cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
472
Views
0
Helpful
4
Replies

Multiple CCM clusters - One Active Directory

jocoates
Level 1
Level 1

What are the implications of running multiple CCM clusters connected to the same AD (AD plugin)? If the "user creation base" and "user search base" are set the same (or creation is "lower" than search) for the first cluster, how are the CCMSysUser, CCMAdministrator, IPMASysUser etc etc created for the second (or third, or fourth) cluster added to the AD tree? As far as I can tell, these System users will not be able to be created for the second cluster when the AD plugin is run, as the users already exist elsewhere in the tree?

From what I can tell all clusters would need to use the same set of users, and all clusters would need to connect higher up the tree?

Is there a way around this? Or have I misunderstood?

Cheers

4 Replies 4

mwheinz
Level 1
Level 1

I did it with CCM 3.34 and used a separate OU for each cluster, ex., ciscoFL and ciscoGA. Also, you'll need 2 "ac" users, as you can't associate users with objects in 2 clusters. You'll edit this username in CCM to be unique for each cluster.

Good luck.

milay
Cisco Employee
Cisco Employee

This can be done, several customers are doing this. The bassics are mantioned by the other post, unique OU's for user creation base & user search base. You do not want Cluster A to find the CCMSysUser, CCMAdministrator & IPMASysUser for cluster B, & vise versa.

For this to be a supported configuration you need to contact you SE and have the design approved by the Cisco Directory team, DE's. As I said several customers are doing this but we want to ensure a success by getting the experts to bless the config.

Mike

Thanks guys - I know you can do it, it was more the CCMSysUser, CCMAdministrator etc etc that I was worried about. I know how to change the ac username, password in the file on CCM, but if you have more than one cluster using the usernames "CCMSysUser", "CCMAdministrator", "CCMIPMAUser" how does it work? I will definitely check with an SE locally before deploying anything like this, but would like to understand how it works.

Do you need to change the usernames each cluster uses as system users?

Is there a trick in AD? ie: can you have the same usernames in different OUs?

Cheers

John

yes,

you can have the same account names in the UO's. The BU will give you all the info you need.

Mike