Failover and Disaster Recovery (DR)

Each BOEv3 session assigned to a TPH will have three total ports available for the TPH’s use:

  • Secaucus Primary port (A)
  • Secaucus Secondary port (B)
  • Chicago DR port (C)

All three ports will have distinct IP addresses assigned. During normal operation, only the primary port in Secaucus (port A) will accept a login request and order/quote traffic. Port B will not accept any login attempts until it is promoted to a primary state due to the failure of Port A. As a result of this design, TPHs may design their system to try to connect to either Port A or Port B and can be confident that the port that accepts their connection is the current primary. Port A and Port B will share common sequences, and in the event of a failover to Port B a TPH should expect sequencing to continue from where it left off on Port A.

The DR port (Port C) will accept login attempts during normal trading operations but will reject all orders and quotes. This means that this port should not be included in a list that the TPH uses for round-robin login attempts on a normal trading day. Port C will reject all orders and quotes until CFE promotes its disaster recovery site to be the primary site. While this may occur intraday, it will only occur only after CFE has provided notification to TPHs. Port C will not share common sequences with Ports A and B. As a result, in the event that a DR failover to the secondary site is performed TPHs should expect all unit sequences to be zero.

To reduce possibility of a single NIC software issue impacting both primary and secondary BOE3 processes Cboe will, by default, configure Port B and C with some features disabled so that a zero value is returned for RequestReceivedTime when Port B or C is promoted to primary state due to the failure of Port A.

Cboe Titanium Cboe Futures Exchange BOEv3 Specification - Failover and Disaster Recovery (DR) | Cboe