Cisco AAA/Identity/Nac :: 1120 - Registering ACS 5.2 Instance To Primary

May 29, 2013

When attempting to register an ACS instance to a primary (via System Administration -> Operations -> Local Operations -> Deployment Operations), I receive the following error as a popup in my browser:
 
"This System Failure occurred:  /opt/CSCOacs/db/acs.crt (No such file or directory). Your changes have not been saved.Click OK to return to the list page."
 
I had 2 ACS 1120 appliances clustered, 1 suffered a hardware failure about a year ago so I replaced it with a VM. That one is now the primary. I'm now wanting to replace the secondary instance (the remaining 1120 appliance) with a VM as well. I removed the current appliance from the network, installed the VM using the same IP address, and attempted to register. It failed as per the above error. After trying this a number of times, I then decided to return the 1120 appliance to secondary status and attempted to register it with the same results as above.

View 3 Replies


ADVERTISEMENT

Cisco AAA/Identity/Nac :: Multiple Instance Of Custom Attributes ACS 5.x?

Nov 27, 2011

is there a way to have multiple instances of user custom attributes and insert those as multiple instances of the A/V Pair in the authorisation profile in ACS 5.2/5.3 ?Background: We have to migrate a ACS 4.2 to 5.3. In ACS 4.2 our client used the multiline attribute
 
Number
#Name
#Description
#Type of Value
#Inbound/Outbound

[code]....

to specify multiple routes to various networks in the RADIUS reply spcific for every single PPP username of routers dialing in.Using the internal user database, extended by a string attribute and using that attribute as source of a dynamic value in the access-policy works basically. But as I have only ONE single line instance of the attribute for every user, I can only return ONE framed-route.We have lots of cases where multiple routes have to be assigned to one router.I 'd like to avoid defining a seperate access profile for every remote RAS router for external PPP Dial-In...[URL]

View 1 Replies View Related

Cisco AAA/Identity/Nac :: ACS 5.4 - Audit Logs Operated By Secondary Instance?

Mar 28, 2013

I'm using ACS 5.4p2 within distributed systems: one primary and one secondary instance.For now, primary instance is acting as Log Collector server and I can see any AAA audit logs.

When the primary instance fails I can authenticate successfully using the secondary instance.However, when primary instance comes back, I'm not able to see any audit logs operated by secondary.

View 9 Replies View Related

Cisco AAA/Identity/Nac :: Maximum Number Of AAA Clients Supported By Single ACS5.3 Instance

Aug 7, 2012

what is the maximum number of AAA clients supported by a single ACS5.3 instance?

View 1 Replies View Related

Cisco AAA/Identity/Nac :: ACS 1120 - How Many Devices (MAB) Can Be Authenticated

Jan 23, 2012

I´m currently looking for a document that specify how many MAC addresses can be stored and authenticated via an ACS (1120)? I prefer to use the internal identity store over AD or LDAP for MAB authentication for 802.1X project. I would like to know what is the impact on the ACS? CPU/MEM? What is the impact on the user authentication? delay, timeout, etc.

View 7 Replies View Related

Cisco AAA/Identity/Nac :: Enabling ICMP On ACS 1120?

Feb 28, 2011

We have downgraded cisco acs appliance 1120 from ACS 5.0 to ACS 4.2.1.15 , when we perform ICMP ping request to acs appliance its not responding , But i can do ping test from acs appliance on console mode not  from GUI mode .
 
Is there any option to enable ICMP Ping response on cisco acs 1120 . else any patch to be upgraded to perform this action , my requirement is enable ICMP ping on acs appliance for troubleshooting . instead always check with telnet x.x.x.x 2002 for service responding

View 5 Replies View Related

Cisco AAA/Identity/Nac :: ACS 1120 And RAID Configuration?

Jul 4, 2011

I encountered some strange issues with one of our appliances in the field. Reinstalled and encountered the strange issues. No errors.. did some memory test and the seagate harddisk test and encountered SMART errors. The device didn't log those errors anywhere.. First reason to check the second harddisk. The appliance is shipped with two so the first thing I was thinking of was RAID. I saw that raid wasn't configured. Try to boot the second harddisk and saw that nothing was on that disk.. so what is the mean reason you got two of those? Got the new machine and try some options to configure RAID.You got two options.. didn't see this before, most of the time you got only one option. Raid driver on or no RAID configuration at all. First tried the intel storage matrix, configured both of the disks for mirror and install the ACS 5.2. The machine boots after installs and rejects the DVD. Result: The installation doesn't boot! Checked the partition with gparted but the partition is active (or flagged as boot) Second option was LSI, got the raid configured for mirror and the installation was also completed. Result: working installation. Tried to test if the installation is still working after removing one of the disks. Appliance is complaining the the RAID is missing one disk (so this works). After that the machine tries to boot, result: no working ACS.

View 1 Replies View Related

Cisco AAA/Identity/Nac :: 1120 ACS 5 - Remote Log Targets?

Mar 19, 2012

I have configured the appliance everything is working fine.We have a remote syslog server and I have configured the  remote syslog server details in the "Remote Log Targets" and  and Logging Categories.But I cannot see any logs on my syslog server  

View 4 Replies View Related

AAA/Identity/Nac :: CSACS-1120 - How To Export License From ACS

Jul 22, 2012

I have an ACS applicance that had a version 5.1 and i did an upgrade to 5.3 with latest patch.For some reason, the runtime process got stuck in (reinitializing and restarting) state.i did the recommended action to perform ACS stop and ACS start and even hard reset of the appliance, but it did not cut itThis process turned out to be a bug and it should have been fixed in version 5.3, but it has not i guess
 
i know that acs reset-config will solve the issue, but i have a problem here , the license file will be deleted as well with the config and i cannot find a way to export the license and then import it into the reseted config ACS hardware. Unfortunately, the license file is not saved anywhere in the company and i cannot affort to lose it.how to export the license from the applicance (CSACS-1120)?

View 3 Replies View Related

Cisco AAA/Identity/Nac :: ACS 1120 Running 5.0.0.21 RADIUS Timeout With WLC 7.0?

Aug 29, 2011

i am configuring a Cisco Secure ACS 1120 appliance running ACS 5.0.0.21 to handle RADIUS request from a Cisco WLC 5508 appliance running version 7.0.116.0.these devices have open communication on all ports - no firewalls or ACL'sthey have successful ping communication The following statements illustrate some but not all the debugging I have done to ensure each device functions as it should in isolation.Using a simple windows RADIUS server (radserv2.exe) instead of the Cisco ACS  This works and the WLC gets RADIUS response from my makeshift serverUsing a simple windows EAP client to query the ACS using RADIUS protocol   this works and the ACS processes the RADIUS request and sends a responsePlaced a wireshark client on the network to inspect timeout. Wireshark logs the packet from the WLC to the ACS using port 1812 but doesn't see any packet  responses from the ACS At the moment I have the WLC accepting the association from the wireless client and sending the RADIUS (PEAP, EAP-FAST or EAP-TLS) request to the ACS, the WLC receives no response and generates a timeout message and disassociates from the client. note this is not a reject or similar message, the ACS simple does not even process the packet. i.e. there is absolutely nothing in the ACS logs to suggest it even received a radius packet from the WLC. In summary the WLC and the ACS successfully function independently but they do not communicate via radius.

View 3 Replies View Related

Cisco AAA/Identity/Nac :: 1120 - Error Opening Acs Logs

Mar 6, 2013

I have problem with ACS 5.0 on reporting.  On "Monitoring and Report" page  in  Faverite Reports when i clicking on "Authentications - RADIUS - Today", My browser displays error "Error while reading skin-access.config. Please make sure the file exists and conforms to the schema specified"
 
I must also mention that I never upgraded the version of ACS from 5.0 also from command line all the acs services are running. It is running on CISCO 1120 Secure Access Controll Server apliance.
 
My second question is can I upgrade the version of ACS to 5.4 with Cisco Secure ACS 5 Base License?

View 4 Replies View Related

Cisco AAA/Identity/Nac :: ACS 5.0 0n 1120 Appliance Stopped Booting

May 10, 2012

I have an acs 5.0 running on Cisco 1120 appliance. It has worked for 2 years. Suddenly, I discovered that user can no longer login with their credentials. On close examination, when I console, the booting does not complete. Screen shot attached.

View 3 Replies View Related

Cisco AAA/Identity/Nac :: ACS-1120 Large Deployment License?

Mar 26, 2011

i  have 4 X ACS-1120. Each 2 are operating as an Primary and backup. I  want to add a license in order for the ACS to support more than 500  networks which includes in the base license.As I understand this is the license required : L-CSACS-5-LRG-LIC=
 ·        
Is this license applicable to ACS-1120 appliance with ver 5.2 ? – I understand that it is. for my scenario, do I need to purchase total of 2 X L-CSACS-5-LRG-LIC=  (one for each environment, one license will serve 2 X ACS in Primary  and Backup) or I need to purchase 4 licenses each for each ACS ? – I  understand that one license will serve deployment of two ACS in primary  and active scenario. 

View 1 Replies View Related

Cisco AAA/Identity/Nac :: CSACS-1120 To Active Directory Without Success

Apr 18, 2011

I'm trying to join a band new CSACS-1120 to our active directory without success. The process in it self should be pretty straigh forward, but so far no luck.
 
I've configured the relevant info under "Users and Identity Stores > External Identity Stores > Active Directory.
 
Active Directory Domain Name: xxx.com
Username/Password : domain administrator account
 
When I test connection I get a info dialog "This machine is currently connected to domain xxx.com".After which I try to save changes which gives a reply ""This System Failure occurred: {0}. Your changes have not been saved. Click OK to return to the list page."
 
I've noticed that in the system log "show logging system tail" that I get a exception as soon as I enter the AD configuration page and subsequently every time I perform a action on that section.
 
Why the AD join keeps on failing and what the debug exception I'm getting means?

View 3 Replies View Related

Cisco AAA/Identity/Nac :: Test EAP TLS Authentication On ACS 4.2.1.15 Running On Appliance 1120

May 2, 2011

i am trying to test EAP_TLS authentication on acs 4.2.1.15 running on Appliance 1120 , I have installed my server certficate along with CA certficate on my appliance box , I have enabled features of  EAP_TLS under golbal authentication setup .
 
I have downloaded client supplicant certficate file for my windows XP machine .When i tried to authenticated i am finding following error message under  failed attempts(EAP-TLS or PEAP authentication failed due to unknown CA certificate during SSL handshake) on my acs appliance box .Under certficate revocation list , I have forced my CA as CRL in use . Attached snap shot of all .

View 2 Replies View Related

Cisco AAA/Identity/Nac :: Required Patch For ACS Appliance 1120 Version 4.2.15.3

May 4, 2011

Need URL for patch 4.2.1.15.3  with comptaible for cisco acs appliance 1120 . Though its for appliance patch should be along with webserver . I have downloaded patch of SE its not comptaible to this hardware .

View 4 Replies View Related

AAA/Identity/Nac :: Upgrade From 5.1 To 5.2 By Having Smarnet On 1120 Secure ACS Appliance?

Mar 13, 2011

Am I entitle to upgrade from 5.1 to 5.2 by having smarnet on my 1120 Secure ACS Appliance?

View 1 Replies View Related

AAA/Identity/Nac :: Windows ACS 4.2.0 Backup Database On 1120 Appliance 4.2.1.15?

Apr 26, 2011

I am running windows based acs 3.3 in my lan environment going to be replaced with acs 1120 appliance running acs 4.2.1.15 , ACS 3.3 database has been built upto  4.2.0.124 ,step by step by upgrade process
 
1) acs 3.3.3.14---> 4.1.1.24
2) acs 4.1.1.24 ----> 4.2.0.124 .
 
now my database is with 4.2.0.124 dmp file , I cannot upgrade my database to 4.2.1.15 because 4.2.1.15 patch is not applicable & executable  on 90 days evalution package of 4.2.0.124 of windows platform .
 
can i import my windows based 4.2.0.124 datbase directly to my acs appliance running 4.2.1.15.3 ??? , else its requires any step to be done to modify the windows based databse matching to appliance windows verison once .
 
I could see on appliance under restore settings the following options (restore from 4.2.0 backup file to acs 4.2.1)

View 8 Replies View Related

Cisco AAA/Identity/Nac :: 1120 - Account Disablement On Specific Date Feature On ACS 5.2

Nov 7, 2011

I have ACS 1120 ACS appliance running ACS version 5.2.0.26.5 ,authenticating VPN users connecting from internet using radius protocol , we have requirement that VPN user account should be disabled by a specific date , Means user ID should be revoked when their contract expire connecting to our data center .
 
I know this feature is available on ACS version 4.2.,but i could not this feature set on ACS 5.2.0 when user account is created , whether any new sepicfic patch has this feature enabled after acs version 5.2.0.26.5.
 
With out this feature this set , i cannot ensure ID are revoked automatically ,when specific date come in to end user.

View 1 Replies View Related

AAA/Identity/Nac :: SSL Certificate Installation On Acs Appliance 1120 For PEAP Clients

Apr 18, 2011

I need this SSL certficate installation on my acs appliance 1120 for PEAP clients.I have exported SSL server certficate from my old acs 3.3 server which is under acscertstore folder issued by CA vendor . I need to reuse this same SSL certificate on my acs appliance .ACS appliance certficate setup requires following two certificate to be installed for PEAP clients authentication

1) Server Certificate

2) CA certificate
 
Server Certificate : For server certifcate , I have my old certificate which is exported from my old acs 3.3 server , when i tried to download my server certficate via ftp server on my acs appliance , its looking for private key & private key file .Private key & file is generated intially on CSR request when this server certificate is requested to CA vendor for my old acs 3.3 . I dont know the private key password . If i need private key & file , then i need to generate new CSR from my acs appliance and i need to submit this CSR output to my CA vendor to generate new SSL server certificate .which is something like new server certificate request .CA certficate : For CA certficate , when i open my existing SSL certificate under detials tab in CRL distribution point , i could see below URL . whn i open this URL it giving certificate revocation list . [1]CRL Distribution Point.

View 10 Replies View Related

Cisco AAA/Identity/Nac :: Database Is Not Lost On Primary ACS 5.1

Apr 23, 2013

We have recently upgraded acs 5.1 to 5.3 ( normal upgrade process), all secondary (ACS-B) was deregistered from primary (ACS-A , used as configuration server and log collector) and updated successfully.  But while upgrading primary acs server was rebooted manually. But later primary server was re upgraded successfully to 5.3.
 
Just to ensure database is not lost on primary acs (ACS-A) , primary acs was registered to one of the secondary acs (ACS-B). Initially  ACS-A registered with ACS-B, both ACS was showing proper role now. ACS-A ( secondary ) and ACS-B (primary). But on New primary ACS (ACS-B) is showing new secondary (ACS-A) offline and replication pending. Whereas on Secondary ACS-B its shows primary ACS-A online and updated. But ACS replication id is gradually incrementing. ACS system is in this system for last 2 day, But not sure if there is real replication happening at backend? How long it take place to replicate completely? and how to check / verify status of upgrade?       

View 3 Replies View Related

Cisco AAA/Identity/Nac :: ACS 5.3 Primary / Secondary Same License?

Jan 22, 2012

I have a question about the number of Cisco licenses needed in two cases for ACS 5.3 Virtual Machine.One primary + One secondary : Just one license for all or one license for the primary + another one for the secondary ?One primary + several secondaries : Just one license for all or one license for the primary + just one license for all the secondaries ? 

View 1 Replies View Related

AAA/Identity/Nac :: Primary ACS 5.2 Lost Connection?

Apr 9, 2012

I have a 802.1x solution with two redundant ACS 5.2. Network A configuration use like Primary ACS-SJM and ACS-GLX like a secondary for network B configuration use like Primary ACS-GLX and ACS-SJM like a secondary. My solution was working fine about one year ago. but one week ago isn´t working fine. The problem my ACS-SJM lost connectión and user can´t authenticated  when the user trye to connect to ACS-GLX either can´t connect. I have to shutdown the ACS-SJM that way can authenticate to the ACS-GLX. I check the log and I didn´t find anything I check the switch.. too where the ACS is connected. but didn´t find anything too.
 
both ACS have the following IOS version:

ACS 5.2.0.26.4

View 0 Replies View Related

Cisco AAA/Identity/Nac :: Use Two Servers ACS 5.2 In (primary And Secondary) Active?

Jun 16, 2011

it is possible de use two servers ACS 5.2 (primary and secondary) in active/ active? or just in active/ passive?

View 3 Replies View Related

Cisco AAA/Identity/Nac :: ACS 5.3 - Unable To Re-register Secondary To Primary?

Jun 11, 2012

Today I ran a failover test between our primary and secondary ACS systems (ran 'acs stop' on the primary) and in the process decided to promote the secondary while I had the primary down. All was fine until I brought the primary back up and tried to re-register the secondary to it. I get the following error message: I went into System Administration >Operations >Distributed System Management on each and it showed the other device as deregestered, tried to promote from there but it failed too, so I deleted them and tried to register the secondary again. After that didn't work I tried rebooting both but that didn't work either. I know the user/pass I'm using is good and I've tried using both the IP address and the hostname.

ACS/admin# sh app version acs
Cisco ACS VERSION INFORMATION-----------------------------Version : 5.3.0.40.5Internal Build ID : B.839Patches :5-3-0-40-5

View 3 Replies View Related

Cisco AAA/Identity/Nac :: N7K Primary Tacacs Server Fail / Won't Switch Over To Another

Jan 23, 2012

Have you ever found the problem that if I set two tacacs server in my N7K and the primary tacacs server fail, won't switch over to another tacacs server.

View 1 Replies View Related

Cisco AAA/Identity/Nac :: ACS 5.2 - Primary-secondary Radius Server Configuration

Apr 21, 2013

I have a couple of ACS 5.2 configured as active and backup and I am   doing dot 1x authentication using these servers . I have configured the  switch with the bellow configuration.
 
radius-server host 10.0.10.15 auth-port 1645 acct-port 1646
radius-server host 10.0.10.16 auth-port 1645 acct-port 1646
radius-server key 7 aaaaaaaaaaaaaa
 
please help to understand what will happen in switch
 
1) in case of primary failure
2)in case if primary returns alive .

View 8 Replies View Related

Cisco AAA/Identity/Nac :: Secondary ACS 5.1 Fails To Deregister After IP Change On Primary

Aug 9, 2011

IP address of Primary had to be changed, to respond to a hardware failure of TACACS server with IP in many device configs.
 
Now the Secondary fails to respond to repeated "Deregister from Primary" requests, even after reload  - apparently because it cannot reach the Primary at its old IP address. 
 
Requesting Deregister in GUI generates pop-up that says,  "This operation will deregister this ACS Instance from the Primary Instance. Management applications on this ACS instance will be restarted and you will be required to login again.  After performing this operation

[code]....

View 1 Replies View Related

Cisco AAA/Identity/Nac :: ACS 5. 2 Secondary Server Is Not Collecting Logs From Primary

Nov 2, 2011

Cisco ACS 5.2 secondary  server is configured as a log collector for both primary and secondary server .Now i am facing problem in log collection from primary server .ACS secondary server is not collecting any logs from primary .

View 2 Replies View Related

Cisco :: LMS 4.2 Sub-interface Not Available In Instance Selection

Apr 26, 2013

I have sub-interfaces created on the switch and are in active(up/up) state,but these sub-interface not available for selection in the instance window while creating the poller, and am not able to monitor the traffic on these sub interface in the performance management.
 
LMS will not display the interfaces in the instance selection window if they are not active, but here the sub-interface are in active state but these are not available.

View 1 Replies View Related

MySQL Server Instance Configuration Not Responding

Apr 30, 2012

I have done some searching, but I am unable to find a solution to this problem. I am wondering if there are any solutions that I was unable to find.

View 13 Replies View Related

Cisco WAN :: Pair Of Nexus 5548 And 3750 Are Configured With MST Instance

Feb 8, 2012

I am having some issue with SPT with the following topology.Pair of Nexus 5548 and 3750  are configured with MST instance 1.when enable STP as MST on Dell switches , it does not recognise it and create loop but if We change MST0 (only tried on one 3750 and two Dell switches in triangle in lab). its work fine.Does Dell switches only understand MST0 ?Can Nexus 5548 support MST0 if we change from MST1 and what will be effect?

View 4 Replies View Related

Cisco Firewall :: 6500 - Passive FTP Through 2 FWSM Contexts Via VRF Instance

Mar 26, 2012

I'm having problems getting FTP to work through two FWSM virtual contexts which are connected via a vrf. All this is configured on a 6500 switch with the FWSM running 3.1(4)
 
CLIENT-----CONTEXT_1-------VRF------CONTEXT_2--------FTP_SERVER
 
At the moment we can make the control connection but when we issue commands the connection times out.
 
Looking at the logs we can see the initial connection made to the server on port 21 from the client, this is also seen on the second firewall context (nearest the FTP server). The data channel is then seen on the first context, made using high src & dst port numbers and initiated from the client, successfully passing the ACL/Inspection, then on the second context we see the connection being denied by the incoming ACL on the second contexts interface connected to the VRF instance.
 
The rules are identical on the contexts and have been made by copying and paste the rule using CSM, we are using the predefined service group 'FTP-Group' which contains both tcp 20 & 21. FTP inspection is at default on both contexts.
 
We have tested with Win XP (capable of Active FTP only) & Firefox 3.6.12 which is the connections we are seeing in the logs trying to do Passive FTP.
 
Is this a problem with teh contexts randomizing sequence numbers or TCP Normalization? Or do we just have a problem with the Inspection engine on one of the contexts (I would have expected to see this on both contexts if it was a bug).

View 1 Replies View Related







Copyrights 2005-15 www.BigResource.com, All rights reserved