Cisco NAC3350-PROF-K9 Hardware Installation Guide - Page 132

Con the HA-Secondary CAM, CCA Manager > SSL > X509 Certificate

Page 132 highlights

Installing a Clean Access Manager High Availability Pair Chapter 4 Configuring High Availability (HA) Step 9 (Optional) If you want to enable the CAM's Heartbeat UDP Interface 3 function, select eth2 or eth3 from the dropdown menu and specify an associated peer IP address in the [Secondary] Heartbeat IP Address on interface 3 field. Otherwise, leave this N/A if not using the additional UDP heartbeat interface. Note Cisco strongly recommends you do not use the serial interface on the NAC-3315/3355/3395 for the HA heartbeat function. Although this element still appears in the CAM web console, the Heartbeat Serial Interface feature is being deprecated in a future Cisco NAC Appliance release. (The associated Heartbeat Timeout value remains a valid configuration point, however, for deployments using optional Heartbeat UDP interfaces 2 and 3.) Step 10 Specify the Heartbeat Timeout value for the HA primary CAM to set the duration the CAM should wait before declaring that it has lost communication with its HA peer, thus assuming the role of the active CAM in the HA pair. The default Heartbeat Timeout value is 30 seconds. Note Starting from Cisco NAC Appliance Release 4.6(1), the Heartbeat Timeout default value has been increased to 30 seconds to help accommodate CAM HA peers located in relatively distant locations on the network, where latency issues might cause a standby HA CAM to assume the active role when it has not received heartbeat packets from its HA peer within the specified Heartbeat Timeout period. In the resulting network scenario, you could potentially end up with two "active" CAMs performing Cisco NAC Appliance functions, requiring you to reboot both CAMs to re-establish the correct primary/secondary HA peer relationship. Step 11 Click Update and then Reboot to restart the Clean Access Manager. After the Clean Access Manager restarts, make sure that the CAM machine is working properly. Check to see if the Clean Access Servers are connected and new users are being authenticated. Configure the HA-Secondary CAM Step 1 Step 2 Step 3 Open the web admin console for the Clean Access Manager to be designated as the HA-Secondary, and go to Administration > CCA Manager > SSL > X509 Certificate. Before starting: • Back up the secondary CAM's private key. • Make sure the private key and SSL certificate files associated with the Service IP/HA-Primary CAM are available (previously exported as described in Configure the HA-Primary CAM, page 4-9). Import the HA-Primary CAM's private key file and certificate as described below: If using a temporary certificate for the HA pair: a. Click Browse and navigate to the location on your local machine where you have saved the temporary certificate and Private Key you previously exported from the HA-Primary CAS. b. Select the certificate file and click Import. c. Repeat the process to import the Private Key. 4-12 Cisco NAC Appliance Hardware Installation Guide OL-20326-01

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176

4-12
Cisco NAC Appliance Hardware Installation Guide
OL-20326-01
Chapter 4
Configuring High Availability (HA)
Installing a Clean Access Manager High Availability Pair
Step 9
(Optional) If you want to enable the CAM’s
Heartbeat UDP Interface 3
function, select
eth2
or
eth3
from the dropdown menu and specify an associated peer IP address in the
[Secondary] Heartbeat IP
Address on interface 3
field. Otherwise, leave this N/A if not using the additional UDP heartbeat
interface.
Note
Cisco strongly recommends you do not use the serial interface on the NAC-3315/3355/3395 for the HA
heartbeat function. Although this element still appears in the CAM web console, the
Heartbeat Serial
Interface
feature is being deprecated in a future Cisco NAC Appliance release. (The associated
Heartbeat Timeout
value remains a valid configuration point, however, for deployments using optional
Heartbeat UDP interfaces 2 and 3.)
Step 10
Specify the
Heartbeat Timeout
value for the HA primary CAM to set the duration the CAM should wait
before declaring that it has lost communication with its HA peer, thus assuming the role of the active
CAM in the HA pair. The default
Heartbeat Timeout
value is 30 seconds.
Note
Starting from Cisco NAC Appliance Release 4.6(1), the
Heartbeat Timeout
default value has
been increased to 30 seconds to help accommodate CAM HA peers located in relatively distant
locations on the network, where latency issues might cause a standby HA CAM to assume the
active role when it has not received heartbeat packets from its HA peer within the specified
Heartbeat Timeout
period. In the resulting network scenario, you could potentially end up with
two “active” CAMs performing Cisco NAC Appliance functions, requiring you to reboot both
CAMs to re-establish the correct primary/secondary HA peer relationship.
Step 11
Click
Update
and then
Reboot
to restart the Clean Access Manager.
After the Clean Access Manager restarts, make sure that the CAM machine is working properly. Check
to see if the Clean Access Servers are connected and new users are being authenticated.
Configure the HA-Secondary CAM
Step 1
Open the web admin console for the Clean Access Manager to be designated as the HA-Secondary, and
go to
Administration
>
CCA Manager > SSL > X509 Certificate
.
Step 2
Before starting:
Back up the secondary CAM’s private key.
Make sure the private key and SSL certificate files associated with the Service IP/HA-Primary CAM
are available (previously exported as described in
Configure the HA-Primary CAM, page 4-9
).
Step 3
Import the HA-Primary CAM’s private key file and certificate as described below:
If using a temporary certificate for the HA pair:
a.
Click
Browse
and navigate to the location on your local machine where you have saved the
temporary certificate and Private Key you previously exported from the HA-Primary CAS.
b.
Select the certificate file and click
Import
.
c.
Repeat the process to import the Private Key.