The Setup → MDR option enables you to have a standby Manager available in cases where the Primary Manager fails.
Manager Disaster Recovery (MDR) feature is available for deployments where the following conditions are met:
Two Managers (called Primary and Secondary) are available. The Primary is in active mode and the secondary in standby mode.
The Primary and Secondary use the same Manager software release version. Manager version of both Primary and Secondary Manager needs to be similar for the creation of MDR pair.
The Primary and Secondary Managers share the same database structure.
The Primary and Secondary Managers can be located in the same Network Operations Center (NOC) or in geographically diverse locations, as long as they can communicate via SSL through TCP port 443. Managers can also be on different hardware.
If the Primary and Secondary Managers are located in different geographical regions, then there needs to be time synchronization between the two Managers keeping the Coordinated Universal Time (UTC) as the standard time.
Let's say, one Manager is in California (UTC - 8 hours), and the other Manager is in New York (UTC - 5 hours). The MDR setup will work in this scenario as long as the time set in both the Managers are in sync with each other. That is, at 09:00 UTC hours, if the Manager in California shows 01:00 hours local time, and the Manager in New York shows 04:00 hours local time, MDR will work.
Note that the Sensor does not have a built-in clock. It gets UTC time from the Manager.
Note
When upgrading the Primary and Secondary Managers, first suspend MDR. Otherwise, MDR may malfunction. Once MDR is suspended, upgrade the Primany Manager, and then upgrade the Secondary Manager. Once both Managers are upgraded, resume MDR.
Sensors communicate to the Primary and Secondary Managers independently. The Secondary Manager receives configuration information from the Primary on a regular basis. If the Managers are unable to communicate with each other, the Secondary Manager queries each Sensor and becomes active only when a majority of Sensors fail to reach the Primary. The Secondary Manager can also become active by performing manual switchover.
Note
New roles created on the Primary Manager are automatically copied onto the Secondary Manager.
When the Secondary Manager becomes active, all the alerts present in Primary manager also appears in the Attack Log page of the Secondary Manager. The switch-back from the active Secondary Manager to the Primary Manager does not occur automatically. There is a manual switch-back action that is required to be performed from the Primary Manager.
After switch-back, alert and packet log data is copied from the Secondary Manager to the Primary Manager. This data can be viewed in the Attack Log page.