<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Cisco ACS 5.3 patch 8 OPT Volume in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cisco-acs-5-3-patch-8-opt-volume/m-p/2269745#M136725</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We currently have 12 ACS appliance with one of them being a dedicated Log Collector. We have 802.1x authentication configured for both network port and wireless access. We are authenticating desktop, laptops, smart phones, etc on our network.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The problem we are having is the OPT volume exceeding 30% volume size recommended by Cisco TAC every few months. We have recently added more network resources to our network (merger). We are now hitting the 30% size in about 1 month. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In the past we have called Cisco TAC when we had issues with Log Collector performance. At that time is was also authenticating 802.1x clients. We added a new appliance and made it a dedicated Log Collector. They would check the OPT volume and find that it was at about 70% use size. They would run the Root Console patch and delete the DB and then recreate it. We have done that about 2 times before we started to monitor the OPT volume size.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This last time we ran into the 30% volume size quicker then we have previously had. I had Cisco TAC delete the OPT volume and recreate it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cisco TAC has recommended we reduce the amount of logs that are being sent to the Log Collector. We are currently exploring that option.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The questions I have is: &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;At what percentage size for the OPT volume should we be concerned before it starts impacting the performance of the Log Collector? &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Is there something else we can be do to reduce the amount of logs that are being sent to the Log Collector?&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;We have Data Purging set to 30 days. We are performing Full and Incremental backups of database. We are also sending the local logs a Syslog server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We are testing making changes to send only the AAA Audit and System Statistics logs to Log Collector.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 03:24:59 GMT</pubDate>
    <dc:creator>Rogelio Mercado</dc:creator>
    <dc:date>2019-03-11T03:24:59Z</dc:date>
    <item>
      <title>Cisco ACS 5.3 patch 8 OPT Volume</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-acs-5-3-patch-8-opt-volume/m-p/2269745#M136725</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We currently have 12 ACS appliance with one of them being a dedicated Log Collector. We have 802.1x authentication configured for both network port and wireless access. We are authenticating desktop, laptops, smart phones, etc on our network.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The problem we are having is the OPT volume exceeding 30% volume size recommended by Cisco TAC every few months. We have recently added more network resources to our network (merger). We are now hitting the 30% size in about 1 month. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In the past we have called Cisco TAC when we had issues with Log Collector performance. At that time is was also authenticating 802.1x clients. We added a new appliance and made it a dedicated Log Collector. They would check the OPT volume and find that it was at about 70% use size. They would run the Root Console patch and delete the DB and then recreate it. We have done that about 2 times before we started to monitor the OPT volume size.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This last time we ran into the 30% volume size quicker then we have previously had. I had Cisco TAC delete the OPT volume and recreate it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cisco TAC has recommended we reduce the amount of logs that are being sent to the Log Collector. We are currently exploring that option.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The questions I have is: &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;At what percentage size for the OPT volume should we be concerned before it starts impacting the performance of the Log Collector? &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Is there something else we can be do to reduce the amount of logs that are being sent to the Log Collector?&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;We have Data Purging set to 30 days. We are performing Full and Incremental backups of database. We are also sending the local logs a Syslog server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We are testing making changes to send only the AAA Audit and System Statistics logs to Log Collector.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 03:24:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-acs-5-3-patch-8-opt-volume/m-p/2269745#M136725</guid>
      <dc:creator>Rogelio Mercado</dc:creator>
      <dc:date>2019-03-11T03:24:59Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ACS 5.3 patch 8 OPT Volume</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-acs-5-3-patch-8-opt-volume/m-p/2269746#M136733</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In distributed setup, its recommended to configure a dedicated&amp;nbsp; secondary server as a log collector. However you've a large deployment&amp;nbsp; so I'm sure authentication rate would be high too causing view-database&amp;nbsp; size keep on increasing.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In order to prevent running out of disk space we need&amp;nbsp; to manage it. That means identifying the files that are created and&amp;nbsp; written to by&amp;nbsp; processes on the system, allocating a space budget to&amp;nbsp; them such that if&amp;nbsp; the files stay within their budget all services can&amp;nbsp; be supported without&amp;nbsp; interruption, and then defining and implementing&amp;nbsp; facilities to keep&amp;nbsp; those files within their budget.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There are two mechanisms to reduce this size and prevent it from exceeding the maximum limit.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. Purge: In this mechanism the data will be purged based&amp;nbsp; on the&amp;nbsp; configured data retention period or upon reaching the upper&amp;nbsp; limit of the&amp;nbsp; database.&amp;nbsp; In Patch 6 new option provided to do on demand&amp;nbsp; purge as&amp;nbsp; well.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2. Compress: This mechanism frees up&amp;nbsp; unused space in the&amp;nbsp; database without deleting any records. Before the&amp;nbsp; compress option could&amp;nbsp; only be run manually.&amp;nbsp; In ACS 5.3 Patch 6 there&amp;nbsp; are enhancements so it&amp;nbsp; will run daily at a predefined time, automatically when specific&amp;nbsp; criteria are met. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;At what percentage size for the OPT volume should we be&amp;nbsp; concerned before it starts impacting the performance of the Log&amp;nbsp; Collector?&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;TAC recommendations are right. You will able to utilize all feature of ACS if /opt is below 30%.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Is there something else we can be do to reduce the amount of logs that are being sent to the Log Collector?&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;It seems you're using most of the features/mechanisms to have /opt low. However, you may be intrested to read more on data purging and data compression enhancements &lt;A href="http://www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_system/5.4/release/notes/acs_54_rn.html" rel="nofollow"&gt;http://www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_system/5.4/release/notes/acs_54_rn.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Please use System Administration &amp;gt;&amp;nbsp; Configuration &amp;gt; Log&amp;nbsp; Configuration &amp;gt;&amp;nbsp; Logging Categories &amp;gt;&amp;nbsp; Global To configure sending&amp;nbsp; only the required logs to the ACS View log-collector.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Provide the fresh screenshot of the page Monitoring&amp;nbsp;&amp;nbsp; Configuration &amp;gt; System Operations &amp;gt; Data Management &amp;gt; Removal&amp;nbsp;&amp;nbsp; and Backup.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- With the below listed command you can check the actual and physical size of the MnT database&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; acs-config&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Username: acsadmin&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Password: ***********&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; acsview show-dbsize&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There are few known defects on the same issue. However, the version you're running improves database management processes. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.cisco.com/cisco/psn/bssprt/bss?searchType=bstbugidsearch&amp;amp;page=bstBugDetail&amp;amp;BugID=CSCto47203" rel="nofollow" target="_blank"&gt;CSCto47203&lt;/A&gt;: ACS 5 runs out of disk space&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.cisco.com/cisco/psn/bssprt/bss?searchType=bstbugidsearch&amp;amp;page=bstBugDetail&amp;amp;BugID=CSCua51804" rel="nofollow" target="_blank"&gt;CSCua51804&lt;/A&gt;: View backup fails&amp;nbsp;&amp;nbsp; even when there is space in disk&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jatin Katyal &lt;BR /&gt; &lt;BR /&gt;- Do rate helpful posts -&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 10 May 2013 01:40:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-acs-5-3-patch-8-opt-volume/m-p/2269746#M136733</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2013-05-10T01:40:01Z</dc:date>
    </item>
    <item>
      <title>Cisco ACS 5.3 patch 8 OPT Volume</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-acs-5-3-patch-8-opt-volume/m-p/2269747#M136742</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;thanks for the reply.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So then it looks the best course of action would be to upgrade to ACS 5.4 to take advantage of the data purging and data compression enhancements.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We are going to be adding 3 more ACS appliances in next few months. So our OPT volume issue will just be getting worse.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there any know issues with upgrading using the "Upgrading an ACS Server Using the Application Upgrade Bundle" path?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Roy&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 10 May 2013 17:39:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-acs-5-3-patch-8-opt-volume/m-p/2269747#M136742</guid>
      <dc:creator>Rogelio Mercado</dc:creator>
      <dc:date>2013-05-10T17:39:21Z</dc:date>
    </item>
    <item>
      <title>Cisco ACS 5.3 patch 8 OPT Volume</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-acs-5-3-patch-8-opt-volume/m-p/2269748#M136749</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;No doubt. There are no known issues with the upgrade however there are couple of points that need to be keep in mind while upgrading to ACS 5.4&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Upgrading an ACS Server using the Application Upgrade Bundle&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Reimaging and Upgrading an ACS Serve&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can only perform an application upgrade bundle, on either a Cisco appliance or a virtual machine, if the disk size is greater than or equal to 500 GB. If you have a smaller disk size, you need to reimage to ACS 5.4 followed by a restore of the backup taken in ACS 5.3 version to trigger the upgrade.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When you upgrade from ACS 5.3 to 5.4, it is mandatory to install ACS 5.3 latest patch prior to the upgrade or the upgrade may fail. If you use the version prior to ACS 5.3.0.40.6, then you might hit an error and the upgrade will not proceed. Note that ACS 5.4 does not include all fixes that are included in 5.3.0.40.8. Therefore, if any of these fixes in 5.3.0.40.8 are required in your deployment, then you should install patch 5.4.0.46.1 after you upgrade to ACS 5.4. Patch 2 is also available now to add windows 2012 support.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Installation guide&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_system/5.4/installation/guide/csacs_upg.html"&gt;http://www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_system/5.4/installation/guide/csacs_upg.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Release notes:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_system/5.4/release/notes/acs_54_rn.html"&gt;http://www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_system/5.4/release/notes/acs_54_rn.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this answers.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jatin Katyal &lt;BR /&gt; &lt;BR /&gt;- Do rate helpful posts -&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 10 May 2013 17:56:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-acs-5-3-patch-8-opt-volume/m-p/2269748#M136749</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2013-05-10T17:56:13Z</dc:date>
    </item>
    <item>
      <title>Cisco ACS 5.3 patch 8 OPT Volume</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-acs-5-3-patch-8-opt-volume/m-p/2269749#M136754</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You may also go through this post the acs 5.4 experience being discussed few days ago.&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="https://community.cisco.com/message/3781934#3781934"&gt;https://supportforums.cisco.com/message/3781934#3781934&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jatin Katyal &lt;BR /&gt; &lt;BR /&gt; &lt;BR /&gt;- Do rate helpful posts -&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 10 May 2013 18:05:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-acs-5-3-patch-8-opt-volume/m-p/2269749#M136754</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2013-05-10T18:05:47Z</dc:date>
    </item>
    <item>
      <title>Cisco ACS 5.3 patch 8 OPT Volume</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-acs-5-3-patch-8-opt-volume/m-p/2269750#M136766</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the information.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We are currently at version 5.3.0.40.8 and have 500 gb thick drive for our VM apliances.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We wilI move forward with upgrading to ACS 5.4 patch 2 to help remedy the OPT volume issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks again,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rogelio Mercado &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 10 May 2013 18:12:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-acs-5-3-patch-8-opt-volume/m-p/2269750#M136766</guid>
      <dc:creator>Rogelio Mercado</dc:creator>
      <dc:date>2013-05-10T18:12:42Z</dc:date>
    </item>
    <item>
      <title>Cisco ACS 5.3 patch 8 OPT Volume</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-acs-5-3-patch-8-opt-volume/m-p/2269751#M136790</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sounds good!!! Have a nice day ahead &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jatin Katyal &lt;BR /&gt; &lt;BR /&gt; &lt;BR /&gt;- Do rate helpful posts -&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 10 May 2013 18:17:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-acs-5-3-patch-8-opt-volume/m-p/2269751#M136790</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2013-05-10T18:17:00Z</dc:date>
    </item>
  </channel>
</rss>

