Cisco NAC3350-PROF-K9 Hardware Installation Guide - Page 127

Before Starting, Supported Hardware and System

Page 127 highlights

Chapter 4 Configuring High Availability (HA) Installing a Clean Access Manager High Availability Pair Note The CAM always uses eth1 as the UDP heartbeat interface. Note When the primary eth1 link has been disconnected and only the serial link remains, the CAM returns a database error indicating that it cannot sync with its HA counterpart, and the administrator sees the following error in the CAM web console: "WARNING! Closed connections to peer [standby IP] database! Please restart peer node to bring databases in sync!!" Warning When connecting high availability (failover) pairs via serial cable, BIOS redirection to the serial port must be disabled for Cisco NAC Appliance CAMs/CASs and any other server hardware platform that supports the BIOS redirection to serial port functionality. See Supported Hardware and System Requirements for Cisco NAC Appliance (Cisco Clean Access) for more information. Note For serial cable connection for HA (either HA-CAM or HA-CAS), the serial cable must be a "null modem" cable. For details, refer to http://www.nullmodem.com/NullModem.htm. The following sections describe the steps for setting up high availability. Note The instructions in this section assume that you are adding a Clean Access Manager to a standalone CAM in order to configure the HA pair for a test network. Before Starting Warning To prevent any possible data loss during database synchronization, always make sure the standby (secondary) Clean Access Manager is up and running before failing over the active (primary) Clean Access Manager. Before configuring high availability, ensure that: • You have obtained a high-availability (failover) license. Note When installing a CAM Failover (HA) license, install the Failover license to the Primary CAM first, then load all the other licenses. • Both CAMs are installed and configured (see Perform the Initial CAM Configuration, page 3-6). • The two CAMs in the HA pair must remain Layer 2 adjacent to support heartbeat and sync functions. • For heartbeat, each CAM needs to have a unique hostname (or node name). For HA CAM pairs, this host name will be provided to the peer, and must be resolved via DNS or added to the peer's /etc/hosts file. • You have a CA-signed certificate for the Service IP of the HA CAM pair. (For testing, you can use the CA-signed certificate of the HA-Primary CAM, but this requires additional steps to configure the HA-Primary CAM's IP as the Service IP). OL-20326-01 Cisco NAC Appliance Hardware Installation Guide 4-7

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176

4-7
Cisco NAC Appliance Hardware Installation Guide
OL-20326-01
Chapter 4
Configuring High Availability (HA)
Installing a Clean Access Manager High Availability Pair
Note
The CAM always uses eth1 as the UDP heartbeat interface.
Note
When the primary eth1 link has been disconnected and only the serial link remains, the CAM returns a
database error indicating that it cannot sync with its HA counterpart, and the administrator sees the
following error in the CAM web console: “WARNING! Closed connections to peer [standby IP]
database! Please restart peer node to bring databases in sync!!”
Warning
When connecting high availability (failover) pairs via serial cable, BIOS redirection to the serial port
must be disabled for Cisco NAC Appliance CAMs/CASs and any other server hardware platform that
supports the BIOS redirection to serial port functionality. See
Supported Hardware and System
Requirements for Cisco NAC Appliance (Cisco Clean Access)
for more information.
Note
For serial cable connection for HA (either HA-CAM or HA-CAS), the serial cable must be a “null
modem” cable. For details, refer to
.
The following sections describe the steps for setting up high availability.
Note
The instructions in this section assume that you are adding a Clean Access Manager to a standalone
CAM in order to configure the HA pair for a test network.
Before Starting
Warning
To prevent any possible data loss during database synchronization, always make sure the standby
(secondary) Clean Access Manager is up and running before failing over the active (primary) Clean
Access Manager.
Before configuring high availability, ensure that:
You have obtained a high-availability (failover) license.
Note
When installing a CAM Failover (HA) license, install the Failover license to the Primary CAM
first, then load all the other licenses.
Both CAMs are installed and configured (see
Perform the Initial CAM Configuration, page 3-6
).
The two CAMs in the HA pair must remain Layer 2 adjacent to support heartbeat and sync functions.
For heartbeat, each CAM needs to have a unique hostname (or node name). For HA CAM pairs, this
host name will be provided to the peer, and must be resolved via DNS or added to the peer's
/etc/hosts file.
You have a CA-signed certificate for the Service IP of the HA CAM pair. (For testing, you can use
the CA-signed certificate of the HA-Primary CAM, but this requires additional steps to configure
the HA-Primary CAM’s IP as the Service IP).