12WS-PAS-Install-Vault Availabilty (Cluster)
12WS-PAS-Install-Vault Availabilty (Cluster)
Vault Availability
Cluster Vault
CyberArk Training
1
OBJECTIVES
2
VAULT AVAILABILITY OVERVIEW
3
VAULT AVAILABILITY SOLUTIONS
Replicate
COLD • Secure replication of encrypted data to a remote Windows server for tape
backup to an off-site facility
4
DISASTER RECOVERY
stand-by copy of a
DR
Production Vault on a Replication
CPM/PVWA/
• The DR-Vault can be PSM… Vault
DR
DC3
activated in the case of a
Replication
Disaster Recovery
situation either DC1
CPM/PVWA/
automatically or manually PSM…
DR
5
DISTRIBUTED VAULTS
• The Distributed Vaults (DV)
solution spreads the load DC4
from a single primary Vault
(Master) to multiple Satellite CPM/PVWA/
Vaults PSM…
AIM CPs Backend Processes
Replication
to another Vault, Satellite or
Master CPM/PVWA/
PSM…
• Since PAS version 11.3 up to DC2
5 satellite vaults can be
deployed Satellite Vault
(Primary Candidate)
6
DISTRIBUTED VAULTS ACTIVE-ACTIVE SERVICES
7
VAULT CLUSTER
accounts in the Vault. In this implementation, Cluster Vault (Passive Cluster Vault (Active Node)
there is always one Server that is on standby Node)
IP Public Network IP + VP
in case the other Server in the cluster fails IP Private Network IP
Shared Storage
Data + Metadata
8
CLUSTER VAULT ARCHITECTURE
9
HIGH AVAILABILITY ARCHITECTURE
Public Network
Storage Network
Shared Storage
10
CYBERARK CLUSTER VAULT MANAGER (CVM)
IP Private Network IP
• Database
• ENE (optional) IP Public Network IP + VIP
• PARAgent (optional)
• The active CVM will also monitor the status
of the remote passive CVM. Public Virtual IP
11
VIRTUAL IP
12
SHARED STORAGE
• Both nodes are connected to the shared storage but only the
active node is in “online status” and can read/write from/to
the disk.
13
QUORUM DISK
14
DETECTING A FAILURE
15
FAILOVER PROCESS
• The Cluster Vault service on the Passive node Active node: Check Passive node:
Changes to
will then reserve the shared resources, such as Failover then
Changes to
the VIP, Shared Storage and Quorum Disk. Active Mode
Passive Mode
16
CLUSTER VAULT MANAGEMENT
17
CLUSTER VAULT MANAGEMENT UTILITY – ACTIVE NODE
18
CLUSTER VAULT MANAGEMENT UTILITY – STANDBY NODE
19
MONITORED SERVICES
20
SIMULATING FAILOVER
• To Perform a switchover
test, open the CVM on the
Active Node of the cluster:
21
CYBERARK DIGITAL CLUSTER VAULT
SERVER INSTALLATION
(PREPARATION AND REQUIREMENTS)
22
PREPARE THE SERVERS
23
STORAGE PREREQUISITES
• Shared storage must support Persistent Reservation
24
PREPARE THE STORAGE
25
CLUSTER INSTALLATION
(INSTALL THE FIRST NODE)
26
INSTALL THE FIRST NODE – VAULT INSTALLATION MODE
27
INSTALL THE FIRST NODE – SAFES LOCATION
28
INSTALL THE FIRST NODE – OPERATOR CD PATH
29
INSTALL THE FIRST NODE – CONFIGURE STORAGE
• In an Administrators Command
Window, navigate to the
PrivateArk\Server\ClusterVault
directory.
30
INSTALL THE FIRST NODE – CONFIGURE CLUSTERVAULT.INI
31
INSTALL THE FIRST NODE – REBOOT
32
PREPARING FOR VAULT INSTALLATION
ON SECOND NODE
33
COPY ENCRYPTION KEYS TO SECOND NODE
• Use the same set of Operator
Keys that you used to install
the first node of the Cluster
Vault.
• Copy the additional keys
listed here, that were
generated during the
installation of the first node to
the same location in the
second node. These keys will
be created in the folder
containing the original
Operator Keys.
• Backup.key
• VaultUser.pass
• ReplicationUser.pass
• VaultEmergency.pass
34
STOP SERVICES ON FIRST NODE
35
SET SHARED DISKS TO OFFLINE ON FIRST NODE
• Use the Disk Management
utility to verify the shared
disks are offline on the first
node.
36
BRING SHARED DISKS ONLINE ON SECOND NODE
37
CLUSTER INSTALLATION
(INSTALL THE SECOND NODE)
38
INSTALL THE SECOND NODE – SAFES LOCATION
39
INSTALL THE SECOND NODE – VAULTID
40
INSTALL THE SECOND NODE – SERVER-ID
41
INSTALL THE SECOND NODE – CONFIGURE STORAGE
The disk identifiers must be
recorded in the ClusterVault.ini
file in the StorageIdentifier and
QuorumDiskIdentifier
parameters.
42
INSTALL THE SECOND NODE – CONFIGURE CLUSTERVAULT.INI
43
INSTALL THE SECOND NODE – REBOOT
44
CLUSTER VAULT LOGS
45
LOGS
• ClusterVaultConsole.log
• Cluster Vault log file
• ClusterVaultTrace.log
• Cluster Vault trace file
46
QUIZ
1. What are the 3 main types of Vault Availability?
• Cold = Replicate backup
• Warm = Disaster Recovery
• Hot = High Availability and Distributed Vaults
47
THANK YOU
48