Cisco NAC3350-PROF-K9 Hardware Installation Guide - Page 152

d. Con the SSL Certificate, Heartbeat Timeout seconds

Page 152 highlights

Installing a Clean Access Server High Availability Pair Chapter 4 Configuring High Availability (HA) Note Cisco strongly recommends you do not use the serial interface on the NAC-3315/3355/3395 for the HA heartbeat function. Although this element still appears in the CAM web console, the Heartbeat Serial Interface feature is being deprecated in a future Cisco NAC Appliance release. (The associated Heartbeat Timeout value remains a valid configuration point, however, for deployments using optional Heartbeat UDP interfaces 2 and 3.) • Heartbeat Timeout (seconds): Choose a value greater than 15 seconds. Note To avoid a potentially serious network issue where two CASs deployed as an HA pair reboot at the same time (in the event power returning after an outage, for example) and both come up as the active CAS in the HA pair, Cisco recommends setting the Heartbeat Timeout to a value greater than 30 seconds. The possible network implication in this scenario is that the to "active" CASs can introduce a Layer 2 broadcast loop that almost immediately brings down the network. Another method you can use to avoid this scenario is to ensure you use an additional Ethernet interface link (eth2, eth3) for heartbeat monitoring between your CAS Ha pair nodes. See Heartbeat UDP Interface 2 and Heartbeat UDP interface 3, above and Configuring Additional NIC Cards, page 3-37, for more information. • Update: Click to update the HA configuration information for the CAS without rebooting it. • Reboot: This is used to reboot the CAS at the end of HA-Primary CAS configuration. (Do not click Reboot at this point.) d. Configure the SSL Certificate 7. Now configure the SSL certificate for the HA-Primary CAS. Navigate to Administration > SSL > X509 Certificate. Figure 4-15 Administration > SSL > X509 Certificate 4-32 Cisco NAC Appliance Hardware Installation Guide OL-20326-01

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176

4-32
Cisco NAC Appliance Hardware Installation Guide
OL-20326-01
Chapter 4
Configuring High Availability (HA)
Installing a Clean Access Server High Availability Pair
Note
Cisco strongly recommends you do not use the serial interface on the NAC-3315/3355/3395 for the HA
heartbeat function. Although this element still appears in the CAM web console, the
Heartbeat Serial
Interface
feature is being deprecated in a future Cisco NAC Appliance release. (The associated
Heartbeat Timeout
value remains a valid configuration point, however, for deployments using optional
Heartbeat UDP interfaces 2 and 3.)
Heartbeat Timeout (seconds)
: Choose a value greater than 15 seconds.
Note
To avoid a potentially serious network issue where two CASs deployed as an HA pair reboot
at the same time (in the event power returning after an outage, for example) and
both
come
up as the active CAS in the HA pair, Cisco recommends setting the
Heartbeat Timeout
to
a value greater than 30 seconds. The possible network implication in this scenario is that the
to “active” CASs can introduce a Layer 2 broadcast loop that almost immediately brings
down the network.
Another method you can use to avoid this scenario is to ensure you use an additional
Ethernet interface link (eth2, eth3) for heartbeat monitoring between your CAS Ha pair
nodes. See
Heartbeat UDP Interface 2
and
Heartbeat UDP interface 3
, above and
Configuring Additional NIC Cards, page 3-37
, for more information.
Update
: Click to update the HA configuration information for the CAS without rebooting it.
Reboot
: This is used to reboot the CAS at the end of HA-Primary CAS configuration. (Do
not
click
Reboot at this point.)
d. Configure the SSL Certificate
7.
Now configure the SSL certificate for the HA-Primary CAS. Navigate to
Administration > SSL >
X509 Certificate
.
Figure 4-15
Administration > SSL > X509 Certificate