Prerequisites for Setting Up Multiple B Series Appliances in Atlas Clusters
You must meet certain prerequisites before you can set up your BeyondTrust cluster.
- Two B300, B400, or PRA Virtual Appliances
These B Series Appliances act as the primary nodes. One will be designated the primary node and the other will be a backup primary node. Both primary nodes must match same B Series Appliance type: B300 to B300, B400 to B400, or PRA Virtual Appliance to PRA Virtual Appliance. Your need for scalability, capacity, and redundancy will determine B Series Appliance needs.
- Two B300/B400/PRA Virtual Appliance traffic nodes per geographic region in a minimum of two regions
Traffic nodes can be a mix of B300, B400, and PRA Virtual Appliances.
Note, however, that mixing B Series Appliance types will yield unbalanced capabilities and potential workflow conflicts. Therefore, it is recommended that all B Series Appliances be the same model or type.
You will also need the following hostnames, at a minimum:
- Site hostname
This is the hostname that customers will visit to initiate support. This hostname must route to the primary node in the cluster.
- Canonical node hostnames
You must have a unique and unchanging hostname for each primary and traffic node. For geographic deployments, consider using the geographic region as part of the hostname. These hostnames should be registered in both the internal and external DNS. Here is an example:
- Primary : primary1.access.example.com
- Backup Primary: primary2.access.example.com
- Traffic Node 1: us-traffic1.access.example.com
- Traffic Node 2: us-traffic2.access.example.com
- Traffic Node 3: asia-traffic1.access.example.com
- Valid SSL certificate for the BeyondTrust site and for each traffic node
It is recommended you use a valid third-party wildcard certificate that covers both your BeyondTrust support site name and each traffic node hostname. If a wildcard certificate is not used, adding additional traffic nodes that use different certificates may require a rebuild of the BeyondTrust software in order to provide support for mobile and Linux platforms.
- TCP port 443 open bi-directionally on all B Series Appliances
All B Series Appliances must be able to communicate over TCP port 443.