cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
185
Views
0
Helpful
1
Replies

SNA redundant site and HA

ahmedFawzy
Level 1
Level 1

I need to use on-prem SAL to increase FMC events retention on SNA and need to provide high availability between two data centers for my deployment. i also have have cisco telemetry broker.

Would it be the same if 1- i configured ftd syslog to point to broker vip and broker direct it to SNA  2- i used Analytics and logging section in FMC 

Do i need any license ? i only have SAL license but i saw in 7.5.3 that this license should be included in flow rate license.

Is site redundancy is the only way to provide high availability between two DC ?

Does Site Redundancy automatically sync configurations between the two manager ? i saw that i should sync it manually.

Does both sites considered as separate deployments from initial configuration phase perspective? as it is recommended to not install data nodes within same data store at different DC.

1 Reply 1

David Salter
Cisco Employee
Cisco Employee

The licensing model was updated with the release of Secure Network Analytics 7.5.3. The separate SAL on-premises license has been retired, with SAL events now included in the Secure Network Analytics flow rate license so an existing SAL on-prem license will need to be converted when upgrading to 7.5.3.

With regard to high availability between DCs, see page 38 onwards in the Data Store design guide for guidance. (https://www.cisco.com/c/dam/en/us/products/collateral/security/stealthwatch/stealthwatch-data-store-guide.pdf).

With regard to your question around synchronization, the primary Secure Network Analytics Manager will update the secondary automatically however redundancy for SAL data is managed by Data Store (see the guide linked above).  The only time a manual sync may be needed is typically when a Manager has to be replaced or when there is a communication issue between the two Managers.