Symantec Access Management

 View Only
  • 1.  CA Directory - Router DSA

    Posted Jul 13, 2018 09:17 AM

    Hello All,

     

    I am setting up CA Directory 14.0 as a Policy store.
    I would like to create a Router DSA which will route the Policy server requests to Data DSAs.
    1. How to configure data DSAs inside a router DSA using management console? i.e, How router DSA will understand that which DSAs will receive its requests.
    2. Can we configure router DSA to either Load balance or fail over the requests to data DSAs?
    3. While configuring the default Policy store objects, do we need to point each data DSA to the Policy server or only the router DSA?

    4. Does router DSA setup provide better performance than the data DSA setup? Any article/discussion link will be helpful

     

    Thanks,

    Pankaj



  • 2.  Re: CA Directory - Router DSA

    Broadcom Employee
    Posted Jul 13, 2018 11:38 AM

    This link will answer some of your questions:

    DSAs - CA Directory - 14.0 - CA Technologies Documentation 

     

    Also, here some more explanation:

    1. How to configure data DSAs inside a router DSA using management console? i.e, How router DSA will understand that which DSAs will receive its requests.

     - Once you have a Router and Data DSA created, go to the Router DSA in the Topology view within the Management UI, and click on Edit.

     - In the Edit mode, click on the 'Knowledge Group' tab, and on the left pan Window, you will see the available DSAs.

     - Here you will move the Data DSAs that you want the Router DSA to have knowledge of, to the right pane window.

     - By doing this you are give the Router DSA knowledge of the Data DSA's.

     

    1. Can we configure router DSA to either Load balance or fail over the requests to data DSAs?

     - By doing the above it essentially will act as a "Load Balancer".  This is because the Router DSA will always be aware of the status of it's Data DSAs.  So it will route the request to the best available Data DSA.

     

    1. While configuring the default Policy store objects, do we need to point each data DSA to the Policy server or only the router DSA?

     - Policy Store -> Router DSA

     - Router DSA -> Data DSA

     - Pointing the Router DSA to the Data DSA, is the configuration in the above item #1

     

    1. Does router DSA setup provide better performance than the data DSA setup? Any article/discussion link will be helpful

     - Yes, the Router DSA provides better reliability, because as mentioned it is always aware of the status of it's DSAs.

     - So, if one Data DSA is not available to accept requests, the router will send the request to the next available.

     

    - Regards. Vijay

     



  • 3.  Re: CA Directory - Router DSA

    Posted Jul 16, 2018 05:46 AM

    Thanks, Vijay.

    In my case, Router DSA is not able to connect to the Policy server. 

    I have 1 more thread running on the same issue - CA Directory - Router DSA 

     

    Regards,

    Pankaj



  • 4.  Re: CA Directory - Router DSA

    Posted Jul 16, 2018 09:15 AM

    The router DSA does not connect to the policy server.  The policy server connects to the router DSA.  Before trying to connect to the policy server to the router, use an LDAP utility like JXplorer to validate your configuration.

    Can you connect to the data DSAs using JXplorer using your admin account that your created?

    If the router is on another server, can you telnet to the data DSA ports from the router server?  If no, then a firewall may be blocking access.  Are the data DSAs set to listen on the correct IP address?

    Can you connect using the same admin account through the router?



  • 5.  Re: CA Directory - Router DSA

    Posted Jul 16, 2018 03:30 PM

    Hi David,

     

    I am able to login to the Data DSA using Jxplorer using the Admin account.

    I am able to login to the Router DSA using anonymous user. However, I am not able to login to Router DSA using Admin account of the Data DSA. 

    I wonder why I should be able to login to Router DSA using Admin account of the Data DSA!

    Router DSA and Data DSAs are configured on the same server.

    I have added more details here CA Directory - Router DSA 

     

    Regards,

    Pankaj



  • 6.  Re: CA Directory - Router DSA
    Best Answer

    Posted Aug 02, 2018 02:20 PM

    I am just marking this case with the link to the answer you had figured out in your other thread so that this discussion, if found, can be linked to the answer.

     

    https://communities.ca.com/thread/241812402-ca-directory-router-dsa#comment-242129110