Cisco AAA/Identity/Nac :: Database Is Not Lost On Primary ACS 5.1

Apr 23, 2013

We have recently upgraded acs 5.1 to 5.3 ( normal upgrade process), all secondary (ACS-B) was deregistered from primary (ACS-A , used as configuration server and log collector) and updated successfully.  But while upgrading primary acs server was rebooted manually. But later primary server was re upgraded successfully to 5.3.
 
Just to ensure database is not lost on primary acs (ACS-A) , primary acs was registered to one of the secondary acs (ACS-B). Initially  ACS-A registered with ACS-B, both ACS was showing proper role now. ACS-A ( secondary ) and ACS-B (primary). But on New primary ACS (ACS-B) is showing new secondary (ACS-A) offline and replication pending. Whereas on Secondary ACS-B its shows primary ACS-A online and updated. But ACS replication id is gradually incrementing. ACS system is in this system for last 2 day, But not sure if there is real replication happening at backend? How long it take place to replicate completely? and how to check / verify status of upgrade?       

View 3 Replies


ADVERTISEMENT

AAA/Identity/Nac :: Primary ACS 5.2 Lost Connection?

Apr 9, 2012

I have a 802.1x solution with two redundant ACS 5.2. Network A configuration use like Primary ACS-SJM and ACS-GLX like a secondary for network B configuration use like Primary ACS-GLX and ACS-SJM like a secondary. My solution was working fine about one year ago. but one week ago isn´t working fine. The problem my ACS-SJM lost connectión and user can´t authenticated  when the user trye to connect to ACS-GLX either can´t connect. I have to shutdown the ACS-SJM that way can authenticate to the ACS-GLX. I check the log and I didn´t find anything I check the switch.. too where the ACS is connected. but didn´t find anything too.
 
both ACS have the following IOS version:

ACS 5.2.0.26.4

View 0 Replies View Related

Cisco AAA/Identity/Nac :: ACS 4.2 To ACS 5.4 Database Replication

May 27, 2013

I would like to know if its possible setup database replication from Cisco ACS 4.2 server to ACS 5.4 server ?

View 3 Replies View Related

AAA/Identity/Nac :: Local Database Of Pix 525?

Feb 18, 2013

i configured pix 525 for easy vpn. About 100 to 200 people will use this service. i dont have much knowledge about radius and tacacas servers. Is local data base enough for extended authentication or should i configure the server for it ?

View 2 Replies View Related

Cisco AAA/Identity/Nac :: ACS 4.2.1 Authentication And Database Replication?

Mar 27, 2011

Firstly the ACS 4.2.1 for Windows database replication does any one have and documentation on the processes required?Secondly I have a single system installed which is providing TACACS authentication for management access to a Cisco 5508 WLC, the controller prompts with a login box on connection to the web interface. When you put in the username and password pair the box comes back as if the authentication has failed. On the ACS I was unable to see any failed authentications so enabled passed authentication reporting and can see the user passing the process. The WLC is running software version 6.0.199.4. On the ACS I have added the extra two options within the TACACS interface configuration and have a ‘role1=all’ against both the user and the group the user is part of so I am confused as to why the user is still denied access.

View 3 Replies View Related

Cisco AAA/Identity/Nac :: ACS 5.0.0.21 Monitoring And Reports Database?

Jun 16, 2010

Just installed ACS 5.0.0.21.  Monitoring and reports database was working, but now is not.  When trying to open, I get "Monitoring and reports database currently unavailable.  Trying reconnect in 5 minutes."    From CLI "sho application status acs" gives me the following:
 
ACS role: PRIMARY
Process 'database'                  runningProcess 'management'                runningProcess 'runtime'                   runningProcess 'adclient'                  runningProcess 'view-database'             runningProcess 'view-collector'            runningProcess 'view-jobmanager'           runningProcess 'view-alertmanager'         running
 
Also, logs show nothing unusual.

View 6 Replies View Related

Cisco AAA/Identity/Nac :: ACS 5.3 Remote Database Compatibility?

May 26, 2013

Would like to check up either Microsoft SQL Express 2012 is able work with ACS 5.3 remote database?

View 5 Replies View Related

Cisco AAA/Identity/Nac :: ACS 5.2 Database Failure Radius Accounting?

Jul 31, 2012

on the dashboard of the "Monitoring & Report Viewer" I see a lot of system alarms related to the database.The explanation of the alarm says to look at the Collector logs for the details.

View 3 Replies View Related

Cisco AAA/Identity/Nac :: ACS 5.2 To Use Local Database When LDAP Fails

Mar 22, 2011

i'm trying to configure acs 5.2 to LDAP external idenity store, when LDAP failes ACS 5.2 should use internal indenity store. I configured A sequence to use LDAP 1st then Internal and i shut off the link to the LDAP but ACS will not use internal,  AAA Diagnostics keeps telling me that Cannot establish connection with LDAP server and will not use the internal store.

View 7 Replies View Related

Cisco AAA/Identity/Nac :: LDAP Or AD For External Database - Secure ACS 5.2

Sep 27, 2012

I am working on project with Secure ACS 5.2.  I am trying to determine the proper External Database to use.  LDAP or direct to AD?
 
Additionally, the Domain that I am connecting to has Multiple sub domains.  All of the users are currently in the Sub domains, but will be moving to root domain later.  How should I configure the connection, do I need to connec to each sub domain or can I just connect to the root?

View 2 Replies View Related

Cisco AAA/Identity/Nac :: ACS 5.1 Updating Internal User Database?

Jul 4, 2011

Using  a CSV file, I can not add user in the internal database of the ACS I have a permanent "error File Format Validation Failed" However the file I want to import is a really CSV file.

View 2 Replies View Related

Cisco AAA/Identity/Nac :: Type Of ACS V4.2 Database Password Hash?

Jan 17, 2012

What's type of ACS v4.2 Database password hash?
example:
-------------------------------------------------
Name          :          ###postureuser
Password      :          0x0020 fe fc f0 11 24 dc dd bd 0f d9 78 56 b8 4a fc f4 40 d0 bd 1d 19 5b 56 7e 14 f0 4e 1a b0 83 66 24
Chap password :          0x000e 22 07 e4 28 c0 09 7f 1a b7 e6 2a 78 a1 52
-------------------------------------------------

View 1 Replies View Related

Cisco AAA/Identity/Nac :: ACS 5.2 System Alarm Database Purging

Apr 19, 2012

On Cisco ACS 5.2.0.26 Patch 10, I got this system alarm:Incremental backup is not configured. Configuring incremental backup is necessary to make the database purge successful. This will be useful to avoid disk space issues. View database Size is 2.92GB and size it occupies on the harddisk is 2.91GB
 
In  "Monitoring Configuration >  System Operations >     Data Management >     Removal and Backup", we got this information:
Database Purging:If database size exceeds 120 GB, a backup (if configured) and purge will be initiated. If database size exceeds 150 GB, a purge will be initiated.
 
Could View database size reach 120 GB ?I want to know how long will Cisco ACS works without problem and if I need to hurry to configure purge.

View 2 Replies View Related

AAA/Identity/Nac :: ACS5 Try To Authenticate User In External Database

Jan 16, 2012

Is it possible to create on ACS5 rule which will:

1. Try to authenticate user in external database1 (radius)
2. When external database1 returns FAIL (because of bad password) ACS5 should try to authenticate user in another external database2 (radius)

View 5 Replies View Related

AAA/Identity/Nac :: CSACSE-1113-K9 / ACS 4.2.1.15 External User Database

Mar 9, 2012

Having CSACSE-1113-K9 with ACS 4.2.15.I want to configure windows user database under extrenal user database but i get an error  (attached) 'An error has occured while processing the Authen DLL Configure pagebecasue an error occured.I tried to stop the services and start agian but the same issue. The eappliance is secondary (backup) ACS. On the primary it is working fine.

View 1 Replies View Related

AAA/Identity/Nac :: Windows ACS 4.2.0 Backup Database On 1120 Appliance 4.2.1.15?

Apr 26, 2011

I am running windows based acs 3.3 in my lan environment going to be replaced with acs 1120 appliance running acs 4.2.1.15 , ACS 3.3 database has been built upto  4.2.0.124 ,step by step by upgrade process
 
1) acs 3.3.3.14---> 4.1.1.24
2) acs 4.1.1.24 ----> 4.2.0.124 .
 
now my database is with 4.2.0.124 dmp file , I cannot upgrade my database to 4.2.1.15 because 4.2.1.15 patch is not applicable & executable  on 90 days evalution package of 4.2.0.124 of windows platform .
 
can i import my windows based 4.2.0.124 datbase directly to my acs appliance running 4.2.1.15.3 ??? , else its requires any step to be done to modify the windows based databse matching to appliance windows verison once .
 
I could see on appliance under restore settings the following options (restore from 4.2.0 backup file to acs 4.2.1)

View 8 Replies View Related

Cisco AAA/Identity/Nac :: N5000 Same User In Tacacs / Local Database With Different Privilege

May 15, 2012

i am running NX-OS image n5000-uk9.5.1.3.N1.1.bin on the nexus 5020 platform.i have configured authorization with tacacs+ on ACS server version 5.2 with fall back to switch local database.a user test with priv 15 is craeted on ACS server, password test2 everything works fine, until i create the same username on the local database with privilege 0. ( it doesnt matter if the user in local database was created before user in ACS or after ) e.g.:  username test password test1 role priv-0   (note passwords are different for users in both databases)
 
after i create the same user in local database with privilege 0,if i try to connect to the switch with this username test and password defined on ACS,  i get only privilege 0 authorization, regardless, that ACS server is up and it should be primary way to authenticate and authorizate the user.

View 3 Replies View Related

Cisco AAA/Identity/Nac :: ACS 1121 / 5.3 - Remote Database Settings In Monitoring And Reporting

Mar 26, 2012

I am configuring new ACS 1121 appliance with version 5.3 and wanted to know how to configure Remote Database settings in ACS5.3 Is that necessary to configure that option ?
 
Also one more thing I can see that ACS 5.3 generates lots of logs is there any solution to reduce such logs. It seems many unuseful logs which are system related are getting logged into device which might no be good for memory requirements of device.

View 6 Replies View Related

Cisco AAA/Identity/Nac :: ASA 5510 / SSH Local Database Username And Password Not Working?

Feb 28, 2012

I have a weird issue. I recently setup an ASA 5510 and had SSH working. To make it easier on my VPN users I then decided I wanted to setup a Windows 2008 Network Policy Server for RADIUS authentication. Ever since I added the RADIUS part to aaa authentication, when I use SSH to connect to the ASA it will not take the local user name and password I have setup. I can however get in using a Domain user name and password. Below is the SSH and AAA configuration. Am I missing something here? The username and password in the ASA is not on the domain and it's like the ASA is not even trying LOCAL when it tries to authenticate. I want it to use the local username and password if possible. I'm kind of new to ASA's..
 
On another note, I have never been able to SSH in on the internal interface. I always get a "The remote system refused the connection" error message. I can only use the outside interface.
 
Site-ASA# sh run | in ssh
aaa authentication ssh console SERVER_RADIUS LOCAL
ssh 0.0.0.0 0.0.0.0 outside
ssh 0.0.0.0 0.0.0.0 inside
ssh timeout 60

[code]....

View 2 Replies View Related

Cisco AAA/Identity/Nac :: ACS 5.3 Primary / Secondary Same License?

Jan 22, 2012

I have a question about the number of Cisco licenses needed in two cases for ACS 5.3 Virtual Machine.One primary + One secondary : Just one license for all or one license for the primary + another one for the secondary ?One primary + several secondaries : Just one license for all or one license for the primary + just one license for all the secondaries ? 

View 1 Replies View Related

Cisco AAA/Identity/Nac :: Use Two Servers ACS 5.2 In (primary And Secondary) Active?

Jun 16, 2011

it is possible de use two servers ACS 5.2 (primary and secondary) in active/ active? or just in active/ passive?

View 3 Replies View Related

Cisco AAA/Identity/Nac :: ACS 5.3 - Unable To Re-register Secondary To Primary?

Jun 11, 2012

Today I ran a failover test between our primary and secondary ACS systems (ran 'acs stop' on the primary) and in the process decided to promote the secondary while I had the primary down. All was fine until I brought the primary back up and tried to re-register the secondary to it. I get the following error message: I went into System Administration >Operations >Distributed System Management on each and it showed the other device as deregestered, tried to promote from there but it failed too, so I deleted them and tried to register the secondary again. After that didn't work I tried rebooting both but that didn't work either. I know the user/pass I'm using is good and I've tried using both the IP address and the hostname.

ACS/admin# sh app version acs
Cisco ACS VERSION INFORMATION-----------------------------Version : 5.3.0.40.5Internal Build ID : B.839Patches :5-3-0-40-5

View 3 Replies View Related

Cisco AAA/Identity/Nac :: 1120 - Registering ACS 5.2 Instance To Primary

May 29, 2013

When attempting to register an ACS instance to a primary (via System Administration -> Operations -> Local Operations -> Deployment Operations), I receive the following error as a popup in my browser:
 
"This System Failure occurred:  /opt/CSCOacs/db/acs.crt (No such file or directory). Your changes have not been saved.Click OK to return to the list page."
 
I had 2 ACS 1120 appliances clustered, 1 suffered a hardware failure about a year ago so I replaced it with a VM. That one is now the primary. I'm now wanting to replace the secondary instance (the remaining 1120 appliance) with a VM as well. I removed the current appliance from the network, installed the VM using the same IP address, and attempted to register. It failed as per the above error. After trying this a number of times, I then decided to return the 1120 appliance to secondary status and attempted to register it with the same results as above.

View 3 Replies View Related

Cisco AAA/Identity/Nac :: N7K Primary Tacacs Server Fail / Won't Switch Over To Another

Jan 23, 2012

Have you ever found the problem that if I set two tacacs server in my N7K and the primary tacacs server fail, won't switch over to another tacacs server.

View 1 Replies View Related

Cisco AAA/Identity/Nac :: ACS 5.2 - Primary-secondary Radius Server Configuration

Apr 21, 2013

I have a couple of ACS 5.2 configured as active and backup and I am   doing dot 1x authentication using these servers . I have configured the  switch with the bellow configuration.
 
radius-server host 10.0.10.15 auth-port 1645 acct-port 1646
radius-server host 10.0.10.16 auth-port 1645 acct-port 1646
radius-server key 7 aaaaaaaaaaaaaa
 
please help to understand what will happen in switch
 
1) in case of primary failure
2)in case if primary returns alive .

View 8 Replies View Related

Cisco AAA/Identity/Nac :: Secondary ACS 5.1 Fails To Deregister After IP Change On Primary

Aug 9, 2011

IP address of Primary had to be changed, to respond to a hardware failure of TACACS server with IP in many device configs.
 
Now the Secondary fails to respond to repeated "Deregister from Primary" requests, even after reload  - apparently because it cannot reach the Primary at its old IP address. 
 
Requesting Deregister in GUI generates pop-up that says,  "This operation will deregister this ACS Instance from the Primary Instance. Management applications on this ACS instance will be restarted and you will be required to login again.  After performing this operation

[code]....

View 1 Replies View Related

Cisco AAA/Identity/Nac :: ACS 5. 2 Secondary Server Is Not Collecting Logs From Primary

Nov 2, 2011

Cisco ACS 5.2 secondary  server is configured as a log collector for both primary and secondary server .Now i am facing problem in log collection from primary server .ACS secondary server is not collecting any logs from primary .

View 2 Replies View Related

Cisco AAA/Identity/Nac :: ACS 1121 With V5.0 PAK Lost

Jan 6, 2012

It has been more than a year since a customer bought a Cisco ACS 1121. It was unpacked then and the PAK is lost, no where to be found. Is there any way to retrive the lost PAK ?

View 19 Replies View Related

Cisco AAA/Identity/Nac :: ACS 4.2 / Logs Are Lost Frequently In Remote Agent Server

May 2, 2013

ACS 4.2 and remote agent was working properly two months before. But in past two months we are facing weird issue in RA server.For Somedays we are missing logs from both ACS and RA server. Once we notice this we use to restart the services in ACS to give workaround. But due to this we loose our daily logs intermittently and facing risk in without having logs.This is not like communication between ACS and RA is not at all happening. It happens properly for a week or month, but again it is going bad without any config change. CSAgent.ini file is properly configured.Full version is 4.2.1.15 and patch is 10 in acs and ra.ACS and Remote Agent Major and Patch version are same.

View 5 Replies View Related

Cisco :: ARP Database Timeout?

Aug 16, 2012

How do I, if I even can, adjust the MAC table timeout from 5 minutes to whatever is bigger and allowable?

I would like to also like to change the ARP table timeout as well.

View 4 Replies View Related

Cisco :: LMS 4.1 / Building DSN For UPM Database?

Jan 26, 2012

I need to generate an ODBC connection to the upm Datasource on LMS 4.1 running on Win2K8.  I have successfully built connections to cmf, ipm and rmeng, however UPM keeps failing saying that the Database is not found.
 
Here are my settings.
 
Driver = CiscoWorks Embedded Database
ODBC Tab - Data source name = upm
ODBC Tab - Description = Device Performance
Login Tab - Supply user ID and Password is selcted
Login Tab - User ID = lmsdatafeed  (i have tried DBA as well)
Login Tab - Password = set using the password I estabplished with the dbaccess.pl and dbpasswd.pl scripts
Database.Server name = upmEng
Network.TCP/IP = HOST=<lms server ip>;DOBROADCAST=NO;ServerPort= 43800
 
I validated the server port using netstat -a -b -o and matching up the PID with the UPMDBEngine process shown in the LMS Manage Processes window.Windows firewalls on the remote machine and the LMS server are off.

View 3 Replies View Related

Cisco :: LMS 3.2 - How To Access Database

Sep 22, 2011

what is the database to use cisco LMS3.2 and how to access the database?

View 3 Replies View Related

Cisco :: LMS 3.2 Need To Restore Cmf Database

Aug 29, 2011

If i reinialize(restore) the cmf database.do i need to reinialize all the databases.???
 
or if i reinialize the cmf database and do bulk import the devices is enough?

View 3 Replies View Related







Copyrights 2005-15 www.BigResource.com, All rights reserved