06-13-2017 09:11 AM
I understand this is not supported but there should be some old documentation or discussion on exactly how this command is used and what data it backup. Can't seem to find these information. Can someone point me to docs on this item?
Solved! Go to Solution.
06-13-2017 11:46 AM
You're very welcome. :)
Correct, it would be pulling from any connected ESA/s. Basically, what you're doing with secondaryconfig, is telling the secondary/backup SMA to pull from a mirrored secondary directory instead of the primary directory, which is then what you're creating on the ESA/s by enabling secondaryconfig.
Thanks!
-Dennis M.
06-13-2017 10:50 AM
Hi,
I do not think there are any more customer facing documents for secondaryconfig as the feature is no longer supported by TAC and it is strongly recommended to not use it.
Secondaryconfig was used to create redundancy between 2 SMA's for tracking and reporting data. Quarantines were not backed up.
With backupconfig feature not available to perform these functions, I would recommend using that instead.
http://www.cisco.com/c/dam/en/us/td/docs/security/security_management/sma/sma10-0/SMA_10-0_User_Guide.pdf
Thank You!
Libin Varghese
06-13-2017 11:04 AM
I do understand it's not supported but my situation is that all of our senior team members insist on using the secondaryconfig even if it causes DB corruptions on the secondary SMA. At the same time, I need to migrate some of the SMAs and need to reconfigure the SecondaryConfig that someone setup prior. So, I need to find some kind of documentation some where in order to perform the migration.
06-13-2017 11:32 AM
Hello,
Secondaryconfig can be easily setup using the following steps.
You'll first need to enable secondaryconfig on the ESA/s to create the 'secondary' directory, and then enable it on the backup SMA to pull from the secondary directory.
Keep in mind this only performs this for Reporting/Tracking and Quarantines can still only be sent to a single SMA at a time.
Thanks!
-Dennis M.
06-13-2017 11:35 AM
Great! thanks for getting all that info.
To be clear, the backup SMA with secondaryconfig is pulling from my ESA cluster ? I was thinking it was pulling from my primary SMA....
06-13-2017 11:46 AM
You're very welcome. :)
Correct, it would be pulling from any connected ESA/s. Basically, what you're doing with secondaryconfig, is telling the secondary/backup SMA to pull from a mirrored secondary directory instead of the primary directory, which is then what you're creating on the ESA/s by enabling secondaryconfig.
Thanks!
-Dennis M.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide