Skip to content
A Practical Guide to Symantec PAM Secondary Sites

A Practical Guide to Symantec PAM Secondary Sites

Security •Mickey • September 29, 2026

Placing secondary sites near regional target devices minimizes session path distance and reduces lag for privileged users.

Deploying two nodes at standard regional sites provides local high availability and handles session capacity without downtime.

Using three nodes at secondary sites is reserved exclusively for warm disaster recovery locations to maintain fault tolerance after promotion.

In our post, Why "Less Is More" in Symantec PAM Clustering , we talked why keeping your primary site lean (ideally three-nodes) is the secret to fast, reliable replication. A tightly scoped primary site keeps database consensus running at peak performance.

That covers your primary site. Now for the rest of your nodes: how many nodes do you need at each secondary site, and where should those sites go?

Extending PAM with secondary sites

Extending PAM to a new location means adding appliances to your existing cluster. Each appliance is self contained, so a new site is simply additional PAM nodes deployed where you need them.

Secondary Sites 101: Put sites close to the devices

Every privileged session to a target device connects through a PAM node, and that makes site placement easy.

When a PAM node is geographically closer to the target device, the session path is short. Every keystroke and screen refresh has less distance to cover, for the entire life of the session.

Adding a secondary site is reducing latency for the privileged user. When target devices are far from your main data center, or the network path to them is variable, placing a secondary site in that region keeps those sessions local, reducing potential lag.

You can place a secondary site wherever your target devices are, regardless of distance, because replication between sites is asynchronous. The primary site commits updates locally and streams them out in the background, so it never waits on a remote site. The connection does not need to be perfect either. If the link between sites degrades or goes down, the secondary site recovers gracefully and applies the transactions it missed once connectivity returns.

The standard secondary site: Why 2 nodes is the sweet spot

For almost every regional secondary site, two-nodes is the right number.

1. Right-sized high availability

With two-nodes, Symantec PAM shares the workload across both appliances. If Node A goes offline for maintenance or a hardware issue, new connections are directed to Node B and the site keeps serving users.

When a node rejoins the cluster after maintenance, it rebuilds its local database copy before returning to service. With a second node in the site, users on Node B and new connections stay active while that happens.

One caveat, because it is easy to miss: two-nodes only help if they can fail separately. Two virtual appliances on the same host, the same datastore, or behind the same switch a single point of failure. Use anti-affinity rules to keep them on separate hosts, and give them independent storage and network paths.

2. High session capacity out of the box

A single Symantec PAM appliance can handle significantly more concurrent privileged sessions than the competition. So you rarely need to stack extra nodes at a secondary site just to keep up with user traffic. In standard enterprise deployments, two-nodes easily handle regional demand.

3. Scaling does not require downtime

If your regional datacenter suddenly grows, you do not need to provision for peak on day one. Symantec PAM allows you to add nodes dynamically to an active secondary site whenever you want, without taking down the cluster or interrupting user access.

The strategic exception: When to choose 3 nodes

If two nodes are the standard, when do you need three? When the site is your dedicated, warm disaster recovery (DR) location.

If your primary data center goes offline, you promote a secondary site to take its place, and it becomes your primary. A primary site commits changes only when a majority of its members agree. A two-node site will run your environment. A three-node site adds margin: the majority is two, so a node can be down and the new primary site keeps working.

4 key things to remember

Stick to two secondary site nodes for everyday access sites. You get local high availability without paying for capacity you will not use.

Choose three secondary site nodes for dedicated DR targets. Ensure your fallback site retains full fault tolerance if it ever becomes the active primary.

Isolate your hardware. Separate physical hosts, storage, and network paths.

Scale on demand. Keep things simple and add secondary nodes whenever your business needs to expand.

Ready to optimize the rest of your deployment? Check out our article, Why "Less Is More" in Symantec PAM Clustering , for a primer on keeping your primary site lean and fast.

And for a deeper dive

Symantec PAM Documentation: Set Up a Cluster

Symantec PAM Documentation: Cluster Synchronization, Promotion, and Recovery

Extracted Entities

Companies (1)

Platforms (1)