About Hitachi block based replication swapping (takeover/takeback)

Ops Center Protector User Guide

Version
7.7.x
Audience
anonymous
Part Number
MK-99PRT002-08
ft:lastEdition
2023-10-26

Protector allows the user to swap the direction of TrueCopy, Universal Replicator and Global-Active Device replications. When a replication is swapped, the S-VOL takes-over the role of the primary volume and the P-VOL takes over the role of the secondary volume. A swapped replication can, of course, be swapped back to its normal state with the P-VOL as the primary and S-VOL as the secondary. The swap operation can also be used to restore consistency between Protector and storage where the direction of a replication in Protector does not match the current actual direction of the replication on storage.

A swap operation is typically performed either because maintenance is required, an application failure has occurred, a storage device has failed or disaster has befallen the primary site. Fail-over to the secondary site is therefore necessary.

For active-passive replications (TC and UR):

  • If both P-VOL and S-VOL are operable and the link between the two sites is available then the replication will be reversed. This is called a swap takeover.
  • If the replication cannot be re-established once in the swapped state (S-VOL to P-VOL), then the pair is placed in the suspend for swapping (SSWS) state until the problem is resolved. Once the problem is resolved, the swap must be completed by retrying the operation. This is called an S-VOL takeover.
  • If a swap fully succeeds, the volume that is now the P-VOL will accept writes, and the volume that is now the S-VOL will not.
For active-active replications (GAD):
  • A swap operation may be performed to move array processing load from the primary to the secondary device. If both P-VOL and S-VOL are operable and the link between the two sites is available, the secondary array will assume the higher processing load.
  • If the replication pair has entered an error or suspended state, then once the problem is resolved, the site with the most recent data must be used to re-establish the replication. Because the replication is active-active and cross-path set-ups are possible, depending on the nature of the fault, the P-VOL or S-VOL could contain the most recent data:
    • If the P-VOL contains the most recent data, no swap is required:
      1. If necessary, unsuspend and unpause the replication.
      2. Resynchronize the replication (via manual trigger or data flow reactivation).
    • If the S-VOL contains the most recent data:
      1. Swap the replication to copy the data from the S-VOL to the P-VOL.
      2. Swap the replication again to restore the original direction. This is optional, but highly recommended.
  • The swap operation will result in the both P-VOL and the S-VOL remaining writable.

The following limitations apply when performing a swap operation:

  • The replication must be implemented using an active live mover; paused or batch replications cannot be swapped.
  • The replication must be implemented using TrueCopy, Universal Replicator or Global-Active Device.
  • Snapshot (TI) and local replication (SI and RTI) operations can be assigned to the P-VOL or S-VOL, however remote replication (TC, UR, GAD and Failover) operations cannot.
  • The state of the takeover is shown on the Monitor page and via the Storage page.
  • The destination proxy node (ISM) must be available and active since it holds the required metadata for the replication.
  • Volumes cannot be added or removed while the replication is reversed or in the SSWS state.
  • When a GAD replication is swapped, the original P-VOL is marked as reserved. If the replication is torn-down whilst in the swapped state, the reserved flag on the original P-VOL will prevent it being reused. By design Protector never modifies P-VOL properties, so the reserved flag must be manually reset. It is only safe to do this if the replication is no longer under Protector's control; as is the case when tear-down is complete.
  • Takeover is not integrated with any application swap automation (high availability fail-over or cluster management) software. Therefore additional steps may be required at the OS and/or application level to complete the process.
  • It is important that Protectors view of the replication direction matches that of the storage. Replications should not be swapped outside of Protector. If this has happened, it is important that the replication direction is corrected to match Protectors direction before any non-swap operations are performed within Protector. This can be done using the swap operation to either alter the replication direction on the storage to match Protector or vice versa depending on the direction chosen in the wizard.