Security

last person joined: 22 hours ago 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Cluster VIP and Preempt

This thread has been viewed 11 times
  • 1.  Cluster VIP and Preempt

    Posted Nov 30, 2016 11:42 AM

    Hi

     

    I have two nodes want to configure them as primary and secondary cluster, so;

    -can I configure VIP floating between the two nodes (active in primary)?

    - if VIP is supported, then is it recommended to configure it or keep each node with different IPs?

    - Is there a preempt option in cluster, that the primary (publisher) will be the primary whenever its active?

     

    Thanks



  • 2.  RE: Cluster VIP and Preempt

    EMPLOYEE
    Posted Nov 30, 2016 05:00 PM


  • 3.  RE: Cluster VIP and Preempt

    Posted Dec 01, 2016 03:21 AM

    Hi

     

    There is no much details in documnet about the VIP and how to create it, and preempt too...

    I doont know which will be better from design perspective, use different IP in each node, or use the VIP "what is the pros and cons for both"



  • 4.  RE: Cluster VIP and Preempt
    Best Answer

    Posted Dec 01, 2016 09:13 AM

    To create the VIP and select the Primary and Back Node (Need to be in the same Layer 2 subnet):

    2016-12-01 09_08_42-ClearPass Policy Manager - Aruba Networks.png

     

    Preemption:

    2016-12-01 09_08_42-ClearPass Policy Manager - Aruba Networks.png

    You can use the Technote tim provided to follow the best practices when setting up a cluster with a VIP



  • 5.  RE: Cluster VIP and Preempt

    Posted Dec 01, 2016 09:29 AM

    But how to configure the VIP and what is the differences between using VIP and separate IP for each node (pros and cons for each), or lets say what are the limitations for each...



  • 6.  RE: Cluster VIP and Preempt

    Posted Dec 02, 2016 10:43 PM

    Did you take a look at the user-guide?

     

    To config the VIP the nodes MUST also have a separate IP address per interface of their own.