Firewall failover pair in CSM with ACS integration
I just need to confirm something. I'm setting up CSM 4.0.1 and I'm using ACS integration. From the documentation, I need to have each firewall/firewall context as a separate entry in ACS. I also see that it says that you only need to configure the primary unit on CSM.
I need ACS to perform authentication for the firewall pair. So here's my question:
How do I configure the pair in ACS? Do I make one entry using the <devicename>_<contextname> name and then enter both IP addresses? Or do I create separate entries and give the secondary a different name?
Re: Firewall failover pair in CSM with ACS integration
you need two separates entries. The primary one (the one that is added to CSM) needs to be added in ACS with the exact display name as in CSM (system) and each context as you mentioned before.
For the secondary unit, if you need authentication via ACS you can add with whatever name you want. In fact for RADIUS authentication for user what the ACS is checking for the matching is the IP address not the hostname. (this is different when we speak about CSM authorization for which we check the hostname and not the ip address)
HIDoes anyone know if there is an easier way than the belowQ. I check connection events for IOC's when requested and sometimes i have to check many url's which i am presently doing one url at a time and is very time consuming, is there a way to check mult...
Cisco Identity Services Engine (ISE) gives you intelligent Integrated protection through intent-based policy and compliance solution. ISE supports external MDM vendor integration to help the customers to look for compliance of a dev...
This video provides the steps to configure the Cisco Threat Response (CTR) and ESA Integration.
This is live on the portal:https://video.cisco.com/video/6159336218001
And on YouTube:https://www.youtube.com/watch?v=UCKIdx5rdFg
I need to migrate from C170 to C190 and have already match to the same Firmware Version. I have a question. Is there any method that can export and import the configuration file instead of form cluster ?