to secure by host? Are you talking about NFS or CIFS? If NFS then absolutely yes.
apaton Posted October 17, 2009 Posted October 17, 2009 Funny you should mention that. Our NetApp dealer actually mentioned it as a reason to stay with NetApp and avoid Sun. ZFS is now Open Source, so I can't see how that can put it back in the box anyway. Its a shame really, as NetApp has become the force it has today partly because of Sun. Early NetApp boxes were NFS servers. NFS is a Sun invention which they opened up back in the late 80's. Andy
jvelador Posted October 18, 2009 Posted October 18, 2009 How did you secure by IP address? I've looked all over (I think) and have come up empty so far. Javier
apaton Posted October 18, 2009 Posted October 18, 2009 How did you secure by IP address? I've looked all over (I think) and have come up empty so far. Javier You can set through NFS exceptions. I find using the Network best with a mask of /32 (255.255.255.255) E.g. if you need host ip 172.16.23.41 to have access set network to 172.16.23.41/32 Also see attached screen-shot
SLMHC Posted April 28, 2010 Posted April 28, 2010 OK, got roaming profiles and users set up and live on our Sun 7110. This is the easiest way of doing it: Make sure you have the latest update on your Sun box, makes this work a whole lot easier! Create a Project for the Users, eg Students. Create a share for each group of users, for instance for each Year Group. On the CIFS share level ACL set your admin group to full control and give a security group with the users who are going to have their home directories in this sgare all read and write access but don't tike the inheritance options. In the CIFS Root directory ACL give your admin group full control and the share users group: Read Data/List Directory Execute File/Traverse Directory Read Attributes Read Extended Attributes Then, in the share create two folders, Documents and Profiles On each of these give your Admin group Full Access Your share users group: Traverse Folders/Execute File List Folder/Read Data Read Attributes Read Extended Attributes Create Folders/Append Data and set this to apply onto this folder only Add permissions for CREATOR OWNER as everything apart from Change Permissions and Take Ownership and set this to apply onto Subfolders and Files only. teeyay, I've been trying to follow along here and I am having some success but I'm getting tripped up on the correct permissions on the share so that the ADUC snap-in can set the home folder. I can do it manually, just not through ADUC.
teejay Posted April 28, 2010 Posted April 28, 2010 Best way I've now found of creating CIFS shares on these is: Create the CIFS share on the Sun box with everyone Full Control, don't make it a hidden $ share (you can do this afterwards if needed) In windows, browse to the root of your S7000, so for example in Windows go to \\SUNBOXNAME\ You will see any non hidden shares, right click on the one you've created and set the permissions required for the share. If you want to make it a hidden share, go back in the Sun box and chaneg the share name to one with a $ on the end. I found, especially with earlier versions of the Sun software, that when you try creating the permissions directly on the Sun box it doesn't always work as expected.
john Posted April 28, 2010 Posted April 28, 2010 Best way I've now found of creating CIFS shares on these is: Create the CIFS share on the Sun box with everyone Full Control, don't make it a hidden $ share (you can do this afterwards if needed) In windows, browse to the root of your S7000, so for example in Windows go to \\SUNBOXNAME\ You will see any non hidden shares, right click on the one you've created and set the permissions required for the share. If you want to make it a hidden share, go back in the Sun box and chaneg the share name to one with a $ on the end. I found, especially with earlier versions of the Sun software, that when you try creating the permissions directly on the Sun box it doesn't always work as expected. I'd mirror that way, I make all mine that way and it seems to be the easiest way and works well
SLMHC Posted April 28, 2010 Posted April 28, 2010 Thanks guys. I'll give that method a shot. I am running the latest build so there should be few issues...I hope.
SLMHC Posted April 28, 2010 Posted April 28, 2010 Are the default share settings ok to go with as well? http://dl.dropbox.com/u/469410/sharesettings.JPG
teejay Posted April 28, 2010 Posted April 28, 2010 I'll grab you some screenshots etc of what to set when I'm in the office tomorrow.
Duke Posted April 29, 2010 Author Posted April 29, 2010 You will see any non hidden shares, right click on the one you've created and set the permissions required for the share. If you want to make it a hidden share, go back in the Sun box and chaneg the share name to one with a $ on the end. I found, especially with earlier versions of the Sun software, that when you try creating the permissions directly on the Sun box it doesn't always work as expected. I'm sure this works great, but how do you handle creating 250 users each year for new students? Are you making 250 shares manually and setting the permissions on them all? Our solution to this was to create a share for the year group's userspace and a share for their roaming profiles. Because only the Sun box can create a share (without fiddling with automated workflows), we created folders inside these shares for each user using our batch user creation tool (UMRA from tools4ever) that happily sees the Sun share as a standard Windows share and will make folders and set permissions on them with no problems. I'd love to use hidden $ shares, but Backup Exec won't see them or back them up... Cheers, Chris
teejay Posted April 29, 2010 Posted April 29, 2010 I'm sure this works great, but how do you handle creating 250 users each year for new students? Are you making 250 shares manually and setting the permissions on them all? Our solution to this was to create a share for the year group's userspace and a share for their roaming profiles. Because only the Sun box can create a share (without fiddling with automated workflows), we created folders inside these shares for each user using our batch user creation tool (UMRA from tools4ever) that happily sees the Sun share as a standard Windows share and will make folders and set permissions on them with no problems. I'd love to use hidden $ shares, but Backup Exec won't see them or back them up... Cheers, Chris We don't create a share for each pupil, we have one share for each year group with 2 folders in it, one called Profiles and one called Documents. There is no need to run batch scripts, the individual user profile folders and Documents folders are created automatically at first login. What I was poitning to above was that it seems to work much better if you set the permissions for the share through Windows rather than the Sun interface.
Duke Posted April 29, 2010 Author Posted April 29, 2010 We don't create a share for each pupil, we have one share for each year group with 2 folders in it, one called Profiles and one called Documents. There is no need to run batch scripts, the individual user profile folders and Documents folders are created automatically at first login. What I was poitning to above was that it seems to work much better if you set the permissions for the share through Windows rather than the Sun interface. Ahh, I see. Sorry, misunderstood what you said - Don't worry I know you know the S7000 stuff better than I do. Definitely agree on setting permissions, I think the Sun whitepaper on MS Windows integration actually recommends you set permissions through Windows rather than the box itself. Stupid question, but how are you doing this bit: the individual user profile folders and Documents folders are created automatically at first login Cheers, Chris
teejay Posted April 29, 2010 Posted April 29, 2010 On the Profile or Documents for you give a security group that the pupils belong to the following rights on the folder only, not subfolders: Traverse folder/execute file List folder/read data Read attributes Create folders/append data You then set CREATOR OWNER to have all permissions execpt Change Permissions and Take Ownership on subfolders and files only. Just automatically does it then :-)
teejay Posted April 29, 2010 Posted April 29, 2010 Are the default share settings ok to go with as well? http://dl.dropbox.com/u/469410/sharesettings.JPG Set it as above, thats fine. You then go into the access tab for the share and under Root Directory ACL you set everyone to full control. Once you've done that, in windows go to \\SUNBOXNAME\ and you'll see your share, you can the right click on it and set the permissions up how you need them.
Duke Posted April 29, 2010 Author Posted April 29, 2010 Just automatically does it then :-) Seriously, I'm clearly being stupid here but humour me... As long as I set the top-level folder permissions correctly to allow access, Active Directory will automatically create the folders and set permissions based on the paths that are entered for the profile and home directory? I've never seen (nor tried) this happen, and we're using Server 2003. Does it just work like that? In all the time I've been working here I was told to create the directories manually, make the user account, enter the paths of the folders I just made in AD for the user, then manually set full-control permissions on the folders for that user. Hope I'm not being incredibly stupid here...
teejay Posted April 29, 2010 Posted April 29, 2010 Seriously, I'm clearly being stupid here but humour me... As long as I set the top-level folder permissions correctly to allow access, Active Directory will automatically create the folders and set permissions based on the paths that are entered for the profile and home directory? I've never seen (nor tried) this happen, and we're using Server 2003. Does it just work like that? In all the time I've been working here I was told to create the directories manually, make the user account, enter the paths of the folders I just made in AD for the user, then manually set full-control permissions on the folders for that user. Hope I'm not being incredibly stupid here... Yes, it does, as long as the permissions are set as above. We don't set a home directory, in group policy and we up folder redirection. It probably works with a home folder set as well, its just we have never used home folders. 1
Duke Posted April 29, 2010 Author Posted April 29, 2010 (edited) Excuse me, I just need to uh, bang my head against the wall... On the plus side, the reason I've never noticed this is that we very rarely create users manually, they're almost all scripted as we do them in batches. I also need to fiddle with permissions on the profiles folder to get it working. EDIT: Oh yeah, just realised that we've never done it before previously because every user also had their own individual share as well, not sure if AD would have handled that? It's only since we've gone to the SAN that it's changed to a top-level share with individual folders. *hangs head in shame* Chris Edited April 29, 2010 by Duke
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now