LINUXOR.SK ... open source notes ...

Balabit - High availability (site 1)

category: solutionz · date: 2018-12-31 · updated: 2026-10-03 · author: LALA

Balabit SCB Solution · Config document · referenced from High availability

The page Basic Settings > High availability of the site 1 cluster: the speed of the DRBD link, the heartbeat interfaces with the addresses of both nodes, and the next-hop address that both nodes ping. The page shows the node in datacenter A as "this node" and the node in datacenter B as "other node".

ItemValue
WhereSCB web interface, Basic Settings > High availability
Clusterdc1-s-xblb001; this node dc1-a-ablb001 (datacenter A), other node dc1-b-ablb001 (datacenter B)
Firmware at the time5 LTS (5.0.3)
SourceMy design document, version 0.5 of 2017-12-01 (draft), chapter 7.2.24, "configuration from real implementation realized in production environment"
Not in itThe cluster status shown on the same page, the node names used by the HA software, any takeover test

The answers

ini
# Page / Field = value, as configured on dc1-s-xblb001, from the design document v0.5, chapter 7.2.24

High availability > DRBD / HA LINK SPEED, this node (Datacenter A) = Auto negotiation
High availability > DRBD / HA LINK SPEED, other node (Datacenter B) = Auto negotiation

High availability > INTERFACES FOR HEARTBEAT / HA INTERFACE, this node (Datacenter A) = Interface IP: 1.2.4.1 (FIX) / Gateway IP:
High availability > INTERFACES FOR HEARTBEAT / HA INTERFACE, other node (Datacenter B) = Interface IP: 1.2.4.2 (FIX) / Gateway IP:
High availability > INTERFACES FOR HEARTBEAT / PHYSICAL INTERFACE 1, this node (Datacenter A) = Interface IP: N/A / Gateway IP: N/A
High availability > INTERFACES FOR HEARTBEAT / PHYSICAL INTERFACE 1, other node (Datacenter B) = Interface IP: N/A / Gateway IP: N/A
High availability > INTERFACES FOR HEARTBEAT / PHYSICAL INTERFACE 2, this node (Datacenter A) = Interface IP: N/A / Gateway IP: N/A
High availability > INTERFACES FOR HEARTBEAT / PHYSICAL INTERFACE 2, other node (Datacenter B) = Interface IP: N/A / Gateway IP: N/A
High availability > INTERFACES FOR HEARTBEAT / PHYSICAL INTERFACE 3, this node (Datacenter A) = Interface IP: 10.11.18.209 / Gateway IP:
High availability > INTERFACES FOR HEARTBEAT / PHYSICAL INTERFACE 3, other node (Datacenter B) = Interface IP: 10.11.18.210 / Gateway IP:

High availability > NEXT HOP MONITORING / PHYSICAL INTERFACE 1, this node (Datacenter A) = Interface IP: N/A
High availability > NEXT HOP MONITORING / PHYSICAL INTERFACE 1, other node (Datacenter B) = Interface IP: N/A
High availability > NEXT HOP MONITORING / PHYSICAL INTERFACE 2, this node (Datacenter A) = Interface IP: N/A
High availability > NEXT HOP MONITORING / PHYSICAL INTERFACE 2, other node (Datacenter B) = Interface IP: N/A
High availability > NEXT HOP MONITORING / PHYSICAL INTERFACE 3, this node (Datacenter A) = Interface IP: 10.11.18.222
High availability > NEXT HOP MONITORING / PHYSICAL INTERFACE 3, other node (Datacenter B) = Interface IP: 10.11.18.222

The design explains the four parts of the page before its table; in short:

AnswerWhat it means
HA INTERFACE 1.2.4.1 (FIX), 1.2.4.2 (FIX)Port 4, labelled HA, is reserved for the cluster: heartbeat and the DRBD synchronisation of all data. (FIX) is printed beside both addresses: they are the fixed HA addresses of the cluster link (the analysis sketch has them too); whether the appliance prescribes them, the design does not say; on the network side the port is an access port in VLAN 1016
PHYSICAL INTERFACE 3, 10.11.18.209 and 10.11.18.210The redundant heartbeat: a virtual interface on port 3 (VLAN 1018, network CLS2 10.11.18.208/28) that only tells each node that the other one is alive. No data is synchronised over it. The Gateway IP fields are empty, so the two nodes reach each other directly in the VLAN
PHYSICAL INTERFACE 1 and 2, N/ANo redundant heartbeat on the in-band management or the production port
NEXT HOP MONITORING, PHYSICAL INTERFACE 3, 10.11.18.222Both nodes ping 10.11.18.222; if the master cannot reach it and the slave can, the slave takes over even though the master is otherwise working. The address is in the CLS2 network 10.11.18.208/28, so it is reached over port 3; nothing is monitored on ports 1 and 2

The site 2 cluster has no redundant heartbeat configured at all; its state is in HA state of the site 2 cluster.

Checked against One Identity Safeguard for Privileged Sessions 9.0

As builtToday
Master and slave nodeRenamed primary and secondary node ("previously also referred to as the master node and the slave node"); the primary still shares all data with the secondary
HA interface on port 4 with fixed addressesPort 4 (HA) is unchanged; the Welcome Wizard says to leave the HA address on auto unless the support team asks otherwise
Redundant heartbeat on physical interface 3, next-hop monitoring, takeover with gratuitous ARPAll three are unchanged features
Nodes in two datacenters, HA link through switches"One Identity recommends a direct physical connection between the nodes"
TakeoverThe 9.0 guide warns that the shift between the nodes might take 5 to 10 minutes and that connections are lost and not restored automatically

The design of this page would carry over to SPS 9.0 almost word for word; the vendor now also states plainly what my design left open, that sessions are cut at a takeover.

← solutionz