Reprotect & Failback
After a workload has failed over and is running at the recovery site, you usually want to (1) protect it again by replicating it back toward the original site — reprotect — and then, when the original site is ready, (2) move it home — failback.
Reprotect
Reprotect reverses the replication direction. The workload, now running at the former recovery site, becomes the source and replicates back toward the original site. This re-establishes protection so you are not exposed while the workload runs at the DR site.
To reprotect:
- Cockpit: in the recovered VM's Replication tab, choose Reprotect.
- DRM: in the Failover view, choose Reprotect for the workload.
After reprotect, a fresh baseline replicates from the current site back to the original site, and new recovery points appear there.
Reverse pairing is required
Failback replicates from the recovery site back to the primary. For that to work, the reverse site pairing must exist — the primary site must be registered on the recovery Cockpit (and DRM), just as the recovery site was registered on the primary during initial setup. See Pairing Two Sites.
Failback
Failback returns the workload to its original site once that site is healthy again. It is, in effect, a planned migration in the reverse direction:
- Ensure the workload has reprotected and has a recovery point back at the original site.
- Perform a planned failover from the current (recovery) site back to the original site — the workload is gracefully stopped, a final delta is synced, and it boots at the original site.
- Optionally reprotect once more so the original A → B protection direction is restored.
To fail back with a plan: author or use a recovery plan at the recovery-site DRM that targets the recovered workload, and run it as a planned failover toward the original site.
Typical end-to-end sequence
A complete round trip looks like this:
- Failover — workload recovers at Site B (see Failover & Recovery).
- Reprotect — Site B now replicates the workload back to Site A.
- Failback — planned failover returns the workload to Site A.
- Reprotect — restore the original Site A → Site B protection.
Verify at each step
After failback, confirm the workload is running at the original site with all disks attached and its data intact, and that replication has re-established in the intended direction before you consider the round trip complete.