Desktop Support Advanced Virtual Desktop Initiative Rick Downs and Jim Jokl University of Virginia June 2011 CSG Meeting
Virtual Desktop History at UVa The Hive: Virtualized Public Computer Labs The State fiscal situation worsens as physical computing labs enter a replacement phase Two years of experience in production server virtualization led to thinking of virtualization as a potential solution Increasing demand for more classroom/other space Statistics reveal computing labs have low use for specialized applications Can we deliver a more useful service to students and save some money?
Virtual Desktop History at UVa The Hive : Virtualized Public Computer Labs Software delivery to the student for computing labs and classrooms via a virtual Windows desktop Eliminates physical desktop, support, and maintenance Creates a dynamic mobile computing environment Frees up physical space for other needs Decreased overall cost
Virtual Desktop History at UVa The Hive : Virtualized Public Computer Labs The Hive has been a significant success Students enjoy access to specialized software from many locations, dorm rooms, home on break, etc. Question: can we easily leverage this technology for standard administrative desktops?
We have all tried the thin client approach many times in the past and we don t see a lot of use. What is special this time around?
Project Charter Create a cost recovery service for departments Build solution leveraging work done for The Hive Develop in partnership with departmental staff Pilot and deploy if successful
Project Goals Reduce TCO Departmental staff time for physical desktop maintenance Thin client support Pre-configured software images Enhance security Patching, updates, backups, and configuration Enable Mobility Your desktop and files from anywhere Nice ipad client available
Departmental Participation LSPs (local technical support partners) participate in the product development cycle LSP input into the build configuration LSP input into standard software Departments via their LSPs actively participate in shaping the outcome Much energy from our College, Physics, our Foundation, Alumni group, Libraries, others, as we started the development work
Virtual Client Security User is not a workstation administrator Group policy enforced Windows and software configuration (Internet Explorer, for example) The workstation image can be updated nightly as necessary Enforced critical updates, antivirus updates and filters against known bad packages
VMWare Platform Security By necessity this platform is more open than our virtualized server environment Protect the hosts and vcenter by a separate firewall, limit access as much as possible Protect the Broker by separate firewall interface Implement the clients on a secure network, VPN protected for remote use
Virtual Computing for Staff VM Linked Clone Pool VM s Running on Hosts VM1 VM2 VM4 VM5 VM7 VM8 VM10 VM11 VM1, VM2,VM3, VM4 VM3 Virtual Center 4.1 Running View Composer (VM) VM6 VM9 VMn Link Aggregated vlan Trunked Switch Stack ESX 4.1 Host 1 Dell R710 VM5, VM6,VM7, VM8 Netapp 6040 Link Aggregated vlan Trunked Switch Stack Firewall Broker Traffic to vcenter Client Directed to Pool Via Broker View 4.5 Broker (VM) Virtual Center / Vmotion / VM Traffic ESX 4.1 Host 2 Dell R710 VM9, VM10,VM11, VMn NFS Storage Traffic VM s Stored on Netapps Intranet Internet ESX 4.1 Host 3 Dell R710 Netapp 6040 Client 1 Client 2 Client n VPN NetworkTraffic Private VCenter / Vmotion Network 1 Traffic Client 1 Client 2 Client n UVa Advanced Virtual Desktop Infrastructure Private VCenter / Vmotion Network 2 Traffic Private Storage Network 1 Traffic Private Storage Network 2 Traffic
AVD Demo
AVD Demo
Where are we now? Technical success Runs well on low-end user hardware Fast response; even on slower networks Nearly ready for production; in pilot mode But, few groups committing to the service Lack of end user administrative control Its not free (savings are soft, not recoverable) To date, one small department, without a lot of local support resources, wants to move forward
Marketing thoughts Is better marketing a solution? Focus more on mobility Your data and applications, secure From many devices, local and remote Handles backups, disaster recovery, security Rapid provisioning Expectation: will be quite popular if a large department or two move forward Policy considerations A proxy solution for access to sensitive data?