FDS BCM Migration User Guide - Die Post

2y ago
18 Views
2 Downloads
256.88 KB
9 Pages
Last View : 26d ago
Last Download : 3m ago
Upload by : Sutton Moon
Transcription

FDS BCM migration user guideFile Delivery ServicesConverting to a location-redundant FDS platform

PublisherPost CH LtdInformation TechnologyWebergutstrasse 123030 Berne (Zollikofen)SwitzerlandContactPost CH LtdInformation TechnologyWebergutstrasse 123030 Berne (Zollikofen)SwitzerlandIT261 FDS OperationE-mail: fds@swisspost.chVersion 2.1 / March 2016Download the latest version from: https://www.swisspost.ch/fdsFDS BCM migration user guideVersion 2.1 / March 2016Page2

Contents1.Introduction . 41.1Architecture . 51.2Innovations . 51.3Connections . 62.Introduction . 73.Migration path. 73.1Communication protocol . 73.1.1SFTP – customer to Swiss Post . 73.1.2SFTP – Swiss Post to customer . 73.1.3Connect:Direct . 83.2Communication channels . 83.2.1Internet . 83.2.2Leased connections . 84.System failure procedure . 95.Notes . 95.1DNS caching . 95.2IP addresses . 9FDS BCM migration user guideVersion 2.1 / March 2016Page3

1.IntroductionFile Delivery Services (FDS) is a service provided by the Information Technology (IT) service unit of Post CH Ltd.FDS acts as a gateway in the IT security system between Post CH Ltd’s intranet and external networks. Itenables files and applications to be exchanged among internal and external partners.Due to the audit requirements placed on Post CH Ltd, the service will be operated as geographically redundantfrom Q1 2016.This user guide will help existing customers to migrate to the location-redundant solution, hereinafter referredto as “FDS BCM”.Swiss Post IT assumes no responsibility for the accuracy of the information in this user guide and reserves theright to correct errors and make changes.FDS BCM migration user guideVersion 2.1 / March 2016Page4

1.1ArchitectureThe high-availability service will be expanded to an additional location in order to cover the outage of a datacenter.The distribution of communications over two locations is accomplished using DNS load balancing (RoundRobin). This means that the IP addresses of both locations are returned alternately for DNS resolution.1.2InnovationsThe following fundamental innovations will come with the new architecture:-Introduction of a secondary location-Introduction of DNS load balancing (Round Robin)-DNS name changeoIntegrationOLD: fdsi.post.chNEW: fdsbci.post.choProductionOLD: fds.post.chNEW: fdsbc.post.ch-IPv4 and IPv6 supportThe use of IPv6 is optional and requires continuous support of IPv6 in the customer’s infrastructure.The user and authentication information remain unchanged. Similarly, there is no change to the directories andthe files that are already stored in the directories. The amendments to be made by the customer are describedin section 3.FDS BCM migration user guideVersion 2.1 / March 2016Page5

1.3ConnectionsThe customer must ensure that communication to or from “FDS BCM” is allowed in his/her network. Usuallythe network team has to allow connections with the appropriate firewall rules.Two IP addresses will now be used. These IP addresses may be used only for configuring firewall rules. It isessential that the DNS name is used (see sections 1.2 and 5.1) for the connection setup.Production and integrationIP location 1IP location 2The IP addresses can be requested at any time fromfds@swisspost.ch.The IP addresses can be requested at any time fromfds@swisspost.ch.Alternatively, both IP addresses can be determined with several DNS lookup requests (for example, nslookupfdsbc.post.ch).FDS BCM migration user guideVersion 2.1 / March 2016Page6

2.IntroductionThe introduction of FDS BCM includes the amendments made to the platform by Swiss Post InformationTechnology in February 2016. Customers are responsible for using FDS BCM via the interfaces.3.Migration pathThis section describes the migration paths for each connection type. The connections are based on thecustomer’s point of view.3.1Communication protocol3.1.1 SFTP – customer to Swiss PostCommunication is set up by the customer (the customer application is the client).CustomerFDS BCMSwiss Post unit1) Ensure that both FDS locations are accessible. (See section 1.3). This is the customer’s responsibility.2) Convert the communication setup to integration fdsbci.post.ch or to production fdsbc.post.ch(customer)For the initial connection setup using the new DNS name, accept the host key with the IP address IPlocation2, if required.Please do not use the IP address(es) (see section 5.2)3.1.2 SFTP – Swiss Post to customerCommunication is set up by Swiss Post (the customer application is the server).Swiss Post unitFDS BCMCustomer1) If the customer needs to define firewall rules for incoming and/or outgoing connections during startup:o Ensure that both FDS locations can access the customer systems (see section 1.3). Theresponsibility lies with the customer. The customer is not required to notify Swiss PostInformation Technology.2) FDS BCM sets up connections from both locations to the customer system. Post CH Ltd automaticallyensures this as soon as point 1) is complete.FDS BCM migration user guideVersion 2.1 / March 2016Page7

3.1.3 Connect:DirectCustomer C:D NodeFDS BCM C:D NodeSwiss Post unitIf Connect:Direct is used as the communication protocol, customers must ensure that communication can alsobe set up for the primary node as well as the alternate node.The alternate node will be used automatically in the event of a system failure. If communication is via a leasedconnection, automatic switching only functions if the leased connections are available to both locations andconstantly active (see section 3.2.2)-Alternate nodeConfigure with a new IP address IP location2Primary nodeConfigure from current IP address IP location1Customers are requested to inform Swiss Post of their progress (by e-mail to fds@swisspost.ch).We also recommend customers migrate interfaces from Connect:Direct to SFTP.3.2Communication channelsThe migration paths differ depending on the type of connection.3.2.1 InternetIf the connection is via the Internet, see the relevant information in section 3.1.3.2.2 Leased connectionsTo ensure that file transfers continue to function in the event of a system failure, there must be a second activeleased connection to the second location. The leased connection must be ordered by the customer.For connections from partners via external networks (MPLS) and via site-2-site VPN, network address translation(NAT) is often used by the customer. This is beyond Post CH Ltd’s control.-As the client, FDS needs to amend the IP address in the event of a system failure in order toaccess the customer system via the second leased connection.For connections to FDS (FDS as server), the partners must use the other IP address in theevent of a system failure.We ask customers to inform Swiss Post (fds@swisspost.ch) if, in the event of a system failure,manual configuration changes have to be made by the customer (only for leased andConnect:Direct connections).Swiss Post Information Technology recommends that customers communicate via the Internet ifpossible.FDS BCM migration user guideVersion 2.1 / March 2016Page8

4. System failure procedureIn the event of a system failure, manual interventions or configuration changes are necessary only for leasedconnections (see section 3.2.2).By setting up an appropriate Connect:Direct configuration and corresponding leased connection (constantlyactive), preparations have been made to render manual action unnecessary in the event of a system failure.5. Notes5.1DNS cachingThe platform operates in active/active mode at two locations. The failover mechanism is guaranteed by aGlobal Server Load Balancing (GSLB) infrastructure. In order to benefit quickly from this failover mechanism,the customer must ensure that no additional DNS caching is done in his/her environment. The Time to Live(TTL) specification given by Swiss Post’s DNS must be respected.5.2IP addressesFDS BCM must be used via the DNS name. The IP addresses are only to be used to create firewall rules, exceptin the following cases:-Use of the Connect:Direct protocolLeased connectionsFDS BCM migration user guideVersion 2.1 / March 2016Page9

FDS BCM migration user guide Version 2.1 / March 2016 Page 4 1. Introduction File Delivery Services (FDS) is a service provided by the Information Technology (IT) service unit of Post CH Ltd. FDS acts as a gateway in the IT security system between Post CH Ltd’s intranet and external networks. It

Related Documents:

global data center portfolios in the industry 2,500 customers financially stable for the long term (5)metropolitan bbb bbb 33 areas (1) 150 properties (1) 26 . rpp bcm bcm bcmpdu basement 2nd floor rpp 3rd floor ups rpp bcm bcm bcm rpp bcm bcm bcm rpp bcm bcm bcm rpp bcm bcm bcm ups rpp

FDS and Opt-in Builder User Guide Advice Technology April 2019 Version 1.1 . 1 1 Introduction The FDS and Opt-in Builder allows you to produce either the FDS, Opt-In or both letters combined. The FDS will provide you with a letter that includes your services provided to the client and their fees for the

FDS Simulation FDS Support To automate the process of simulation runs, for each configuration an fds-manager script was created which provides for the following actions: it accepts and checks input arguments specifying the FDS input file and cluster configuration (the number of nodes, cores, and eventually the number of MPI

Facility Data Sheet Guide The Facility Data Sheet (FDS) is a means of reporting certain demographic information and data to Baby-Friendly USA (BFUSA). This guide provides instructions for facilities on completing and submitting the FDS. Completing the FDS web form The FDS is submitted directly through the BFUSA website portal as a web form.

Fire Dynamics Simulator with Evacuation: FDS Evac Technical Reference and User's Guide Abstract This document describes how to simulate human egress using the evacuation module, FDS Evac, which is fully embedded in Fire Dynamics Simulator (FDS). This manual applies to the FDS Evac version is 2.1.1, which is

Data Migration Planning Analysis, Solution Design and Development Mock Migration Pilot Migration Released Data Migration Active Data and User Migration Inactive Data Migration Post Migration Activities Small Bang The details for each step include: Data Migration Planing - Develop the migration strategy and approach, and define the scope,

Courtesy of FORD MOTOR CO. REMOVAL AND INSTALLATION BODY CONTROL MODULE (BCM) INSTALLATION NOTE: If installing a new BCM, the ignition cannot be turned on until a parameter reset is performed and 2 keys are programmed to the vehicle. The BCM still communicates with the scan tool with the ignition off. Use the previous scan tool session or

An Introduction to Description Logics Daniele Nardi Ronald J. Brachman Abstract This introduction presents the main motivations for the development of Description Logics (DL) as a formalism for representing knowledge, as well as some important basic notions underlying all systems that have been created in the DL tradition. In addition, we provide the reader with an overview of the entire book .