Cisco NAC3350-PROF-K9 Hardware Installation Guide - Page 107
Connectivity Across a Wide Area Network, Configuring Additional NIC Cards
View all Cisco NAC3350-PROF-K9 manuals
Add to My Manuals
Save this manual to your list of manuals |
Page 107 highlights
Chapter 3 Installing the Clean Access Manager and Clean Access Server Connectivity Across a Wide Area Network Step 2 Step 3 Step 4 Step 5 Change directories to /perfigo/access/bin/. You will need to edit two files: restartweb and starttomcat. Locate the CATALINA_OPTS variable definition in each file. Add -Djava.rmi.server.hostname= to the variable, replacing caserver1_hostname with the host name of the server you are modifying. For example: CATALINA_OPTS="-server -Xms64m -Xmx${MAX}m -Xincgc -Djava.util.logging.config.file=${CATALINA_HOME}/conf/redirect-log.properties -Dperfigo.jmx.context=${PERFIGO_SECRET} -Djava.security.auth.login.config=${CATALINA_HOME}/conf/sso-login.conf -Dsun.net.inetaddr.ttl=60 -Dsun.net.inetaddr.negative.ttl=10 -Djava.security.egd=file:/dev/urandom" -Djava.rmi.server.hostname=caserver1" Step 6 Restart the CAS by entering the service perfigo restart command. Step 7 Repeat the preceding steps for each Clean Access Server in your deployment. Step 8 Connect to the Clean Access Manager by SSH or using a serial console. Login as root. Step 9 Change directories to /etc/. Step 10 Edit the hosts file by appending the following line: where: • - The address that is accessible outside the firewall. • - The host name of each Clean Access Server behind the firewall. The Clean Access Server(s) should now be addressable behind the firewall. Connectivity Across a Wide Area Network When deploying the CAM/CAS across a WAN, you must prioritize all CAM/CAS traffic and SNMP traffic, and include the eth0/eth1 IP addresses of the CAM and CAS in addition to the Service IP address for HA pairs. Configuring Additional NIC Cards The Configuration Utility script requires that the CAM and CAS machines come with eth0 (NIC1) and eth1 (NIC2) interfaces by default and prompts you to configure these during initial installation. If your system has additional network interface cards (e.g. NIC3, NIC4), you can use the following instructions to configure the additional interfaces (e.g. eth2, eth3) on those cards. Typically, eth2 needs to be configured when setting up CAS systems for High Availability (HA). For HA, once the eth2 (NIC3) interface is configured with the proper addressing, it can then be configured as the dedicated and/or redundant UDP heartbeat interface for the HA-CAM/CAS. Note • For Cisco NAC Appliance hardware, the following instructions assume that the NIC is plugged in and "working" (i.e. recognized by BIOS and by Linux). OL-20326-01 Cisco NAC Appliance Hardware Installation Guide 3-37