background image

24

Novell Business Continuity Clustering 1.1 for NetWare Administration Guide

no

vd

ocx (

e

n)

  1

1

 Decemb

er

 2

007

Selecting the

 Identity Manager Templates for Windows iManager Servers

 installs the templates 

on the local Windows server. You must have iManager installed on the Windows server before 
installing the templates. The templates add functionality to iManager so you can manage your 
business continuity cluster. You will be asked to specify the path to Tomcat (a default path is 
provided) on the Windows server later in the installation.
The Business Continuity Cluster component contains the core software engine files that make 
up the Business Continuity Cluster product. The Business Continuity Cluster software must be 
installed on all nodes in each cluster that will be part of a Business Continuity Cluster.

4

Do one of the following:

Š

 If you chose to install the IDM iManager templates on a NetWare server, specify the name 
of the eDirectory tree and the fully distinguished name for the server where you want to 
install the templates. Then click 

Next

.

If you don’t know the fully distinguished name for the server, you can browse and select 
it.

Š

 If you chose to install the IDM iManager templates on a Windows server, specify the path 
to Tomcat (a default path is provided) on the server. Then click 

Next

.

You must have iManager installed on the Windows server before installing the templates.

5

Continue through the Upgrade Reminder screen and then specify the name of the eDirectory 
tree and the fully distinguished name for the cluster where you want to install the core software 
files.
If you don’t know the fully distinguished name for the cluster, you can browse and select it.

6

Select the servers in the cluster where you want to install the core software files for the 
Business Continuity Cluster product.
All servers currently in the cluster you specified are listed and are selected by default.
You can choose to automatically start Business Continuity Cluster software on each selected 
node after the installation is complete. If Business Continuity Cluster software is not started 
automatically after the installation, you can start it manually later by rebooting the cluster 
server or by entering 

LDBCC

 at the server console.

7

Enter the name and password of an eDirectory user (or browse and select one) with sufficient 
rights to manage your BCC. This name should be entered in eDirectory dot format. For 
example, admin.servers.novell.
This user should have at least Read and Write rights to the All Attribute Rights property on the 
Cluster object of the remote cluster.

8

Continue through the final installation screen and then restart the cluster nodes where IDM is 
running and where you have upgraded 

libc.nlm

.

Restarting the cluster nodes can be performed in a rolling fashion in which one server is 
restarted while the other servers in the cluster continue running. Then another server is 
restarted, and then another, until all servers in the cluster have been restarted.
This lets you keep your cluster up and running and lets your users continue to access the 
network while cluster nodes are being restarted.

9

Repeat the above procedure for each cluster that will be part of the business continuity cluster.

Содержание BUSINESS CONTINUITY CLUSTERING FOR NETWARE 1.1 - ADMINISTRATION

Страница 1: ...l c o m novdocx en 11 December 2007 Novell Business Continuity Clustering 1 1 for NetWare Administration Guide Business Continuity Clustering for NetWare 1 1 F e b r u a r y 1 5 2 0 0 8 A D M I N I S...

Страница 2: ...t or re export to entities on the current U S export exclusion lists or to any embargoed or terrorist countries as specified in the U S export laws You agree to not use deliverables for prohibited nuc...

Страница 3: ...ll Trademarks For Novell Trademarks see the Novell Trademark and Service Mark list http www novell com company legal trademarks tmlist html Third Party Materials All third party trademarks are the pro...

Страница 4: ...novdocx en 11 December 2007...

Страница 5: ...nuity Cluster Component Locations 25 2 4 Configuring File System Mirroring 25 2 4 1 Configuring NSS Mirroring 26 2 4 2 Configuring SAN Based Mirroring 29 2 4 3 LUN Masking 29 2 5 Setting Up Novell Bus...

Страница 6: ...ters Not Functional 65 4 14 Resource Does Not Migrate to Another Cluster 65 4 15 Resource Cannot Be Brought Online 65 4 16 Dumping Syslog on NetWare 66 4 17 Slow Failovers 66 4 18 Resource Script Sear...

Страница 7: ...B Setting Up Auto Failover 87 B 1 Enabling Auto Failover 87 B 2 Creating an Auto Failover Policy 88 B 3 Refining the Auto Failover Policy 88 B 4 Adding or Editing Monitor Configurations 89 C Security...

Страница 8: ...8 Novell Business Continuity Clustering 1 1 for NetWare Administration Guide novdocx en 11 December 2007...

Страница 9: ...installing configuring and managing Novell Cluster Services Feedback We want to hear your comments and suggestions about this manual and the other documentation included with this product Please use...

Страница 10: ...10 Novell Business Continuity Clustering 1 1 for NetWare Administration Guide novdocx en 11 December 2007...

Страница 11: ...have to be carefully planned and replicated One mistake and the redundant site is no longer able to effectively take over in the event of a disaster 1 1 Disaster Recovery Implications The implication...

Страница 12: ...isaster occurs in one data center the other automatically takes over Figure 1 1 Stretch Cluster Cluster of Clusters A cluster of clusters consists of two or more clusters in which each cluster is loca...

Страница 13: ...ibre Channel Switch Fibre Channel Disk Arrays Building A Building B Server 2A Ethernet Switch Server 3A Server 1A Server 4A Fibre Channel Switch Fibre Channel Disk Arrays Disk blocks Ethernet Switch W...

Страница 14: ...in a separate eDirectory tree IP addresses for each cluster can be on different IP subnets It accommodates more than two sites and cluster resources can fail over to separate clusters multiple site f...

Страница 15: ...g software provides the following advantages Integrates with SAN hardware devices to automate the failover process using standards based mechanisms such as SMI S Utilizes Novell Identity Manager techn...

Страница 16: ...arios include A Two Site Business Continuity Cluster Solution A Multiple Site Business Continuity Cluster Solution A Low Cost Business Continuity Cluster Solution Two Site Business Continuity Cluster...

Страница 17: ...ks is typically done by SAN vendors but can be done by host based mirroring for synchronous replication over short distances The illustration below depicts a four site business continuity cluster Serv...

Страница 18: ...and hotels Low Cost Business Continuity Cluster Solution The low cost business continuity cluster solution is similar to the previous two solutions but replaces Fibre Channel arrays with iSCSI arrays...

Страница 19: ...ection 2 1 1 NetWare 6 5 SP 5 or SP 6 OES 1 SP2 or SP3 NetWare on page 19 Section 2 1 2 Novell eDirectory 8 8 on page 20 Section 2 1 3 Novell Cluster Services 1 8 2 for NetWare on page 20 Section 2 1...

Страница 20: ...erface separately The CLI for the SAN might not initially be included with your hardware Also some SAN hardware may not be SMI S compliant and can t be managed using SMI S commands The recommended con...

Страница 21: ...xec ncf File The sys system autoexec ncf file must be modified so that the call to sys bin unixenv ncf is before the calls to openwbem ncf and ldbcc ncf 2 1 9 Shared Disk Systems For Business Continui...

Страница 22: ...e 25 for specific information on where to install IDM components NOTE Filtered eDirectory replicas are not supported with this version of Business Continuity Cluster software Full replicas are require...

Страница 23: ...the following sections Section 2 3 1 Business Continuity Cluster Licensing on page 23 Section 2 3 2 Running the Business Continuity Cluster Installation Program on page 23 Section 2 3 3 Business Cont...

Страница 24: ...uished name for the cluster where you want to install the core software files If you don t know the fully distinguished name for the cluster you can browse and select it 6 Select the servers in the cl...

Страница 25: ...ach method has its own strengths and weaknesses After considering the different methods you will need to choose either host based mirroring or SAN based mirroring also called array based mirroring and...

Страница 26: ...e mirrored after they are created If you have an existing partition that you want to mirror you can either create another partition of equal size on another device to mirror the first partition to or...

Страница 27: ...be activated and cluster enabled when it is created The Activate on Creation feature is enabled by default This causes the pool to be activated as soon as it is created If you choose not to activate...

Страница 28: ...of the Novell Cluster Services 1 8 2 Administration Guide for NetWare Novell Cluster Services Configuration and Setup After configuring NSS mirroring and creating a pool and volume on the mirrored NS...

Страница 29: ...ntinuity Cluster software consists of Configuring Business Continuity Specific IDM Drivers on page 29 Configuring Clusters for Business Continuity on page 35 Configuring Cluster Resources for Business...

Страница 30: ...iver link 4 Choose to place the new driver in a new driver set then click Next Both the User Object Synchronization Driver and the Cluster Resource Synchronization Driver can be added to the same driv...

Страница 31: ...olume objects You would then specify the context of the new container in this step The IDM Driver object must have sufficient rights to create modify and delete objects and attributes in the following...

Страница 32: ...ext You must specify the driver name including the context you supplied in Step 8 on page 30 for this cluster Use the following format when specifying the driver name DriverName DriverSet Organization...

Страница 33: ...in a manner that prevents IDM synchronization loops IDM synchronization loops can cause excessive network traffic and slow server communication and performance For example in a three cluster business...

Страница 34: ...nge your BCC synchronization scenario 1 In the Connections section of the Business Continuity Cluster Properties page select one or more peer clusters that you want a cluster to synchronize to then cl...

Страница 35: ...e cluster you are enabling for business continuity 2 Enter your username and password 3 Ensure that the Business Continuity specific IDM drivers are running 3a In the left column click DirXML and then...

Страница 36: ...esources to 4 Continue with Step 1 in the Adding Resource Script Search and Replace Values section below Adding Resource Script Search and Replace Values To enable a resource for business continuity c...

Страница 37: ...iguration Information You can create scripts and add commands that are specific to your SAN hardware These scripts and commands might be needed to promote mirrored LUNs to primary on the cluster where...

Страница 38: ...rt If you checked the CIM Client check box in the previous screen accept the default port number or specify a different port number This is the port number that CIMOM your SAN manager uses Consult you...

Страница 39: ...ch time the server starts For this reason you can t assign eDirectory trustee rights to the _Admin volume To assign BCC administrative user eDirectory trustee rights 1 Start your Internet browser and...

Страница 40: ...rite fileScan modify rights addTrustee Note the following items with this example The name element is the BCC administrative user The tree name is required The filename element must be _ADMIN Novell C...

Страница 41: ...ling a Cluster Resource for Business Continuity Cluster resources must be enabled for business continuity on the primary cluster before they can be synchronized and appear as resources in the other cl...

Страница 42: ...for business continuity certain values such as IP addresses DNS names and tree names specified in resource load and unload scripts need to be changed in corresponding resources in the other clusters...

Страница 43: ...load and unload scripts in the source cluster to their original values Selecting Peer Clusters for the Resource Peer clusters are the other clusters that this cluster resource can be migrated to The c...

Страница 44: ...ster site to manually migrate or bring up resources at that site Each resource will start on its preferred node on the destination cluster TIP You can use the cluster migrate command to start resource...

Страница 45: ...and password for the administrative user that the selected cluster will use to connect to a selected peer cluster You might need to do this if the administrator username or password changes for any cl...

Страница 46: ...er connections are down You can also see the status of the BCC resources in the business continuity cluster Using the Server Console At the server console of a server in the business continuity cluste...

Страница 47: ...clusters where you no longer want the resource to run IMPORTANT If you disable BCC for a cluster using either iManager or the Cluster Disable console command BCC will also be disabled for those clust...

Страница 48: ...be BCC enabled This can be a time consuming process if you have many BCC enabled cluster resources For this reason you should use caution when disabling BCC for an entire cluster CLUSTER ENABLE resour...

Страница 49: ...one node is a member of the cluster 1 After a failure bring up one node in the cluster All other nodes should remain powered off 2 Run the cluster resetresources command 3 Bring up the remaining nodes...

Страница 50: ...t manually The former primary SAN must be demoted to secondary before bringing cluster servers back up Consult your SAN hardware documentation for instructions on demoting and promoting SANs You can u...

Страница 51: ...Lost Users might not be able to access servers in the primary cluster but can possibly access servers in the secondary cluster If both clusters are up nothing additional is required An error will be d...

Страница 52: ...ack up Additional response is the same as for SAN based mirroring described above Secondary SAN Fails but Secondary Cluster Does Not Bring up your secondary SAN or iSCSI target before bringing up your...

Страница 53: ...on on what is required for BCC 1 1 See Upgrading to OES NetWare http www novell com documentation oes install nw data hqwoj1yu html hqwoj1yu for more information on upgrading NetWare In addition to up...

Страница 54: ...orms the necessary updates to convert BCC 1 0 to BCC 1 1 This includes searching eDirectoryTM for SAN scripts and updating those scripts to be SMI S compliant 3 1 4 Resetting BCC Administrative User C...

Страница 55: ...nodes in BCC 1 0 clusters to BCC 1 1 for NetWare To do this follow the instructions in Section 3 1 Upgrading BCC 1 0 to BCC 1 1 for NetWare on page 53 IMPORTANT All cluster nodes in every cluster in y...

Страница 56: ...cember 2007 The same restrictions that apply to migrating or failing over resources between nodes within a mixed cluster also apply to migrating or failing over resources between clusters in a mixed B...

Страница 57: ...3 Administration of Peer Clusters Not Functional on page 65 Section 4 14 Resource Does Not Migrate to Another Cluster on page 65 Section 4 15 Resource Cannot Be Brought Online on page 65 Section 4 16...

Страница 58: ...u entered the wrong username and or password for the selected peer cluster Enter the correct username and password that this cluster will use to connect to the selected peer cluster Cannot Connect 3 T...

Страница 59: ...text field view and if necessary change the port numbers next to the IP address For example the Authentication context field might contain a value similar to 123 12 23 12 2003 2003 In this example the...

Страница 60: ...ropriate contexts in your eDirectory tree to manage your BCC The IDM Driver object must have sufficient rights to create modify and delete objects and attributes in the following containers The Identi...

Страница 61: ...recommends using SSL certificates for encryption and security NOTE You should create or use a different certificate than the default dummy certificate BCC Cluster Sync KMO that is included with BCC Se...

Страница 62: ...lag with this option Stop BCC by entering rcnovell bccd stop at the server console then restart it by entering opt novell bcc sbin bccd flags Replace flags with any combination of v t and or d 4 8 Pro...

Страница 63: ...led Click the red icon for the driver on the DirXML Driver Overview page You can enable the driver using the radio buttons in the Driver Startup section of the page that displays Selecting the Auto St...

Страница 64: ...er the URL for iManager The URL is http server_ip_address nps iManager html Replace server_ip_address with the IP address or DNS name of the server that has iManager and the IDM preconfigured template...

Страница 65: ...e a resource from one cluster to another the problem might be caused by one of the following conditions The resource has not been BCC enabled Remote clusters cannot communicate See Section 4 12 Peer C...

Страница 66: ...n back online for changes to the unload script to take effect Be aware that client data may be lost if clients are accessing the resource when it is brought offline 4 18 Resource Script Search and Rep...

Страница 67: ...enable the General tab 6 Click Apply to save your changes 4 20 IP Address Virtual Server DN or Pool Name Does Not Appear on the iManager Cluster Configuration Page You might see a DSML read error if...

Страница 68: ...ry Ensure that eDirectory and your clusters are stable before implementing BCC Engage Novell Consulting Engage a consulting group from your SAN vendor The cluster node that hosts the IDM driver should...

Страница 69: ...e All user objects must be modified to have their Home Directory attribute reference the new volume object volume reference Use LDIF and ICE in the NSMI script Disk Array Mapping Information area This...

Страница 70: ...er Message 1000 Unknown error 1001 Received XML is invalid 1002 The object pointers in eDirectory for the given cluster resource are invalid 1003 The referenced object is not a valid NCS BCC object 10...

Страница 71: ...nced in the message that appears You can get additional information on how to use the log file by entering help log at the NetWare server console 1020 CIM Client error 1021 Error creating a system res...

Страница 72: ...72 Novell Business Continuity Clustering 1 1 for NetWare Administration Guide novdocx en 11 December 2007...

Страница 73: ...their virtual nature virtual IP addresses and virtual NICs behave like physical IP addresses and physical NICs and they are similarly configured using either the INETCFG server based utility or the Ne...

Страница 74: ...s is especially true in the event of server NIC failures This assumes that the server is running a routing protocol and is advertising its internal virtual IP network which only it knows about and can...

Страница 75: ...dvertise reachability to the 1 0 0 0 FF 0 0 0 network and the client would continue to forward packets to Router 1 Being undeliverable these packets would ultimately be dropped by Router 1 Therefore i...

Страница 76: ...effects that directly follow from the highly reachable nature of virtual IP addresses They completely and uniquely identify a multihomed server A multihomed server with a virtual IP address no longer...

Страница 77: ...The need often arises to move a machine hosting a particular service to some other IP network or to move a service hosted on a particular machine to be rehosted on some other machine connected to a di...

Страница 78: ...o recognize and honor the advertised host routes In autonomous systems that use variable length subnet masking VLSM together with routing protocols like RIP II or OSPF the consumption of additional IP...

Страница 79: ...OVERRIDE ON 2 The command to bind a virtual IP address for the service must be added to the cluster resource load script The following is an example of a cluster resource load script for a standard Ne...

Страница 80: ...needed for any nonvolume cluster resources like DHCP 5 5 1 Displaying Bound Virtual IP Addresses To verify that a virtual IP address is bound enter display secondary ipaddress at the server console of...

Страница 81: ...Directory tree For example if you have one tree that has 10 000 users and a second new tree that does not yet have users defined you can use DirXML to quickly copy the 10 000 users to the new tree For...

Страница 82: ...n click OK 13 Optional Exclude the Admin User object from being synchronized 13a Click the Exclude Administrative Roles button then click Add 13b Browse to and select the Admin User object then click...

Страница 83: ...e DirXMLOverview link 4 Search for and find the BCC driver set 5 Click the red Cluster Sync icon for the driver you want to sync then click the Migrate from eDirectory button 6 Click Add browse to and...

Страница 84: ...Cluster Three both synchronize with Cluster One This is illustrated in Figure 2 4 below Figure A 2 Three Cluster IDM Synchronization Master You could also have Cluster One synchronize with Cluster Two...

Страница 85: ...tree and you want to maintain that pool s volume trustee assignments you must migrate the pool to a server with an eDirectory replica The replica must be at least read only and must contain all users...

Страница 86: ...86 Novell Business Continuity Clustering 1 1 for NetWare Administration Guide novdocx en 11 December 2007...

Страница 87: ...luster has been restored some of the data on each cluster will be different This is called data divergence Also the mirroring or synchronization process will either fail or will attempt to overwrite a...

Страница 88: ...ation The policy for automatic failover is configured by creating rules Each row in the Failover Policy Configuration table represents a rule that applies to a single cluster or to all clusters in the...

Страница 89: ...ng the Advanced button will also display an additional section on this page called Health Monitor Configuration Monitors are an important part of the automatic failover feature and are separate proces...

Страница 90: ...decnt monitors This value may be used for some custom monitors 5 Specify which platforms Linux or NetWare you want to be monitored by the health monitor and whether you want the monitor enabled for th...

Страница 91: ...mation for Other Products on page 95 Feature Yes No Details Users are authenticated Yes Administrative users are authenticated via eDirectory Users are authorized Yes Users are authorized via eDirecto...

Страница 92: ...me bccgroup adminGroupName authorizationCacheTTL 300 authorizationCacheTTL cimConnectTimeout 15 cimConnectTimeout cimReceiveTimeout 30 cimReceiveTimeout cimSendTimeout 30 cimSendTimeout idlePriorityTh...

Страница 93: ...acheTTL The number of seconds the authorization rights are cached in the BCC OpenWBEM provider 300 seconds This is not supported until the first support pack cimConnectTimeout BCC CIM client connect t...

Страница 94: ...ment address of chicago_cluster now specifies non secure http communication The BCC management port can also be changed by modifying the NCS BCC Peers attribute values The default ports for secure and...

Страница 95: ...www novell com documentation oes nss_enu data bx8gp06 html eDirectory Security for eDirectory is provided by NICI See the NICI 2 7x Administration Guide http www novell com documentation nici27x nici...

Страница 96: ...ounts or that protect BCC data should be examined periodically to ensure that they have not been tampered with When synchronizing cluster or user information between servers outside the corporate fire...

Страница 97: ...changes are grouped and sequenced alphabetically Each change entry provides a link to the related topic and a brief description of the change This document was updated on the following dates Section...

Страница 98: ...Administration Guide novdocx en 11 December 2007 D 1 2 Troubleshooting BCC 1 1 Location Change Section 4 4 Security Equivalent User on page 60 The NCP server objects for the virtual server of a BCC e...

Отзывы: