cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
fw_mon
Reliable Contributor
Reliable Contributor
Report Inappropriate Content
Message 1 of 4

ATD/TIS Loadbalancing and High Availability with two hardware Appliances

Jump to solution

if I've understood the manual correctly, for HA/LB not just two but at least three appliances (better 4+) are required (please correct me if I'm wrong):

  • primary - holds the VIP, configuration, integrations and submissions run through this node
  • backup - Receives and analyzes samples. If the primary node fails, the backup node assumes the primary node responsibilities and cluster IP address
  • secondary (one or more) - Receives and analyzes samples

I consider it very ineffective.

With just two appliances are two variants possible, it doesn't make sense:

  • primary + backup, that provides HA VIP but only one scanning node
  • primary + secondary, that provides neigther HA nor LB

For those who have just two sandbox appliances, what is your setup? How you split the traffic, implement LB and HA?

BTW, the MWG MATD configuration accepts several ATD URLs, what if I configure both ATDs and implement some logic that only one appliance process the sample? How to consolidate allowlist, blocklist and reports?

I've considered putting two ATDs behind an external load balancer and apply API for allowlist, blocklist and reports, but then I found out that API can be used for checking only and only single hash value can be verified at a time.

 

Was my response useful to you? If so, please consider marking it as an Accepted Solution and giving it a Kudo to help other community members.
MWG+Splunk=❤
1 Solution

Accepted Solutions
hsadi
Employee
Employee
Report Inappropriate Content
Message 2 of 4

Re: ATD/TIS Loadbalancing and High Availability with two hardware Appliances

Jump to solution

Hi fw_mon

In a cluster environment the Primary also scans samples, so the logic is as follow

  • primary + backup, that provides HA VIP and LB, both nodes scan samples, primary has a mechanism to distribute the load equally between itself and the Backup
  • primary + secondary, it doesn't provide HA but LB will work, as explained above, so both nodes take samples as well.
  • So, if you want to have HA and LB i would recommend having a Primary and a Backup
  • If you just want LB only, then you could have the Primary and the Secondary, in this set up you don't need the VIP because there won't be HA, so you can use the Primary IP to achieve the LB.

For the half part of your question i would advise to submit the question to MWG support community.

Hope this helps.

View solution in original post

3 Replies
hsadi
Employee
Employee
Report Inappropriate Content
Message 2 of 4

Re: ATD/TIS Loadbalancing and High Availability with two hardware Appliances

Jump to solution

Hi fw_mon

In a cluster environment the Primary also scans samples, so the logic is as follow

  • primary + backup, that provides HA VIP and LB, both nodes scan samples, primary has a mechanism to distribute the load equally between itself and the Backup
  • primary + secondary, it doesn't provide HA but LB will work, as explained above, so both nodes take samples as well.
  • So, if you want to have HA and LB i would recommend having a Primary and a Backup
  • If you just want LB only, then you could have the Primary and the Secondary, in this set up you don't need the VIP because there won't be HA, so you can use the Primary IP to achieve the LB.

For the half part of your question i would advise to submit the question to MWG support community.

Hope this helps.

fw_mon
Reliable Contributor
Reliable Contributor
Report Inappropriate Content
Message 3 of 4

Re: ATD/TIS Loadbalancing and High Availability with two hardware Appliances

Jump to solution

thank you @hsadi for the explanation!

The description of the clustering in the product guide is very vague and need some rework.

Was my response useful to you? If so, please consider marking it as an Accepted Solution and giving it a Kudo to help other community members.
MWG+Splunk=❤
hsadi
Employee
Employee
Report Inappropriate Content
Message 4 of 4

Re: ATD/TIS Loadbalancing and High Availability with two hardware Appliances

Jump to solution

Hi fw_mon,

I will discuss this with engineering so they can enhance the quality of the product guide.

Best regards,

You Deserve an Award
Don't forget, when your helpful posts earn a kudos or get accepted as a solution you can unlock perks and badges. Those aren't the only badges, either. How many can you collect? Click here to learn more.

Community Help Hub

    New to the forums or need help finding your way around the forums? There's a whole hub of community resources to help you.

  • Find Forum FAQs
  • Learn How to Earn Badges
  • Ask for Help
Go to Community Help

Join the Community

    Thousands of customers use our Community for peer-to-peer and expert product support. Enjoy these benefits with a free membership:

  • Get helpful solutions from product experts.
  • Stay connected to product conversations that matter to you.
  • Participate in product groups led by employees.
Join the Community
Join the Community