Configuring clustering for load balancing and failover

Depending on your network topology, you might want to use the special separator characters together to suit more complex configuration scenarios. For example, you might configure the maximum of three tiers for your cluster, but support load balancing within each tier. To illustrate this scenario, you might have appliances with the following IP addresses:

  • First tier:
  • Second tier:
  • Third tier:

When configuring communication for these tiers, you would specify the addresses and tiers like this:||

This example would be translated to the following key server instances:


The connectors will always try to connect to the appliances in the first tier, distributing the workload to both the and appliances. If the appliance with the IP address goes down, all connector traffic is routed to the appliance with the IP address The connector will continue to use only the appliances in the first tier as long as there are appliances available in that tier. If no appliances are available in the first tier—that is, both and become unavailable—the connector will try to connect to the appliances in the second tier.

In most cases, the appliances in different tiers are configured in separate sites, so that appliances in the first tier are closest in the network topology to the client computer—in this case, the connectors—to ensure the best performance. Appliances in the second and third tiers might be in remote sites where the performance is poorer but are only used as a matter of last resort if no appliances in the primary tier are available.

Because clustering support is implemented using the SafeNet KeySecure client libraries, you should refer to your KeySecure documentation for additional information about configuring an appliance cluster.