19 Dec 2024 02:52 PM - last edited on 20 Dec 2024 08:09 AM by MaciejNeumann
Hello:
We have a managed cluster environment.
We contract with a business partner that provides several VM application servers and a VM databases to us from their presence in the cloud (I think it is AWS).
Since these are actual VM's, we are wanting to install copies of managed on prem Dyantrace once agents onto the VM's they have specifically dedicated for our company.
If I understand correctly, there are 2 options:
1) Install the Dynatrace One Agent on each of the servers, and have those servers communicated back directly using SSL over port 9999 to our Cluster Active Gate located in our DMZ.
2) Install the One Agent on each of the servers AND bring up an Environment Active Gate in their cloud space. Then the One Agents communicate with the Environment AG, and then the Environment AG communicates back on 443 to our cluster Active gate
I understand that their firewall and routing rules would need to be updated to allow access and communication to our routable address on the Cluster AG.
Are there other factors to consider regarding access and communication since we are the agent in another network, but allowing it to communicate back to the Cluster AG in our network?
Please advise and thank you!
-C
20 Dec 2024 04:10 AM
Hello @runatyr, you got the understanding and I would recommend the second option to reduce the number of exit and entry points of OneAgent communication. Keep in mind every time you add a layer add 1 min delay to your data if it is within the region.
Thanks
Raj
All