You can create an IBMHyperSwap® topology system configuration where each control enclosure that is used to access a HyperSwap volume is physically on a different site. When used with active-active relationships to create HyperSwap volumes, these configurations can be used to maintain access to data on the system when power failures or site-wide outages occur.
In a HyperSwap configuration, each site is defined as an independent failure domain. If one site experiences a failure, then the other site can continue to operate without disruption. You must also configure a third site to host a quorum device or IP quorum application that provides an automatic tie-break in case of a link failure between the two main sites. The main site can be in the same room or across rooms in the data center, buildings on the same campus, or buildings in different cities. Different kinds of sites protect against different types of failures.
If configured properly, the system continues to operate after the loss of one site. The key prerequisite is that each site contains one of the control enclosures that are used to access copies of the HyperSwap volume.In the management GUI, the Modify System Topology wizard simplifies setting up HyperSwap system topology. After you configure HyperSwap topology, you can use the Create Volumes wizard to create HyperSwap volumes and copies for each site. In addition, the HyperSwap volume wizard automatically creates active-active relationships and change volumes to manage replication between sites. If you are configuring HyperSwap by using the command-line interface, you must also configure the system topology, volumes, and active-active relationships separately.
http://support.lenovo.com/us/en/products/servers/lenovo-storage
http://support.lenovo.com/us/en/products/servers/lenovo-storage
A HyperSwap system locates the active quorum disk at a third site. If communication is lost between the primary and secondary sites, the site with access to the active quorum disk continues to process transactions. If communication is lost to the active quorum disk, an alternative quorum disk at another site can become the active quorum disk.
A system of nodes can be configured to use up to three quorum disks. However, only one quorum disk can be elected to resolve a situation where the system is partitioned into two sets of nodes of equal size. The purpose of the other quorum disks is to provide redundancy if a quorum disk fails before the system is partitioned.
An alternative configuration can use an extra Fibre Channel switch at the third site with connections from that switch to the primary site and to the secondary site.
A HyperSwap system configuration is supported only when the storage system that hosts the quorum disks supports extended quorum. Although the system can use other types of storage systems for providing quorum disks, access to these quorum disks is always through a single path.
For quorum disk configuration requirements, see the technote Guidance for Identifying and Changing Managed Disks Assigned as Quorum Disk Candidates.