cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
760
Views
0
Helpful
3
Replies

Multiple ACS servers

deanyoung
Level 1
Level 1

Hi,

I would like to deploy 2 ACS servers. One would be used to authenticate staff members and the other would authenticate guest users.

I am using Catalyst 2950 switches in the access layer and Catalyst 6500 switches in the distribution layer. I will be deploying 802.1x as part om the solution.

I would like to know how to split the staff and guest authentication to point to different ACS servers?

Regards

Dean

3 Replies 3

grant.maynard
Level 4
Level 4

I don't think you could do that. I think you'd be best conbfiguring one ACS for all authentication, then configuring the other to be a replica (for resilience).

seagordo
Level 1
Level 1

Can't be done, to my knowledge.

You can only point a Cisco device to one active ACS server.

I'm with Dean, just create two groups withing ACS and use the other ACS server for backups and redundancy.

Sean

koksm
Level 1
Level 1

Maybe you can configure one ACS server as radius server in the switches, and configure the second ACS as an external database to the first ACS? So when the first ACS doesn't know the account, it asks the second ACS.

But i agree, why not use both ACS server in a redundant way? Different network management groups?