IT Systems Integration vsphere Update Manager 6.0 Patch and Upgrade Management Guide. Prepared By IT Systems Version History Version Date Notes 1.0 01/13/17 Initial Release
1 Introduction VMware Update Manager() is a utility that oversees the installation of updates for existing installations of VMware ESX Server and guest operating systems. Update Manager tracks vulnerabilities within the virtual infrastructure and automatically applies user-defined patches to eliminate those vulnerabilities. 1.1 Target Audience/Purpose/Scope: Using vsphere Update Manager to upgrade and patch ESXI Server, Guest Operating Systems, and Applications. Below procedures will illustrate the facilitate upgrades and patching of ESX Server installations, guest operating systems, and applications. Using current versions of software helps establish a consistently secure and patched environment. 1.2 Assumptions-Prerequisite Requirements. vsphere vcenter 5.5, 6.0, or 6.5 has been installed. vsphere Update Manager() 5.5, 6.0 or 6.5 has been installed. vsphere Update Manager() Client installed. Please reference vcenter and installation guide sections if none of the 1.2 has been completed. vcenter 6.5 Installation Guide http://blog.itsysintegration.net/vcenter-6-5-installation-guide/ vsphere Update Manager Installation Guide. http://blog.itsysintegration.net/vsphere-update-manager-installation-guide/ vsphere Update Manager() Client Installation Guide. http://blog.itsysintegration.net/install-vmware-update-manager-client-vum/. Page 2 of 44 01/14/17
2 ESXI Patching/Upgrade Below procedures will illustrate the facilitate upgrades and patching of ESX Server installations, guest operating systems, and applications. By helping software helps establish a consistently secure and patched environment. In below illustrate We will perform ESXI host patching and upgrade from ESXI,6.0.0,249458 to 4600944 Version 2.1. Prerequisite Validate Patching Download Frequency To set up frequency of the repository update, Update Manager downloads the list of available patches from vmware.com 1. Validate Patch Schedule--Click Home.--->Update Manager icon. Page 3 of 44 01/14/17
2. Under the Configuration tab, 3. Click Download Schedule *below is example, download schedule is daily. Page 4 of 44 01/14/17
4. To view the Patch Download scheduled task: a. Click Home--- Scheduled Tasks. Page 5 of 44 01/14/17
Illustrate Update Manager Update Download Schedule Tasks. Notes: To manually run this task, right-click the task and click Run. When running the task, you see Download Patch Definitions task in the Recent Tasks. 2.2. ESXI Hosting Patching and Upgrade Procedure. This section will provide how to patch ESXI Host patching and Upgrade. 1. Prerequisite. a. Make sure all Virtual Machine reside on the ESXI host are powered off or vacated (Vmotion migrate) prior performing Patching and Upgrades. b. Turn off vsphere HA- i. Go to Hosts and Clusters- Edit Settings Page 6 of 44 01/14/17
ii. Uncheck both Turn On vsphere HA/DRS-Click Ok. Page 7 of 44 01/14/17
c. ESXI Host Put Host in Maintenance Mode. i. Click Yes Prompt. ii. If there any Virtual Machine powered up and DRS is enabled- Below Warring Message will pop up Click Ok. Page 8 of 44 01/14/17
iii. ESXI Host will go show in Recent Task- Enter Maintenance Mode. Status % 2. Click Home > Hosts and Clusters-- Highlight the ESX host you want to update and click the Update Manager tab. Page 9 of 44 01/14/17
3. To scan the ESX host for missing patches against the repository, right-click on the ESX host and click Scan for Updates > Patches and Extensions > Scan. 4. Confirm Scan- Check both Patches and Extensions Click Scan *Recent task will show Scan Entity Status on ESXI host. Page 10 of 44 01/14/17
Once Scan Entity completes- The Update Manager Complaint Status will illustrate on Right 5. Attach. Select Critical Host Patches and Non-Critical Host Patches baselines and click Attach. Page 11 of 44 01/14/17
6. Click Create baselines under Individual Baselines by type. *you create a Baseline Groups also- for this demonstration, will use individual Baselines by type.. 7. Baseline Name and Type- Input the below values- Click Next. Name: For example, ESXI Host Baseline 01/2017 Patching. Description: this is an example of ESXI host Baseline patching for ESXI host. Select Host Patching. * repeat same steps for Host Extension, Host Upgrade,etc. Page 12 of 44 01/14/17
8. Select Dynamic Dynamic baseline are updated when new patches meeting the specified criteria are added to the repository. 9. Select Default- Any.-Click Next. Page 13 of 44 01/14/17
10. Patches to Exclude-Keep Default. Click Next. *you can select specific patch and click down arrow if there any patches to be excluded. 11. Additional Patches- Click Next. To Proceed. Page 14 of 44 01/14/17
12. Ready To Complete- Click Plus + under Patches to view patches matching criteria currently in the repository. 13. Click Finish Page 15 of 44 01/14/17
14. Newly Individual Baselines by Type- Created- Patch Baselines. Click box ESXI- BaselineJan2017 15. Click Attached. To Attached newly ESXI Baseline Jan2017 Patches Page 16 of 44 01/14/17
On Update Manager Baseline Compliant will show NON-Complaint Above example, shows there 59 Patches are available to apply. Click Detail to get more information. Page 17 of 44 01/14/17
Illustration of Patch Details. 16. Click Stage on right bottom to stage Patches to ESXI host. Page 18 of 44 01/14/17
17. Stage Wizard- Keep Default- Click Next. 18. Patch and Extension Exclusion- Click Next. Page 19 of 44 01/14/17
19. Ready to Complete Click Finish *You will noticed there Stage patching to enitity status under Recent Task Window-% Page 20 of 44 01/14/17
Once it shows complete-click Remediate- 20. Click Remediate- To remediate the missing patches to the ESXI host: 21. Remediation Selection- Click Next. Page 21 of 44 01/14/17
22. Patches and Extensions-Illustrate Patches will be applied to ESXI Host.-Click Next. 23. Schedule Keep default- and Click Next. *Immediately Page 22 of 44 01/14/17
24. Host Remediation Options. Keep Default -Click Next. *check box-retry entering maintenance mode in case failure. 25. Cluster Remediation Options.-Keep Default Click Next. Page 23 of 44 01/14/17
26. Ready To Complete- Keep Default- Click Finish- *Remediate Entity Status Will Show Up Under Recent Task Complete % - *Check, Install, Reboot ESXI Host. Remediate progress is shown by the Remediate Entity task in the Recent Tasks. This task might take some time as Update Manager starts downloading patches from vmware.com. Once ESXI host completes the reboot the remediation task should have completed. Page 24 of 44 01/14/17
27. Validate Update Manager Patch Tasks Completed Successfully- a. Go Home-- Hosts and Cluster - Select ESXI host - Go to Update Manager Tab- Notice the version of ESXI, 6.0.0 is now 4600944 and Host Compliance is Green Status. Notes: *If the scan fails, ensure that the ports between Update Manager and the ESX host are open. For more information, see VMware Update Manager network port requirements (1004543). *When the scan is complete you see the number of patches missing on the ESX host. If no patches are missing, you see Compliant. *If the remediation fails, ensure the ports between Update Manager, the ESX host, and vmware.com are open. For more information, see VMware Update Manager network port requirements (1004543). Page 25 of 44 01/14/17
28. Patching ESXI Host via PowerCLI due to patching method is not working.(optional) 1. Prerequisite steps pre ESXi host patching a. Put host in Maintenance Mode. b. Download ESXI 6.0.0-2016111001 Build Number 41600944 from Vmware c. Extract ESXI-600.2016111001 to upload to Datastore. Page 26 of 44 01/14/17
d. Upload to Datastore- GoESXI - Configuration- Storage-Browse Datastore Page 27 of 44 01/14/17
e. Click Browse Datastore f. Upload Folder- g. Click Ok. Page 28 of 44 01/14/17
h. Click Yes. *upload status UI. i. Identify the VMFS directory where - by ssh into the ESXI Host. /vmfs/volumes/15836bd4-6540c405/esxi600-201611001/metadata.zip Page 29 of 44 01/14/17
2. Open Powercli Command Line to log into Vcenter or ESXI. a.. Log into the Host level via Powercli. Type - connect-viserver < ESXI host address/fqdn/ip> i.e. mvp-vs01.mcp.local Connect-viserver mvp-vs01.mcp.local. b. Get Prompt User and Password. Input vcenter or ESXI user ID and password Page 30 of 44 01/14/17
*successful log into ESXI host level via powercli *if you recall the ESXI.6.0.0 Update 2 was upload to Datastore SAN05 c. Run the follow command, install-vmhostpatch HostPath /vmfs/volumes/15836bd4-6540c405/esxi600-201611001/metadata.zip Page 31 of 44 01/14/17
d. Scroll to the top to validate ESXI 6.0.0. Update 2 upgrade had completed. e. Scroll back down to command prompt and type restart ESXI host by typing following command. Restart-VMhost. f. Confirm Restart of ESXI Host- Type Y- Page 32 of 44 01/14/17
3. End Result of ESXI Version Level 29. Post Patching Tasks- Take ESXI host out of Maintenance Mode and Enable Cluster HA and DRS. 1. Select ESXI Host ---Right Click - Exit Maintenance Mode- 2. Exit Maintenance Mode Status-Recent Task- Will See Task Message Exiting Maintenance Mode. Page 33 of 44 01/14/17
3. Go to Datacenter- Clusters-- Edit Settings 4. Turn On- HA and DRS by Click on both checkboxes for HA and DRS *vsphere HA agent reinitialize status message will show up under Recent Tasks. Page 34 of 44 01/14/17
This should complete the ESXI Host Level Patching and Upgrade Procedures via Update Manager(). 2.2 Guest OS Patching This section will show how to leverage to patch and updates to Guest OS Virtual Machines. 1.Go to Home- VMs and Templates- Update Manager. Tab. Page 35 of 44 01/14/17
2. Create a Baseline- Click Scan- 3. Confirm Scan- Keep Default- Virtual Appliance upgrades, VMware Tools updates, VM Hardware upgrades. Click Scan- *Scan Status Under Recent Task- will get a scan entity 4. Click Attach Page 36 of 44 01/14/17
5. Attached Baseline or Group-Check both VMware Tools Upgrade and VM hardware. Check boxes-click Attached. Page 37 of 44 01/14/17
6. VM/VA Compliance-Status- Will Show Status how patches are out of compliance 7. Click Remediate- To Apply Patch to VM or VA Appliance Page 38 of 44 01/14/17
8. Remediation Selection-Keep Default and Click Next. 9. Schedule- Keep Default- Click Next. Page 39 of 44 01/14/17
10. Rollback Options- Keep Default- Click Next. *you have option to create a snapshot to VM before applying patch to VM. 11. Ready To Complete- Click Finish This will conclude the Guest OS VM patching via Update Manager(). Page 40 of 44 01/14/17
3 Reference 3.1 Updating an ESXi/ESX host using VMware vcenter Update Manager 4x,5x,and 6x. https://kb.vmware.com/selfservice/microsites/search.do?language=en_us& cmd=displaykc&externalid=1019545 3.2 Administration Guide. http://www.vmware.com/pdf/vi3_vum_10_admin_guide.pdf 3.3 ESXI Patching via PowerCli https://www.vmware.com/support/developer/powercli/powercli41u 1/html/Install-VMHostPatch.html 3.4 ESXI600.-201611001- Build Number 4600944 https://my.vmware.com/group/vmware/patch?clickid=cf44fs74kvskx fn4la7lesxplzf4n7xqenea#search Page 41 of 44 01/14/17
Page 42 of 44 01/14/17