This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Migrate one SG UTM in an HA Pair to a Different Datacenter

Hello,

We have two SG software appliances (HP DL360 Gen9 servers) running at version 9.716-2 in an HA pair in the same datacenter. Their HA connection is an Ethernet cable directly linking Eth0 on both servers. 

We're looking to move one of the pair to a separate datacentre about 20 miles away. The datacenters are connected with redundant 10G circuits. The Internet breakout is BGP based so it can "exit" from either datacenter. All VLANs are "stretched" between the two datacenters. Jumbo frames is enabled end-to-end. So, in terms of network  topology I think we're ok.

My question is more around what would be the best way to perform the migration of the SLAVE to the other datacenter.

Can we just power down the SLAVE, unpatch the HA cable, move the SLAVE to the 2nd datacenter and patch in the HA interface (Eth0) at both sites to switch ports on the same VLAN. The migrated server's Outside and Inside ports would of course be patched to switch ports with the same VLANs defined for the equivalent ports used by the MASTER's Outside and Inside interfaces. And then power on the SLAVE. Is that likely to work?

Or would it be recommended to break the HA which will factory reset the SLAVE, migrate that server to the new datacenter, patch it in, perform a basic installation, upgrade to the matching version (9.716-2) and then re-establish HA?

Any advice will be welcome!

Ross



This thread was automatically locked due to age.
  • Looks, as your setup should work.
    i#ve built (and repaired/replaced) stretched clusters multiple times.
    i would shut down the slave, and reconnect only the HA-link at the new location.
    If the cluster looks good, you may connect the other ports.


    Dirk

    Systema Gesellschaft für angewandte Datentechnik mbH  // Sophos Platinum Partner
    Sophos Solution Partner since 2003
    If a post solves your question, click the 'Verify Answer' link at this post.

  • Hi Dirk,

    Thanks for you reply/information. Good to have some advice from someone who has "been there, done that". I'll follow your approach and report back the result. Will probably be in a few weeks time.

    Ross