Cisco NAC3350-PROF-K9 Hardware Installation Guide - Page 158

d. Con the SSL Certificate, e. Reboot the HA-Secondary CAS

Page 158 highlights

Installing a Clean Access Server High Availability Pair Chapter 4 Configuring High Availability (HA) • Heartbeat Timeout (seconds): Choose a value greater than 15 seconds. Note To avoid a potentially serious network issue where two CASs deployed as an HA pair reboot at the same time (in the event power returning after an outage, for example) and both come up as the active CAS in the HA pair, Cisco recommends setting the Heartbeat Timeout to a value greater than 30 seconds. The possible network implication in this scenario is that the to "active" CASs can introduce a Layer 2 broadcast loop that almost immediately brings down the network. Another method you can use to avoid this scenario is to ensure you use an additional Ethernet interface link (eth2, eth3) for heartbeat monitoring between your CAS Ha pair nodes. See Heartbeat UDP Interface 2 and Heartbeat UDP interface 3, above and Configuring Additional NIC Cards, page 3-37, for more information. • Update: Click to update the HA configuration information for the CAS without rebooting it. • Reboot: This is used to reboot the CAS at the end of HA-Primary CAS configuration. (Do not click Reboot at this point.) d. Configure the SSL Certificate 7. Now configure the SSL certificate for the HA-Secondary CAS. Navigate to Administration > SSL > X509 Certificate and perform one of the following procedures: If using a temporary certificate for the HA pair: a. Click Browse and navigate to the location on your local machine where you have saved the temporary certificate and Private Key you previously exported from the HA-Primary CAS. b. Select the certificate file and click Import. c. Repeat the process to import the Private Key. If using a CA-signed certificate for the HA pair: a. Click Browse and navigate to the location on your local machine where you have saved the CA-signed certificate you received from your Certificate Authority and the associated Private Key you exported from the HA-Primary CAS and saved to your local machine. b. Select the CA-signed certificate file and click Import. c. Repeat the process to import the Private Key. For more information, see the "Manage CAS SSL Certificates" section in the Cisco NAC Appliance Clean Access Server Configuration Guide, Release 4.8(3). e. Reboot the HA-Secondary CAS 8. From the CAS direct access interface (Network Settings > Failover > General), click the Reboot button to reboot the Clean Access Server. Connect the Clean Access Servers and Complete the Configuration 1. Shut down the HA-Primary CAS machine and connect the rjcas_1 and rjcas_2 machines using a serial null modem cable (connecting available serial ports) and/or a crossover cable (connecting Ethernet ports if using a pair of Ethernet interfaces such as eth2 or eth3 for failover). 4-38 Cisco NAC Appliance Hardware Installation Guide OL-20326-01

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176

4-38
Cisco NAC Appliance Hardware Installation Guide
OL-20326-01
Chapter 4
Configuring High Availability (HA)
Installing a Clean Access Server High Availability Pair
Heartbeat Timeout (seconds)
: Choose a value greater than 15 seconds.
Note
To avoid a potentially serious network issue where two CASs deployed as an HA pair reboot
at the same time (in the event power returning after an outage, for example) and
both
come
up as the active CAS in the HA pair, Cisco recommends setting the
Heartbeat Timeout
to
a value greater than 30 seconds. The possible network implication in this scenario is that the
to “active” CASs can introduce a Layer 2 broadcast loop that almost immediately brings
down the network.
Another method you can use to avoid this scenario is to ensure you use an additional
Ethernet interface link (eth2, eth3) for heartbeat monitoring between your CAS Ha pair
nodes. See
Heartbeat UDP Interface 2
and
Heartbeat UDP interface 3
, above and
Configuring Additional NIC Cards, page 3-37
, for more information.
Update
: Click to update the HA configuration information for the CAS without rebooting it.
Reboot
: This is used to reboot the CAS at the end of HA-Primary CAS configuration. (Do
not
click
Reboot at this point.)
d. Configure the SSL Certificate
7.
Now configure the SSL certificate for the HA-Secondary CAS. Navigate to
Administration > SSL
> X509 Certificate
and perform one of the following procedures:
If using a temporary certificate for the HA pair:
a.
Click
Browse
and navigate to the location on your local machine where you have saved the
temporary certificate and Private Key you previously exported from the HA-Primary CAS.
b.
Select the certificate file and click
Import
.
c.
Repeat the process to import the Private Key.
If using a CA-signed certificate for the HA pair:
a.
Click
Browse
and navigate to the location on your local machine where you have saved the
CA-signed certificate you received from your Certificate Authority and the associated Private
Key you exported from the HA-Primary CAS and saved to your local machine.
b.
Select the CA-signed certificate file and click
Import
.
c.
Repeat the process to import the Private Key.
For more information, see the “Manage CAS SSL Certificates” section in the
Cisco NAC Appliance -
Clean Access Server Configuration Guide, Release 4.8(3)
.
e. Reboot the HA-Secondary CAS
8.
From the CAS direct access interface (
Network Settings > Failover > General
), click the
Reboot
button to reboot the Clean Access Server.
Connect the Clean Access Servers and Complete the Configuration
1.
Shut down the HA-Primary CAS machine and connect the
rjcas_1
and
rjcas_2
machines using a
serial null modem cable (connecting available serial ports) and/or a crossover cable (connecting
Ethernet ports if using a pair of Ethernet interfaces such as eth2 or eth3 for failover).