To restart an OpenSwitch server and an RCM instance after the failure of an OpenSwitch server in a redundant environment and, therefore, after the failure of the corresponding RCM instance:
Restart the failed OpenSwitch server.
Stop the RCM instance that is still running (the redundant RCM instance).
Restart the primary and redundant RCM instances (using the -R command line option for the redundant RCM).
This ensures that:
Only one RCM instance is controlling failover
All RCM connections are reestablished to both OpenSwitch servers
User logins to both OpenSwitch servers are handled by the appropriate RCM instance