Sometimes the worst happens. In this age, where outages to IT systems can cost millions of dollars in lost revenue, lost productivity, and legal issues, every organization must face the near certainty of a system failure occurring at a future date. Anticipating these events and planning corrective courses of action is a prerequisite to business success. Most organizations now employ some manner of business continuity planning (BCP), a subset of which is disaster recovery planning (DRP). To this end, Trellix IPS has long provided a Sensor high-availability configuration; but what if the worst should happen to your Manager server? Most companies are not willing to rely on the manual method of Manager data archival, restoration of backups, and importing of exported policies to recover their Manager as part of their IPS DRP.
Here enters the MDR feature. With MDR, two Manager servers are deployed as part of Trellix IPS. One host is configured as the Primary system; the other as the Secondary. Each uses the same major release Manager software with mirrored databases; however, the two hosts’ hardware configuration does not need to be identical. The Secondary Manager can be deployed anywhere, for example, at a disaster recovery site, far from the Primary Manager.
The Primary Manager is the active Manager by default. This Manager communicates with the Update Server, pushes configuration data to the Sensors, and receives alerts from the Sensors.
The Secondary Manager remains in a standby state by default. While in standby mode it monitors the health status of the Primary Manager and retrieves Sensor configuration information from the Primary Manager at configured intervals of time.
Note
The Secondary Manager is a warm standby system; it will not guarantee state synchronization with the Primary Manager. It does update configuration information at regular intervals (every 15 minutes), but it does not maintain state. (You can also manually update Secondary Manager configuration rather than waiting for the automatic update.)
An MDR pair can manage both hardware Sensors as well as Virtual Sensors deployed in an AWS environment.
A Sensor connected to an MDR pair maintains communication with both Managers at all times. The Sensor sends alerts, packet logs to both the Managers. Real-time synchronization between the MDR pair ensures that the data present in the active mode is exactly mirrored in the standby.
In case one of the Managers goes down, after it comes up, it will be updated with the missed alerts and packet log data during the next synchronization from the peer Manager. This synchronization restores the missed alerts and packet log data only from previous 24 hours. The maximum number of alerts and packet logs restored with synchronization is 10,000.
Sensors can only be added to an active Manager. (A new Sensor added to the active Manager in an MDR pair establishes trust first with the Primary Sensor, and then attempts on its own to establish trust with the Secondary.)
.png)