设置配置服务器,以便将物理服务器灾难恢复到 AzureSet up the configuration server for disaster recovery of physical servers to Azure

本文介绍如何设置本地环境,以便开始将运行 Windows 或 Linux 的物理服务器复制到 Azure 中。This article describes how to set up your on-premises environment to start replicating physical servers running Windows or Linux into Azure.

先决条件Prerequisites

本文假设已有:The article assumes that you already have:

  • Azure 门户中的恢复服务保管库。A Recovery Services vault in the Azure portal.
  • 要在其上安装配置服务器的物理计算机。A physical computer on which to install the configuration server.
  • 如果已在要安装配置服务器的计算机上禁用了 TLS 1.0,请确保该计算机上已启用 TLS 1.2 并已安装 .NET Framework 4.6 或更高版本(已禁用强加密)。If you've disabled TLS 1.0 on the machine on which you're installing the configuration server, make sure that TLs 1.2 is enabled, and that the .NET Framework version 4.6 or later is installed on the machine (with strong cryptography disabled). 了解详细信息Learn more.

配置服务器的最低要求Configuration server minimum requirements

下表列出了配置服务器的最低硬件、软件和网络要求。The following table lists the minimum hardware, software, and network requirements for a configuration server.

配置/进程服务器要求Configuration/Process server requirements

组件Component 要求Requirement
硬件设置HARDWARE SETTINGS
CPU 核心数CPU cores 88
RAMRAM 16 GB16 GB
磁盘数目Number of disks 3,包括操作系统磁盘、进程服务器缓存磁盘和用于故障回复保留驱动器3, including the OS disk, process server cache disk, and retention drive for failback
可用磁盘空间(进程服务器缓存)Free disk space (process server cache) 600 GB600 GB
可用磁盘空间(保留磁盘)Free disk space (retention disk) 600 GB600 GB
软件设置SOFTWARE SETTINGS
操作系统Operating system Windows Server 2012 R2Windows Server 2012 R2
Windows Server 2016Windows Server 2016
操作系统区域设置Operating system locale 美国英语English (en-us)
Windows Server 角色Windows Server roles 请勿启用以下角色:Don't enable these roles:
- Active Directory 域服务- Active Directory Domain Services
- Internet Information Services- Internet Information Services
- Hyper-V- Hyper-V
组策略Group policies 请勿启用以下组策略:Don't enable these group policies:
- 阻止访问命令提示符。- Prevent access to the command prompt.
- 阻止访问注册表编辑工具。- Prevent access to registry editing tools.
- 信任文件附件的逻辑。- Trust logic for file attachments.
- 打开脚本执行。- Turn on Script Execution.
了解详细信息Learn more
IISIIS - 无预先存在的默认网站- No pre-existing default website
- 端口 443 上没有预先存在的网站/应用程序侦听- No preexisting website/application listening on port 443
- 启用匿名身份验证- Enable anonymous authentication
- 启用 FastCGI 设置- Enable FastCGI setting
网络设置NETWORK SETTINGS
IP 地址类型IP address type 静态Static
端口Ports 443(控制通道协调)443 (Control channel orchestration)
9443(数据传输)9443 (Data transport)
NIC 类型NIC type VMXNET3(如果配置服务器是 VMware VM)VMXNET3 (if the Configuration Server is a VMware VM)
Internet 访问 服务器需要访问以下 URL(直接或通过代理):Internet access (The server needs access to following URLs - directly or via proxy):
*.backup.windowsazure.cn*.backup.windowsazure.cn 用于复制的数据传输和协调Used for replicated data transfer and coordination
*.store.core.chinacloudapi.cn*.store.core.chinacloudapi.cn 用于复制的数据传输和协调Used for replicated data transfer and coordination
*.blob.core.chinacloudapi.cn*.blob.core.chinacloudapi.cn 用于访问存储所复制数据的存储帐户Used to access storage account that stores replicated data
*.hypervrecoverymanager.windowsazure.cn*.hypervrecoverymanager.windowsazure.cn 用于复制管理操作和协调Used for replication management operations and coordination
https://management.chinacloudapi.cnhttps://management.chinacloudapi.cn 用于复制管理操作和协调Used for replication management operations and coordination
*.services.visualstudio.com*.services.visualstudio.com 用于遥测数据(可选)Used for telemetry purposes (It is optional)
time.nist.govtime.nist.gov 用于检查系统时间与全球时间之间的时间同步。Used to check time synchronization between system and global time.
time.windows.comtime.windows.com 用于检查系统时间与全球时间之间的时间同步。Used to check time synchronization between system and global time.
- https://login.chinacloudapi.cn- https://login.chinacloudapi.cn
- https://secure.aadcdn.microsoftonline-p.com- https://secure.aadcdn.microsoftonline-p.com
- https://login.live.com- https://login.live.com
- https://graph.chinacloudapi.cn- https://graph.chinacloudapi.cn
- https://login.chinacloudapi.cn- https://login.chinacloudapi.cn
- https://www.live.com- https://www.live.com
- https://www.microsoft.com- https://www.microsoft.com
OVF 设置需要访问以下这些 URL:OVF set up needs access to these URLs. 它们由 Azure Active Directory 用于访问控制和标识管理They are used for access control and identity management by Azure Active Directory
https://dev.mysql.com/get/Downloads/MySQLInstaller/mysql-installer-community-5.7.20.0.msihttps://dev.mysql.com/get/Downloads/MySQLInstaller/mysql-installer-community-5.7.20.0.msi 完成 MySQL 下载To complete MySQL download
要安装的软件SOFTWARE TO INSTALL
VMware vSphere PowerCLIVMware vSphere PowerCLI 如果配置服务器在 VMware VM 上运行,则应安装 PowerCLI 版本 6.0PowerCLI version 6.0 should be installed if the Configuration Server is running on a VMware VM.
MYSQLMYSQL 应安装 MySQL。MySQL should be installed. 可以手动安装,或者让 Site Recovery 进行安装。You can install manually, or Site Recovery can install it. (有关详细信息,请参阅配置设置(Refer to configure settings for more information)

配置/进程服务器大小要求Configuration/Process server sizing requirements

CPUCPU 内存Memory 缓存磁盘Cache disk 数据更改率Data change rate 复制的计算机Replicated machines
8 个 vCPU8 vCPUs

2 个插槽 * 4 个核心 @ 2.5 GHz2 sockets * 4 cores @ 2.5 GHz
16GB16GB 300 GB300 GB 500 GB 或更少500 GB or less < 100 台计算机< 100 machines
12 个 vCPU12 vCPUs

2 个插槽 * 6 个核心 @ 2.5 GHz2 socks * 6 cores @ 2.5 GHz
18 GB18 GB 600 GB600 GB 500 GB-1 TB500 GB-1 TB 100 到 150 台计算机100 to 150 machines
16 个 vCPU16 vCPUs

2 个插槽 * 8 个核心 @ 2.5 GHz2 socks * 8 cores @ 2.5 GHz
32 GB32 GB 1 TB1 TB 1-2 TB1-2 TB 150 -200 台计算机150 -200 machines

Note

配置服务器不支持基于 HTTPS 的代理服务器。HTTPS-based proxy servers are not supported by the configuration server.

选择保护目标Choose your protection goals

  1. 在 Azure 门户中,转到“恢复服务保管库” 边栏选项卡,然后选择保管库。In the Azure portal, go to the Recovery Services vaults blade and select your vault.

  2. 在保管库的“资源” 菜单中,单击“开始使用” > “Site Recovery” > “步骤 1: 准备基础结构” > “保护目标” 。In the Resource menu of the vault, click Getting Started > Site Recovery > Step 1: Prepare Infrastructure > Protection goal.

    选择目标

  3. 在“保护目标” 中,依次选择“到 Azure” 和“未虚拟化/其他” ,并单击“确定” 。In Protection goal, select To Azure and Not virtualized/Other, and then click OK.

    选择目标

设置源环境Set up the source environment

  1. 如果没有配置服务器,请在“准备源”中单击“+配置服务器”添加一个。 In Prepare source, if you don't have a configuration server, click +Configuration server to add one.

    设置源

  2. 在“添加服务器”边栏选项卡中,检查“配置服务器”是否已出现在“服务器类型”中。 In the Add Server blade, check that Configuration Server appears in Server type.

  3. 下载站点恢复统一安装程序安装文件。Download the Site Recovery Unified Setup installation file.

  4. 下载保管库注册密钥。Download the vault registration key. 运行统一安装程序时,需要注册密钥。You need the registration key when you run Unified Setup. 生成的密钥有效期为 5 天。The key is valid for five days after you generate it.

    设置源

  5. 在用作配置服务器的计算机上,运行 Azure Site Recovery 统一安装程序安装配置服务器、进程服务器和主目标服务器。On the machine you're using as the configuration server, run Azure Site Recovery Unified Setup to install the configuration server, the process server, and the master target server.

运行 Azure Site Recovery 统一安装程序Run Azure Site Recovery Unified Setup

Tip

如果计算机上的系统时钟时间与本地时间相差 5 分钟以上,则配置服务器注册会失败。Configuration server registration fails if the time on your computer's system clock is more than five minutes off of local time. 在开始安装之前,请将系统时钟与时间服务器同步。Synchronize your system clock with a time server before starting the installation.

  1. 运行统一安装程序安装文件。Run the Unified Setup installation file.

  2. 在“开始之前”中,选择“安装配置服务器和进程服务器”。In Before You Begin, select Install the configuration server and process server.

    开始之前

  3. 在“第三方软件许可证”中单击“我接受”,下载并安装 MySQL。In Third Party Software License, click I Accept to download and install MySQL.

    第三方软件

  4. 在“注册”中,选择从保管库下载的注册密钥。In Registration, select the registration key you downloaded from the vault.

    注册

  5. 在“Internet 设置”中,指定配置服务器上运行的提供程序通过 Internet 连接到 Azure Site Recovery 的方式。In Internet Settings, specify how the Provider running on the configuration server connects to Azure Site Recovery over the Internet. 确保已允许所需的 URL。Make sure you've allowed the required URLs.

    • 如果想要使用当前已在计算机上设置的代理进行连接,请选择“使用代理服务器连接到 Azure Site Recovery”。If you want to connect with the proxy that's currently set up on the machine, select Connect to Azure Site Recovery using a proxy server.
    • 如果希望提供程序直接进行连接,请选择“在不使用代理服务器的情况下直接连接到 Azure Site Recovery”。If you want the Provider to connect directly, select Connect directly to Azure Site Recovery without a proxy server.
    • 如果现有代理要求身份验证,或者你想要使用自定义代理进行提供程序连接,请选择“使用自定义代理设置进行连接”,并指定地址、端口和凭据。If the existing proxy requires authentication, or if you want to use a custom proxy for the Provider connection, select Connect with custom proxy settings, and specify the address, port, and credentials. 防火墙Firewall
  6. 在“先决条件检查” 全局时间同步检查的警告,请检查系统时钟的时间(“日期和时间”设置)是否与时区相同。In Prerequisites Check, Setup runs a check to make sure that installation can run. 如果看到有关全局时间同步检查的警告,请检查系统时钟的时间(“日期和时间”设置)是否与时区相同。If a warning appears about the Global time sync check, verify that the time on the system clock (Date and Time settings) is the same as the time zone.

    先决条件

  7. 在“MySQL 配置”中,创建用于登录到已安装的 MySQL 服务器实例的凭据。In MySQL Configuration, create credentials for logging on to the MySQL server instance that is installed.

    MySQL

  8. 在“环境详细信息”中,如果要复制 Azure Stack VM 或物理服务器,请选择“否”。In Environment Details, select No if you're replicating Azure Stack VMs or physical servers.

  9. 在“安装位置”中,选择要安装二进制文件和存储缓存的位置。In Install Location, select where you want to install the binaries and store the cache. 所选驱动器必须至少有 5 GB 的可用磁盘空间,但建议选择至少有 600 GB 可用空间的缓存驱动器。The drive you select must have at least 5 GB of disk space available, but we recommend a cache drive with at least 600 GB of free space.

    安装位置

  10. 在“网络选择”中,指定侦听器(网络适配器和 SSL 端口),以便配置服务器在其上发送和接收复制数据。In Network Selection, specify the listener (network adapter and SSL port) on which the configuration server sends and receives replication data. 端口 9443 是用于发送和接收复制流量的默认端口,但可以根据环境的要求修改此端口号。Port 9443 is the default port used for sending and receiving replication traffic, but you can modify this port number to suit your environment's requirements. 除了端口 9443 以外,还要打开端口 443,Web 服务器要使用该端口协调复制操作。In addition to the port 9443, we also open port 443, which is used by a web server to orchestrate replication operations. 请不要使用端口 443 来发送或接收复制流量。Do not use port 443 for sending or receiving replication traffic.

    网络选择

  11. 在“摘要”中复查信息,然后单击“安装”。In Summary, review the information and click Install. 安装完成后,将生成密码。When installation finishes, a passphrase is generated. 启用复制时需要用到它,因此请复制并将它保存在安全的位置。You will need this when you enable replication, so copy it and keep it in a secure location.

    摘要

注册完成后,服务器将显示在保管库的“设置” > “服务器”边栏选项卡中。After registration finishes, the server is displayed on the Settings > Servers blade in the vault.

Note

可通过命令行安装配置服务器。The configuration server can be installed via a command line. 了解详细信息Learn more.

常见问题Common issues

安装失败Installation failures

示例错误消息Sample error message 建议的操作Recommended action
错误...未能加载帐户。ERROR Failed to load Accounts. 错误:System.IO.IOException:安装和注册 CS 服务器时无法从传输连接读取数据。Error: System.IO.IOException: Unable to read data from the transport connection when installing and registering the CS server. 确保在计算机上启用 TLS 1.0。Ensure that TLS 1.0 is enabled on the computer.

注册失败Registration failures

可以通过检查 %ProgramData%\ASRLogs 文件夹中的日志来调试注册失败。Registration failures can be debugged by reviewing the logs in the %ProgramData%\ASRLogs folder.

示例错误消息Sample error message 建议的操作Recommended action
09:20:06:InnerException.Type:SrsRestApiClientLib.AcsException,InnerException。09:20:06:InnerException.Type: SrsRestApiClientLib.AcsException,InnerException.
消息:ACS50008:SAML 令牌无效。Message: ACS50008: SAML token is invalid.
跟踪 ID:1921ea5b-4723-4be7-8087-a75d3f9e1072Trace ID: 1921ea5b-4723-4be7-8087-a75d3f9e1072
相关 ID:62fea7e6-2197-4be4-a2c0-71ceb7aa2d97>Correlation ID: 62fea7e6-2197-4be4-a2c0-71ceb7aa2d97>
时间戳:2016-12-12 14:50:08Z
Timestamp: 2016-12-12 14:50:08Z
确保系统时钟上的时间与本地时间之间的偏差不超过 15 分钟。Ensure that the time on your system clock is not more than 15 minutes off the local time. 重新运行安装程序完成注册。Rerun the installer to complete the registration.
09:35:27: 尝试获取所选证书的所有灾难恢复保管库时,引发 DRRegistrationException: :引发了 Exception.Type:Microsoft.DisasterRecovery.Registration.DRRegistrationException, Exception.Message:ACS50008:SAML 令牌无效。09:35:27 :DRRegistrationException while trying to get all disaster recovery vault for the selected certificate: : Threw Exception.Type:Microsoft.DisasterRecovery.Registration.DRRegistrationException, Exception.Message: ACS50008: SAML token is invalid.
跟踪 ID: e5ad1af1-2d39-4970-8eef-096e325c9950Trace ID: e5ad1af1-2d39-4970-8eef-096e325c9950
相关 ID: abe9deb8-3e64-464d-8375-36db9816427aCorrelation ID: abe9deb8-3e64-464d-8375-36db9816427a
时间戳:2016-05-19 01:35:39ZTimestamp: 2016-05-19 01:35:39Z
确保系统时钟上的时间与本地时间之间的偏差不超过 15 分钟。Ensure that the time on your system clock is not more than 15 minutes off the local time. 重新运行安装程序以完成注册。Rerun the installer to complete the registration.
06:28:45: 未能创建证书06:28:45:Failed to create certificate
06:28:45: 安装无法继续。06:28:45:Setup cannot proceed. 无法创建用于在 Site Recovery 中进行身份验证的证书。A certificate required to authenticate to Site Recovery cannot be created. 重新运行安装程序Rerun Setup
确保以本地管理员的身份运行安装程序。Ensure you are running setup as a local administrator.

后续步骤Next steps

下一步涉及在 Azure 中设置目标环境Next step involves setting up your target environment in Azure.