Create the Virtual Intelligent Sandbox cluster

Prev Next

Create clusters of one or more Virtual Intelligent Sandbox appliances.

  • You have admin-user rights for the primary node's web application.

  • The primary and secondary nodes are not part of any other cluster.

  • On Azure, ensure that you give the private IP address of your primary and secondary node VMs.

  • The software version (active version) of all nodes that you plan to use are an exact match.

  1. Identify a Virtual Intelligent Sandbox Appliance as the primary node and log on to its web application.

    Use a user name that has admin rights.

  2. Select ManageLoad Balancing.

    The Load Balancing Cluster Setting page displays.

  3. In the Node IP address field, enter the management port IP address of the primary node, select Primary from the drop - down and click Add Node.

    Caution

    If you are creating a cluster on Azure, ensure that you give the private IP address of the VM that you want to designate as the primary node.

  4. Confirm if you want to create the cluster.

    Virtual Intelligent Sandbox sets itself as the primary node for the cluster.

  5. In the Node IP address field, enter the management port IP address of a secondary node, select Secondary, then click Add Node.

    Caution

    If you are creating a cluster on Azure, ensure that you give the private IP address of the VM that you want to designate as the secondary node.

  6. Click Yes to add the secondary node.

    Note

    When you click Yesin the confirmation message box, the primary node saves its configuration in a file and sends this to the secondary node. This file contains those configurations, which this document refers to as synchronized configuration. See How does the Intelligent Sandbox cluster work? in the Installation Guide. for information about synchronized configuration. The secondary uses this configuration file to overwrite the corresponding configuration in its database. So, make sure that you have taken a backup of the secondary's configuration before you continue. When you remove the secondary from the cluster, it retains the primary node's configuration.

  7. Following a similar procedure, add the other secondary nodes.

  8. In the Cluster IP address field, enter cluster IP address and click Save. Select Backup from the drop - down and enter the management port IP address of the Backup node in the Node IP address field. Click Add Node.

    Note

    Configuring or changing Cluster IP address resets all SFTP services.

  9. The details of all nodes in the cluster are displayed in a table. Similar to other tables in the Virtual Intelligent Sandbox web application user-interfaces, you can sort , hide or display the required columns.

    Note

    Except for ATD ID, IP Address, Role, and Withdraw From Cluster, none of the options are available in the Load Balancing Cluster Setting page for the secondary nodes.

    Option definitions

    Option

    Definition

    Node IP address

    Enter the management port IP address of the Virtual Intelligent Sandbox Appliance that you want to add to the cluster.

    Drop - Down

    Select Primary / Backup / Secondary according to the requirement.

    Add Node

    Click to add the primary, secondary, and backup node to the cluster.

    The primary node or secondary node IP address is the IP address that you use to access the Intelligent Sandbox web application.

    Cluster IP address

    Enter the cluster IP address to be used by Active node (Primary node or Backup node).

    Save

    Click to save the cluster IP address before adding Backup node.

    Indicates the status of a node.

    • GUID-52CD5CCE-4F05-4E94-986A-474BF552EE11-low.png: Indicates that the node is up and ready. If it is a secondary, it also means that the primary node is receiving the secondary's heartbeat signal.

    • GUID-F47901B4-FB75-497A-86F9-097C27541AD2-low.png: Indicates that the node is up but needs your attention. For example, the configuration might not be in sync with that of the primary.

    • GUID-2ACE5FBA-8C02-4D26-84BC-87F0C6DED4C8-low.png: Indicates that the primary node is not receiving the secondary node's heartbeat signal. Also indicates VM synchronization failure in the node.

    The primary node distributes files only to those nodes, which are in the green status. If the status of a secondary node turns red midway of a file transfer, the primary node allocates the file to the next node in queue. If all the secondary nodes are in overloaded state, samples get distributed among the nodes in round robin fashion, even when the nodes are in amber status.

    ATD ID

    This is a system-generated integer value to identify the nodes in a cluster. The primary node generates this unique value and assigns it to the nodes in the cluster.

    This ID is displayed in the Analysis Status and Analysis Results left-hand-side tree structure on the primary node. This enables you to identify the node that analyzed a specific sample.

    The uniqueness of the ATD ID is based on the IP address of a node as stored in the primary node's database. Consider that you have 3 nodes in the cluster. You remove the secondary node with ATD ID 2 from the cluster and add it back again to the cluster. Then this secondary node is assigned the same ATD ID of 2 if all these conditions are met:

    • You have not changed the IP address of the node's eth-0 interface (management port).

    • The primary node's database still has a record for the secondary's IP address.

    IP Address

    The management port IP address of the node.

    Model

    The Virtual Intelligent Sandbox appliance model type. It could be either 1008, 1016, 3032, or 6064.

    Role

    Indicates if a node is a primary or a secondary or a backup node. It also indicates which node is behaving as Active node.

    Config Version

    When you save any of the synchronized configurations, the primary node sends its configuration file to the secondary nodes and also versions this configuration file for reference. For each node, the version number of its latest configuration file is displayed.

    If the version number of a secondary node does not match with that of the primary, it indicates a possible difference in how the secondary node is configured. So, the status color for that secondary node turns to amber. The reason is also mentioned in the State column. Also, the primary node automatically pushes its configuration file to that node.

    This ensures that all nodes are configured similarly about synchronized configuration.

    S/W Version

    Indicates the Virtual Intelligent Sandbox software version of the nodes. The complete software version must exactly match for all nodes. If not, the status turns to amber for the corresponding nodes.

    State

    Indicates the status of node and any critical information related to that node.

    Some possible states are:

    • Up and Ready: Indicates that the node is ready to receive samples

    • Heartbeat not received

    • Node is on different config version

    • Node Overloaded: Indicates that the total amount of average processing time for all samples submitted exceeds Max Wait-Time Threshold (780 seconds, by default). The threshold value can be configured using the following path. Select Manage Common SettingsPerformance Tuning. Use CLI command show filequeue to check the current average processing time of the submitted samples.

    Remove Node

    Select a node and click to remove the node from the cluster. The configuration from the primary node is retained even when you remove a secondary node from the cluster. You cannot remove a primary node or a Backup node, if it is in active state, before you remove all secondary nodes.

    This option is not available for a secondary node.

    Sync All Nodes

    Click Sync All to trigger the configuration-synchronization for all secondary nodes in the cluster.

    Note

    When you add a secondary node or when you save any of the synchronized configurations in the primary node, the primary automatically triggers a synchronization to all secondary nodes in green and amber state.

    Details of the configuration sync are displayed for each node based on the success or failure of the synchronization.

    Sync All VMs

    Manually triggers the synchronization of primary node and secondary node VMs in a cluster. This function is applicable only when you have a synchronization error between primary node and secondary node VMs.

    Note

    Synchronizing VMs should be carried out during downtime, as it triggers synchronization of VMs in all nodes in the cluster and nodes will not participate in sample analysis.

    Withdraw from Cluster

    This button is relevant only for secondary nodes. Click to withdraw a secondary node from the cluster and to use the secondary node as a standalone Virtual Intelligent Sandbox Appliance.

    Recall that if the primary and Backup nodes are down simultaneously, the load-balancing cluster is down. In the previously mentioned case, click Withdraw from Cluster in the secondary nodes to withdraw from the cluster and to use the secondary nodes as standalone appliances.