Seeking Guidance on BeyondTrust Password Safe Cold Spare DR Setup (AWS Multi-Region)
Hi Team,
We are planning to implement a BeyondTrust Password Safe Cold Spare DR appliance in AWS West while our production environment is running in AWS East.
Could anyone share the implementation steps, prerequisites, and best practices for setting up a Cold Spare appliance?
Specifically looking for guidance on:
- Prerequisites before enabling Cold Spare
- Hostname/DNS requirements
- SSL certificate requirements
- Backup and restore process
- Validation/testing after setup
- DR activation procedure during a regional outage
- Failback process once the production region is restored
- Any lessons learned or common issues to avoid
Any documentation, implementation guides, or real-world experiences would be greatly appreciated.
Our production environment consists of an HA pair in AWS US East (10.209.66.xxx/ 10.209.66.xxx) and a Cold Spare appliance in AWS US West (10.207.12.xxx). The Cold Spare KB states that a Temporary Appliance Name must differ from the primary hostname, while the U-Series Business Continuity documentation states that the source and spare appliances must have the same name. Please confirm the recommended hostname configuration during deployment and the required hostname/DNS changes during DR activation.
Thank you.
Billa Shivateja.





