How high availability on AWS works
-
High availability within same zone
-
High availability across different zones
High availability within the same zones
-
Management interface on the same subnet (referred as management subnet)
-
Client interface on the same subnet (referred as client subnet)
-
Server interface on the same subnet (referred as server subnet)
-
Both the VPX instances have the same number of NICs and subnet mapping according to NIC enumeration.
-
Each VPX NIC has one extra private IP address, except the first NIC - which corresponds to the management IP address. The extra private IP address appears as the primary private IP address in the AWS web console. In our document, we refer to this extra IP address as the dummy IP address).
-
The dummy IP addresses must be not configured on the NetScaler instance as VIP and SNIP.
-
Other secondary private IP addresses must be created, as required, and configured as VIP and SNIP.
-
On failover, the new primary node looks for configured SNIPs and VIPs and moves them from NICs attached to the previous primary to corresponding NICs on the new primary.
-
NetScaler instances require IAM permissions for HA to work. Add the following IAM privileges to the IAM policy added to each instance.
"iam:GetRole" "ec2:DescribeInstances" "ec2:DescribeNetworkInterfaces" "ec2:AssignPrivateIpAddresses"
unassignPrivateIpAddress is not required.
"iam:GetRole" "ec2:DescribeInstances" "ec2:DescribeAddresses" "ec2:AssociateAddress" "ec2:DisassociateAddress"
High availability across different zones
-
Checks the virtual servers that have
IPSetsattached to them. -
Finds the IP address that has an associated public IP, from the two IP addresses the virtual server is listening on. One that is directly attached to the virtual server, and one that is attached through the IP set.
-
Reassociates the public IP (EIP) to the private IP belonging to the new primary VIP.
"iam:GetRole" "ec2:DescribeInstances" "ec2:DescribeAddresses" "ec2:AssociateAddress" "ec2:DisassociateAddress"
Before you start your deployment
Troubleshooting
cloud-ha-daemon.log file stored in the /var/log/ location.