<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ACS appliance failover( High Availibility) documentation in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/acs-appliance-failover-high-availibility-documentation/m-p/1987803#M207719</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi there,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The ACS doesn't work like an ASA where you can have one active and the other standby. What you can do is to have one primary and another as the secondary, where depending on your TACACS+/Radius commands the authentication server role will change, for example:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;tacacs-server host 10.0.0.1 key xxx&lt;/P&gt;&lt;P&gt;tacacs-server host 20.0.0.1 key xxx&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This configuration means that the router will try to contact 10.0.0.1 always, but if this server goes down, the router will try to contact 20.0.0.1 until the 10.0.0.1 is up again.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So as you can see the ACS servers doesn't have control about which will be the active server, only which is the primary and which is the secondary (primary and secondary is important because you configure the settings in the primary and this one replicates those changes to the secondary).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Documentation:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_system/5.2/user/guide/admin_operations.html#wp1066095"&gt;http://www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_system/5.2/user/guide/admin_operations.html#wp1066095&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 30 May 2012 16:23:20 GMT</pubDate>
    <dc:creator>mauzamor</dc:creator>
    <dc:date>2012-05-30T16:23:20Z</dc:date>
    <item>
      <title>ACS appliance failover( High Availibility) documentation</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-appliance-failover-high-availibility-documentation/m-p/1987802#M207717</link>
      <description>&lt;P&gt;Hi &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have to configure Cisco ACS for Active/Passive role. I am looking for some documentation on that on cisco website but can not find it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can anyone suggest me proper best practice documentation ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you,&lt;/P&gt;&lt;P&gt;Nilay&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 02:08:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-appliance-failover-high-availibility-documentation/m-p/1987802#M207717</guid>
      <dc:creator>Nilaykumar Patel</dc:creator>
      <dc:date>2019-03-11T02:08:48Z</dc:date>
    </item>
    <item>
      <title>ACS appliance failover( High Availibility) documentation</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-appliance-failover-high-availibility-documentation/m-p/1987803#M207719</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi there,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The ACS doesn't work like an ASA where you can have one active and the other standby. What you can do is to have one primary and another as the secondary, where depending on your TACACS+/Radius commands the authentication server role will change, for example:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;tacacs-server host 10.0.0.1 key xxx&lt;/P&gt;&lt;P&gt;tacacs-server host 20.0.0.1 key xxx&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This configuration means that the router will try to contact 10.0.0.1 always, but if this server goes down, the router will try to contact 20.0.0.1 until the 10.0.0.1 is up again.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So as you can see the ACS servers doesn't have control about which will be the active server, only which is the primary and which is the secondary (primary and secondary is important because you configure the settings in the primary and this one replicates those changes to the secondary).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Documentation:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_system/5.2/user/guide/admin_operations.html#wp1066095"&gt;http://www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_system/5.2/user/guide/admin_operations.html#wp1066095&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 30 May 2012 16:23:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-appliance-failover-high-availibility-documentation/m-p/1987803#M207719</guid>
      <dc:creator>mauzamor</dc:creator>
      <dc:date>2012-05-30T16:23:20Z</dc:date>
    </item>
    <item>
      <title>ACS appliance failover( High Availibility) documentation</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-appliance-failover-high-availibility-documentation/m-p/1987804#M207720</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Nilay.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mauricio is right. To expand his answer, if you have several&amp;nbsp; ACS appliances only one of them is primary and all the other ones are&amp;nbsp; secondary.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"Primary" and "secondary" concepts are different from "active" and "standby" concepts. All ACS are "active".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The&amp;nbsp; switch configuration tells the switch which ACS to talk to. It can be&amp;nbsp; one, two, three, any number of ACS. Also if there are more than one ACS,&amp;nbsp; the switch configuration gives the preference to the first ACS declared&amp;nbsp; in the configuration. Only if the first ACS doesn't respond at all&amp;nbsp; then the switch will try to talk to the second ACS declared. Only if the&amp;nbsp; second ACS doesn't respond at all then the switch will try to talk to&amp;nbsp; the third ACS and so on.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;here's an example of switch configuration with three ACS&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;radius-server host 192.168.1.10 key MYPASSWORD&lt;/P&gt;&lt;P&gt;radius-server host 192.168.1.11 key MYPASSWORD&lt;/P&gt;&lt;P&gt;radius-server host 192.168.1.12 key MYPASSWORD&lt;/P&gt;&lt;P&gt;radius-server vsa send authentication&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa new-model&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;aaa group server radius ACS&lt;/P&gt;&lt;P&gt; server 192.168.1.10&lt;/P&gt;&lt;P&gt; server 192.168.1.11&lt;/P&gt;&lt;P&gt; server 192.168.1.12&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;aaa authentication dot1x default group ACS&lt;/P&gt;&lt;P&gt;aaa authorization network default group ACS &lt;/P&gt;&lt;P&gt;aaa accounting dot1x default start-stop group ACS&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 30 May 2012 22:04:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-appliance-failover-high-availibility-documentation/m-p/1987804#M207720</guid>
      <dc:creator>Eduardo Aliaga</dc:creator>
      <dc:date>2012-05-30T22:04:31Z</dc:date>
    </item>
    <item>
      <title>ACS appliance failover( High Availibility) documentation</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-appliance-failover-high-availibility-documentation/m-p/1987805#M207721</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; I configured distributed deployment explained in above document and it works fire. Thank you for your help.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Nilay&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 01 Jun 2012 19:05:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-appliance-failover-high-availibility-documentation/m-p/1987805#M207721</guid>
      <dc:creator>Nilaykumar Patel</dc:creator>
      <dc:date>2012-06-01T19:05:52Z</dc:date>
    </item>
  </channel>
</rss>

