Cisco NAC3350-PROF-K9 Hardware Installation Guide - Page 129

Serial Connection, Con the HA-Primary CAM

Page 129 highlights

Chapter 4 Configuring High Availability (HA) Installing a Clean Access Manager High Availability Pair Serial Connection By default, the first serial port detected on the CAM server is configured for console input/output (to facilitate installation and other types of administrative access). If the machine has only one serial port (COM1 or ttyS0), you can reconfigure the port to serve as the high-availability heartbeat connection. This is because, after the CAM software is installed, SSH or KVM console can always be used to access the command line interface of the CAM. Note When the primary eth1 link has been disconnected and only the serial link remains, the CAM returns a database error indicating that it cannot sync with its HA counterpart, and the administrator sees the following error in the CAM web console: "WARNING! Closed connections to peer [standby IP] database! Please restart peer node to bring databases in sync!!" Caution To help prevent a potential network security threat, Cisco strongly recommends physically disconnecting from the Cisco NAC console management port when you are not using it. For more details, see http://seclists.org/fulldisclosure/2011/Apr/55, which applies to the Cisco ISE, Cisco NAC Appliance, and Cisco Secure ACS hardware platforms. Warning When connecting high availability (failover) pairs via serial cable, BIOS redirection to the serial port must be disabled for Cisco NAC Appliance CAMs/CASs and any other server hardware platform that supports the BIOS redirection to serial port functionality. See Supported Hardware and System Requirements for Cisco NAC Appliance (Cisco Clean Access) for more information. Configure the HA-Primary CAM Once you have verified the prerequisites, perform the following steps to configure the Clean Access Manager as the HA-Primary for the high availability pair. See Figure 4-4 for an example high-availability configuration. Step 1 Open the web admin console for the Clean Access Manager to be designated as the HA-Primary, and go to Administration > CCA Manager > SSL > X509 Certificate to configure the SSL certificate for the primary CAM. Note The HA configuration steps in this chapter assume that a temporary certificate will be exported from the HA-Primary CAM to the HA-Secondary CAM. If using a temporary certificate for the HA pair: a. Click Generate Temporary Certificate, enter information for all of the fields in the form, and click Generate. The certificate must be associated with the Service IP addresses of the HA pair. b. When finished generating the temporary certificate, click the checkboxes for the certificate and Private Key to highlight them in the table. c. Click Export to save the certificate and Private Key to your local machine. You must import the certificate and Private Key later when configuring the HA-Secondary CAM. OL-20326-01 Cisco NAC Appliance Hardware Installation Guide 4-9

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176

4-9
Cisco NAC Appliance Hardware Installation Guide
OL-20326-01
Chapter 4
Configuring High Availability (HA)
Installing a Clean Access Manager High Availability Pair
Serial Connection
By default, the first serial port detected on the CAM server is configured for console input/output (to
facilitate installation and other types of administrative access).
If the machine has only one serial port (COM1 or ttyS0), you can reconfigure the port to serve as the
high-availability heartbeat connection. This is because, after the CAM software is installed, SSH or
KVM console can always be used to access the command line interface of the CAM.
Note
When the primary eth1 link has been disconnected and only the serial link remains, the CAM returns a
database error indicating that it cannot sync with its HA counterpart, and the administrator sees the
following error in the CAM web console: “WARNING! Closed connections to peer [standby IP]
database! Please restart peer node to bring databases in sync!!”
Caution
To help prevent a potential network security threat, Cisco strongly recommends physically disconnecting
from the Cisco NAC console management port when you are not using it. For more details, see
http://seclists.org/fulldisclosure/2011/Apr/55
, which applies to the Cisco ISE, Cisco NAC Appliance,
and Cisco Secure ACS hardware platforms.
Warning
When connecting high availability (failover) pairs via serial cable, BIOS redirection to the serial port
must be disabled for Cisco NAC Appliance CAMs/CASs and any other server hardware platform that
supports the BIOS redirection to serial port functionality. See
Supported Hardware and System
Requirements for Cisco NAC Appliance (Cisco Clean Access)
for more information.
Configure the HA-Primary CAM
Once you have verified the prerequisites, perform the following steps to configure the Clean Access
Manager as the HA-Primary for the high availability pair. See
Figure 4-4
for an example
high-availability configuration.
Step 1
Open the web admin console for the Clean Access Manager to be designated as the HA-Primary, and go
to
Administration
>
CCA Manager > SSL > X509 Certificate
to configure the SSL certificate for the
primary CAM.
Note
The HA configuration steps in this chapter assume that a temporary certificate will be exported
from the HA-Primary CAM to the HA-Secondary CAM.
If using a temporary certificate for the HA pair:
a.
Click
Generate Temporary Certificate
, enter information for all of the fields in the form, and click
Generate
. The certificate must be associated with the Service IP addresses of the HA pair.
b.
When finished generating the temporary certificate, click the checkboxes for the certificate and
Private Key to highlight them in the table.
c.
Click
Export
to save the certificate and Private Key to your local machine. You must import the
certificate and Private Key later when configuring the HA-Secondary CAM.