Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Adding member to cluster from remote location

This thread has been viewed 1 times
  • 1.  Adding member to cluster from remote location

    Posted Sep 18, 2015 07:17 AM

    Hi,

     

    We are looking at adding a new member to our existing cluster.
    The existing cluster is made up of two CPPM servers running version 6.4.5.71725. We intend to upgrade before adding the new subscriber.

     

    The new subscriber will be from our office located in China. We have a direct VPN connection to this office with around 300ms response time.

     

    I am just wondering if there are any challenges that we might face? Is there anything special we need to do to ensure the success of this new CPPM joining the existing cluster? Will the latency pose any major issues?

     

    Thank you,

     

    Cheers



  • 2.  RE: Adding member to cluster from remote location
    Best Answer

    EMPLOYEE
    Posted Sep 18, 2015 09:14 AM

    It should be fine.  These are the ports that the cluster communicates on.

     

    • TCP Port 80 HTTP (Between Nodes)
    • UDP Port 123 NTP (Subscriber to publisher)
    • TCP Port 443 HTTPS (Bi-directional)
    • TCP Port 4231 NetWatch (Post Authentication module and the node where Insight is enabled)
    • TCP Port 5432 PostgreSQL for DB replication (Subscriber to publisher)


  • 3.  RE: Adding member to cluster from remote location

    Posted Sep 18, 2015 09:46 AM

    Thanks @SethFiermonti

     

    Much appreciated.

     

    Am I correct in assuming that the licensing still works the same with the CPPM clustering. Where all the licenses are shared amongt the individual CPPM servers? We will be purchasing a new CPPM license for the new subscriber, but will be sharing our current pool of Onboard and Guest licenses.



  • 4.  RE: Adding member to cluster from remote location

    Posted Oct 19, 2015 01:48 PM

    correct the base licenses are per unit, they are also related to the chosen unit, i.e. CP-500, 500 of them.

     

    the other licenses are shared within the cluster.



  • 5.  RE: Adding member to cluster from remote location

    Posted Oct 20, 2015 11:10 AM

    Thanks @boneyard for the confirmation!