Physical locations of primary and replica instances

Page 118 of the RSA Authentication Manager 8.1 Administrator's Guide shows the following graphic:


I would like to install the Authentication Manager Primary Instance and LDAP Directory Server 1 in the Headquarters building, and the Secondary Instance and LDAP Directory Server 2 in the DR building, physically and geographically separated...then make the above connections.



Does this work? Does it make sense? I'm scared senseless that all of IT will be using a passcode with key fobs, and then AD turns to mush...and we can't get logged in to fix it. I'm hoping the above scenario will fix that?