<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ACS 5.7 replication issues in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/acs-5-7-replication-issues/m-p/3324909#M908523</link>
    <description>&lt;P&gt;Hi Chris,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Did you manage to solve this problem? What was the solution?&lt;/P&gt;</description>
    <pubDate>Sun, 04 Feb 2018 17:57:33 GMT</pubDate>
    <dc:creator>Guy Greenshtein</dc:creator>
    <dc:date>2018-02-04T17:57:33Z</dc:date>
    <item>
      <title>ACS 5.7 replication issues</title>
      <link>https://community.cisco.com/t5/network-security/acs-5-7-replication-issues/m-p/3073519#M908519</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I have two ACS appliances running 5.7.0.15.2.&amp;nbsp;&amp;nbsp; Appliance 1 has policies on, appliance 2 is to be the secondary appliance.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; I've been trying to add the secondary to the primary for replication and the secondary appliance does not seem to be behaving/replicating. There is a firewall between the two with all required ports open &amp;amp; can see no traffic being blocked.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Appliance 2 appears on appliance 1 as a secondary, but offline and replication status pending.&amp;nbsp;&amp;nbsp; After I add it in and it tries to restart its services, they stay down for ages, in some cases don't restart at all, so&amp;nbsp;I've reset the acs configuration&amp;nbsp;on several occaisons and only occasionally will the services restart, but replication doesn't happen and&amp;nbsp;&amp;nbsp;appliance 2 stays offline in appliance 1 (I saw it briefly flick online once but then it went offline again), I have seen a bug for this issue&amp;nbsp;however as the replication isn't happening at all, there's something a bit deeper going on.&lt;/P&gt;
&lt;P&gt;.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If the acs services do restart on appliance 2, replication_status command says the appliance is replicated, however trying a replication force_sync fails saying a full synchronisation is in progress (and I have left it overnight for in some cases 12 hours to give it time to replicate, so its not going to).&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; I've reset the ACS configuration and retried joining it to the primary appliance on numerous occaisons with no success.&amp;nbsp; I have tried looking at debugging logs but can't really interpret them (unfortunately these appliances aren't on a support contract at the moment - this is being worked on!), but have seen some&amp;nbsp;possible database errors&amp;nbsp;that make me wonder if the database is corrupted or damaged in some way.&amp;nbsp;&amp;nbsp; On the firewall monitoring I can see appliance 1 connecting to appliance 2 but nothing in the other direction.&lt;/P&gt;
&lt;P&gt;Has anyone else had this problem or can suggest a way of fixing the database?.&amp;nbsp;&amp;nbsp; I have wondered whether to reinstall the application but its on a remote site that I'd have to send a disk to, so is it possible to completely remove and&amp;nbsp;reinstall the ACS application remotely using a configured repository?&lt;/P&gt;
&lt;P&gt;Not sure if its relevant but initially when I first tried to join the appliance to the primary I hadn't noticed that it didn't have patch 2 installed - subsequently I've managed to patch it so they are on exactly the same version.&amp;nbsp;&amp;nbsp;&amp;nbsp; I haven't tried to patch both further yet as the replication should have worked without these (had no issues doing this at my last workplace).&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;thanks&lt;/P&gt;
&lt;P&gt;chris&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 14:01:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/acs-5-7-replication-issues/m-p/3073519#M908519</guid>
      <dc:creator>chris.wood11</dc:creator>
      <dc:date>2020-02-21T14:01:34Z</dc:date>
    </item>
    <item>
      <title>Re: ACS 5.7 replication issues</title>
      <link>https://community.cisco.com/t5/network-security/acs-5-7-replication-issues/m-p/3324909#M908523</link>
      <description>&lt;P&gt;Hi Chris,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Did you manage to solve this problem? What was the solution?&lt;/P&gt;</description>
      <pubDate>Sun, 04 Feb 2018 17:57:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/acs-5-7-replication-issues/m-p/3324909#M908523</guid>
      <dc:creator>Guy Greenshtein</dc:creator>
      <dc:date>2018-02-04T17:57:33Z</dc:date>
    </item>
    <item>
      <title>Re: ACS 5.7 replication issues</title>
      <link>https://community.cisco.com/t5/network-security/acs-5-7-replication-issues/m-p/3348636#M908525</link>
      <description>&lt;P&gt;Hi Guy,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Yes, its important to check firewalls between them to ensure ALL required ports are allowed.&amp;nbsp;&amp;nbsp; Its even worth checking for dropped traffic&amp;nbsp; in case logging isn't showing it..&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Chris&lt;/P&gt;</description>
      <pubDate>Wed, 14 Mar 2018 17:34:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/acs-5-7-replication-issues/m-p/3348636#M908525</guid>
      <dc:creator>chris.wood11</dc:creator>
      <dc:date>2018-03-14T17:34:26Z</dc:date>
    </item>
  </channel>
</rss>

