<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Moving ACS to a new server in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/moving-acs-to-a-new-server/m-p/685631#M422556</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What is in the authen failure code column of the failed attempts report in ACS?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 10 Nov 2006 22:13:38 GMT</pubDate>
    <dc:creator>darpotter</dc:creator>
    <dc:date>2006-11-10T22:13:38Z</dc:date>
    <item>
      <title>Moving ACS to a new server</title>
      <link>https://community.cisco.com/t5/network-access-control/moving-acs-to-a-new-server/m-p/685624#M422549</link>
      <description>&lt;P&gt;I have been informed that I am to move the ACS 3.3 from one server to another. So I have some basic questions. &lt;/P&gt;&lt;P&gt;1) I am going to do a fresh install and then would like to copy the existing files to the new server.&lt;/P&gt;&lt;P&gt;2) If I can copy all of the files (I feel that I should be able to) what executables do I need to run in order to get ACS running? If the files are copied all of the settings should be in place, correct? &lt;/P&gt;&lt;P&gt;3) I do believe I only need to change onle line of config on the PIX. It is the only line of config I can find related to the IP of the ACS server. Here is the line: aaa-server TACACS+ (inside) host 192.168.169.21 $$TF_acs! time out 10 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am assuming that is the line that needs to be changed on the firewall?&lt;/P&gt;&lt;P&gt;I would like to make this cahnge as seamless as possible. I think I am on the right track but just want to make sure.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Scott&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 21:49:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/moving-acs-to-a-new-server/m-p/685624#M422549</guid>
      <dc:creator>Scott Payne</dc:creator>
      <dc:date>2019-03-10T21:49:16Z</dc:date>
    </item>
    <item>
      <title>Re: Moving ACS to a new server</title>
      <link>https://community.cisco.com/t5/network-access-control/moving-acs-to-a-new-server/m-p/685625#M422550</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ok, the thing to do is to create an ACS Backup on the existing server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then restore the backup onto the new server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There's one slight issue with this, in the registry there is always a host entry for the ACS server itself. After doing the restore, in the network config, you'll see an entry for the original ACS server - this one can be deleted.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Darran&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 31 Oct 2006 15:22:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/moving-acs-to-a-new-server/m-p/685625#M422550</guid>
      <dc:creator>darpotter</dc:creator>
      <dc:date>2006-10-31T15:22:02Z</dc:date>
    </item>
    <item>
      <title>Re: Moving ACS to a new server</title>
      <link>https://community.cisco.com/t5/network-access-control/moving-acs-to-a-new-server/m-p/685626#M422551</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Let me make sure about this. So you are saying i DON'T need to do an install at all. Just do a backup/restore and copy those files to the new server? Or do I still need to do an install and then restore the backup to the new server? What do you think about that config change? I am correct about that, I do beleive. This sounds pretty easy.&lt;/P&gt;&lt;P&gt;I'll let you know.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 31 Oct 2006 15:30:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/moving-acs-to-a-new-server/m-p/685626#M422551</guid>
      <dc:creator>Scott Payne</dc:creator>
      <dc:date>2006-10-31T15:30:44Z</dc:date>
    </item>
    <item>
      <title>Re: Moving ACS to a new server</title>
      <link>https://community.cisco.com/t5/network-access-control/moving-acs-to-a-new-server/m-p/685627#M422552</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You definately need to do another install... otherwise you wont have anything onto which you can restore your config!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 06 Nov 2006 17:29:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/moving-acs-to-a-new-server/m-p/685627#M422552</guid>
      <dc:creator>darpotter</dc:creator>
      <dc:date>2006-11-06T17:29:47Z</dc:date>
    </item>
    <item>
      <title>Re: Moving ACS to a new server</title>
      <link>https://community.cisco.com/t5/network-access-control/moving-acs-to-a-new-server/m-p/685628#M422553</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;darpotter,&lt;/P&gt;&lt;P&gt;  Thanks for your help so far. I went ahead and setup the new ACS server. It was very easy and presented no problems at all. However, When I point the firewall to the new ACS server I get 403 errors. The users aren't authenticating. The ACS and PIX are communicationg properly. However authentication is not occuring. One thing I noticed on the new ACS server is that the failed authentication reoprts (or any reports)are being written to. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have you run into that problem before? I believe if the informatio will write to the reports, the problem will be solved.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 Nov 2006 14:18:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/moving-acs-to-a-new-server/m-p/685628#M422553</guid>
      <dc:creator>Scott Payne</dc:creator>
      <dc:date>2006-11-07T14:18:14Z</dc:date>
    </item>
    <item>
      <title>Re: Moving ACS to a new server</title>
      <link>https://community.cisco.com/t5/network-access-control/moving-acs-to-a-new-server/m-p/685629#M422554</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;whats in the failed attempts report?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 09 Nov 2006 14:34:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/moving-acs-to-a-new-server/m-p/685629#M422554</guid>
      <dc:creator>darpotter</dc:creator>
      <dc:date>2006-11-09T14:34:24Z</dc:date>
    </item>
    <item>
      <title>Re: Moving ACS to a new server</title>
      <link>https://community.cisco.com/t5/network-access-control/moving-acs-to-a-new-server/m-p/685630#M422555</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am getting a Reason 413. I have pasted a portion of the config below. The new_TACACS+ is the server I am trying to point to. As you can see, the VPNGROUP is pointing to the new ACS but nothing authenticates. The logging still occurs in the old ACS. Should I just remove the old  ACS config??&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa-server TACACS+ protocol tacacs+&lt;/P&gt;&lt;P&gt;aaa-server TACACS+ max-failed-attempts 3&lt;/P&gt;&lt;P&gt;aaa-server TACACS+ deadtime 10&lt;/P&gt;&lt;P&gt;aaa-server TACACS+ (inside) host 192.168.169.21 $$TF_acs! timeout 10&lt;/P&gt;&lt;P&gt;aaa-server RADIUS protocol radius&lt;/P&gt;&lt;P&gt;aaa-server RADIUS max-failed-attempts 3&lt;/P&gt;&lt;P&gt;aaa-server RADIUS deadtime 10&lt;/P&gt;&lt;P&gt;aaa-server LOCAL protocol local&lt;/P&gt;&lt;P&gt;aaa-server new_TACACS+ protocol tacacs+&lt;/P&gt;&lt;P&gt;aaa-server new_TACACS+ max-failed-attempts 3&lt;/P&gt;&lt;P&gt;aaa-server new_TACACS+ deadtime 10&lt;/P&gt;&lt;P&gt;aaa-server new_TACACS+ (inside) host 192.168.172.11 $$TF_acs! timeout 10&lt;/P&gt;&lt;P&gt;aaa accounting match ACCOUNTING outside new_TACACS+&lt;/P&gt;&lt;P&gt;aaa accounting match ACCOUNTING inside new_TACACS+&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;vpngroup tfipsec address-pool ipsecpool&lt;/P&gt;&lt;P&gt;vpngroup tfipsec dns-server 192.168.172.11 192.168.169.20&lt;/P&gt;&lt;P&gt;vpngroup tfipsec default-domain travelfocus.com&lt;/P&gt;&lt;P&gt;vpngroup tfipsec split-tunnel vpn_in&lt;/P&gt;&lt;P&gt;vpngroup tfipsec idle-time 1800&lt;/P&gt;&lt;P&gt;vpngroup tfipsec authentication-server new_TACACS+&lt;/P&gt;&lt;P&gt;vpngroup tfipsec user-authentication&lt;/P&gt;&lt;P&gt;vpngroup tfipsec password ********&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 10 Nov 2006 14:43:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/moving-acs-to-a-new-server/m-p/685630#M422555</guid>
      <dc:creator>Scott Payne</dc:creator>
      <dc:date>2006-11-10T14:43:45Z</dc:date>
    </item>
    <item>
      <title>Re: Moving ACS to a new server</title>
      <link>https://community.cisco.com/t5/network-access-control/moving-acs-to-a-new-server/m-p/685631#M422556</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What is in the authen failure code column of the failed attempts report in ACS?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 10 Nov 2006 22:13:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/moving-acs-to-a-new-server/m-p/685631#M422556</guid>
      <dc:creator>darpotter</dc:creator>
      <dc:date>2006-11-10T22:13:38Z</dc:date>
    </item>
    <item>
      <title>Re: Moving ACS to a new server</title>
      <link>https://community.cisco.com/t5/network-access-control/moving-acs-to-a-new-server/m-p/685632#M422557</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That is the problem. Nothing is being written to the logs. GRRRRR!!!! Cisco has informed me they have never seen this problem before.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 11 Nov 2006 18:19:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/moving-acs-to-a-new-server/m-p/685632#M422557</guid>
      <dc:creator>Scott Payne</dc:creator>
      <dc:date>2006-11-11T18:19:54Z</dc:date>
    </item>
    <item>
      <title>Re: Moving ACS to a new server</title>
      <link>https://community.cisco.com/t5/network-access-control/moving-acs-to-a-new-server/m-p/685633#M422558</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;OK, try setting the service logging level to max.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;After that try a test authentication, then look in the CSRadius &amp;amp; CSAuth service logs files for errors.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Errors have an "E" in the message type field.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There should be a clue there somewhere.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 12 Nov 2006 20:37:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/moving-acs-to-a-new-server/m-p/685633#M422558</guid>
      <dc:creator>darpotter</dc:creator>
      <dc:date>2006-11-12T20:37:12Z</dc:date>
    </item>
  </channel>
</rss>

