<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ACS 3.2(2) Build 5 replication issue in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/acs-3-2-2-build-5-replication-issue/m-p/1264727#M323408</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ACS uses port TCP/2000 for replication. This port is also used by the skinny protocol, making the port used by ACS replication process.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ACS replication from primary to secondary fails, the primary reports that it can't contact the secondary, and the secondary does not show any replication activity from the primary.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;A firewall between the two ACS servers is configured to inspect the skinny protocol, which uses the same port (TCP/2000) as the ACS replication process.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you do not have a call manager behind your firewall, please disable&lt;/P&gt;&lt;P&gt;skinny inspect if it is enabled.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;#Under the global policy, take the skinny inspection out of the #class inspection_default,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;no inspect skinny&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You need to do this on both the side.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jk&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Plz rate helpful posts-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 05 Nov 2009 20:46:22 GMT</pubDate>
    <dc:creator>Jatin Katyal</dc:creator>
    <dc:date>2009-11-05T20:46:22Z</dc:date>
    <item>
      <title>ACS 3.2(2) Build 5 replication issue</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-3-2-2-build-5-replication-issue/m-p/1264726#M323407</link>
      <description>&lt;P&gt;Hello All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There are two ACS servers one sits on the inside of an ASA 5510 at the head office and the other sits on the inside of an ASA 5510 at the hot site. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Those ASA 5510s were put in to replace two PIX 515Es and the claim is that since the ASAs went in replication has stopped working. This of course makes no sense to me since there is communication between the ACS servers and the firewall is not dropping anything whenever 'replicate now' is issued.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Unfortunately I dont know much about ACS so is there anything I can look for to help troubelshoot this the ACS logs say &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;WARNING Cannot replicate to 'server4' - server not responding &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Which doesnt help much is there any way to get more detailed log info that could point to an issue? Thanks.&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 23:46:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-3-2-2-build-5-replication-issue/m-p/1264726#M323407</guid>
      <dc:creator>kwillacey</dc:creator>
      <dc:date>2019-03-10T23:46:44Z</dc:date>
    </item>
    <item>
      <title>Re: ACS 3.2(2) Build 5 replication issue</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-3-2-2-build-5-replication-issue/m-p/1264727#M323408</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ACS uses port TCP/2000 for replication. This port is also used by the skinny protocol, making the port used by ACS replication process.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ACS replication from primary to secondary fails, the primary reports that it can't contact the secondary, and the secondary does not show any replication activity from the primary.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;A firewall between the two ACS servers is configured to inspect the skinny protocol, which uses the same port (TCP/2000) as the ACS replication process.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you do not have a call manager behind your firewall, please disable&lt;/P&gt;&lt;P&gt;skinny inspect if it is enabled.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;#Under the global policy, take the skinny inspection out of the #class inspection_default,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;no inspect skinny&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You need to do this on both the side.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jk&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Plz rate helpful posts-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Nov 2009 20:46:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-3-2-2-build-5-replication-issue/m-p/1264727#M323408</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2009-11-05T20:46:22Z</dc:date>
    </item>
    <item>
      <title>Re: ACS 3.2(2) Build 5 replication issue</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-3-2-2-build-5-replication-issue/m-p/1264728#M323409</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Wow that did the trick, thanks alot!!! I am concerned that this was not reflected in the firewall logs. I am assuming it was silently dropping it. Is there any way I can ensure that anything that is dropped is logged? &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Nov 2009 21:35:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-3-2-2-build-5-replication-issue/m-p/1264728#M323409</guid>
      <dc:creator>kwillacey</dc:creator>
      <dc:date>2009-11-05T21:35:10Z</dc:date>
    </item>
  </channel>
</rss>

