Overview of Failover Support

You can configure failover support in Secure Proxy to manage connections from a trading partner to a company server and ensure that your operation functions even when a component such as a perimeter server, Secure Proxy engine, Sterling External Authentication Server, or Sterling B2B Integrator server in the configuration is not operational.

This document provides overview information about a failover environment and instructions on how to configure failover. It assumes that you have configured a basic Secure Proxy engine and defined adapters.

Illustration of Failover Support in Secure Proxy

Following is an illustration of a basic Secure Proxy configuration. This illustration does not include any components to support failover.


Illustration of Failover Support in SSP

The following illustration builds on the basic Secure Proxy configuration and illustrates one way to configure failover support:


One way to configure failover support

To set up the sample failover environment illustrated above, add the following components to the basic configuration:
  • A second external inbound perimeter server computer (PS Box 2) with two perimeter server instances
  • A second perimeter server instance on the initial inbound PS computer (PS Box 1)
  • A second Secure Proxy engine (SSP Box 2)
  • A second Sterling External Authentication Server with two perimeter server instances (EA Box 2)
  • A second perimeter server instance on Sterling External Authentication Server 1 (EA Box 1)
  • A second Sterling File Gateway, configured as part of a two-node cluster (File Gateway Box 2)
  • A second LDAP server (Secondary LDAP)

This sample configuration illustrates one way to set up Secure Proxy for failover support. Your failover setup depends upon your hardware configuration and security requirements.

The following diagram illustrates the flow of traffic through one leg of an Secure Proxy setup when failover support is configured and all components are operating. Traffic is allowed through the first leg of the setup and moves through the Secure Proxy engine 1.


Flow of traffic through one leg of an SSP setup when failover support is configured and all components are operating

The following diagram illustrates the flow of traffic when Secure Proxy engine 1 is not available and failover support is enabled:


Flow of traffic when SSP engine 1 is not available and failover support is enabled