<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Replication Problems v3.3.4 in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/replication-problems-v3-3-4/m-p/665916#M421310</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Cool, I have attached a screen shot of both servers registry entries.  They are different.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 15 Mar 2007 15:06:39 GMT</pubDate>
    <dc:creator>mapones</dc:creator>
    <dc:date>2007-03-15T15:06:39Z</dc:date>
    <item>
      <title>Replication Problems v3.3.4</title>
      <link>https://community.cisco.com/t5/network-access-control/replication-problems-v3-3-4/m-p/665912#M421305</link>
      <description>&lt;P&gt;I just upgraded to 3.3.4 and I am seeing a problem with the replication.  I have two ACS servers and they are authenticating to a CrytoCard Server.  So I configured the external DB on both servers to point to it.  I have users created and they are pointed to that external DB.  Everything works perfect, even the failover if I shut the services on the primary server.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However when I replicate the failover does not work any more.  What I see is if I look at a user on the backup server the Password Authentication section for all the users is "Unknown Radius Server".  I can select the CryptoCard server and it all works fine again.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any ideas how I can fix/troubleshoot this?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any help would be appreciated.  TAC is working on it also, but I wanted to see if anyone else has experianced this problem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;BTW this is running on a windows server...&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 22:02:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/replication-problems-v3-3-4/m-p/665912#M421305</guid>
      <dc:creator>mapones</dc:creator>
      <dc:date>2019-03-10T22:02:33Z</dc:date>
    </item>
    <item>
      <title>Re: Replication Problems v3.3.4</title>
      <link>https://community.cisco.com/t5/network-access-control/replication-problems-v3-3-4/m-p/665913#M421307</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have seen this problem couple of times. This is caused because ACS refers to the database by numbers internally.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So when the primary server replicates to the secondary it sets the user to authenticate to say "Database 2". On the secondary the Crytocard maybe at "Database 1". So everytime there is a replication, the user on the secondary server starts pointing to "Database 2" instead of "Database 1".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;One workaround to this is to create another database pointing to the same cryptocard and see if the the new one lands in the right number.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Vivek&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 15 Mar 2007 14:45:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/replication-problems-v3-3-4/m-p/665913#M421307</guid>
      <dc:creator>Vivek Santuka</dc:creator>
      <dc:date>2007-03-15T14:45:14Z</dc:date>
    </item>
    <item>
      <title>Re: Replication Problems v3.3.4</title>
      <link>https://community.cisco.com/t5/network-access-control/replication-problems-v3-3-4/m-p/665914#M421308</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Very interesting and it makes sence.  Is there a way to see what number each server thinks the DB is?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 15 Mar 2007 14:49:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/replication-problems-v3-3-4/m-p/665914#M421308</guid>
      <dc:creator>mapones</dc:creator>
      <dc:date>2007-03-15T14:49:11Z</dc:date>
    </item>
    <item>
      <title>Re: Replication Problems v3.3.4</title>
      <link>https://community.cisco.com/t5/network-access-control/replication-problems-v3-3-4/m-p/665915#M421309</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Since we are on 3.x the following registry entry should give us an indication :-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HKLM\SOFTWARE\Cisco\CiscoAAAv3.3\Authenticators\Libraries\30&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;30 is for the Radius Token Servers. Under 30 you will find entries such as "00","01" etc.. This is the database "number" I was referring to.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If we are using ACS Solution Engine then we need to create a package.cab file from System Configuration-&amp;gt;Support. The package.cab file will have ACS.reg&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Vivek&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 15 Mar 2007 14:58:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/replication-problems-v3-3-4/m-p/665915#M421309</guid>
      <dc:creator>Vivek Santuka</dc:creator>
      <dc:date>2007-03-15T14:58:43Z</dc:date>
    </item>
    <item>
      <title>Re: Replication Problems v3.3.4</title>
      <link>https://community.cisco.com/t5/network-access-control/replication-problems-v3-3-4/m-p/665916#M421310</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Cool, I have attached a screen shot of both servers registry entries.  They are different.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 15 Mar 2007 15:06:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/replication-problems-v3-3-4/m-p/665916#M421310</guid>
      <dc:creator>mapones</dc:creator>
      <dc:date>2007-03-15T15:06:39Z</dc:date>
    </item>
    <item>
      <title>Re: Replication Problems v3.3.4</title>
      <link>https://community.cisco.com/t5/network-access-control/replication-problems-v3-3-4/m-p/665917#M421311</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yup, numbering problem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On the secondary we need to create a new Radius Token Server Entry while keeping the old one intact.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Configure the new entry exactly like the old one except the name.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That will resolve the problem &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Vivek&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 15 Mar 2007 15:11:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/replication-problems-v3-3-4/m-p/665917#M421311</guid>
      <dc:creator>Vivek Santuka</dc:creator>
      <dc:date>2007-03-15T15:11:40Z</dc:date>
    </item>
    <item>
      <title>Re: Replication Problems v3.3.4</title>
      <link>https://community.cisco.com/t5/network-access-control/replication-problems-v3-3-4/m-p/665918#M421312</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Once I create that can I remove the old one so there will be no confusion down the road?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 15 Mar 2007 15:15:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/replication-problems-v3-3-4/m-p/665918#M421312</guid>
      <dc:creator>mapones</dc:creator>
      <dc:date>2007-03-15T15:15:17Z</dc:date>
    </item>
    <item>
      <title>Re: Replication Problems v3.3.4</title>
      <link>https://community.cisco.com/t5/network-access-control/replication-problems-v3-3-4/m-p/665919#M421313</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I think we can delete the old database entry because ACS will not reindex the numbers but am not very sure about this one.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Vivek&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 15 Mar 2007 15:16:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/replication-problems-v3-3-4/m-p/665919#M421313</guid>
      <dc:creator>Vivek Santuka</dc:creator>
      <dc:date>2007-03-15T15:16:30Z</dc:date>
    </item>
    <item>
      <title>Re: Replication Problems v3.3.4</title>
      <link>https://community.cisco.com/t5/network-access-control/replication-problems-v3-3-4/m-p/665920#M421314</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;YOU ROCK, that is it.  Plus I was able to delete the old entry so and the index number stayed.  Everything is working correctly with the replication now.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;THANKS A TON.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 15 Mar 2007 15:29:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/replication-problems-v3-3-4/m-p/665920#M421314</guid>
      <dc:creator>mapones</dc:creator>
      <dc:date>2007-03-15T15:29:55Z</dc:date>
    </item>
  </channel>
</rss>

