Cisco Security :: High Availability Failure On NAC 3310 CAS?
Dec 20, 2011
Yesterday I discovered the primary and secondary CAS were both in active state and reporting their fellow peer as dead (I did this using ./fostate.sh), causing authentication errors on the network. I had to stop the perfigo process on the primary one to restore service.
After closer investigation I have discovered that when I put my laptop on the same subnet as their eth2 interfaces (eth0, eth1 and serial are not used for heartbeat only eth2), I can ping the eth2 ip address for the primary device, but can't ping that of the secondary device. See configs and outputs below. I am also wondering why the secondary CAS shows its eth0 and eth1 interfaces as fake0 and fake1.
[root@CAS-SEC ~]# ifconfig eth2
eth2 Link encap:Ethernet HWaddr 00:1F:29:5D:1C:6C
inet addr:172.29.254.10 Bcast:172.29.254.11 Mask:255.255.255.252
UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
RX packets:11205 errors:0 dropped:0 overruns:0 frame:0
[code].....
View 2 Replies
ADVERTISEMENT
Apr 10, 2011
I would like to know how to implement high availability on a S160 ironport device.i have two S160 device but the user guide is not useful.
View 1 Replies
View Related
Jun 10, 2011
I have two cisco wlc 5508. I wan to install them in two differents site. One WLC in the site A and the another WLC in the site B.
Site B is the WAN of the site A. The site A is the headquarter.
But i need to configure them in High Availability. For example if the Cisco WLC in site A goes down, the ap's have to registered in the WLC of the site B.
Then the traffic LWAPP have to pass over the WAN between site A to site B.
I have to configure two cisco wlc in HA over a WAN . Is ok configure the roamming L3 intercontroller?
View 5 Replies
View Related
Oct 1, 2012
One of my customer wants to upgrade their Cisco ACS version from 4.0 to 5.3. The client has existing ACS version 4.0 windows on VM with two instance and need to upgrade to 5.3 Linux.As per my understanding following version are supporter to upgrade ACS to version 5.3 ACS 4.1.1.24ACS 4.1.4ACS 4.2.0.124ACS 4.2.1 but unfortunatlly there is running 4.0.I suggested to my client the upgradation for ACS and proposed this Upgrade lisence L-CSACS-53VMUP-K9 and CON-SAS-CSACS3V? how I can do the smooth deployment / Migration from 4.0 to 5.3 with (A/P)high availability.
View 1 Replies
View Related
Oct 28, 2012
Current environment is Cisco 2125 WLC managing ~12 3502E AP's for a single location. Client is looking to provide HA for the single 2125 WLC. With the 2125 now EO-Sale is it possible to go with one additional 2504 WLC and leverage the existing 2125 or would it require going with just (2) 2504's?
View 1 Replies
View Related
Jan 19, 2012
I have 2 WLC (5508), i configured the option for enable the high availability, but when the 2 WLC is working the mesh network is unstable, when only wlc is working the mesh is fine.
View 3 Replies
View Related
May 7, 2012
We want to make High Availability between two Cisco 3560G switches. Can you tell how we should proceed?Is there any HA module available for Cisco 3560G?
View 1 Replies
View Related
Sep 18, 2011
I am upgrading the Wireless Infrastructure with two 5508 WLC.I am setting up High Availability, but I think is not quite working.
Primary Controller = WLC1
Secondary Controller = WLC2
LAP = LAP1
LAP1 has WLC2 as the primary controller for HA
LAP1 has WLC1 as the secondary controller for HA
While connected to LAP1, I shutdown WLC2. After ~ 20 seconds, LAP1 move to WLC1.I lost connection from LAP1 Don't LAP1 should move with all its clients to WLC1?Am I missing something in my configuration?
View 7 Replies
View Related
Jul 7, 2011
I have to install and configure two 2901 routers at different location with high availability. These 2 routers would be connected through WAN, now I would like to configure high availability bwtween two routers.
I have attached a small diagram of the placement of 2 routers.
how do I configure high availability between these 2 links or routers.
View 3 Replies
View Related
Sep 1, 2011
I just want to know if i need to support High Availability in Cisco Secure ACS 5.1 appliance, will the base license suffice or do i need to buy Security Group Access System License/ Large deployment License. Again, do we require license for each appliance or just one is enough?
I Suppose the licensing rules are same for the Vmware version also.
View 2 Replies
View Related
Mar 20, 2011
A customer is currently running a 5520 ASA pair in active/standby HA mode. The devices also have an IPS module, one of them using a temporary (60-day) license. So, right now, licensing is identical on both ASAs and HA is operational.
The question is what exactly will happen after 60 days, once the temporary license expires? Does HA shutdown completely once it's determined that the licensing isn't a 100% match any longer, or does it just cripple one feature (such as the IPS module)?
The customer is balking at purchasing SMARTnet for the 2nd ASA, so I need to explain exactly what is going to happen (if anything) once the license on the 2nd ASA drops off...
View 4 Replies
View Related
Sep 16, 2007
do i still need ACS if i have the NAC appliance say 3310.
View 3 Replies
View Related
Mar 20, 2011
One of my remote sites acquires Internet connectivity via a cable modem service. This goes down intermittently, of course. I would like to purchase DSL service from the local telco and configure the edge ASA (currently a 5505) to use the cable modem path normally ... and fall back to the DSL path if necessary.
These seems hard to do. The edge box would need to evaluate the viability of a WAN path using some set of tests ... perhaps pings to a handful of major Internet sites. If all those pings start failing, it would stall for a minute, to give the WAN service provider time to recover ... then cut over to the second path. Cutting to the second path might mean pushing new DNS server addresses to clients (or perhaps the edge box would hand out both sets of DNS servers all the time and rely on the clients to try them all.) Once the cable modem provider restored service, the edge box would stall for a while (ten minutes? an hour?) and then cut back.
I'm willing to replace the edge box with something fancier (a bigger ASA or something sold as a router or whatever), although I'd like to stay under 10K (list) for such a replacement.
View 3 Replies
View Related
Feb 18, 2013
I will install next week at a customers side a new Pair of 5508 Controller. They have at the moment one old 4404 with about 70 APs.So the bought the new 5508 with HA Pair.For the HA i will need 7.3 i read in the High Availability (AP SSO) Deployment Guide.There are now two 7.3 Versions, or i can choose the new 7.4 Version.
AIR-CT5500-K9-7-3-101-0.aes
AIR-CT5500-K9-7-3-112-0.aes
AIR-CT5500-K9-7-4-100-0.aes
So what software version will be the best at the moment?I will install also a Cisco Prime Infrastructure on a ESX host.For the 7.3 in can use the 1.2 , but for the 7.4 i must take the 1.3.
View 4 Replies
View Related
Nov 1, 2011
I am new to Cisco firewalls. We are moving from a different vendor to Cisco ASA 5520s.I have two ASA 5520s running ASA 8.2(5). I am managing them with ASDM 6.4(5).I am trying to setup Active/Standby using the High Availability Wizard. I have interfaces on each device setup with just an IP address and subnet mask. Primary is 10.1.70.1/24 and secondary is 10.1.70.2/24. The interfaces are connected to a switch and these interfaces are the only nodes on this switch. When I run the Wizard on the primary, configure for Active/Standby, enter the peer IP of 10.1.70.2 and I get an error message saying that the peer test failed, followed by an error saying ASDM is temporarily unable to connect to the firewall.
View 5 Replies
View Related
Jul 19, 2010
We'll be implementing Cisco NAC guest server for Guest Wireless users, ( Model #3310), the question is do we need to configure separate physical interface for User authentication requests( from Wireless ) and a separate Interface for Guest server to talk to AD for SSO?
View 2 Replies
View Related
Jul 18, 2010
I'm trying to configure the NAC Profiler with a 3310 CAS Collector. In the "Edit Collector" menú, it shows all the modules as "Running", except for the NetWatch module which shows a state "Invalid configuration file (missingInternalAddress)".
I configured the eth3 interface of the CAS as a monitor interface in the Profiler (see attached image), and I tested that the SPANed traffic actually reaches that interface from the access switch. I'm using software version 3.1.0_24 in both the Profiler and the Collector.
View 2 Replies
View Related
Aug 1, 2011
Is possible connect and configuring two cisco wlc in high availability to 3 switches in stack 3750 in difference ports?For example
WLC A (Primary) - SWITCH MASTER
WLC B (Secondary) - SWITCH SLAVE
How can i connect the wlc's in HA to get a redundancy in the stack?
View 8 Replies
View Related
Jun 26, 2012
I have set up a zone-based policy firewall with HA on two 2911 routers as per the Cisco security configuration guide, for an active/passive LAN-LAN cluster. All works as expected, but there is one problem I find: when the control link between the two devices fails, they go into an active/active state as each member assumes it's the last surviving member. The ARP entries for the Virtual IPs on the neighboring devices point to the device that last claimed the active role (usually the standby device). This works in a way, just sessions don't get synched anymore (control link is the same as data link). Now when the link comes back up, the preemtion works and the active, former standby device goes back to standby. But the ARP entries on the neighboring devices still point to the standby device and nothing goes (also sessions established during the active/active state are lost due to resync with the now active member).
This is a single point of failure and what I need is a way to mitigate that. Under:
redundancy
application redundancy
group 1
control <interface> protocol 1
only one control interface is allowed. Other manufacturers with similar functionality provide for the possibilty of a backup control link, for example the internal LAN interface or a dedicated backup link.
How would I go about that? Maybe use a port-channel for the control/data link (but I'm out of interfaces)?
View 1 Replies
View Related
Mar 24, 2012
What consequences could i have if i install a WiSM-2 module into a pair of 6500 configured in VSS and another WiSM-2 module into other pair of 6500 configured in VSS for serving a 300 APs??...in this case, do i need to configure mobility groups for guarantee a high availability and also redundancy of controllers?Under the best practices, is much better having the two WiSM-2 modules into a single pair of 6500 configured in VSS??
View 4 Replies
View Related
May 28, 2012
We have two 4400 WLC's. We have around 20 access points in our network.If we assign controller1 as primary for half of the access points and controller 2 as primary for the other half, does this mean the association of the ap's indicate load balancing by the controllers. Does this mean wlc does load balancing as different ap's associate on different controllers. or does it only server as active-standby wlc.
View 2 Replies
View Related
Mar 30, 2013
As part of my business' PCI compliance regime, we are regularly scanned for vulnerabilities. Today we started getting notifications of failure on all of the QuickVPN ports (443, 60443) for the following:
Details: Multiple Vendor TLS Protocol Session Renegotiation Security Vulnerability
06/11/12 CVE 2009-3555 Multiple vendors TLS protocol implementations are prone to a security vulnerability related to the session-renegotiation process which allows man-in-the-middle attackers to insert data into HTTPS sessions, and possibly other types of sessions protected by TLS or SSL, by sending an unauthenticated request that is processed retroactively by a server in a post-renegotiation context.
Cisco, will you be issuing a firmware update to address this anytime in the near future? Presumably it effects all the other RV routers as well.
View 3 Replies
View Related
Mar 27, 2011
Ive got a virtualised firewall running 3 security contexts in routed mode. What am experiencing is that i cannot connect to an OUTSIDE host through the security contexts. From the firewall itself i cannot ping the directly attached host on the OUTSIDE interface but i can ping the directly attached host on the INSIDE interface. When i reload the firewall box, the first ping to the OUTSIDE host would be successful but subsequent pings fail and thus total connectivity is lost.
I even tried upgrading to ASA version 8.4(1) but still the same.
View 5 Replies
View Related
Apr 26, 2012
MSE can not boot.MSE show error log. [code] How to recovery MSE 3310,I find in documents not show method recovery. Any solution recovery MSE 3310
View 2 Replies
View Related
Feb 22, 2012
I performed a software reboot on the MSE3310. After the reboot the MSE was no longer visible on the network. I went and consoled into the device and it was operational. I ran the msed stop and msed start commands. I got this message when it tried to load eth0.Bringing up interface eth0: e1000 device eth0 does not seem to be present, delaying initialization.Earlier in the day I had updgraded the firmware from 6.0 to 7.0.230.0.
View 6 Replies
View Related
Feb 24, 2013
I've got an MSE 3310 that came with four-post rails for rack mounting. These came without instructions and we are having a hard time figuring out exactly how they work. They say General Devices C-300-S-124-RC-MOD
View 4 Replies
View Related
Jun 8, 2012
I recently configured CISCO 3310 box with MSE version 7.2. Services are up and running in the box, I could add the MSE to WCS and also able to track the location using WCS. However, I could not connect the third party software to MSE web services to get the location information there. When I hit the server url "https://<my mse>" I get list of possible services like:
Error 404 - Not Found.No service matched or handled this request.
Known services are:
http://my server:8880/hs/
http://my server:8880/mdp/
http://my server:8880/admin/
[code]....
I browsed through the documentation (CAS_71.pdf) and found a text saying:
Note Port 80 will be enabled on the MSE if the enable HTTP command was entered on MSE. Ports 8880 and 8843 will be closed on the MSE when the CA-issued certificates are installed on the MSE. I am running the test system so I do not really want to install CA signed certificate, so I used self signed certificate and restarted the server, but it did not work.
View 10 Replies
View Related
Mar 11, 2012
I am getting a hard time in order to understand the real difference between the two types of context aware licenses for the MSE:
1 . AIR-CAS-1KC-K9 - Context Aware License For 1K Clients and Tags (RSSI based)
2. AIR-CAS-1KT-K9 - Context Aware License For 1K Tags(RSSI, Chokeponts and TDOA)
For a regular network without any devices with tags such as RFID, I understand I do not need to get the .2, only .1, even though the .1 also is shared with clients at 1K of each. Also, the .2 does not say clients, only tags and advanced features as TDOA. Going through the Q&A it does not clearly says the difference, when to use one or the other.
View 3 Replies
View Related
Aug 27, 2012
The rouge access points being detected by the 5508 WLC are not showing up on the Context Aware tab of NCS? I have a MSE 3310 installed and configured and it shows to be syncronizing with the WLC. I'm sure I am missing some part of the configuration just not sure where.
View 3 Replies
View Related
May 11, 2011
I am trying to upgrade an MSE from version 6 to 7.0.201.204. I am able to copy across all the files and have tried using WCS and FTP for the CISCO-MSE-L-K9-7-0-201-0-64bit.bin file but the installation procedure always fails.
I will download all the images again tonight. Is there a way to delete the images from the /opt/installers/ directory?
Also the upgrade procedure in the 7.0.201.204 is pretty bad, there is no detail in any of the steps.
Here is output from the upgrade -
[root@SDC-MSE-01 installers]# dirCISCO-MSE-L-K9-7-0-201-0-64bit.bin database_installer_part3_4.zipdatabase_installer_part1_4.zip database_installer_part4_4.zipdatabase_installer_part2_4.zip
[Code].....
View 6 Replies
View Related
Oct 13, 2011
Today I've received reports of slow internet access/activity and have noticed myself that it seems a bit slow today. On the dashboard of our asa 5510 the "outside interface" traffic usage is running constantly high. It's at the top of the graph. How can I tell what is causing the spike in utilization. It usually runs at about 1500-2000 Kbps, and now it's up over 10,000.
View 6 Replies
View Related
Nov 26, 2012
We installed a solution with 2 Cisco 2801, BGP multihomed failover.
1) The router which is currently getting all the traffic gets to 55% to 60% of CPU usage when handling 40 SIP/RTP streams . This equals 10Mbit up/10Mbit down and it showed around 5800 packets TX and around 5800 packets RX, with a majority of them CEF switched. As those figures are way less than the performance figures published by Cisco, we wonder if we made any mistake in setting up our router, or if we can do something to improve the router setup.
2) Does it have an impact on router performance if we increase/decrease RTP packet size, thus increasing or decreasing the pps relative to the consumed bandwidth?
3) If it is not possible to improve router configuration, we also wonder about possible replacement units for those routers. Would a 2901 do a good job? By how much would it rise the capacity? What other models would you recommend if we plan to rise the number of concurrent calls by a factor of 4 or even 8 times of what we have now (so up to 48000 pps and 80Mbit).
Here is what we tried:
- ip route-cache same-interface does not seem to improve anything
- ip flow ingress on or off makes no difference
- disabling the inbound ACL on fa0/0 seems to reduce load by 10%, although I don't understand why - a very high percentage is CPU interrupts, and ACLs are process switched, or not?
- we tried following the Cisco guide for high CPU due to high interrupts, with no success
Here are some usage statistics:
The graphs that we plot via SNMP show a propotional growth/increase of CPU and bandwidth (and thus pps) At the highest loads, we had a bit more than 55% CPU utilization with more than 50% interrupt CPU.
CPU utilization for five seconds: 36%/30%; one minute: 30%; five minutes: 30%
PID Runtime(ms) Invoked uSecs 5Sec 1Min 5Min TTY Process
127 13140 954 13773 2.00% 0.29% 0.07% 194 SSH Process
[Code].....
View 8 Replies
View Related
Jun 22, 2011
I'm polling a few thousand locations using IP SLA, I have responder enabled on all destinations, and I'm using 60 byte voice packets with a QoS policy.When I run an IP SLA Summary availability report, I have a bunch of locations showing 9% availability 8.5% etc. When I go to the actual collector, and pull up a graph of the same time period, that graph shows 100% availability.
Same collector, same data, just different views giving completely different results. I have to assume that the IP SLA summary report is wrong, these sites were not down 90% of the time.
Just a random though to go with that, I do have the IP SLA to only pull information during the locations operational hours, and I did pull the report from midnight to 11am, the statistics should have been gathered for 4 hours of the 11, which is still higher than 9%, and I would expect all of my locations to report like that, not just a few hundred.
All of the devices are similar in hardware and IOS, and I have verified on a handful that IP SLA responder is enabled, and I see the connections, I have also verified the source configuration via command line.
View 5 Replies
View Related