03-02-2014 03:30 AM
Hi All,
I searched on the internet but I did not find any relevant article on how to enable and configure the Centralized management feature on Cisco Ironport appliance. here are few Details:
Ironport Appliance : C160
Centralized Management Feature License : yes Purchased
If any one can help me with a Link or article or screenshot or document prepared by any individual will be useful.
Thanking you in advance.
Regards,
Ritesh Hegde.
Solved! Go to Solution.
03-03-2014 12:03 AM
Hi Ritesh,
Centralized Management is well covered in the manuals. if you are on 7.6 it is in the Advanced User Guide chapter 8. Or you could use the online help which has the same information (make sure you spell centralized with a "z" not an "s").
Centralized Management is basically about how to manage a set of appliances in a cluster, so that if you configure one you configure them all.
03-03-2014 05:13 AM
Article #392: What are the requirements for setting up a cluster?
Link: http://tools.cisco.com/squish/5562B
Before you start, please make sure that you have a valid centralized management feature key on each Cisco IronPort Email appliance that you wish to join into a cluster.
For the most current version of this information, see the AsyncOS Advanced User's Guide/Online Help for your version of AsyncOS.
Machines in a cluster must have resolvable hostnames in DNS. Alternatively, you can use IP addresses instead, but you may not mix the two.
The port used is configurable. SSH is typically enabled on port 22, and by default CCS is on port 2222, but you can configure either of these services on a different port.
In addition to the normal firewall ports that must be opened for the appliance, clustered machines communicating via CCS must be able to connect with each other via the CCS port.
You must use the Command Line Interface (CLI) command clusterconfig to create, join, or configure clusters of machines. Once you have created a cluster, you can manage non-cluster configuration settings from either the GUI or the CLI.
#########################
Article #1385: What is IronPort centralized management for? How do I create a new centralized management cluster?
Link: http://tools.cisco.com/squish/c64a9
The IronPort centralized management feature allows you to manage and configure multiple appliances at the same time, to provide increased reliability, flexibility, and scalability within your network, allowing you to manage globally while complying with local policies. A cluster consists of a set of machines with common configuration information. Within each cluster, the appliances can be further divided into machine groups, where a single machine can be a member of only one group at a time. Clusters are implemented in a peer-to-peer architecture - with no master/slave relationship. You may log into any machine to control and administer the entire cluster or group. This allows the administrator to configure different elements of the system on a cluster-wide, group-wide, or per-machine basis, with based on their own logical groupings.
Before implementing a cluster there are a few requirements to keep in mind:
Note that many settings can be altered for individual machines or machine groups to override various settings. The order in which clustered appliances inherit their settings is as follows:
1) MACHINE
2) GROUP
3) CLUSTER.
Some settings such as hostnames and IP interfaces, however, are only available at the machine level and not replicated to other cluster members.
Please also note that the clustering feature is for configuration management purposes only. It does not provide any inherent mechanism to prioritize or schedule the flow of e-mail traffic between different members. To achieve this, one would need to use identical DNS record pre fences (MX) or a separate load balancing device or some other external mechanism.
Solution:
To begin with a new cluster, you should choose an appliance that has already been fully implemented as a standalone machine. This machine should be completely configured with all desired features such as host / recipient access tables (HAT / RAT), mail flow policies, content filters, and so on. This will be a point of reference by which you can form the cluster. There are a few cautionary steps you should take:
Next, we can create both the cluster and machine groups using the 'clusterconfig' command, and join one or more additional appliances to it:
Begin the "clusterconfig" configuration sequence and provide a name for your new cluster
clusterconfig > Create A New Cluster
Define the IP communication parameters, choosing either IP address or hostname resolutionNOTE: at this point the cluster may take a few seconds to build and the changes will be committed automatically
Here you may choose to create a new group before adding machines to the new cluster. When you create a new cluster, a default group called Main_Group is created automatically. However, you may decide to rename this or create additional groups using the following commands:
clusterconfig > renamegroup
clusterconfig > addgroup
Add new machines to the cluster and group. These steps are to be performed on any remaining machines that have yet to be made cluster members and can be repeated as needed. The process can be slightly different depending on the communication protocol chosen earlier.
clusterconfig > Join an existing cluster over SSH
clusterconfig > Join an existing cluster over CCS:
Use outputs such as 'status' and your 'System Overview' report to verify all mail flow and system operation is intact before making another configuration backup. If at any point something does not seem right - simply use 'clusterconfig > removemachine' to remove the device from the cluster and revert back to its machine-level settings.NOTE: removing the final machine from a cluster is no different from removing machines in general, and will effectively eliminate the cluster altogether.
Now that the cluster is created and functioning properly, you can begin to make different group and cluster changes and see them apply across each appliance.
Hope this helps!
-Robert
(*If you have received the answer to your original question, and found this helpful/correct - please mark the question as answered, and be sure to leave a rating to reflect!)
03-03-2014 12:03 AM
Hi Ritesh,
Centralized Management is well covered in the manuals. if you are on 7.6 it is in the Advanced User Guide chapter 8. Or you could use the online help which has the same information (make sure you spell centralized with a "z" not an "s").
Centralized Management is basically about how to manage a set of appliances in a cluster, so that if you configure one you configure them all.
03-03-2014 05:13 AM
Article #392: What are the requirements for setting up a cluster?
Link: http://tools.cisco.com/squish/5562B
Before you start, please make sure that you have a valid centralized management feature key on each Cisco IronPort Email appliance that you wish to join into a cluster.
For the most current version of this information, see the AsyncOS Advanced User's Guide/Online Help for your version of AsyncOS.
Machines in a cluster must have resolvable hostnames in DNS. Alternatively, you can use IP addresses instead, but you may not mix the two.
The port used is configurable. SSH is typically enabled on port 22, and by default CCS is on port 2222, but you can configure either of these services on a different port.
In addition to the normal firewall ports that must be opened for the appliance, clustered machines communicating via CCS must be able to connect with each other via the CCS port.
You must use the Command Line Interface (CLI) command clusterconfig to create, join, or configure clusters of machines. Once you have created a cluster, you can manage non-cluster configuration settings from either the GUI or the CLI.
#########################
Article #1385: What is IronPort centralized management for? How do I create a new centralized management cluster?
Link: http://tools.cisco.com/squish/c64a9
The IronPort centralized management feature allows you to manage and configure multiple appliances at the same time, to provide increased reliability, flexibility, and scalability within your network, allowing you to manage globally while complying with local policies. A cluster consists of a set of machines with common configuration information. Within each cluster, the appliances can be further divided into machine groups, where a single machine can be a member of only one group at a time. Clusters are implemented in a peer-to-peer architecture - with no master/slave relationship. You may log into any machine to control and administer the entire cluster or group. This allows the administrator to configure different elements of the system on a cluster-wide, group-wide, or per-machine basis, with based on their own logical groupings.
Before implementing a cluster there are a few requirements to keep in mind:
Note that many settings can be altered for individual machines or machine groups to override various settings. The order in which clustered appliances inherit their settings is as follows:
1) MACHINE
2) GROUP
3) CLUSTER.
Some settings such as hostnames and IP interfaces, however, are only available at the machine level and not replicated to other cluster members.
Please also note that the clustering feature is for configuration management purposes only. It does not provide any inherent mechanism to prioritize or schedule the flow of e-mail traffic between different members. To achieve this, one would need to use identical DNS record pre fences (MX) or a separate load balancing device or some other external mechanism.
Solution:
To begin with a new cluster, you should choose an appliance that has already been fully implemented as a standalone machine. This machine should be completely configured with all desired features such as host / recipient access tables (HAT / RAT), mail flow policies, content filters, and so on. This will be a point of reference by which you can form the cluster. There are a few cautionary steps you should take:
Next, we can create both the cluster and machine groups using the 'clusterconfig' command, and join one or more additional appliances to it:
Begin the "clusterconfig" configuration sequence and provide a name for your new cluster
clusterconfig > Create A New Cluster
Define the IP communication parameters, choosing either IP address or hostname resolutionNOTE: at this point the cluster may take a few seconds to build and the changes will be committed automatically
Here you may choose to create a new group before adding machines to the new cluster. When you create a new cluster, a default group called Main_Group is created automatically. However, you may decide to rename this or create additional groups using the following commands:
clusterconfig > renamegroup
clusterconfig > addgroup
Add new machines to the cluster and group. These steps are to be performed on any remaining machines that have yet to be made cluster members and can be repeated as needed. The process can be slightly different depending on the communication protocol chosen earlier.
clusterconfig > Join an existing cluster over SSH
clusterconfig > Join an existing cluster over CCS:
Use outputs such as 'status' and your 'System Overview' report to verify all mail flow and system operation is intact before making another configuration backup. If at any point something does not seem right - simply use 'clusterconfig > removemachine' to remove the device from the cluster and revert back to its machine-level settings.NOTE: removing the final machine from a cluster is no different from removing machines in general, and will effectively eliminate the cluster altogether.
Now that the cluster is created and functioning properly, you can begin to make different group and cluster changes and see them apply across each appliance.
Hope this helps!
-Robert
(*If you have received the answer to your original question, and found this helpful/correct - please mark the question as answered, and be sure to leave a rating to reflect!)
03-03-2014 05:45 AM
Hi Friends,
Thanks for your quick response. I was able to create work instruction and docukent for client by refering to advance user guide and the url shared by Robert.
Thanks.
Regards.
Ritesh Hegde
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide