Symantec Privileged Access Management

 View Only
  • 1.  Do I need VIP if each site only has one node

    Posted Mar 16, 2020 11:11 AM
    Hi team

    Currently have a cluster of 4 PAM nodes and running PAM 3.2. The nodes are in two different data centers about 200 km apart.

    We are upgrading to PAM 3.3, and I know that In PAM 3.3, we need to have an odd number of nodes per site. So we are planning on having 4 sites with one node per site.

    The current PAM cluster is configured with a VIP. This is not used by end users. End users either go directly to a specific node, or they access via an external load balancer, which forwards requests directly to the individual nodes. 

    I read in the documentation that:
    "We recommend always using a VIP. If a site has only one member, the VIP is not required.
    However, if the site has more members, or if you plan to add members later, then a virtual IP is required."

    Is this still correct?
    Is it OK to have 4 sites with one node per site and no VIPs?
    Users will continue to access via the external load balancer,

    Thanks

    Pearse


  • 2.  RE: Do I need VIP if each site only has one node
    Best Answer

    Broadcom Employee
    Posted Mar 16, 2020 11:33 AM

    Hello Pearse,

     

    Yes – this is correct in 3.3 – the Cluster Configuration GUI will not allow to configure a site with more than one node without VIP

    I am uncertain what happens when you do the upgrade without meeting this requirement – I guess the cluster will not start.

    Better reconfigure the cluster accordingly before doing the upgrade.

     

    Regards,

    Andreas