Professional Documents
Culture Documents
High Level Steps For DR Architecture
High Level Steps For DR Architecture
PS (Public Storage) has hosted their Production (US-Central1 region) and DR (US-EAST4 region)
Environment in GCP. Keeping this in mind, the drafted design provides disaster recovery and
restoration using GCP’s native backup and DR service.
Virtual Machines
Cloud Storage
172.20.80.0/24 ps-sb-transit No
172.20.81.0/26 ps-sb-transit-pan-fw No
172.20.96.0/24 ps-sb-mgmt No
172.20.97.0/26 ps-sb-mgmt-pan-fw No
172.20.112.0/24 ps-sb-prod-egress No
172.20.113.0/26 ps-sb-prod-egress-pan-fw No
DR(US-CENTRAL1)
172.20.0.0/24 ps-sb-dr-anc Yes
172.20.129.0/24 ps-sb-dr-domain-infra No
172.20.130.0/24 ps-sb-dr-corp-db No
172.20.131.0/24 ps-sb-dr-pci-db No
172.20.4.0/24 ps-sb-dr-pci-app Yes
172.20.5.0/24 ps-sb-dr-pci-web Yes
172.20.6.0/24 ps-sb-dr-financial Yes
172.20.136.0/26 ps-sb-dr-pan-fw No
172.20.7.0/24 ps-sb-dr-member-svr Yes
172.20.15.0/24 s-sb-dr-dev-app Yes
172.20.192.0/24 ps-sb-dr-mgmt No
172.20.193.0/26 ps-sb-dr-mgmt-pan-fw No
172.20.208.0/24 ps-sb-dr-transit No
172.20.210.0/26 ps-sb-dr-transit-pan-fw No
172.20.224.0/24 ps-sb-dr-egress No
172.20.226.0/26 ps-sb-dr-egress-pan-fw No
Virtual Machines
Confirm the health status of Google compute Engine in US-Central1(Iowa) from GCP cloud
status portal (https://status.cloud.google.com/regional/americas)
Make sure, there are no such service interruption in US-East4(Northern Virginia)
Pause/stop the AD replication between production and DR.
Pause/stop the PCI DB replication between production and DR.
Disconnect the VPN tunnels by disabling the BGP on both production and DR gateway.
Project: ps-shared-host-prj-a6
Hybrid Connectivity > VPN > ha-prod-to-dr-vpn-t2
Edit the BGP session, disable BGP Peer
Connect to the DR PAN Firewall (172.20.210.6), Update the below static routes.
Network>Virtual Routers>default>static Routes
Name: route-to-prod
Destination: 172.20.0.0/17
Interface:
Value:
Reach out to robert.shepherd@zayo.com for changes being carried out in Velo orchestrator.
This would involve the forwarding the property and Glendale traffic towards DR sdwan
firewall instead of production sdwan firewall.
Spin up the VM using the Snapshot which is taken using Backup and DR Google cloud
Service.
Go to Backup and DR Management Console and click on the Backup and Restore Tab
Select the Restore.
Once you're In Restore window search for server, and click on that say next
Select the Snapshot as shown in the screenshot and click on Mount Button.
Once you are in the Mount window, select Mount as New GCE INSTANCE.
Note: If we want to spin a new VM in another Project or in DR Region then you can select the --
Mount as New GCE INSTANCE.
If you want to restore in the Same VM then select Mount TO EXISTING GCE INSTANCE
Select the or Change the Project Name, which Project we have to Build the VM using
Snapshot.
Change the Region as per your requirement and Zone
Please select the Service account of the target Project and paste in the Service account box.
Select the Network and Subnet.
As the name suggested, these are global in nature and do not restrict themselves to any
region, so in case of US-Central1 being unavailable, we would need to change the backend
for the External (Global) load balancers.
The internal (Regional) load balancers would be available in DR with the same name and IP
address assigned to it but the backend would be dummy instance groups which would need
to be replaced by correct instance groups, once we restore the production instances in DR.
Cloud Storage