Cisco NAC3350-PROF-K9 Hardware Installation Guide - Page 134

Primary] Heartbeat IP Address on interface 3

Page 134 highlights

Installing a Clean Access Manager High Availability Pair Chapter 4 Configuring High Availability (HA) Step 8 (Recommended) Specify parameters to enable failover based on eth0 link failure detection for the HA-Secondary CAM: a. Enter IP addresses for the interfaces the HA pair uses to failover from the primary to the secondary CAM in the Link-detect IP Address for eth0 field. b. Specify the duration (in seconds) the CAM continues to ping the Link-detect IP address before determining that the eth0 interface may have gone down, thus initiating a failover to the secondary CAM, in the Link-detect Timeout field. The minimum value for this setting is 10 seconds, but Cisco recommends at least a 25-second timeout interval. Note Link-detect settings on the CAM (Release 4.1(3) and later) are needed to allow the active CAM to failover to the standby CAM in case of a switch port failure or a link failure on the switch port connected to eth0 of the active CAM. In the event a failover must take place, the Link detect setting allows the standby CAM to ensure that the secondary CAM eth0 interface is up and able to take on the active role. Step 9 Step 10 Set the [Primary] Peer Host Name value to the HA-Primary CAM's host name. If you are using the default setting for the mandatory eth1 UDP heartbeat interface, leave the Auto eth1 Setup checkbox enabled (checked). If you want to specify a different [Primary] Heartbeat eth1 Address, uncheck the Auto eth1 Setup checkbox and enter the new IP address in the (peer IP on heartbeat udp interface on eth1) field. Note The Auto eth1 Setup option automatically assigns 192.168.0.254 as the primary CAM's eth1 (heartbeat) interface and assumes the IP address for the peer (secondary) eth1 interface is 192.168.0.253. Warning To specify redundant failover links as described in Step 12, you must first configure the appropriate Ethernet interfaces on the CAM before you try to set up HA. If you attempt to configure these interfaces, however, and the NICs on which the Ethernet interfaces reside are not configured correctly, the CAM will enter maintenance mode (will not boot properly) when you reboot. Step 11 Step 12 (Optional) If you enabled the HA-Primary CAM's Heartbeat UDP Interface 2 function that sets up a redundant failover heartbeat via the CAM eth0 interface on the HA-Primary CAM, enable the eth0 checkbox and specify the same peer IP address in the [Primary] Heartbeat IP Address on eth0 field as on the HA-Primary CAM. (Optional) If you enabled the HA-Primary CAM's Heartbeat UDP Interface 3 function on the HA-Primary CAM, select eth2 or eth3 from the dropdown menu and the same associated peer IP address in the [Primary] Heartbeat IP Address on interface 3 field as on the HA-Primary CAM. Note Cisco strongly recommends you do not use the serial interface on the NAC-3315/3355/3395 for the HA heartbeat function. Although this element still appears in the CAM web console, the Heartbeat Serial Interface feature is being deprecated in a future Cisco NAC Appliance release. (The associated Heartbeat Timeout value remains a valid configuration point, however, for deployments using optional Heartbeat UDP interfaces 2 and 3.) Step 13 Specify the Heartbeat Timeout value for the HA secondary CAM to set the duration the CAM should wait before declaring that it has lost communication with its HA peer, thus assuming the role of the active CAM in the HA pair. The default Heartbeat Timeout value is 30 seconds. 4-14 Cisco NAC Appliance Hardware Installation Guide OL-20326-01

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176

4-14
Cisco NAC Appliance Hardware Installation Guide
OL-20326-01
Chapter 4
Configuring High Availability (HA)
Installing a Clean Access Manager High Availability Pair
Step 8
(Recommended) Specify parameters to enable failover based on eth0 link failure detection for the
HA-Secondary CAM:
a.
Enter IP addresses for the interfaces the HA pair uses to failover from the primary to the secondary
CAM in the
Link-detect IP Address for eth0
field.
b.
Specify the duration (in seconds) the CAM continues to ping the Link-detect IP address before
determining that the eth0 interface may have gone down, thus initiating a failover to the secondary
CAM, in the
Link-detect Timeout
field. The minimum value for this setting is 10 seconds, but
Cisco recommends at least a 25-second timeout interval.
Note
Link-detect settings on the CAM (Release 4.1(3) and later) are needed to allow the active
CAM to failover to the standby CAM in case of a switch port failure or a link failure on the
switch port connected to eth0 of the active CAM. In the event a failover must take place, the
Link detect setting allows the standby CAM to ensure that the secondary CAM eth0 interface
is up and able to take on the active role.
Step 9
Set the
[Primary] Peer Host Name
value to the HA-Primary CAM’s host name.
Step 10
If you are using the default setting for the mandatory eth1 UDP heartbeat interface, leave the
Auto eth1
Setup
checkbox enabled (checked). If you want to specify a different
[Primary] Heartbeat eth1
Address
, uncheck the
Auto eth1 Setup
checkbox and enter the new IP address in the
(peer IP on
heartbeat udp interface on eth1)
field.
Note
The
Auto eth1 Setup
option automatically assigns 192.168.0.254 as the primary CAM's eth1
(heartbeat) interface and assumes the IP address for the peer (secondary) eth1 interface is
192.168.0.253.
Warning
To specify redundant failover links as described in
Step 12
, you must first configure the appropriate
Ethernet interfaces on the CAM before you try to set up HA. If you attempt to configure these
interfaces, however, and the NICs on which the Ethernet interfaces reside are not configured
correctly, the CAM will enter maintenance mode (will not boot properly) when you reboot.
Step 11
(Optional) If you enabled the HA-Primary CAM’s
Heartbeat UDP Interface 2
function that sets up a
redundant failover heartbeat via the CAM eth0 interface on the HA-Primary CAM, enable the
eth0
checkbox and specify the same peer IP address in the
[Primary] Heartbeat IP Address on eth0
field
as on the HA-Primary CAM.
Step 12
(Optional) If you enabled the HA-Primary CAM’s
Heartbeat UDP Interface 3
function on the
HA-Primary CAM, select
eth2
or
eth3
from the dropdown menu and the same associated peer IP address
in the
[Primary] Heartbeat IP Address on interface 3
field as on the HA-Primary CAM.
Note
Cisco strongly recommends you do not use the serial interface on the NAC-3315/3355/3395 for the HA
heartbeat function. Although this element still appears in the CAM web console, the
Heartbeat Serial
Interface
feature is being deprecated in a future Cisco NAC Appliance release. (The associated
Heartbeat Timeout
value remains a valid configuration point, however, for deployments using optional
Heartbeat UDP interfaces 2 and 3.)
Step 13
Specify the
Heartbeat Timeout
value for the HA secondary CAM to set the duration the CAM should
wait before declaring that it has lost communication with its HA peer, thus assuming the role of the active
CAM in the HA pair. The default
Heartbeat Timeout
value is 30 seconds.