07-07-2010 07:29 AM - edited 03-10-2019 05:14 PM
Hi
I've just installed ACS 5.1 and noticed that it seems to count managed devices differently than previous versions.
I have a 500 count license which should be fine as I have about 100 devices which will use ACS for TACACS. On ACS 3.x and 4.x, I would set up AAA clients by using a wild card for the subnets that host our routers/switches, say 192.168.1.0/24, 172.16.1.0/24 and 10.1.1.0/24. when I do this with ACS 5, I get a Managed Device Count Exceeded error messasge becasue of the potential of more than 500 AAA clients. It seems to be counting every IP address in the subnet as a managed device, even if there are only a handful actually in use. Is there a way around this short of having to manually enter (and maintain) the exact IP Address of every managed switch and rotuer which will use the ACS server for TACACS?
thanks in advance!
Bob
06-08-2011 08:39 AM
Can someone please answer this question? I am running into the same exact issue.
Thanks for your help.
06-08-2011 11:51 AM
We ran into the same problem. Bob had subnets 192.168.1.0/24, 172.16.1.0/24, and 10.1.1.0/24 which is 768 hosts. We had to add each device we wanted to use with TACACS in manually with a single IP address.
06-08-2011 12:01 PM
That is a ton of work. Is there any way to automate this process somehow, or some kind of bulk CLI method?
06-08-2011 12:07 PM
You can add all the devices as a template or limit your subnets to under 500 hosts.
03-27-2012 04:16 AM
Are there any issue when you get this message "managed device count exceeded" on ACS?
I just add 50 Device to the ACS 5.1. ACS count 520 hosts but actually it´s working 300 device. I know ACS count all host included in the networks masks, for example, with /24 ACS count 256 devices. I get the alert "managed device count exceeded" but device authentication is working properly. Are ther any issue when I get this message. I think is only an advertisement but I´m not sure.
Can you help me?
03-27-2012 04:49 AM
The device count in ACS 5.x is made by the number of hosts inserted when adding Network device. so if you configure the device with a full class C ip range, it's counted on 254 devices.
the error appears but you can continue workking, and being authenticated.
the other option is to buy a licence of ACS 5 Large Deployment Add.
Antero
03-27-2012 05:49 AM
So, If I insert 501 host with mask /32 device won´t can work but, If I insert 300 host /32 and 1 network /24 I´ll can work properly despite I get the error message.
This is true?
03-27-2012 06:01 AM
Use the Default Network Device . I find that works best for device authentication.
01-18-2013 09:52 AM
Wesley, Thanks for this. I'm now re-attaching the hair I've pulled out after days trying to figure my customers migration out :-)
5 stars
Cheers
Dan
01-18-2013 09:59 AM
You are very welcome. I lost a few hairs over this one myself!
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide