HDR with CMs in proxy mode
Posted in 2014
Topics: High Availability & Replication, Server Administration, Clustering, Grid & MACH11
Good morning.
I'm trying to create a read only environment for aplication support group
based on a HDR pair. This is an easy task, but the problem comes when I must
do it across two connection manager instances, due to a three level security
requirements (firewalls between servers).
Must connect ifx_pri to CM1, CM1 to CM2, and finally, CM2 to ifx_sec (which
will be read only).
Should be SLA MODE=proxy the answer? Does anybody know where can I get
documentation about this issue?
And one more question: common way to start HDR is "onmode -d primary ifx_sec"
on primary server, copy DB to secondary and "onmode -d secondary ifx_pri". But
ifx_pri and ifx_sec does not have direct connection.
Any help will be welcome.
Thanks in advance.
Proxy mode can be used to make clients access servers without direct
connection being possible.
CM would be in the DMZ...
But you want to use 2... I doubt that was ever considered in the design....
CM chaining... I never tried it, and I'd doubt that works or is supported...
Regarding your other question:
1- The commands should be given after the backup/restore
2- A primary server needs to have access to the secondary servers and
vice-versa...
Your setup requirements seem very weird... Typically the databases are in
the "protected" or internal network... Having them on networks which are
not accessible from each other was never in the design... Again some sort
of "proxy" would be required. But for that there are solutions on the
network layer:
1- VPNs
2- NAT
3- Customization of firewall rules
On the Informix side you can also turn on encryption for the replication.
With it you can even use Internet as the link between servers...
Regards
On Fri, Oct 17, 2014 at 1:34 PM, RAFAEL GOMEZ <rgomezs@gmail.com> wrote:
> Good morning.
>
> I'm trying to create a read only environment for aplication support group
> based on a HDR pair. This is an easy task, but the problem comes when I
> must
> do it across two connection manager instances, due to a three level
> security
> requirements (firewalls between servers).
>
> Must connect ifx_pri to CM1, CM1 to CM2, and finally, CM2 to ifx_sec (which
> will be read only).
>
> Should be SLA MODE=proxy the answer? Does anybody know where can I get
> documentation about this issue?
>
> And one more question: common way to start HDR is "onmode -d primary
> ifx_sec"
> on primary server, copy DB to secondary and "onmode -d secondary ifx_pri".
> But
> ifx_pri and ifx_sec does not have direct connection.
>
> Any help will be welcome.
>
> Thanks in advance.
>
>
>
>
*******************************************************************************
> Forum Note: Use "Reply" to post a response in the discussion forum.
>
>
--
Fernando Nunes
Portugal
http://informix-technology.blogspot.com
My email works... but I don't check it frequently...
--001a1140eb2088eb9b0505a74d26
Hi Fernando.
Thanks for your answer.
I know my environment is quite weird but it's imposed by managers, not my
desing.
We have some IDS's working, and now we have to make new servers in a three
isolated layer architecture: external layer for clients, intermediate layer
for app. servers (Tuxedo, Weblogic, Tomcat...), and internal layer for BD
servers (Informix, Oracle, SQL Srv and MySQL).
Old servers are outside this schema and I have to configura HDR between one
old server and a new one in the internal layer. Only comunications allowed
are: outside-extermal, external-intermediate and intermediate internal.
So I was trying to place a first CM in external layer to grant access from old
IDS's to intermediate layer, and a second CM in intermediate layer to give
acces to new IDS in internal.
At this moment, CM1 connects to ids_pri and CM2 connects to ids_sec. But I
can't get connencted both CM's and CM1-CM2 doesn't make "bridge" between
ids_pri and ids_sec.
About backup in HDR, I'm using piped backup to load secondary server, so this
backup-restore is executed betwwen "onmode -d primary..." and "onmode -d
secondary...", it's easier an faster in my opinion.
A manager said it's feasible in Oracle and it's working by now (he's an Oracle
man), and I bite the bait... ;)
HDR primary and secondary have to talk to each other, CM can't be in the
middle, not even in proxy mode.
Art
Art S. Kagel, President and Principal Consultant
ASK Database Management
www.askdbmgt.com
Blog: http://informix-myview.blogspot.com/
Disclaimer: Please keep in mind that my own opinions are my own opinions
and do not reflect on the IIUG, nor any other organization with which I am
associated either explicitly, implicitly, or by inference. Neither do
those opinions reflect those of other individuals affiliated with any
entity with which I am affiliated nor those of the entities themselves.
On Mon, Oct 20, 2014 at 3:49 AM, RAFAEL GOMEZ <rgomezs@gmail.com> wrote:
> Hi Fernando.
>
> Thanks for your answer.
>
> I know my environment is quite weird but it's imposed by managers, not my
> desing.
>
> We have some IDS's working, and now we have to make new servers in a three
> isolated layer architecture: external layer for clients, intermediate layer
> for app. servers (Tuxedo, Weblogic, Tomcat...), and internal layer for BD
> servers (Informix, Oracle, SQL Srv and MySQL).
>
> Old servers are outside this schema and I have to configura HDR between one
> old server and a new one in the internal layer. Only comunications allowed
> are: outside-extermal, external-intermediate and intermediate internal.
>
> So I was trying to place a first CM in external layer to grant access from
> old
> IDS's to intermediate layer, and a second CM in intermediate layer to give
> acces to new IDS in internal.
>
> At this moment, CM1 connects to ids_pri and CM2 connects to ids_sec. But I
> can't get connencted both CM's and CM1-CM2 doesn't make "bridge" between
> ids_pri and ids_sec.
>
> About backup in HDR, I'm using piped backup to load secondary server, so
> this
> backup-restore is executed betwwen "onmode -d primary..." and "onmode -d
> secondary...", it's easier an faster in my opinion.
>
> A manager said it's feasible in Oracle and it's working by now (he's an
> Oracle
> man), and I bite the bait... ;)
>
>
>
>
*******************************************************************************
> Forum Note: Use "Reply" to post a response in the discussion forum.
>
>
--089e0160b3bafd056a0505d87b0f