VMware Cloud Community
kfkehua
Contributor
Contributor

network design for HA/DR Replication

i think this is more of a network question rather than a vmware question.

We are thinking about replicating our VM's offsite using Veeam or similar software, but I'm not sure how this will work out.

What I'm thinking is to use a site to site VPN and replicate the over the VM's to an ESX box offsite.

main site subnet: 192.168.1.x

VM's in main site: 192.168.1.x

Offsite VPN subnet: 192.168.2.x

however the VM's being replicated are: 192.168.1.x

In a situation of a DR, when we turn on the VM's in the offsite, how will my users here in the main office see the VM's accross the VPN??

or am I approaching this the wrong way??

0 Kudos
1 Reply
habibalby
Hot Shot
Hot Shot






Hello,

Replication will work via Site-to-Site VPN or direct leased line, as long as you can connect to the other vCenter located in the other end you will be able to replicate.

Now, how your clients who are located in the HQ can access particular VM(s) that is located in the DR.

In that case you have to spilt your DR scenario to multiple scenarios. You can take cases of building collapsed, fire in the server room, or application/physical server failure because sometime you don't need all users to be connected to the DR site for all applications, but you need them to access particular VM/application.

In east of west you need your VMs to be accessible by your users. In this case, you have to stretched your vLAN from HQ to DR, so you will have two subnet 192.168.1.x available in the HQ as well as in the DR. Once your vLAN stretched to the DR, in your esx hosts you can connect to HQ vLAN in the DR to particular pNICs to the ESX and keep them shutdown, or you can shutdown the Ethernet interface located in the DR Ethernet Routing Switch to avoid conflicts in IP and DNS. Incase of DR, you can enable that interface and communication will be available to your VMs.

Or you can do another vSwitch without vNICs that have private portgroup, assign your VMs to the private portgroup and during DR you can assign them to your production portgroup where it has outbound adapters to your Stretched HQ vLAN.

But if you have Branches that are connected to your HQ Datacenter via Leased Line, you have to consider that as well. Either your ISP should switch the line from HQ to the DR or another Site-to-Site VPN via internet will do, but you have to do it with lots of consideration and cares.

Best Regards,

Hussain Al Sayed

Revisit your posts and award points for "correct" or "helpful".

Best Regards, Hussain Al Sayed Consider awarding points for "correct" or "helpful".
0 Kudos