Network and computer prerequisites
Before you can start using XProtect Management Server Failover, you must make sure that you go through the following network and computer prerequisites:
-
Operating system - Install two identical operating systems on Node 1 and Node 2. To see a list of supported operating systems, go to https://www.milestonesys.com/systemrequirements/.
-
Addresses - In the same subnet, assign static IPv4 addresses to the nodes and reserve an IPv4 address for the virtual IP. The virtual IP allows the remote servers to connect seamlessly to the running management server.
If the host name and address of a node does not resolve as expected by the system, the configuration might fail. See DNS lookups .
Do not assign IPv6 addresses to the computers that run the management server and external SQL Server. XProtect Management Server Failover does not support the IPv6 protocol.
-
Domain or workgroup environment - Configure the failover cluster in an Active Directory (AD) domain or workgroup environment.
Domain
Use the same AD domain on both nodes.
Workgroup
Prerequisite
Description
Workgroup membership Add Node 1 and Node 2 to the same workgroup. (When without DNS server) Host name mapping Map the host names of the nodes to their IP addresses. See Map the host names of the nodes.
Windows group You must add a new Windows group in XProtect Management Client on both nodes.
Go to Roles and add the BUILTIN/Administrators Windows group to the Administrators role.
Basic user To make sure you can always log in, add a basic user to the Administrators role in XProtect Management Client for the VMS installations on both nodes.
Go to Roles and add an existing basic user or create a new one.
-
Time - Synchronize the time and time zones between the nodes.
-
ICMP traffic - Allow inbound ICMP traffic through Windows Defender Firewall.
-
PowerShell execution policy - Set your PowerShell execution policy to Unrestricted. This allows the configuration wizard to run PowerShell scripts on both nodes. See about_Execution_Policies.
-
Windows Defender Advanced Thread Protection Service - You must disable Windows Defender Advanced Thread Protection Service. See Disable Windows Defender Advanced Thread Protection Service.