Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
this_guy_again
Contributor

VSNext in remote site

Hello team,

Is there a blueprint/recommended design for a VSNext setup in a site which is remote from the Security Management Server's location?

 

I thought of 2 hypothetical designs, attached.

  • Design 1 has VS0 with a public IP assigned to it directly (public network to vSwitch, bounced to VS0 and VS1).
  • Design 2 has the public IP hosted on VS1-Perimeter, which is then NATed to VS0.

Con of design 1 is that VS0 is exposed directly to the internet - if that's really a noteworthy con (a regular gateway would have the same "issue").

Con of design 2 is that VS0 (hence SSH/HTTPS) depends on VS1-Perimeter. If something goes wrong with VS1 or the ElasticXL cluster in general, the setup may become unrecoverable without a completely OOB solution.

 

What are your thoughts? Thanks!

Design 1:

design1.png

 

Design 2:

design2.png

  

0 Kudos
2 Replies
PhoneBoy
Admin
Admin

Moving this to the appropriate technical space.

0 Kudos
Bob_Zimmerman
MVP Gold
MVP Gold

Yes, VSX in all forms makes it much easier to accidentally lock yourself out of the box in ways which are difficult to recover. No matter which option you pick, you need to have some kind of separate access which doesn't depend on the firewall functioning properly. Internet connection through some other firewall to LOM, some kind of cell modem console server, there are a lot of options for this.

In VSNext, VS0 is no longer quite so special. It runs the SSH and HTTPS services, but you no longer need the management to be able to reach it to make routing changes and so forth.

With that said, either design you showed seems fine.

0 Kudos