Define Alternate Nodes for Failover Support

About this task

If you are using standard routing to connect to a Sterling Connect:Express server in the secure zone, you identify a primary server to connect to in the adapter. The primary nodes are defined in the netmap. For each PNODE definition in the netmap, you can identify up to three alternate outbound nodes to connect to if the primary Sterling Connect:Express server is not available.

Two methods of configuring alternate server routing are available.

  • Select a previously defined outbound node from the drop-down list on the Netmap - Advanced tab. To configure this method, you first configure an outbound node definition in the netmap for each alternate node you want to use. Each connection uses the security and Sterling External Authentication Server settings defined for that outbound node in the netmap.
  • Select IP address/port from the drop-down Node list on the Advanced tab and enter values for the IP address and port. If you use this method, you do not have to define the alternate outbound nodes in the netmap, and each alternate connection shares the security and Sterling External Authentication Server settings defined in the primary node definition.

If you configure alternate server definitions in the PNODE definition, when a connection to the primary outbound node is unsuccessful Secure Proxy tries to connect to the alternate node you defined as Node 1. If the connection to the first alternate node is unsuccessful, Secure Proxy tries to connect to the second alternate node, Node 2 and then to the third alternate, Node 3. If all are unsuccessful, the inbound connection fails.

To configure alternate outbound connections:

Procedure

  1. From IBM Sterling Secure Proxy, select Configuration from the left hand-side navigation panel.
  2. Click Netmaps, then click View all Netmaps to display the list of created Netmaps.
  3. Choose the netmap you wish to edit, then click on the Edit icon.
  4. In the Netmap Node section, select the node to modify and click Edit.
  5. Click the Advanced tab.
  6. Do one of the following:
  7. To identify an alternate node that is defined in the netmap and use its security settings, select the outbound node name from the drop-down list. To configure an alternate node that is not in the netmap and use the security settings defined in the primary node definition:
    1. Select Address/Port from the drop-down list in the Alternate Destinations Node field.
    2. Provide the IP Address and Port number for the alternate outbound node.
  8. Click Save.