
MarkTaber (Customer) to rsaSFDCadmin (RSA): asked a question.
Move Primary Instance from RSA 130 Authentication Manager Hardware Appliance to Hyper-V
I would like to find recommendations for the easiest way to move our primary
AM instance from RSA 130 hardware appliance to a hyper V image.
I have two scenarios listed below; but I am not sure which will be the least
problematic.
Any recommendations or suggestions are appreciated.
Our Current Configuration:
* Primary = RSA ver 8.6 Auth Mgr Hardware Appliance w/ IP 10.0.0.1 (example)
* Replica = RSA ver 8.6 Hyper-V (on different subnet) w/ IP 10.0.1.1 (example)
Required configuration change:
Need to shift the primary instance from RSA Auth Mgr hardware appliance
10.0.0.1 to a new hyper-V primary instance on the same subnet and decommission
the hardware appliance.
Scenario 1:
1. Create an additional Auth Mgr hyper-V instance as a **replica** on the same subnet as the Auth Mgr hardware appliance and assign IP 10.0.0.2
2. Attach the new Auth Mgr hyper-V **replica** to the current primary Auth Mgr hardware appliance.
3. Promote the new hyper-V replica to **primary** “for maintenance”.
4. Disconnect the original RSA Auth Mgr **primary** hardware appliance 10.0.0.1
5. Rename and assign IP 10.0.0.1 to the newly promoted hyper-V instance to match the disconnected hardware appliance.
6. Check to confirm tokens are updating correctly and the original Hyper-V replica 10.0.1.1 is still in sync with the newly promoted primary 10.0.0.1
Scenario 2:
1. Create a backup of the current RSA Auth Mgr primary hardware appliance 10.0.0.1
2. Save the image to a location outside of the hardware appliance.
3. Disconnect the current RSA Auth Mgr primary hardware appliance.
4. Create a new Auth Mgr hyper-V primary instance on the same subnet as the Auth Mgr hardware appliance and assign the same IP 10.0.0.1 and server name to match the original Auth Mgr hardware appliance.
5. Perform a restore operation on the new hyper-V primary instance.
6. Check to confirm tokens are updating correctly and the original Hyper-V replica 10.0.1.1 is still in sync with the newly created primary 10.0.0.1
Thanks in advance,
Mark
AM instance from RSA 130 hardware appliance to a hyper V image.
I have two scenarios listed below; but I am not sure which will be the least
problematic.
Any recommendations or suggestions are appreciated.
Our Current Configuration:
* Primary = RSA ver 8.6 Auth Mgr Hardware Appliance w/ IP 10.0.0.1 (example)
* Replica = RSA ver 8.6 Hyper-V (on different subnet) w/ IP 10.0.1.1 (example)
Required configuration change:
Need to shift the primary instance from RSA Auth Mgr hardware appliance
10.0.0.1 to a new hyper-V primary instance on the same subnet and decommission
the hardware appliance.
Scenario 1:
1. Create an additional Auth Mgr hyper-V instance as a **replica** on the same subnet as the Auth Mgr hardware appliance and assign IP 10.0.0.2
2. Attach the new Auth Mgr hyper-V **replica** to the current primary Auth Mgr hardware appliance.
3. Promote the new hyper-V replica to **primary** “for maintenance”.
4. Disconnect the original RSA Auth Mgr **primary** hardware appliance 10.0.0.1
5. Rename and assign IP 10.0.0.1 to the newly promoted hyper-V instance to match the disconnected hardware appliance.
6. Check to confirm tokens are updating correctly and the original Hyper-V replica 10.0.1.1 is still in sync with the newly promoted primary 10.0.0.1
Scenario 2:
1. Create a backup of the current RSA Auth Mgr primary hardware appliance 10.0.0.1
2. Save the image to a location outside of the hardware appliance.
3. Disconnect the current RSA Auth Mgr primary hardware appliance.
4. Create a new Auth Mgr hyper-V primary instance on the same subnet as the Auth Mgr hardware appliance and assign the same IP 10.0.0.1 and server name to match the original Auth Mgr hardware appliance.
5. Perform a restore operation on the new hyper-V primary instance.
6. Check to confirm tokens are updating correctly and the original Hyper-V replica 10.0.1.1 is still in sync with the newly created primary 10.0.0.1
Thanks in advance,
Mark
after the instance is built:
0\. Backup the Primary and checkpoint Replica VM.
1\. Promote existing Hyper-V Replica to Primary. (Hardware instance demotes
to a Replica instance). Checkpoint Replica VM.
2\. Remove hardware Replica from the architecture. (Only have one instance
now, the VM Primary).
3\. Create new Hyper-V instance using the old hardware's IP and hostname and
join this VM as a Replica instance.
4\. Promote this new Hyper-V Replica as the Primary (The older Hyper-V
instance is demoted back to Replica again).
5\. Test. If test fails, you should have enough backups and checkpoints to
try your Scenarios 1 and 2.