Hi all,
We are currently in the process of getting a Globus subscription, and the matter of how to connect the storage and what we can do with it has come up. Currently, I have a test set up in my DMZ with all the various ports and whatnot translated to a single endpoint with 4 DTNs. Those machines are mounting only a single storage system, a relatively small NAS I have in the DMZ with them.
This leads to a couple of potential issues:
1. Someone (either the users or me) has to transfer data to be shared to that storage system in the DMZ. Given the sizes of data sets involved (10s of terabytes likely), this is going to be a long process. There's also only one of me, so I don't want to be doing this for everyone and their brother, even if I can do it way faster than they can through their workstations.
2. The size of the storage in the DMZ is a couple of orders of magnitude smaller than our internal storage systems.
We are also interested in the use case of using Globus to do internal and internal->dmz data transfers; it's much more palatable to have the users push their data out to the dmz if they can just use the Globus web app to do it and have it go asynchronously. I imagine some users will also want to share internal stuff externally, for whatever that's worth. Not my preference, but all the ways I can think of of making this work would allow that.
Additionally to the internal->dmz transfers and internal->external transfers, it would be really useful to be able to do big asynchronous transfers between internal storage systems. Currently I do these using Starfish (but that's me again), or users can use the HPC cluster, but that doesn't have access to our archive storage system.
What we've been tossing around idea-wise is one of 3 things (and please let me know if there's another way):
1. Mount the internal storage systems on the DTNs in the DMZ through the firewall--this is likely to be slow and cumbersome, and confusing for our network administrators (don't ask...)
2. Multi-home the DTNs so that they have a DMZ interface and an internal interface that can access the internal storage systems. This requires hardening the DTNs and fiddling with routing tables, but that's doable. It's probably the fastest option, both to use and to set up.
3. Set up internal DTNs that are assigned external addresses and ports through the firewall.
Any ideas on how to work through this? My wishlist would be to have a fully internal GCS that I didn't need to have externally resolvable, but I don't think that is an option from what I've read.
Thanks,
Ken