Overview
XDR operates as a control plane layer over the underlying compute and storage infrastructure, orchestrating continuous replication and coordinated recovery across geographically separated sites. Understanding the component architecture helps administrators size deployments, plan network requirements, and diagnose failures effectively.Prerequisites
- Administrator credentials on both primary and DR sites
- Familiarity with RPO/RTO concepts and distributed storage replication terminology
Component Topology
Core Components
Replication Pipeline
Data flows through a multi-stage pipeline from the primary site to the DR site:Change capture
The XDR agent on the primary site intercepts write operations at the storage
layer, capturing changed data blocks as a continuous stream. For
application-consistent replication, the agent coordinates with in-guest
agents to quiesce writes at consistent intervals.
Compression and encryption
The change stream is optionally compressed (recommended for WAN links) and
encrypted using TLS 1.3 before transmission. Compression reduces bandwidth
consumption by 30–60% for typical mixed workloads.
Transfer
The compressed, encrypted stream is transmitted over the replication link
to the DR-site XDR agent. Bandwidth throttling applies during peak hours
if configured.
Apply to replicas
The DR-site agent writes the received changes to the standby storage replicas.
Compute replicas remain stopped — the data is current but the instances are
not running.
Recovery point snapshot
At configurable intervals, the XDR agent creates a recovery point — a
consistent snapshot of the replicated state. Recovery points define the
available restore targets during failover.
Deployment Models
- Active-Passive (Standard)
- Active-Active (Bidirectional)
- Multi-Site Fan-Out
The most common deployment model. One site runs production workloads; the
other site holds warm replicas that activate only during failover.
Control Plane Placement
The XDR controller can be co-located with the primary site or deployed on a separate management network:Network Requirements
All ports must be open in both directions between primary and DR site networks.
Use a dedicated VLAN or MPLS circuit for replication traffic to avoid impacting
production workloads during initial sync or peak change rate periods.
Next Steps
Replication Configuration
Register sites and configure the replication link
Recovery Plans
Define resource groups and recovery ordering
Monitoring
Configure XIMP alerts for replication health
DR Automation
Set up automatic failover triggers and runbook scripts