08-14-2017 02:57 AM
Hi,
I have 1 vSMA(600) and 2 vESA(600), i was able to merge all the reporting and quarantine stuff including PVO and they are working perfectly.
However, if i want to change the policy, i did see any policy like incoming and outgoing mail policies, etc... in the SMA, how can i enable it to SMA so that i don't have to login to any of the ESA. and i want to make sure the configuration change in the first ESA will be replicated in second ESA.
Thanks,
Solved! Go to Solution.
08-14-2017 05:34 AM
Hi,
Centralized configuration of the ESA would need to be managed using clustering and not from the SMA.
You can create and manage clusters on the ESA using command "clusterconfig". Usage and implementation steps are available in the end user guides.
Chapter 40: Centralized Management Using Clusters
https://www.cisco.com/c/dam/en/us/td/docs/security/esa/esa10-0/ESA_10-0_User_Guide.pdf
Once appliances are part of a cluster changes made on one ESA would reflect on the other ESA's part of the same cluster group.
Regards,
Libin Varghese
08-14-2017 07:17 AM
You can do the configuration on either ESA, and it replicates to the other(s). It's "multi-master"
08-14-2017 05:34 AM
Hi,
Centralized configuration of the ESA would need to be managed using clustering and not from the SMA.
You can create and manage clusters on the ESA using command "clusterconfig". Usage and implementation steps are available in the end user guides.
Chapter 40: Centralized Management Using Clusters
https://www.cisco.com/c/dam/en/us/td/docs/security/esa/esa10-0/ESA_10-0_User_Guide.pdf
Once appliances are part of a cluster changes made on one ESA would reflect on the other ESA's part of the same cluster group.
Regards,
Libin Varghese
08-14-2017 06:57 AM
Hi,
so in that case after configuring the cluster for example in the first ESA, and added the second ESA.
Does it means that i will always do the configuration from the first ESA, then it will sync with the second ESA automatically?
Please confirm!
08-14-2017 07:17 AM
You can do the configuration on either ESA, and it replicates to the other(s). It's "multi-master"
08-14-2017 07:19 AM
There isn't a primary secondary on the clustered appliances.
So you could login to either of the 2 ESA's, make a configuration change and commit changes and it would take effect on the other ESA as well.
- Libin V
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide