<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Export then import AAA client database from ACS server in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/export-then-import-aaa-client-database-from-acs-server/m-p/723885#M420717</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Nope - I just tried it and it won't work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I tried copying one individual host (key) from one registry to the other -- it didn't work and the ACS "freaked out".  Once I deleted the host out of the registry everything went back to normal.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm not sure if it's because one server is Windows 2000 and the other is 2003 or if it's simply a matter of certain checksums in the key portion that are system specific.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Either way, importing registry entries won't work and isn't an option.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Maybe I can just do a database dump, import the whole thing into the new server, then just delete the parts I don't want after the fact. Still considering all my options.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 17 May 2007 01:56:18 GMT</pubDate>
    <dc:creator>jeremyault</dc:creator>
    <dc:date>2007-05-17T01:56:18Z</dc:date>
    <item>
      <title>Export then import AAA client database from ACS server</title>
      <link>https://community.cisco.com/t5/network-access-control/export-then-import-aaa-client-database-from-acs-server/m-p/723882#M420714</link>
      <description>&lt;P&gt;I have a Cisco ACS server (lets call it server A) running on Windows 2000 server. It has several hundred AAA clients and several hundred user accounts.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now I have a new Cisco ACS server (we'll call it Server B) which now uses an exteral database to authenticate users but I want to move all the AAA clients from server A to this new server B.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I looked up the CSUtil.exe and I see I can dump the database.. but I want to import only the devices into the new server.  Not the users, not the administrators, or any other info.  Just the AAA clients.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any ideas?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 22:09:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/export-then-import-aaa-client-database-from-acs-server/m-p/723882#M420714</guid>
      <dc:creator>jeremyault</dc:creator>
      <dc:date>2019-03-10T22:09:52Z</dc:date>
    </item>
    <item>
      <title>Re: Export then import AAA client database from ACS server</title>
      <link>https://community.cisco.com/t5/network-access-control/export-then-import-aaa-client-database-from-acs-server/m-p/723883#M420715</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If the versions of ACS match the easiest thing is to replicate just the network config db from one to the other.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Pre v4.0 and you can copy the network config registry between servers (non appliance)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Darran&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 15 May 2007 18:37:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/export-then-import-aaa-client-database-from-acs-server/m-p/723883#M420715</guid>
      <dc:creator>darpotter</dc:creator>
      <dc:date>2007-05-15T18:37:20Z</dc:date>
    </item>
    <item>
      <title>Re: Export then import AAA client database from ACS server</title>
      <link>https://community.cisco.com/t5/network-access-control/export-then-import-aaa-client-database-from-acs-server/m-p/723884#M420716</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Excellent - just the information I was looking for. I didn't realize everything was stored in the registry.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This should be a fairly straightforward process of exporting reistry branches and exporting them back in on the destination system.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 15 May 2007 19:36:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/export-then-import-aaa-client-database-from-acs-server/m-p/723884#M420716</guid>
      <dc:creator>jeremyault</dc:creator>
      <dc:date>2007-05-15T19:36:12Z</dc:date>
    </item>
    <item>
      <title>Re: Export then import AAA client database from ACS server</title>
      <link>https://community.cisco.com/t5/network-access-control/export-then-import-aaa-client-database-from-acs-server/m-p/723885#M420717</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Nope - I just tried it and it won't work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I tried copying one individual host (key) from one registry to the other -- it didn't work and the ACS "freaked out".  Once I deleted the host out of the registry everything went back to normal.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm not sure if it's because one server is Windows 2000 and the other is 2003 or if it's simply a matter of certain checksums in the key portion that are system specific.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Either way, importing registry entries won't work and isn't an option.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Maybe I can just do a database dump, import the whole thing into the new server, then just delete the parts I don't want after the fact. Still considering all my options.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 17 May 2007 01:56:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/export-then-import-aaa-client-database-from-acs-server/m-p/723885#M420717</guid>
      <dc:creator>jeremyault</dc:creator>
      <dc:date>2007-05-17T01:56:18Z</dc:date>
    </item>
    <item>
      <title>Re: Export then import AAA client database from ACS server</title>
      <link>https://community.cisco.com/t5/network-access-control/export-then-import-aaa-client-database-from-acs-server/m-p/723886#M420718</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;OK, I forgot the master encryption key is per install. Sorry.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ok not perfect but on the trial download page of extraxi.com there is a script called "getacsdb" which does just that for v3.x&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It will create a cab inside which are exported CSVs of the nas's and ndgs. You could extract this and munge it into a csutil nas import file (see online docs for csutil).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you're using NDGs these would have to manually created first.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Darran&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 17 May 2007 19:43:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/export-then-import-aaa-client-database-from-acs-server/m-p/723886#M420718</guid>
      <dc:creator>darpotter</dc:creator>
      <dc:date>2007-05-17T19:43:28Z</dc:date>
    </item>
    <item>
      <title>Re: Export then import AAA client database from ACS server</title>
      <link>https://community.cisco.com/t5/network-access-control/export-then-import-aaa-client-database-from-acs-server/m-p/723887#M420719</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Could try this... create a nas with a known secret on the new server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Dump the reg, copy and paste the secret from the new reg into that exported from the old ACS server. Paste the key into every NAS record.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You'll get a config that works... but all with the same shared secret. Again not perfect but most of the heavy lifting is done.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 17 May 2007 19:46:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/export-then-import-aaa-client-database-from-acs-server/m-p/723887#M420719</guid>
      <dc:creator>darpotter</dc:creator>
      <dc:date>2007-05-17T19:46:04Z</dc:date>
    </item>
    <item>
      <title>Re: Export then import AAA client database from ACS server</title>
      <link>https://community.cisco.com/t5/network-access-control/export-then-import-aaa-client-database-from-acs-server/m-p/723888#M420720</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I tried something like what you're saying. I too thought that the "key" was just the shared secret and could be pasted from an existing device on the new server.. but it didn't work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The "key" part of an aaa host in the registry appears to be a hash derrived from combining the host name, group, authentication type, shared secret, etc.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So doing something as simple as changing one letter in the host name or moving it to a different group completely changed the resultant "key".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Like you said -- since the master encryption is system specific, the checksum doesn't match up to all the rest of the settings and it just won't work.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 17 May 2007 20:32:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/export-then-import-aaa-client-database-from-acs-server/m-p/723888#M420720</guid>
      <dc:creator>jeremyault</dc:creator>
      <dc:date>2007-05-17T20:32:29Z</dc:date>
    </item>
    <item>
      <title>Re: Export then import AAA client database from ACS server</title>
      <link>https://community.cisco.com/t5/network-access-control/export-then-import-aaa-client-database-from-acs-server/m-p/723889#M420721</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I figured out how (quite a while back) how to export and import all the devices from one ACS server to another.  It's actually quite low tech.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Go into the Network portion of the ACS server and do a "search" using all wildcards. That will dump out a list of all network devices, their IP address, and group.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then, click download and save it as a .csv file. From there it's just a matter of inserting a key for each host, putting it into the proper text format and importing the entire thing into the new ACS using the CSUtil.exe.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Simple really.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Oh, just be sure to create the network groups on the new ACS server before importing or the devices will go to the "unknown" group.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 29 Aug 2007 23:15:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/export-then-import-aaa-client-database-from-acs-server/m-p/723889#M420721</guid>
      <dc:creator>jeremyault</dc:creator>
      <dc:date>2007-08-29T23:15:00Z</dc:date>
    </item>
    <item>
      <title>Re: Export then import AAA client database from ACS server</title>
      <link>https://community.cisco.com/t5/network-access-control/export-then-import-aaa-client-database-from-acs-server/m-p/723890#M420723</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Darran,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could you please be more specific about how exactly to import the NAS list from the old ACS server?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 28 Nov 2007 16:36:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/export-then-import-aaa-client-database-from-acs-server/m-p/723890#M420723</guid>
      <dc:creator>v.kirillov</dc:creator>
      <dc:date>2007-11-28T16:36:20Z</dc:date>
    </item>
    <item>
      <title>Re: Export then import AAA client database from ACS server</title>
      <link>https://community.cisco.com/t5/network-access-control/export-then-import-aaa-client-database-from-acs-server/m-p/723891#M420725</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I was never able to successfully copy the data from one server's registry to another. It doesn't work because parts of the data are stored using encryption. What I ended up doing was to create a text file of the NAS list (do a seach for all devices in ACS, then do a download of the result into a spreadsheet) which I was then able to modify into the specific format and save as a text file. I then imported the text file into the new system's database using the CSUTIL command.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The format of the text file needs to be exactly as follows (note - the first line should be the word offline or online). Also, you might be using RADIUS in the place of TACACS+. See &lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/sw/secursw/ps2086/products_user_guide_chapter09186a008007d0c9.html" target="_blank"&gt;http://www.cisco.com/en/US/products/sw/secursw/ps2086/products_user_guide_chapter09186a008007d0c9.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;OFFLINE&lt;/P&gt;&lt;P&gt;ADD_NAS:ROUTERH01:IP:10.10.36.5:KEY:Super$ecretKey99:VENDOR:"TACACS+ (Cisco IOS)":NDG:"Houston"&lt;/P&gt;&lt;P&gt;ADD_NAS:ROUTERH02:IP:10.10.36.6:KEY:Super$ecretKey99:VENDOR:"TACACS+ (Cisco IOS)":NDG:"Houston"&lt;/P&gt;&lt;P&gt;ADD_NAS:ROUTERS01:IP:10.10.72.5:KEY:Super$ecretKey99:VENDOR:"TACACS+ (Cisco IOS)":NDG:"Springfield"&lt;/P&gt;&lt;P&gt;ADD_NAS:ROUTERS02:IP:10.10.72.6:KEY:Super$ecretKey99:VENDOR:"TACACS+ (Cisco IOS)":NDG:"Springfield"&lt;/P&gt;&lt;P&gt;ADD_NAS:ROUTERD01:IP:10.10.84.5:KEY:Super$ecretKey99:VENDOR:"TACACS+ (Cisco IOS)":NDG:"Dallas"&lt;/P&gt;&lt;P&gt;ADD_NAS:ROUTERD02:IP:10.10.84.6:KEY:Super$ecretKey99:VENDOR:"TACACS+ (Cisco IOS)":NDG:"Dallas"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hint: you will need to create each of the network device groups before you import the text file.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 28 Nov 2007 17:37:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/export-then-import-aaa-client-database-from-acs-server/m-p/723891#M420725</guid>
      <dc:creator>jeremyault</dc:creator>
      <dc:date>2007-11-28T17:37:53Z</dc:date>
    </item>
    <item>
      <title>Re: Export then import AAA client database from ACS server</title>
      <link>https://community.cisco.com/t5/network-access-control/export-then-import-aaa-client-database-from-acs-server/m-p/723892#M420726</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I would always keep the import file as your master repository.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That way if you need to move to another ACS you already have the data.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can do it copying registry. but you'd have to edit each NAS in turn to reset the shared key.. which doesnt scale.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 30 Nov 2007 11:06:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/export-then-import-aaa-client-database-from-acs-server/m-p/723892#M420726</guid>
      <dc:creator>darpotter</dc:creator>
      <dc:date>2007-11-30T11:06:52Z</dc:date>
    </item>
  </channel>
</rss>

