Cluster Server 8.0.2 Configuration and Upgrade Guide - AIX
- Section I. Configuring Cluster Server using the script-based installer
- I/O fencing requirements
- Preparing to configure VCS clusters for data integrity
- About planning to configure I/O fencing
- Setting up the CP server
- Configuring VCS
- Overview of tasks to configure VCS using the product installer
- Starting the software configuration
- Specifying systems for configuration
- Configuring the cluster name
- Configuring private heartbeat links
- Configuring the virtual IP of the cluster
- Configuring VCS in secure mode
- Setting up trust relationships for your VCS cluster
- Configuring a secure cluster node by node
- Adding VCS users
- Configuring SMTP email notification
- Configuring SNMP trap notification
- Configuring global clusters
- Completing the VCS configuration
- About Veritas License Audit Tool
- Verifying and updating licenses on the system
- Configuring VCS clusters for data integrity
- Setting up disk-based I/O fencing using installer
- Setting up server-based I/O fencing using installer
- Setting up non-SCSI-3 I/O fencing in virtual environments using installer
- Setting up majority-based I/O fencing using installer
- Enabling or disabling the preferred fencing policy
- Section II. Automated configuration using response files
- Performing an automated VCS configuration
- Performing an automated I/O fencing configuration using response files
- Configuring I/O fencing using response files
- Response file variables to configure disk-based I/O fencing
- Sample response file for configuring disk-based I/O fencing
- Response file variables to configure server-based I/O fencing
- Sample response file for configuring server-based I/O fencing
- Response file variables to configure non-SCSI-3 I/O fencing
- Sample response file for configuring non-SCSI-3 I/O fencing
- Response file variables to configure majority-based I/O fencing
- Sample response file for configuring majority-based I/O fencing
- Section III. Manual configuration
- Manually configuring VCS
- About configuring VCS manually
- Configuring LLT manually
- Configuring GAB manually
- Configuring VCS manually
- Configuring VCS in single node mode
- Starting LLT, GAB, and VCS after manual configuration
- About configuring cluster using VCS Cluster Configuration wizard
- Before configuring a VCS cluster using the VCS Cluster Configuration wizard
- Launching the VCS Cluster Configuration wizard
- Configuring a cluster by using the VCS cluster configuration wizard
- Adding a system to a VCS cluster
- Modifying the VCS configuration
- Manually configuring the clusters for data integrity
- Setting up disk-based I/O fencing manually
- Setting up server-based I/O fencing manually
- Preparing the CP servers manually for use by the VCS cluster
- Generating the client key and certificates manually on the client nodes
- Configuring server-based fencing on the VCS cluster manually
- Configuring CoordPoint agent to monitor coordination points
- Verifying server-based I/O fencing configuration
- Setting up non-SCSI-3 fencing in virtual environments manually
- Setting up majority-based I/O fencing manually
- Manually configuring VCS
- Section IV. Upgrading VCS
- Planning to upgrade VCS
- About upgrading to VCS 8.0.2
- Upgrading VCS in secure enterprise environments
- Supported upgrade paths
- Considerations for upgrading secure VCS 6.x clusters to VCS 8.0.2
- Considerations for upgrading VCS to 8.0.2 on systems configured with an Oracle resource
- Considerations for upgrading CP servers
- Considerations for upgrading CP clients
- Considerations for upgrading REST server
- Using Install Bundles to simultaneously install or upgrade full releases (base, maintenance, rolling patch), and individual patches
- Performing a VCS upgrade using the installer
- Before upgrading VCS using the script-based installer
- Upgrading VCS using the product installer
- Upgrading to 2048 bit key and SHA256 signature certificates
- Tasks to perform after upgrading to 2048 bit key and SHA256 signature certificates
- Deleting certificates of non-root users after upgrading to 2048 bit key and SHA256 signature certificates
- Re-establishing WAC communication in global clusters after upgrading to 2048 bit key and SHA256 signature certificates
- Re-establishing CP server and CP client communication after upgrading to 2048 bit key and SHA256 signature certificates
- Re-establishing trust with Steward after upgrading to 2048 bit key and SHA256 signature certificates
- Upgrading Steward to 2048 bit key and SHA256 signature certificates
- Performing an online upgrade
- Performing a phased upgrade of VCS
- About phased upgrade
- Performing a phased upgrade using the product installer
- Moving the service groups to the second subcluster
- Upgrading the operating system on the first subcluster
- Upgrading the first subcluster
- Preparing the second subcluster
- Activating the first subcluster
- Upgrading the operating system on the second subcluster
- Upgrading the second subcluster
- Finishing the phased upgrade
- Performing an automated VCS upgrade using response files
- Planning to upgrade VCS
- Section V. Adding and removing cluster nodes
- Adding a node to a single-node cluster
- Adding a node to a single-node cluster
- Adding a node to a multi-node VCS cluster
- Adding nodes using the VCS installer
- Manually adding a node to a cluster
- Setting up the hardware
- Installing the VCS software manually when adding a node
- Setting up the node to run in secure mode
- Configuring LLT and GAB when adding a node to the cluster
- Configuring I/O fencing on the new node
- Adding the node to the existing cluster
- Starting VCS and verifying the cluster
- Adding a node using response files
- Removing a node from a VCS cluster
- Removing a node from a VCS cluster
- Verifying the status of nodes and service groups
- Deleting the departing node from VCS configuration
- Modifying configuration files on each remaining node
- Removing the node configuration from the CP server
- Removing security credentials from the leaving node
- Unloading LLT and GAB and removing Veritas InfoScale Availability or Enterprise on the departing node
- Removing a node from a VCS cluster
- Adding a node to a single-node cluster
- Section VI. Installation reference
- Appendix A. Services and ports
- Appendix B. Configuration files
- Appendix C. Configuring LLT over UDP
- Using the UDP layer for LLT
- Manually configuring LLT over UDP using IPv4
- Broadcast address in the /etc/llttab file
- The link command in the /etc/llttab file
- The set-addr command in the /etc/llttab file
- Selecting UDP ports
- Configuring the netmask for LLT
- Configuring the broadcast address for LLT
- Sample configuration: direct-attached links
- Sample configuration: links crossing IP routers
- Manually configuring LLT over UDP using IPv6
- LLT over UDP sample /etc/llttab
- Appendix D. Migrating LLT links from IPv4 to IPv6 or dual-stack
- Appendix E. Configuring the secure shell or the remote shell for communications
- About configuring secure shell or remote shell communication modes before installing products
- Manually configuring passwordless ssh
- Setting up ssh and rsh connection using the installer -comsetup command
- Setting up ssh and rsh connection using the pwdutil.pl utility
- Restarting the ssh session
- Enabling rsh for AIX
- Appendix F. Installation script options
- Appendix G. Troubleshooting VCS configuration
- Restarting the installer after a failed network connection
- Cannot launch the cluster view link
- Starting and stopping processes for the Veritas InfoScale products
- Installer cannot create UUID for the cluster
- LLT startup script displays errors
- The vxfentsthdw utility fails for Active/Passive arrays when you test disks in raw format
- The vxfentsthdw utility fails when SCSI TEST UNIT READY command fails
- Issues during fencing startup on VCS cluster nodes set up for server-based fencing
- Appendix H. Sample VCS cluster setup diagrams for CP server-based I/O fencing
- Appendix I. Changing NFS server major numbers for VxVM volumes
- Appendix J. Upgrading the Steward process
Setting up server-based I/O fencing using installer
You can configure server-based I/O fencing for the VCS cluster using the installer.
With server-based fencing, you can have the coordination points in your configuration as follows:
Combination of CP servers and SCSI-3 compliant coordinator disks
CP servers only
Veritas also supports server-based fencing with a single highly available CP server that acts as a single coordination point.
See About planning to configure I/O fencing.
See Recommended CP server configurations.
This section covers the following example procedures:
Mix of CP servers and coordinator disks | See “To configure server-based fencing for the VCS cluster (one CP server and two coordinator disks)”. |
Single CP server | See “To configure server-based fencing for the VCS cluster”. |
To configure server-based fencing for the VCS cluster (one CP server and two coordinator disks)
Depending on the server-based configuration model in your setup, make sure of the following:
CP servers are configured and are reachable from the VCS cluster. The VCS cluster is also referred to as the application cluster or the client cluster.
The coordination disks are verified for SCSI3-PR compliance.
- Start the installer with the -fencing option.
# /opt/VRTS/install/installer -fencing
The installer starts with a copyright message and verifies the cluster information.
Note the location of log files which you can access in the event of any problem with the configuration process.
- Confirm that you want to proceed with the I/O fencing configuration at the prompt.
The program checks that the local node running the script can communicate with remote nodes and checks whether VCS 8.0.2 is configured properly.
- Review the I/O fencing configuration options that the program presents. Type 1 to configure server-based I/O fencing.
Select the fencing mechanism to be configured in this Application Cluster [1-3,b,q] 1
- Make sure that the storage supports SCSI3-PR, and answer y at the following prompt.
Does your storage environment support SCSI3 PR? [y,n,q] (y)
Provide the following details about the coordination points at the installer prompt:
Enter the total number of coordination points including both servers and disks. This number should be at least 3.
Enter the total number of co-ordination points including both Coordination Point servers and disks: [b] (3)
Enter the total number of coordinator disks among the coordination points.
Enter the total number of disks among these: [b] (0) 2
Provide the following CP server details at the installer prompt:
Enter the total number of virtual IP addresses or the total number of fully qualified host names for each of the CP servers.
How many IP addresses would you like to use to communicate to Coordination Point Server #1?: [b,q,?] (1) 1
Enter the virtual IP addresses or the fully qualified host name for each of the CP servers. The installer assumes these values to be identical as viewed from all the application cluster nodes.
Enter the Virtual IP address or fully qualified host name #1 for the HTTPS Coordination Point Server #1: [b] 10.209.80.197
The installer prompts for this information for the number of virtual IP addresses you want to configure for each CP server.
Enter the port that the CP server would be listening on.
Enter the port that the coordination point server 10.209.80.197 would be listening on or accept the default port suggested: [b] (443)
Provide the following coordinator disks-related details at the installer prompt:
Choose the coordinator disks from the list of available disks that the installer displays. Ensure that the disk you choose is available from all the VCS (application cluster) nodes.
The number of times that the installer asks you to choose the disks depends on the information that you provided in step 6. For example, if you had chosen to configure two coordinator disks, the installer asks you to choose the first disk and then the second disk:
Select disk number 1 for co-ordination point 1) rhdisk75 2) rhdisk76 3) rhdisk77 Please enter a valid disk which is available from all the cluster nodes for co-ordination point [1-3,q] 1
If you have not already checked the disks for SCSI-3 PR compliance in step 1, check the disks now.
The installer displays a message that recommends you to verify the disks in another window and then return to this configuration procedure.
Press Enter to continue, and confirm your disk selection at the installer prompt.
Enter a disk group name for the coordinator disks or accept the default.
Enter the disk group name for coordinating disk(s): [b] (vxfencoorddg)
- Verify and confirm the coordination points information for the fencing configuration.
For example:
Total number of coordination points being used: 3 Coordination Point Server ([VIP or FQHN]:Port): 1. 10.209.80.197 ([10.209.80.197]:443) SCSI-3 disks: 1. rhdisk75 2. rhdisk76 Disk Group name for the disks in customized fencing: vxfencoorddg Disk policy used for customized fencing: dmpThe installer initializes the disks and the disk group and deports the disk group on the VCS (application cluster) node.
- Verify and confirm the I/O fencing configuration information.
CPS Admin utility location: /opt/VRTScps/bin/cpsadm Cluster ID: 2122 Cluster Name: clus1 UUID for the above cluster: {ae5e589a-1dd1-11b2-dd44-00144f79240c} - Review the output as the installer updates the application cluster information on each of the CP servers to ensure connectivity between them. The installer then populates the
/etc/vxfenmodefile with the appropriate details in each of the application cluster nodes.Updating client cluster information on Coordination Point Server 10.209.80.197 Adding the client cluster to the Coordination Point Server 10.209.80.197 .......... Done Registering client node sys1 with Coordination Point Server 10.209.80.197...... Done Adding CPClient user for communicating to Coordination Point Server 10.209.80.197 .... Done Adding cluster clus1 to the CPClient user on Coordination Point Server 10.209.80.197 .. Done Registering client node sys2 with Coordination Point Server 10.209.80.197 ..... Done Adding CPClient user for communicating to Coordination Point Server 10.209.80.197 .... Done Adding cluster clus1 to the CPClient user on Coordination Point Server 10.209.80.197 ..Done Updating /etc/vxfenmode file on sys1 .................................. Done Updating /etc/vxfenmode file on sys2 ......... ........................ Done
- Review the output as the installer stops and restarts the VCS and the fencing processes on each application cluster node, and completes the I/O fencing configuration.
- Configure the CP agent on the VCS (application cluster). The Coordination Point Agent monitors the registrations on the coordination points.
Do you want to configure Coordination Point Agent on the client cluster? [y,n,q] (y) Enter a non-existing name for the service group for Coordination Point Agent: [b] (vxfen)
- Additionally the coordination point agent can also monitor changes to the Coordinator Disk Group constitution such as a disk being accidently deleted from the Coordinator Disk Group. The frequency of this detailed monitoring can be tuned with the LevelTwoMonitorFreq attribute. For example, if you set this attribute to 5, the agent will monitor the Coordinator Disk Group constitution every five monitor cycles.
Note that for the LevelTwoMonitorFreq attribute to be applicable there must be disks as part of the Coordinator Disk Group.
Enter the value of the LevelTwoMonitorFreq attribute: (5)
- Enable auto refresh of coordination points.
Do you want to enable auto refresh of coordination points if registration keys are missing on any of them? [y,n,q,b,?] (n)
- Note the location of the configuration log files, summary files, and response files that the installer displays for later use.
- Verify the fencing configuration using:
# vxfenadm -d
- Verify the list of coordination points.
# vxfenconfig -l
To configure server-based fencing for the VCS cluster
- Make sure that the CP server is configured and is reachable from the VCS cluster. The VCS cluster is also referred to as the application cluster or the client cluster.
- See Setting up the CP server.
- Start the installer with -fencing option.
# /opt/VRTS/install/installer -fencing
The installer starts with a copyright message and verifies the cluster information.
Note the location of log files which you can access in the event of any problem with the configuration process.
- Confirm that you want to proceed with the I/O fencing configuration at the prompt.
The program checks that the local node running the script can communicate with remote nodes and checks whether VCS 8.0.2 is configured properly.
- Review the I/O fencing configuration options that the program presents. Type 1 to configure server-based I/O fencing.
Select the fencing mechanism to be configured in this Application Cluster [1-7,q] 1
- Make sure that the storage supports SCSI3-PR, and answer y at the following prompt.
Does your storage environment support SCSI3 PR? [y,n,q] (y)
- Enter the total number of coordination points as 1.
Enter the total number of co-ordination points including both Coordination Point servers and disks: [b] (3) 1
Read the installer warning carefully before you proceed with the configuration.
Provide the following CP server details at the installer prompt:
Enter the total number of virtual IP addresses or the total number of fully qualified host names for each of the CP servers.
How many IP addresses would you like to use to communicate to Coordination Point Server #1? [b,q,?] (1) 1
Enter the virtual IP address or the fully qualified host name for the CP server. The installer assumes these values to be identical as viewed from all the application cluster nodes.
Enter the Virtual IP address or fully qualified host name #1 for the Coordination Point Server #1: [b] 10.209.80.197
The installer prompts for this information for the number of virtual IP addresses you want to configure for each CP server.
Enter the port that the CP server would be listening on.
Enter the port in the range [49152, 65535] which the Coordination Point Server 10.209.80.197 would be listening on or simply accept the default port suggested: [b] (443)
- Verify and confirm the coordination points information for the fencing configuration.
For example:
Total number of coordination points being used: 1 Coordination Point Server ([VIP or FQHN]:Port): 1. 10.209.80.197 ([10.209.80.197]:443) - Verify and confirm the I/O fencing configuration information.
CPS Admin utility location: /opt/VRTScps/bin/cpsadm Cluster ID: 2122 Cluster Name: clus1 UUID for the above cluster: {ae5e589a-1dd1-11b2-dd44-00144f79240c} - Review the output as the installer updates the application cluster information on each of the CP servers to ensure connectivity between them. The installer then populates the
/etc/vxfenmodefile with the appropriate details in each of the application cluster nodes.The installer also populates the
/etc/vxfenmodefile with the entry single_cp=1 for such single CP server fencing configuration.Updating client cluster information on Coordination Point Server 10.209.80.197 Adding the client cluster to the Coordination Point Server 10.209.80.197 .......... Done Registering client node sys1 with Coordination Point Server 10.209.80.197...... Done Adding CPClient user for communicating to Coordination Point Server 10.209.80.197 .... Done Adding cluster clus1 to the CPClient user on Coordination Point Server 10.209.80.197 .. Done Registering client node sys2 with Coordination Point Server 10.209.80.197 ..... Done Adding CPClient user for communicating to Coordination Point Server 10.209.80.197 .... Done Adding cluster clus1 to the CPClient user on Coordination Point Server 10.209.80.197 .. Done Updating /etc/vxfenmode file on sys1 .................................. Done Updating /etc/vxfenmode file on sys2 ......... ........................ Done
- Review the output as the installer stops and restarts the VCS and the fencing processes on each application cluster node, and completes the I/O fencing configuration.
- Configure the CP agent on the VCS (application cluster).
Do you want to configure Coordination Point Agent on the client cluster? [y,n,q] (y) Enter a non-existing name for the service group for Coordination Point Agent: [b] (vxfen)
- Enable auto refresh of coordination points.
Do you want to enable auto refresh of coordination points if registration keys are missing on any of them? [y,n,q,b,?] (n)
- Note the location of the configuration log files, summary files, and response files that the installer displays for later use.