eviden-logo

Evidian > Products > High Availability Software - Zero Extra Hardware > Siemens SIMATIC WinCC: redundancy & high availability with a very simple active active solution

Siemens SIMATIC WinCC: redundancy & high availability with a very simple active active solution

With the synchronous replication and automatic failover of Evidian SafeKit

How to implement redundancy of Siemens SIMATIC WinCC with a very simple high availability cluster?

The solution for Siemens SIMATIC WinCC

Evidian SafeKit brings redundancy and high availability to Siemens SIMATIC WinCC between two active servers.

This article explains how to implement quickly a Siemens SIMATIC WinCC cluster without specific skills. No specific WinCC configuration is required for redundancy.

The principle of the solution is to put WinCC applications in virtual machines under Hyper-V. SafeKit implements real-time replication and automatic failover of the virtual machines.

No specific hardware, no specific hypervisor

Hyper-V is the native Windows hypervisor included for free in all versions of Windows, even Windows for PC. And SafeKit is working with Windows for servers and PC.

SafeKit is hardware agnostic . It's a pure software solution that does not require any additional hardware. There is no need for a shared disk, a replicated SAN, dedicated disks, dedicated networks.

A Hyper-V cluster with SafeKit

About products under Siemens LMS licensing

  • To avoid the broken Siemens license on failover, the dongle containing the Siemens key can be put in a USB over IP device (like DIGI AnywhereUSB).
  • The dongle can also be put in an external PC with the LMS license server on the PC (for example the PC which manages the Siemens graphical interface).

SafeKit brings two solutions for redundancy and high availability of a SCADA software

Redundancy and high availability at the application level

In this type of solution, only application data are replicated. And only the application is restared in case of failure.

Redundancy at the application level for a SCADA software

With this solution, restart scripts must be written to restart the application. This solution is platform agnostic and works with applications inside physical machines, virtual machines, in the Cloud. Any hypervisor is supported (VMware, Hyper-V...).

  • Solution for a new application (restart scripts to write): Windows, Linux

Redundancy and high availability at the virtual machine level

In this type of solution, the SCADA software is put inside a virtual machine. The full Virtual Machine (VM) is replicated and restarted (Application + OS).

Redundancy at the virtual machine level for a SCADA software

The advantage of this solution is that there is no restart scripts to write per application. This solution is generic for any SCADA software. It works with Windows/Hyper-V and Linux/KVM but not with VMware. This is an active/active solution with several virtual machines replicated and restarted between two nodes.

SafeKit, a recognized solution on the SCADA market

Solution preferred by Siemens

SafeKit with the Siemens Desigo CC SCADA system

SafeKit is available in the Siemens marketplace with its SCADA sofware: Desigo CC (building management), SIMATIC WinCC, SIMATIC PCS 7 and also with the Siveillance suite (video and access control).

SafeKit is deployed by Siemens in Australia, France, the Netherlands, Qatar, Switzerland, the UAE, the UK, the US.

SafeKit chosen by Alstef Group

SafeKit with the Alstef Group SCADA system, BAGware

Alstef Group, a key player in baggage handling systems, deploys SafeKit for redundancy and high availability of its SCADA software suite, BAGware.

SafeKit has been deployed by Alstef Group in many airports with BAGware.

Fives Syleps has chosen SafeKit

SafeKit with the Fives Syleps automated logistics system

Fives Syleps, a key player in automated logistics, deploys SafeKit for redundancy and high availability of its software suite.

SafeKit has been deployed by Fives Syleps in many factories.

Comparison

Built-in Hyper-V replication

Built-in Hyper-V replication

  • Asynchronous replication => data loss
  • Manual failover (no automatic failover)
  • Not a high availability solution

Microsoft clustering (same as VMware HA)

Microsoft clustering / Hyper-V solution

  • Requires a shared disk
  • Price of the shared disk and its installation (SAN, iSCSI)
  • Configuration complexity of Windows failover cluster (AD…)
  • Remote sites = replicated storage

Evidian SafeKit

SafeKit / Hyper-V solution

  • Simple and economical
  • Synchronous replication => no data loss
  • Automatic failover and failback
  • No shared disk
  • Free trial and quick installation guide

SafeKit free trial + Hyper-V mirror module for Siemens SIMATIC WinCC + quick installation guide

How the SafeKit Hyper-V cluster works with replication and failover of Siemens SIMATIC WinCC?

The following steps are described for one virtual machine containing Siemens SIMATIC WinCC inside one mirror module. Each replicated virtual machine runs in an independent mirror module (with a maximum of 25 virtual machines) with a primary server that can be either the Hyper-V server 1 or the Hyper-V server 2.

Step 1. Real-time replication

Server 1 (PRIM) runs the VM (virtual machine) containing Siemens SIMATIC WinCC. SafeKit replicates in real time the VM files (virtual hard disk, VM configuration). Only changes made in the files are replicated across the network.

Synchronous replication in a Hyper-V cluster with Siemens SIMATIC WinCC

The replication is synchronous with no data loss on failure contrary to asynchronous replication.

You just have to configure the VM directory name in SafeKit. There are no pre-requisites on disk organization. The directory may be located in the system disk.

Step 2. Automatic failover

When Server 1 fails, Server 2 takes over. SafeKit restarts the VM containing Siemens SIMATIC WinCC on Server 2. Hyper-V finds the files replicated by SafeKit uptodate on Server 2. 

The VM continues to run on Server 2 by locally modifying its files that are no longer replicated to Server 1.

Failover in a Hyper-V cluster with Siemens SIMATIC WinCC

The failover time is equal to the fault-detection time (set to 30 seconds by default) plus the VM reboot time. 

Step 3. Automatic failback

Failback involves restarting Server 1 after fixing the problem that caused it to fail. SafeKit automatically resynchronizes the VM files.

Failback in a Hyper-V cluster with Siemens SIMATIC WinCC

Failback takes place without disturbing the VM containing Siemens SIMATIC WinCC, which can continue running on Server 2.

Step 4. Back to normal

After reintegration, the VM files are once again in mirror mode, as in step 1. The system is back in high-availability mode, with the VM containing Siemens SIMATIC WinCC running on Server 2 and SafeKit replicating file updates to Server 1.

Return to high availability in a Hyper-V cluster with Siemens SIMATIC WinCC

If the administrator wishes the VM to run on Server 1, he/she can execute a "swap" command either manually at an appropriate time, or automatically through configuration.

Typical usage with SafeKit

Why a replication of a few Tera-bytes?

Resynchronization time after a failure (step 3)

  • 1 Gb/s network ≈ 3 Hours for 1 Tera-bytes.
  • 10 Gb/s network ≈ 1 Hour for 1 Tera-bytes or less depending on disk write performances.

Alternative

Why a replication < 1,000,000 files?

  • Resynchronization time performance after a failure (step 3).
  • Time to check each file between both nodes.

Alternative

  • Put the many files to replicate in a virtual hard disk / virtual machine.
  • Only the files representing the virtual hard disk / virtual machine will be replicated and resynchronized in this case.

Why a failover < 25 replicated VMs?

  • Each VM runs in an independent mirror module.
  • Maximum of 25 mirror modules running on the same cluster.

Alternative

  • Use an external shared storage and another VM clustering solution.
  • More expensive, more complex.

Why a LAN/VLAN network between remote sites?

Alternative

  • Use a load balancer for the virtual IP address if the 2 nodes are in 2 subnets (supported by SafeKit, especially in the cloud).
  • Use backup solutions with asynchronous replication for high latency network.

SafeKit Customers in all Business Activities

  • Best high availability use cases with SafeKit

    Best use cases [+]

  • High availability of video management, access control, building management with SafeKit

    Video management, access control, building management [+]

  • Harmonic has deployed more than 80 SafeKit clusters for TV broadcasting

    TV broadcasting [+]

  • Natixis uses SafeKit as a high availability solution for banking applications

    Finance [+]

  • Fives Syleps implements high availability with SafeKit for automated logistics

    Industry [+]

  • Air traffic control systems supplier, Copperchase, deploys SafeKit high availability in airports.

    Air traffic control [+]

  • Software vendor Wellington IT deploys SafeKit in banks

    Bank [+]

  • Paris transport company (RATP) chose the SafeKit high availability for metro lines

    Transport [+]

  • Systel deploys SafeKit in emergency call centers

    Healthcare [+]

  • ERP high availability and load balancing of the French army (DGA) are made with SafeKit.

    Government [+]

Partners, the success with SafeKit

This platform agnostic solution is ideal for a partner reselling a critical application and who wants to provide a redundancy and high availability option easy to deploy to many customers.

With many references in many countries won by partners, SafeKit has proven to be the easiest solution to implement for redundancy and high availability of building management, video management, access control, SCADA software...

Building Management Software (BMS)

Video Management Software (VMS)

Electronic Access Control Software (EACS)

SCADA Software (Industry)

Demonstrations of Redundancy and High Availability Solutions

SafeKit Overview

Examples of redundancy and high availability solutions with SafeKit.

Full training here

Microsoft SQL Server Cluster

This video shows a mirror module configuration with synchronous real-time replication and failover.

The file replication and the failover are configured for Microsoft SQL Server but it works in the same manner for other databases.

Free trial here

Apache Cluster

This video shows a farm module configuration with load balancing and failover.

The load balancing and the failover are configured for Apache but it works in the same manner for other web services.

Free trial here

Hyper-V Cluster

This video shows a Hyper-V cluster with full replications of virtual machines.

Virtual machines can run on both Hyper-V servers and they are restarted in case of failure.

Free trial here

Redundancy and High Availability Differentiators against Competition

SafeKit Modules for Plug&Play Redundancy and High Availability Solutions

Advanced clustering architectures

Several modules can be deployed on the same cluster. Thus, advanced clustering architectures can be implemented:

SafeKit Technical Documentation

SafeKit Training

Introduction

  1. Overview / pptx

    • Demonstration
    • Examples of redundancy and high availability solution
    • Evidian SafeKit sold in many different countries with Milestone
    • 2 solutions: virtual machine or application cluster
    • Distinctive advantages
    • More information on the web site
    • SafeKit training
  2. Competition / pptx

    • Cluster of virtual machines
    • Mirror cluster
    • Farm cluster

Installation, Console, CLI

  1. Install and setup / pptx
    • Package installation
    • Nodes setup
    • Upgrade
  2. Web console / pptx
    • Cluster configuration
    • Configuration tab
    • Control tab
    • Monitor tab
    • Advanced Configuration tab
    • Troubleshooting
  3. Command line / pptx
    • Cluster administration
    • Module administration
    • Control commands
    • Troubleshooting

Advanced configuration

  1. Mirror module / pptx
    • Mirror's states in action
    • start_prim / stop_prim scripts
    • userconfig.xml
    • Heartbeat (<hearbeat>)
    • Virtual IP address (<vip>)
    • Real-time file replication (<rfs>)
    • How real-time file replication works?
    • Troubleshooting
  2. Farm  module / pptx
    • Farm's states in action
    • start_both / stop_both scripts
    • userconfig.xml
    • Farm heartbeats (<farm>)
    • Virtual IP address (<vip>)
    • Troubleshooting

Advanced configuration

  1. Checkers / pptx
    • Checkers in action
    • userconfig.xml
    • errd checker
    • intf and ip checkers
    • custom checker
    • splitbrain checker for a mirror module
    • tcp, ping, module checkers
    • Troubleshooting

Support

  1. Support tools / pptx
    • How to analyze snapshots?
    • Best practises
  2. Evidian support / pptx
    • Get permanent license key
    • Register on support.evidian.com
    • Call desk