Balabit - High availability (site 1)
Balabit SCB Solution · Config document · referenced from High availability
The page Basic Settings > High availability of the site 1 cluster: the speed of the DRBD link, the heartbeat interfaces with the addresses of both nodes, and the next-hop address that both nodes ping. The page shows the node in datacenter A as "this node" and the node in datacenter B as "other node".
| Item | Value |
|---|---|
| Where | SCB web interface, Basic Settings > High availability |
| Cluster | dc1-s-xblb001; this node dc1-a-ablb001 (datacenter A), other node dc1-b-ablb001 (datacenter B) |
| Firmware at the time | 5 LTS (5.0.3) |
| Source | My design document, version 0.5 of 2017-12-01 (draft), chapter 7.2.24, "configuration from real implementation realized in production environment" |
| Not in it | The cluster status shown on the same page, the node names used by the HA software, any takeover test |
The answers
# Page / Field = value, as configured on dc1-s-xblb001, from the design document v0.5, chapter 7.2.24 High availability > DRBD / HA LINK SPEED, this node (Datacenter A) = Auto negotiation High availability > DRBD / HA LINK SPEED, other node (Datacenter B) = Auto negotiation High availability > INTERFACES FOR HEARTBEAT / HA INTERFACE, this node (Datacenter A) = Interface IP: 1.2.4.1 (FIX) / Gateway IP: High availability > INTERFACES FOR HEARTBEAT / HA INTERFACE, other node (Datacenter B) = Interface IP: 1.2.4.2 (FIX) / Gateway IP: High availability > INTERFACES FOR HEARTBEAT / PHYSICAL INTERFACE 1, this node (Datacenter A) = Interface IP: N/A / Gateway IP: N/A High availability > INTERFACES FOR HEARTBEAT / PHYSICAL INTERFACE 1, other node (Datacenter B) = Interface IP: N/A / Gateway IP: N/A High availability > INTERFACES FOR HEARTBEAT / PHYSICAL INTERFACE 2, this node (Datacenter A) = Interface IP: N/A / Gateway IP: N/A High availability > INTERFACES FOR HEARTBEAT / PHYSICAL INTERFACE 2, other node (Datacenter B) = Interface IP: N/A / Gateway IP: N/A High availability > INTERFACES FOR HEARTBEAT / PHYSICAL INTERFACE 3, this node (Datacenter A) = Interface IP: 10.11.18.209 / Gateway IP: High availability > INTERFACES FOR HEARTBEAT / PHYSICAL INTERFACE 3, other node (Datacenter B) = Interface IP: 10.11.18.210 / Gateway IP: High availability > NEXT HOP MONITORING / PHYSICAL INTERFACE 1, this node (Datacenter A) = Interface IP: N/A High availability > NEXT HOP MONITORING / PHYSICAL INTERFACE 1, other node (Datacenter B) = Interface IP: N/A High availability > NEXT HOP MONITORING / PHYSICAL INTERFACE 2, this node (Datacenter A) = Interface IP: N/A High availability > NEXT HOP MONITORING / PHYSICAL INTERFACE 2, other node (Datacenter B) = Interface IP: N/A High availability > NEXT HOP MONITORING / PHYSICAL INTERFACE 3, this node (Datacenter A) = Interface IP: 10.11.18.222 High availability > NEXT HOP MONITORING / PHYSICAL INTERFACE 3, other node (Datacenter B) = Interface IP: 10.11.18.222
The design explains the four parts of the page before its table; in short:
| Answer | What it means |
|---|---|
HA INTERFACE 1.2.4.1 (FIX), 1.2.4.2 (FIX) | Port 4, labelled HA, is reserved for the cluster: heartbeat and the DRBD synchronisation of all data. (FIX) is printed beside both addresses: they are the fixed HA addresses of the cluster link (the analysis sketch has them too); whether the appliance prescribes them, the design does not say; on the network side the port is an access port in VLAN 1016 |
PHYSICAL INTERFACE 3, 10.11.18.209 and 10.11.18.210 | The redundant heartbeat: a virtual interface on port 3 (VLAN 1018, network CLS2 10.11.18.208/28) that only tells each node that the other one is alive. No data is synchronised over it. The Gateway IP fields are empty, so the two nodes reach each other directly in the VLAN |
PHYSICAL INTERFACE 1 and 2, N/A | No redundant heartbeat on the in-band management or the production port |
NEXT HOP MONITORING, PHYSICAL INTERFACE 3, 10.11.18.222 | Both nodes ping 10.11.18.222; if the master cannot reach it and the slave can, the slave takes over even though the master is otherwise working. The address is in the CLS2 network 10.11.18.208/28, so it is reached over port 3; nothing is monitored on ports 1 and 2 |
The site 2 cluster has no redundant heartbeat configured at all; its state is in HA state of the site 2 cluster.
Checked against One Identity Safeguard for Privileged Sessions 9.0
| As built | Today |
|---|---|
| Master and slave node | Renamed primary and secondary node ("previously also referred to as the master node and the slave node"); the primary still shares all data with the secondary |
| HA interface on port 4 with fixed addresses | Port 4 (HA) is unchanged; the Welcome Wizard says to leave the HA address on auto unless the support team asks otherwise |
| Redundant heartbeat on physical interface 3, next-hop monitoring, takeover with gratuitous ARP | All three are unchanged features |
| Nodes in two datacenters, HA link through switches | "One Identity recommends a direct physical connection between the nodes" |
| Takeover | The 9.0 guide warns that the shift between the nodes might take 5 to 10 minutes and that connections are lost and not restored automatically |
The design of this page would carry over to SPS 9.0 almost word for word; the vendor now also states plainly what my design left open, that sessions are cut at a takeover.