Symantec IGA

 View Only
  • 1.  CA Identity Suite - 14.2 How to DC and DR userstore and PD replication to be done.

    Posted Aug 14, 2019 02:55 AM

    Hi All,

    I want to perform userstore and Provisioning Directory replication (MMR)between DC (vApp1 & vApp2) and DR (vApp3) of CA Identity Suite.

    Our CA Identity Suite version is 14.2.

    Please let me know the process for achieving the same.

    regards
    Ramesh



  • 2.  RE: CA Identity Suite - 14.2 How to DC and DR userstore and PD replication to be done.

    Broadcom Employee
    Posted Aug 14, 2019 11:45 AM
    In vApp all nodes are treated as the same.  You would deploy everything as normal and leave services off until DR is needed.  If trying to segregate network this would take manual configuration.

    https://docops.ca.com/ca-identity-suite/14-3/EN/ca-identity-suite-reference-architecture/foundation-physical-architecture/foundation-logical-architecture-and-network-context/disaster-recovery-dr-environment

    @Hitesh Patel, Do you have any information from the Directory side?

    We will open this up to the greater community to see if someone has anything similar.  You may also want to contact your Broadcom Account team to review your UC and potential solution.


    ------------------------------
    Best regards,

    Scott Owens
    Sr Support Engineer
    Enterprise Software Division
    Broadcom Inc.
    ------------------------------



  • 3.  RE: CA Identity Suite - 14.2 How to DC and DR userstore and PD replication to be done.

    Broadcom Employee
    Posted Aug 14, 2019 11:50 AM
    If vApp allows modifications, all you need to know can be found in CA Directory docops space.
    e.g. how to manually configure MW replication among DSAs.

    -Hitesh


  • 4.  RE: CA Identity Suite - 14.2 How to DC and DR userstore and PD replication to be done.
    Best Answer

    Broadcom Employee
    Posted Aug 14, 2019 12:26 PM
    Replication should be configured by default. Once you deploy a second vApp instance, all the load-balancing and HA will be configured for you (at least for the corporate user store). vApp does this through a router DSA.




  • 5.  RE: CA Identity Suite - 14.2 How to DC and DR userstore and PD replication to be done.

    Posted Aug 22, 2019 10:51 AM
    Hi Lyes

    If I perform a new installation in an alternate data center, directing the connections to a new database instance, can I use this method or should I perform a new installation? Can I replicate the data and configurations of the alternate data center in real time?

    Julian Riaño


  • 6.  RE: CA Identity Suite - 14.2 How to DC and DR userstore and PD replication to be done.

    Broadcom Employee
    Posted Aug 22, 2019 11:17 AM
    Hi,

    Replication of the user store will happen automatically if you add a new vApp node to the cluster.

    Unfortunately vAPP does not support the movement of DB data between different instance. 

    You can always use multiple services (any combination of IM, IG, IP in data center B and A) with Oracle DB in Data Center A. But if you need to move the database from one data center to another, you will need to export and reimport the data as vApp does not support the movement of DB data (it only supports the movement of the DB service). 

    Please consult the replication section in this page:

    https://docops.ca.com/ca-identity-suite/14-3/EN/virtual-appliance/administering-virtual-appliance