IBM QRadar

IBM QRadar

Join this online user group to communicate across Security product users and IBM experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.

 View Only
  • 1.  HA pair - bonding also on crossover interface

    Posted 9 days ago

    Hello,

    we're going to deploy an HA pair on two physical DELL Servers, each one has 4 physical NICs.

    Our customer wants to create interface bonding both on management\data NIC (and this is quite straightforward) but also on the crossover link between the two servers that will be used for storage synchronization once HA is in place. Is this feasible and how can we do this when creating HA?

    Another question, the bonding of two NICs is active\passive (only one at a time is active) or is configured in LACP style, e.g. load balancing traffic?

    B Regards,

    Davide



    ------------------------------
    Davide Salardi
    ------------------------------


  • 2.  RE: HA pair - bonding also on crossover interface

    Posted 8 days ago

    Yes, you can create a bonded crossover connection between HA hosts. When you create HA you need to select which interface would you like to use. If you select more than one interface (pressing shift or ctrl together while clicking on the GUI) it will create a bond. 

    But i think there is not possible to add special bond parameters here like LACP option. The workaround we use was the following:

    1. configure network devices to work without LACP
    2. create a HA pair with bonded interfaces and wait until is finish successfully
    3. modify the network device configuration to use the required LACP and in same time configure LACP in /etc/sysconfig/network-scripts/ for the crossover bond on both HA pair in command line
    4. restart the bonded interfaces on both HA pair and check the HA status with /opt/qradar/ha/bin/ha cstate

    I'm not sure it is supported by IBM but it worked for me.



    ------------------------------
    Tamás Simon
    ------------------------------



  • 3.  RE: HA pair - bonding also on crossover interface

    Posted 8 days ago

    Thanks Tamas, LACP is not really needed but our customer wanted to know which type of bonding would be done, I think active\passive is fine.

    I won't be able to try this configuration soon because physical servers are still not ready, once they will I'll apply this configuration and might update this post.

    Davide



    ------------------------------
    Davide Salardi
    ------------------------------