<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Issues with ACS replication in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/issues-with-acs-replication/m-p/955643#M419645</link>
    <description>&lt;P&gt;We have 2 ACS appliances that are separated by a WAN.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Both appliances are at the same software version and I have replication set up per Cisco's (as well as others') directions.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I run replication, I get the error "Cannot replicate to 'ciscoacs2' - server not responding".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If I try replication in the other direction, I get the same error.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can ping both appliances and access the web interface from both subnets.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There is a firewall between them, but I have port 2000 open and I do not see any other deny messages relating to the ACS replication in the firewall logging.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I ran a sniffer on the receiving appliance's port and got the following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;10.127.101.5	10.127.80.63	TCP	evb-elm &amp;gt; cisco-sccp [SYN] Seq=0 Win=65535 Len=0 MSS=1380&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;10.127.101.5	10.127.80.63	TCP	evb-elm &amp;gt; cisco-sccp [ACK] Seq=1 Ack=1 Win=65535 Len=0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;10.127.80.63	10.127.101.5	TCP	cisco-sccp &amp;gt; evb-elm [SYN, ACK] Seq=0 Ack=1 Win=65535 Len=0 MSS=1460&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;10.127.101.5	10.127.80.63	TCP	evb-elm &amp;gt; cisco-sccp [RST] Seq=25 Win=0 Len=0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;10.127.80.63	10.127.101.5	TCP	[TCP Dup ACK 1515#1] cisco-sccp &amp;gt; evb-elm [ACK] Seq=1 Ack=1 Win=65535 Len=0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Logging on the devices themselves is terrible, so I really have no idea what would be causing replication to fail.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jason&lt;/P&gt;</description>
    <pubDate>Sun, 10 Mar 2019 22:43:23 GMT</pubDate>
    <dc:creator>jwilliams</dc:creator>
    <dc:date>2019-03-10T22:43:23Z</dc:date>
    <item>
      <title>Issues with ACS replication</title>
      <link>https://community.cisco.com/t5/network-access-control/issues-with-acs-replication/m-p/955643#M419645</link>
      <description>&lt;P&gt;We have 2 ACS appliances that are separated by a WAN.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Both appliances are at the same software version and I have replication set up per Cisco's (as well as others') directions.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I run replication, I get the error "Cannot replicate to 'ciscoacs2' - server not responding".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If I try replication in the other direction, I get the same error.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can ping both appliances and access the web interface from both subnets.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There is a firewall between them, but I have port 2000 open and I do not see any other deny messages relating to the ACS replication in the firewall logging.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I ran a sniffer on the receiving appliance's port and got the following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;10.127.101.5	10.127.80.63	TCP	evb-elm &amp;gt; cisco-sccp [SYN] Seq=0 Win=65535 Len=0 MSS=1380&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;10.127.101.5	10.127.80.63	TCP	evb-elm &amp;gt; cisco-sccp [ACK] Seq=1 Ack=1 Win=65535 Len=0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;10.127.80.63	10.127.101.5	TCP	cisco-sccp &amp;gt; evb-elm [SYN, ACK] Seq=0 Ack=1 Win=65535 Len=0 MSS=1460&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;10.127.101.5	10.127.80.63	TCP	evb-elm &amp;gt; cisco-sccp [RST] Seq=25 Win=0 Len=0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;10.127.80.63	10.127.101.5	TCP	[TCP Dup ACK 1515#1] cisco-sccp &amp;gt; evb-elm [ACK] Seq=1 Ack=1 Win=65535 Len=0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Logging on the devices themselves is terrible, so I really have no idea what would be causing replication to fail.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jason&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 22:43:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/issues-with-acs-replication/m-p/955643#M419645</guid>
      <dc:creator>jwilliams</dc:creator>
      <dc:date>2019-03-10T22:43:23Z</dc:date>
    </item>
    <item>
      <title>Re: Issues with ACS replication</title>
      <link>https://community.cisco.com/t5/network-access-control/issues-with-acs-replication/m-p/955644#M419646</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;One update if it will help.  I've been doing some research and I found that ACS replication doesn't like NAT and replication will fail if the IP address is changed through NAT.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;While NAT is running on the firewall that our ACS appliance is behind, there is a static mapping to basically keep the NAT address the same.  So NAT is being applied, but NAT is just giving it the same address.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I don't know if the NAT process is what's causing the problem?  Based on the sniff I posted earlier, the source address of 101.5 is the IP of the ACS appliance.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Taking the device out from behind the firewall could be an option, but it would be a last resort because we would then need to reconfigure all of our equipment to point to the new address, and we have a lot of equipment.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jason&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 20 Mar 2008 15:36:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/issues-with-acs-replication/m-p/955644#M419646</guid>
      <dc:creator>jwilliams</dc:creator>
      <dc:date>2008-03-20T15:36:04Z</dc:date>
    </item>
    <item>
      <title>Re: Issues with ACS replication</title>
      <link>https://community.cisco.com/t5/network-access-control/issues-with-acs-replication/m-p/955645#M419647</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Following links may help you&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/sw/secursw/ps2086/products_configuration_example09186a00800e518a.shtml" target="_blank"&gt;http://www.cisco.com/en/US/products/sw/secursw/ps2086/products_configuration_example09186a00800e518a.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a0080742f60.shtml" target="_blank"&gt;http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a0080742f60.shtml&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 20 Mar 2008 18:22:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/issues-with-acs-replication/m-p/955645#M419647</guid>
      <dc:creator>tstanik</dc:creator>
      <dc:date>2008-03-20T18:22:48Z</dc:date>
    </item>
  </channel>
</rss>

