06-05-2013 08:54 AM - edited 03-10-2019 08:30 PM
Hello there,
I am a router/switch/load-balancing person who is new to Cisco ACS management and am now tasked with moving the ACS from one domain (ads.company.com) to another. (corp.company.com).
We are currently running ACS v5.2 and are importing external databases via AD (ads.company.com) and LDAP (corp.company.com). We use ACS for TACACS+ auth for network gear and 802.1x auth for wireless. All users have already been migrated over to the corp.company.domain
I have read through a few books and have familiarized myself with the interfaces, terminology etc.
Could someone please point out what items I need to keep in mind when doing such a migration ?
Appreciate the help.
- Nick
Solved! Go to Solution.
06-05-2013 11:04 AM
Hi Nikhil,
The short story is that there's no such thing as a migration as far as ACS and your requirement is concerned... You will have to delete all references to the AD from your ACS config, leave your current domain, join the new domain, and then re-enter your AD-based config.
If you're lucky, what I've suggested will work, but older versions of ACS are notoriously bad when you changed domains and occasionally need to be re-built from scratch.
Richard
06-05-2013 11:04 AM
Hi Nikhil,
The short story is that there's no such thing as a migration as far as ACS and your requirement is concerned... You will have to delete all references to the AD from your ACS config, leave your current domain, join the new domain, and then re-enter your AD-based config.
If you're lucky, what I've suggested will work, but older versions of ACS are notoriously bad when you changed domains and occasionally need to be re-built from scratch.
Richard
06-05-2013 11:27 AM
Thanks for the quick reply, Richard.
06-05-2013 11:36 AM
When you clear configuration after deleting all the references from ACS. It will delete all the parameters/object from/ of the previous domain. When you join to a new domain just make sure you have add/delete a computer object on the new domain, DNS and NTP status etc.
As pointed by Richard, there are hell lots of issues with ACS-AD on older versions of ACS.
The most stable version you can upgrade to is 5.3 patch 4 or above.
Jatin Katyal
- Do rate helpful posts -
06-05-2013 01:35 PM
Thanks Jatin.
I double checked the version of the ACS and it is actually 5.3.0.40.6 so hopefully we'll be fine post-change.
06-06-2013 04:16 PM
Good that you're running the stable version. However, I'd also like to add that with ACS 5.4, you can join the ACS nodes from same deployment to different AD domains. However, each node can be joined to a single AD domain.
New and added feature.
acs troubleshoot adcheck and ad troubleshoot adinfo
Jatin Katyal
- Do rate helpful posts -
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide