Create a DR Site Pair
A DR Site Pair links this site to a second Asternodis controller, your recovery site. Replication and failover happen over this pair. You’ll need Asternodis installed at both sites first.
How pairing works
Pairing is a two-step handshake, done on the Site Pairs page:
- On one controller, create a pair. Asternodis generates a short pairing code and shows this site’s fingerprint.
- On the other controller, join using that code and the peer’s address.
The two sides authenticate each other, pin each other’s fingerprints, and
establish a mutually-authenticated (mTLS) link on the peer port (:8444). Every
message across the link is authenticated against the pair: there’s no global
trust, so one controller can safely hold many independent pairs.
Over the internet
You don’t need a VPN for security: the control channel and VM replication data are mutually TLS-authenticated, and container and ZFS-send replication runs over key-authenticated SSH. A pair works across the internet as long as the documented ports are reachable between the sites. See the port table in Install. At scale, teams often still put the data plane inside a WireGuard/IPsec tunnel because it uses a dynamic per-disk port range. The tunnel is convenient, not a security requirement.
Roles and direction
A pair has a primary (production) and a recovery side, and the roles are fixed. While a guest is failed over, the primary keeps its protection record; a failback returns the workload home, and forward protection from the primary resumes on its own. Nothing swaps roles, and there is no separate reprotect step. A site can hold several pairs, so one recovery site can protect more than one primary; each pair is configured on its own.
Next
- Choose where recovered VMs land: recovery placement.
- Start protecting guests: Replication.