11-20-2007 08:06 AM - edited 03-10-2019 03:31 PM
Hi all,
I'am setting up replication on a pair of ACS SE 3.3. ACS's are on two diffrent Subnet separated by a Firewall.
The 'AAA Server' tab are filled with tha same key on both server (self + remote).
I have set up the ACS001 to replicate to ACS002.
Altough i can see the tcp session on port 2000 established in the firewall log, in the ACS001 log i can see 'SRO-ACS002 not responding' after 5 minutes (i.e. the replication timeout).
Any idea ?
Thank you very much.
Cheers.
Laurent.
11-21-2007 06:51 AM
Hi Laurent!
I assume you use 7.x.x softver on the PIX or ASA. If the situation is it, the skinny inspection drops the ACS replication packets. Unfortunately there is a bug that you can't see the packets that are dropped by the SKINNY inspection.
I hope I could help you.
Best Regards,
Miklos Andrasi
Hungary
11-21-2007 08:44 AM
Hi Miklos,
Thank you for your answer. The customer is using Netscreen Firewalls, not PIX or ASA.
I will try to check if there is a special treatment for skinny trafic.
Thanks.
Best regards,
Laurent.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide