<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ACS and remote agent upgrade question in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/acs-and-remote-agent-upgrade-question/m-p/1353055#M322998</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;Chris:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;Well, yes you can upgrade the primary server but why I suggested you to upgrade the secondary first; all your NAS devices should have the primary server listed first so if there is no communication with primary server there might be some delay while user try to authenticate.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;&lt;STRONG&gt;IMP&lt;/STRONG&gt; :&amp;nbsp; Whenever we change/delete the primary/secondary remote agent under external user database...group mapping will disappear. &lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;HTH&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;Regards,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;JK&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;Pla rate helpful posts-&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 24 Dec 2009 14:06:24 GMT</pubDate>
    <dc:creator>Jatin Katyal</dc:creator>
    <dc:date>2009-12-24T14:06:24Z</dc:date>
    <item>
      <title>ACS and remote agent upgrade question</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-and-remote-agent-upgrade-question/m-p/1353052#M322995</link>
      <description>&lt;P&gt;Just looking for a clarification on upgrading. Short story long, 2 ACS&lt;/P&gt;&lt;P&gt;SEs, single remote agent being used for wireless authentication.&lt;/P&gt;&lt;P&gt;Current version 3.3.3.11. Upgrading to 4.1.4.13.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The ACSs are in a primary/backup. My plan is to upgrade the backup appliance offline.&lt;/P&gt;&lt;P&gt;That doesn't worry me, my biggest worry is in the remote agent upgrade for reasons I&lt;/P&gt;&lt;P&gt;won't get into here. Then upgrade the remote agent, then upgrade the primary offline.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My question is, if I do the upgrade this way, when I re-install the remote agent, should I&lt;/P&gt;&lt;P&gt;set the config provider to the IP of the upgraded unit (the backup). The config provider is&lt;/P&gt;&lt;P&gt;currently set to the primary unit. I can't determine from the docs if this is the case, but&lt;/P&gt;&lt;P&gt;the docs to say that the config provider must respond to the remote agent upon startup&lt;/P&gt;&lt;P&gt;of the remote agent. I believe this is what I need to do.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have no problem adjuting the ini file and restarting the agent, then switching back after the&lt;/P&gt;&lt;P&gt;primary is upgraded, if this is what is needed. Wireless being a rather touchy subject where&lt;/P&gt;&lt;P&gt;I work, I can't afford extended downtime.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Once again, just looking for clarification. Any help/advice is appreciated - chris&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 23:51:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-and-remote-agent-upgrade-question/m-p/1353052#M322995</guid>
      <dc:creator>cmarva</dc:creator>
      <dc:date>2019-03-10T23:51:35Z</dc:date>
    </item>
    <item>
      <title>Re: ACS and remote agent upgrade question</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-and-remote-agent-upgrade-question/m-p/1353053#M322996</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;BR /&gt;&lt;SPAN style="color: #800000;"&gt;Chris:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;I understand your plan for upgrading appliances and remote agent server. This is actually the right practice.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;&lt;SPAN style="text-decoration: underline;"&gt;&lt;SPAN style="color: #800000;"&gt;We should always have the ip address of primary ACS SE as a configuration provider&lt;/SPAN&gt; &lt;/SPAN&gt;so If you are upgrading backup one first then let the primary server catering the authentication request and upgrade the remote agent server while upgrading the primary ACS SE.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="color: #800000; "&gt;From installation guide:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;Although a remote agent can accept inbound communication from many appliances, it accepts configuration instructions from only a single appliance that you specify in the CSAgent.ini file. This special appliance is called a configuration provider.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;When a remote agent starts, it reads its CSAgent.ini file to determine which services should be available and which appliance is its configuration provider. Then it contacts the configuration provider and requests its configuration.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;After receiving its configuration from the configuration provider, the remote agent is available to provide the services configured in CSAgent.ini.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_server_for_solution_engine/4.2/installation/guide/remote_agent/rawo.html#wp219996"&gt;http://www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_server_for_solution_engine/4.2/installation/guide/remote_agent/rawo.html#wp219996&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;HTH&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;Regards,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;JK&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;Plz rate helpful posts-&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 Dec 2009 22:15:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-and-remote-agent-upgrade-question/m-p/1353053#M322996</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2009-12-23T22:15:39Z</dc:date>
    </item>
    <item>
      <title>Re: ACS and remote agent upgrade question</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-and-remote-agent-upgrade-question/m-p/1353054#M322997</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;JK, I appreciate the reply. That's the clarification I needed, configuration provider is always the primary.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It just seems to me, though, that if the config provider is always the primary, then why not upgrade the primary&lt;/P&gt;&lt;P&gt;first and let the backup handle the auth requests. I mean, it just seems like doing the backup first doesn't&lt;/P&gt;&lt;P&gt;achieve a whole lot if the RA is upgraded when the primary ACS is upgraded. But I'm just thinking out loud......&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks again for the help - chris&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 24 Dec 2009 12:51:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-and-remote-agent-upgrade-question/m-p/1353054#M322997</guid>
      <dc:creator>cmarva</dc:creator>
      <dc:date>2009-12-24T12:51:30Z</dc:date>
    </item>
    <item>
      <title>Re: ACS and remote agent upgrade question</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-and-remote-agent-upgrade-question/m-p/1353055#M322998</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;Chris:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;Well, yes you can upgrade the primary server but why I suggested you to upgrade the secondary first; all your NAS devices should have the primary server listed first so if there is no communication with primary server there might be some delay while user try to authenticate.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;&lt;STRONG&gt;IMP&lt;/STRONG&gt; :&amp;nbsp; Whenever we change/delete the primary/secondary remote agent under external user database...group mapping will disappear. &lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;HTH&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;Regards,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;JK&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #800000;"&gt;Pla rate helpful posts-&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 24 Dec 2009 14:06:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-and-remote-agent-upgrade-question/m-p/1353055#M322998</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2009-12-24T14:06:24Z</dc:date>
    </item>
    <item>
      <title>Re: ACS and remote agent upgrade question</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-and-remote-agent-upgrade-question/m-p/1353056#M322999</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;Understood, just thinking out loud....the procedure just seems a little bit odd unless I'm missing something. No big deal, I'll get through it.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;also, on your note about group mappings, I did see this in the documentation, but it didn't quite sink in. Now it is stuck in my head to double&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;check group mappings after the upgrade is done. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;Thanks again, I appreciate it - chris&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 24 Dec 2009 17:31:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-and-remote-agent-upgrade-question/m-p/1353056#M322999</guid>
      <dc:creator>cmarva</dc:creator>
      <dc:date>2009-12-24T17:31:04Z</dc:date>
    </item>
  </channel>
</rss>

