IBM Security Guardium

 View Only
  • 1.  Guardium Failover test with Backup CM

    Posted Wed February 10, 2021 07:07 AM
    Hi Everyone,

    Is it possible to promote Backup CM as a Primary CM for failover testing and again shall we revert it?
    Here are some doubts about above question:

    1. Is it possible without making down Primary CM to promote Backup as Primary one?
    2. If at all Backup CM is promoted as Primary without making Primary CM down, does Primary CM becomes Backup CM temporarily?
    3. If we need to revert again to original state, how can it happen?

    Thanks,
    Panendar Rao.C

    ------------------------------
    PHANENDRA RAO CHAVANA
    ------------------------------


  • 2.  RE: Guardium Failover test with Backup CM

    Posted Wed February 10, 2021 04:15 PM
    1. Yes, you can promote the backup CM to primary CM regardless if the original primary CM is down or not.
    2 & 3: In order for your original primary CM to become a backup CM, you need to register and designate it as a backup CM. Then after your test, you can promote it back to primary CM.
     
    Please refer to the Central Manager Redundancy section in the Knowledge Center for details on the steps. (Note: You can easily switch to the Guardium version you use)


    ------------------------------
    Leila Johannesen
    ------------------------------



  • 3.  RE: Guardium Failover test with Backup CM

    Posted Thu February 11, 2021 04:30 AM

    Hi,

    Switching to Backup CM works smoothly for small test environment - the test in lab is not this same as execution this procedure on production env.

    I strongly suggest do not do that for large production environment. In this case the process can take hours or more.

    Even IBM support suggests to restore the failed primary CM using backup than simple switch to the Backup CM.

    Backup CM should be promoted to primary role if there is no possibility to restore original primary CM in the reasonable time.

    Be aware that temporary unavailability of primary CM does not interrupt events gathering.



    ------------------------------
    Zbigniew (Zibi) Szmigiero
    IBM
    Międzyrzecz
    ------------------------------



  • 4.  RE: Guardium Failover test with Backup CM

    Posted Tue January 03, 2023 04:45 AM
    Hi Zibi.
    We need to migrate our current Guardium infrastructure (about 50 virtual appliances, 11.4) to new virtual infrastructure and core network (IP addresses of appliances will change). Our initial plan is to deploy backup CM to new infrastructure and promote it. Then move other managed units over to new infrastructure, by changing IP address. Of cause this is very simplified description. But main focus for the discussion is use of backup CM. 
    Now reading your recommendation I started to doubt if use of CM HA configuration would be good idea for such transition. Any comments?

    ------------------------------
    Taavi Kainel
    ------------------------------



  • 5.  RE: Guardium Failover test with Backup CM

    Posted Tue January 03, 2023 07:45 AM

    Hi Taavi,
    Your migration procedure makes sense. I stressed in my article to do not use CM backup for short time switch in case on primary CM unavailability and large envuronments.



    ------------------------------
    Zbigniew (Zibi) Szmigiero
    IBM
    Międzyrzecz
    ------------------------------



  • 6.  RE: Guardium Failover test with Backup CM

    Posted Thu February 11, 2021 04:36 AM

    In addition to my previous message:

    1. Is it possible without making down Primary CM to promote Backup as Primary one?

    No, if Primary CM is operational during this procedure, it will be removed from current GDP configuration


    2. If at all Backup CM is promoted as Primary without making Primary CM down, does Primary CM becomes Backup CM temporarily?

    No, you need clean up it to standard aggregator using "store unit type standalone"


    3. If we need to revert again to original state, how can it happen?

    a) you need add old CM working as standalone to existing GDP infra

    b) promote it as backup CM

    c) promote it again as primary one

    here my article about this:

    https://guardiumnotes.wordpress.com/2016/05/22/central-manager-in-ha-configuration/



    ------------------------------
    Zbigniew (Zibi) Szmigiero
    IBM
    Międzyrzecz
    ------------------------------