Cisco NAC3350-PROF-K9 Hardware Installation Guide - Page 159

Failing Over an HA-CAS Pair, Device Management > CCA Servers > List of Servers, List of Servers

Page 159 highlights

Chapter 4 Configuring High Availability (HA) Installing a Clean Access Server High Availability Pair 2. Open the Clean Access Manager administration console. 3. Go to Device Management > CCA Servers > List of Servers. The Active CAS of a high-availability pair is displayed in brackets next to the Service IP for the pair, as shown in Figure 4-17. Since the HA-Primary CAS is turned off, the IP address of the HA-Secondary CAS should appear in brackets in the List of Servers with a status of Connected. Figure 4-17 Active CAS in an HA-Pair 4. Click the Manage button for the pair. The management pages of the HA-Secondary CAS (now the Active CAS) should appear. 5. From a client computer connected to the Clean Access Server's untrusted interface, test the configuration by trying to log on to the untrusted (managed) network as an authorized user. If successful, remain logged on and proceed to the next step. Failing Over an HA-CAS Pair To test your HA system, use the following steps: 1. Turn on the HA-Primary CAS machine. Make sure that the CAS is fully started and functioning before proceeding. 2. From the client computer, log off the user's session and try to log onto the untrusted (managed) network again as the user. 3. The HA-Secondary CAS should still be active and providing services for the user. 4. Shut down the HA-Secondary CAS machine. Note Cisco recommends "shutdown" or "reboot" on the machine to test failover, or, if a CLI command is preferred, service perfigo stop and service perfigo start. For a Virtual Gateway CAS, use service perfigo maintenance instead to bring the CAS to maintenance mode and allow network connectivity to the management VLAN. See Useful CLI Commands for HA, page 4-43 for details. 5. After about 15 seconds, you should be able to continue browsing, with the HA-Primary CAS becoming the Active server and providing the service. 6. Turn on the HA-Secondary CAS machine (the standby server). 7. Check the event log on the Clean Access Manager. It should correctly indicate the status of the Clean Access Servers (e.g., "rjcas_1 is dead. rjcas_2 is up"). 8. Testing of the high availability configuration is now complete. OL-20326-01 Cisco NAC Appliance Hardware Installation Guide 4-39

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176

4-39
Cisco NAC Appliance Hardware Installation Guide
OL-20326-01
Chapter 4
Configuring High Availability (HA)
Installing a Clean Access Server High Availability Pair
2.
Open the Clean Access Manager administration console.
3.
Go to
Device Management > CCA Servers > List of Servers
.
The Active CAS of a
high-availability pair is displayed in brackets next to the Service IP for the pair, as shown in
Figure 4-17
. Since the HA-Primary CAS is turned off, the IP address of the HA-Secondary CAS
should appear in brackets in the
List of Servers
with a status of Connected.
Figure 4-17
Active CAS in an HA-Pair
4.
Click the
Manage
button for the pair. The management pages of the HA-Secondary CAS (now the
Active CAS) should appear.
5.
From a client computer connected to the Clean Access Server’s untrusted interface, test the
configuration by trying to log on to the untrusted (managed) network as an authorized user. If
successful, remain logged on and proceed to the next step.
Failing Over an HA-CAS Pair
To test your HA system, use the following steps:
1.
Turn on the HA-Primary CAS machine. Make sure that the CAS is fully started and functioning
before proceeding.
2.
From the client computer, log off the user’s session and try to log onto the untrusted (managed)
network again as the user.
3.
The HA-Secondary CAS should still be active and providing services for the user.
4.
Shut down the HA-Secondary CAS machine.
Note
Cisco recommends “shutdown” or “reboot” on the machine to test failover, or, if a CLI command
is preferred,
service perfigo stop
and
service perfigo start
. For a Virtual Gateway CAS,
use
service perfigo maintenance
instead to bring the CAS to maintenance mode and allow
network connectivity to the management VLAN. See
Useful CLI Commands for HA, page 4-43
for details.
5.
After about 15 seconds, you should be able to continue browsing, with the HA-Primary CAS
becoming the Active server and providing the service.
6.
Turn on the HA-Secondary CAS machine (the standby server).
7.
Check the event log on the Clean Access Manager. It should correctly indicate the status of the Clean
Access Servers (e.g.,
“rjcas_1 is dead. rjcas_2 is up
”)
.
8.
Testing of the high availability configuration is now complete.