<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Getting 2 ACS servers to replicate in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/getting-2-acs-servers-to-replicate/m-p/466734#M427876</link>
    <description>&lt;P&gt;We have two Data Centres with the primary ACS server in one and I am trying to install a secondary ACS server in the second one.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;They communicate at a TCP level but I can&amp;#146;t get the second ACS to replicate the first one.  They are both installed on windows 2003 server and they are both also DNS and domain controllers.  In desperation I tried setting the timeout to 240 minutes and going home and leaving it but to no avail..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ANY ideas will be welcome, don&amp;#146;t think &amp;#147;he MUST have tried that&amp;#148; because I may not have&amp;#133;&amp;#133;.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
    <pubDate>Sun, 10 Mar 2019 21:26:37 GMT</pubDate>
    <dc:creator>timdeadman</dc:creator>
    <dc:date>2019-03-10T21:26:37Z</dc:date>
    <item>
      <title>Getting 2 ACS servers to replicate</title>
      <link>https://community.cisco.com/t5/network-access-control/getting-2-acs-servers-to-replicate/m-p/466734#M427876</link>
      <description>&lt;P&gt;We have two Data Centres with the primary ACS server in one and I am trying to install a secondary ACS server in the second one.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;They communicate at a TCP level but I can&amp;#146;t get the second ACS to replicate the first one.  They are both installed on windows 2003 server and they are both also DNS and domain controllers.  In desperation I tried setting the timeout to 240 minutes and going home and leaving it but to no avail..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ANY ideas will be welcome, don&amp;#146;t think &amp;#147;he MUST have tried that&amp;#148; because I may not have&amp;#133;&amp;#133;.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 21:26:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/getting-2-acs-servers-to-replicate/m-p/466734#M427876</guid>
      <dc:creator>timdeadman</dc:creator>
      <dc:date>2019-03-10T21:26:37Z</dc:date>
    </item>
    <item>
      <title>Re: Getting 2 ACS servers to replicate</title>
      <link>https://community.cisco.com/t5/network-access-control/getting-2-acs-servers-to-replicate/m-p/466735#M427877</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Some more information&amp;#133;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The two data centres each have an ASA protecting them.  As we are at the lab stage the ASAs are left open and the WAN is simulated via a couple of routers and a LAN.  If I by-pass the ASAs and just use a routed connection, the two servers replicate.  Going through the ASAs seems to stop replication from happening and the log of the second ACS is totally blank.  A sniffer on the LAN picks up a heap load of packets between the two ACSs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If I had a beard I would be stroking it and going &amp;#147;hmmm&amp;#148; while looking puzzled.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 20 Jan 2006 13:07:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/getting-2-acs-servers-to-replicate/m-p/466735#M427877</guid>
      <dc:creator>timdeadman</dc:creator>
      <dc:date>2006-01-20T13:07:15Z</dc:date>
    </item>
    <item>
      <title>Re: Getting 2 ACS servers to replicate</title>
      <link>https://community.cisco.com/t5/network-access-control/getting-2-acs-servers-to-replicate/m-p/466736#M427878</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I think the beard idea works really well. You need to make sure its good and long and bushy enough to hold several pencils &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;...but back to replication If you look in the csauth/logs/auth.log on the master server do you see replication error messages. Hint look for strings of the form "replice(out)". If its having trouble talking to the slave there will be heaps of errors.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;All traffic is on tcp/ip port 2000.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 23 Jan 2006 21:24:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/getting-2-acs-servers-to-replicate/m-p/466736#M427878</guid>
      <dc:creator>darpotter</dc:creator>
      <dc:date>2006-01-23T21:24:03Z</dc:date>
    </item>
    <item>
      <title>Re: Getting 2 ACS servers to replicate</title>
      <link>https://community.cisco.com/t5/network-access-control/getting-2-acs-servers-to-replicate/m-p/466737#M427879</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for that.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There is nothing in the logs other than "replication failed, ACS02 did not respond"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This problem has moved on a bit as it now seems the ASA between the two ACSs is spoofing traffic.  I have reposted the complete story in the Firewall section.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tim&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 24 Jan 2006 09:17:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/getting-2-acs-servers-to-replicate/m-p/466737#M427879</guid>
      <dc:creator>timdeadman</dc:creator>
      <dc:date>2006-01-24T09:17:24Z</dc:date>
    </item>
  </channel>
</rss>

