cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1371
Views
0
Helpful
5
Replies

ACS 5.4 IP Change After Configuration Complete

ranjit123
Level 3
Level 3

Dear All,

I have ACS Appliance with the below sofware version,

Cisco ACS VERSION INFORMATION

-----------------------------

Version : 5.4.0.46.0a

Internal Build ID : B.221

I have configured the BOX as per our requirement with all the policies and rules with the same IP address as the currentl running ACS in our netowrk

Now i need to check whether all the rules and authorization are working properly or not so want to integrate the same in network with a different IP address

I tried changing the IP address of the same but the WEB management service is not coming up on the changed IP

I have assigned old IP addredd to GIG 0 and when i assign a new IP addresss to GIG 1 i shut the GIG 0 port.

Also tried telnettin on port 443 its not opening.

please update me is it possible?

Regards,

Ranjit

5 Replies 5

Jatin Katyal
Cisco Employee
Cisco Employee

Are you running acs appliance? If yes, What is the model of the appliance?

Sent from Cisco Technical Support Android App

~Jatin

Scott Robertson
Level 1
Level 1

Hi Jatin

http://www.cisco.com/en/US/partner/docs/net_mgmt/cisco_secure_access_control_system/5.4/installation/guide/csacs_hw_ins.html#wp1136860

Refer to table 4-4. Looks like Gig 0 must be configured for http/ssh management, Gig 1 will not allow http/ssh management.

  Regards,

Scott

Yes. I agree. However, with Cisco 3415 hardware running ACS 5.4 we can configure NIC redundany for CMIC interface.

Cisco Integrated Management Interface (CIMC)

http://www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_system/5.4/installation/guide/csacs_hw_ins_ucs.html#wp1188250

Use this utility to change the NIC redundancy to your preference. This server has three possible NIC redundancy settings:

–None—The Ethernet ports operate independently and do not fail over if there is a problem.

–Active-standby—If an active Ethernet port fails, traffic fails over to a standby port.

–Active-active—All Ethernet ports are utilized simultaneously.

~BR
Jatin Katyal

**Do rate helpful posts**

~Jatin

Dear Jatin,

Thanks for the update i am using ACS Appliance 1121

Regards,

Ranjit

Ranjit123,

As scott said, With 1121, CS  management functions use ONLY the Ethernet 0 interface, whereas  authentication, authorization, and accounting (AAA) protocols use all of  the configured network interfaces.

  ACS 5.4 Functional Interface Distribution Among Network Interfaces

Functional Interface
Network Interface

Customer Logging

Ethernet 0

Device Administration (TACACS+)

All

Distributed Management

Ethernet 0

External ID Stores (AD, LDAP, and RSA)

Ethernet 0

Management GUI (HTTP)

Ethernet 0

Management CLI (Secure Shell [SSH])

Ethernet 0

Monitoring and Troubleshooting/ACS View Syslog

All

Network Access (Radius)

All

RADIUS Proxy

All

TACACS+ Proxy

All

~BR
Jatin Katyal

**Do rate helpful posts**

~Jatin