IBM QRadar

IBM QRadar

Join this online topic group to communicate across Security product users and IBM experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.


#Security
#QRadar
#SecuringhybridcloudandAI
 View Only
  • 1.  HA Implementation in two different data centres

    Posted 12/12/20 03:30 AM
    Hello, 

    Please I want to implement HA in two different data centers, I know that certain requirements need to be considers as listed below:
    1) same subnet :- in this case does it mean i need to create an IPsec VPN tunnel to establish network connectivity between site A and site B
    2) min of 1Gbps:-  should i consider something higher , say 5Gbps - 10Gbps
    3) Latency of ,< 2ms :-  should i consider something less say < 1ms

    And lastly , i am not clear on this. When HA  is eventually set up between these two sites, i known the contents in /Store and /transient on both QRadar systems becomes the same (equal), does this include custom rules, custom apps, custom saved searches. OR i will have to use the content management tool to import these security content into the new QRadar system (Secondary node).

    Thank You Team. I will really appreciate your response.

    ------------------------------
    benjamin Nworah
    ------------------------------


  • 2.  RE: HA Implementation in two different data centres

    Posted 12/12/20 06:33 AM
    The failover requires no content sync to have everything the node
    needs. Its is twice the hardware but i would implement HA locally in
    each data center and keep backups off site.


    Reason being if there is a localized datacenter loss or disaster, HA,
    especially if it's the secondary left standing is a pain for
    management and updates unless primary is active and secondary
    available and on standby.

    For DRBD sync Usually on HW I take one of those handy left over ports
    and fiber crossover the boxes. You probably want 10gb as anytime that
    IPSEC is down you have a resync ahead also.

    I have never done anything but local HA to ad more info about. I would
    shy away from it if it was my choice.




  • 3.  RE: HA Implementation in two different data centres

    Posted 12/12/20 10:02 AM
    Hello,

    Thank you for the response, but this is what i want to know:-

    The Question is how do i implement HA in two different data centers? do I set up an IPsec VPN, such that the ACL within the IPsec will be such that the VIP, primary IP, and the Secondary IP will be able to communicate with each other.??

    The Other question is that, when i pair HA, does the custom rules automatically get imported into the secondary or i will have to use the CMT tool to import these rules into the secondary node?

    Thank You.

    ------------------------------
    benjamin Nworah
    ------------------------------



  • 4.  RE: HA Implementation in two different data centres

    Posted 12/12/20 10:24 AM
    You would need the VIP-ip available in both datacenters to collect
    logs and be manageable by the console, you would require all of the
    minimum standards for the HA communication listed, and the content
    updates automatically there is nothing to do there. You also need the
    IP used for the HA communication to be presented as you described.

    on failover the collection IP the VIP moves as the host is going active.

    if the processor stack is managing wincollect agents, then port 8413
    should be considered as well for wincollect agents to follow the VIP
    successfully between datacenters.

    If your network can solve for the access, bandwidth and latency it is
    technically possible as much as it is not a solution I have ever
    implemented or would want to pursue personally.




  • 5.  RE: HA Implementation in two different data centres

    Posted 12/14/20 01:17 AM
    Hello Benjamin,

    as well as the minimum requirements you should consider this from the architectural perspective. What is your need? What is the goal you are trying to reach?

    What is the QRadar component you want to protect with HA?

    For example, if you are thinking at the Console, then all the MH must be able to reach the standby node; if your are thinking to the Event Processor, all the connected (ECs and DataNode) and all the sources must be able to reach the standby node in case of failover.

    The HA is intended to provide (locally) a component failure protection. If you are looking for other solution (Business Continuity, Disaster Recovery) I think the HA is not the right answer.

    Best regards,
    Mario

    ------------------------------
    Mario Sebastiani
    ------------------------------