I currently have 8 SBG scanners located in 4 DMZ zones. Each DMZ (2 Scanners) is managed by a control center. These are old 8200 boxes. Total of 30 million mail / day inbound, 2 million outbound. About to upgrade to some # of 8380's.
City 1 Data Center 1 -- 2 scanners in DMZ, 1 control center/scanner,
City 1 Data Center 2 -- 2 scanners in DMZ, 1 control center/scanner,
City 2 Data Center 1 -- 2 scanners in DMZ, 1 control center/scanner,
City 2 Data Center 2 -- 2 scanners in DMZ, 1 control center/scanner,
the control/scanner on the inside of the network also acts as a smart host for internal senders (many Unix boxes) and then relays out to the DMZ for outbound flow. The inside senders talk to the outbound interface.
Mail volumn
I'd like to reduce the number of control centers so I'm not having to enter config changes into 4 control centers..
I'd also like to separate DMZ spam/virus/policy layer from the inside "smart host" layer.
I also need to support 4-6 domains (not just subdomains). I've been told that each control center can support 4 scanners (including any local scanner on the CC).
I'm considering the following:
1. City 1 Data Center 1
Inside: Control Center for all DMZ boxes in city 1 (4 scanner)
Inside: Scanner 1 for smarthost/policy layer
DMZ : 2 scanners
2. City 1, data Center 2
Inside: Control Center for Smart hosts, Scanner 2 for smart hosts
DMZ: 2 scanners
Ditto for city 2.
I have a concern about rebuilding a control center if I loose a building. The replacement scanner would be in new address space, and recovery from backup recovers IP addressing.
I suppose I'd restore then use the serial console to change IP addressing.
Thoughts?