ACS Appliance 4.2 - Internal database replication Problem

Answered Question
May 18th, 2009
User Badges:

hellow

i'm yunchoul jung in korea


now i'm configuring ACS Appliace 1113 ver4.2

in internal database replication, Primary and secondary ACS server can not repliacate the database because of the default SELF(127.0.0.1) configuration in network configuration.


so i have a guestion how i can replace 127.0.0.1 address to the desired ip address or delete the SELF(127.0.0.1) address


i dont understand a solution procedure in the bellow documentation .


thanks for your help in advance


Problem: 127.0.0.1 is a reserved address

You have two units of ACS SE 1113 and want to replicate the internal database from primary to secondary,

but you notice this error message in the secondary unit:

Inbound database replication from ACS <secondary ACS unit name> denied - shared secret mismatch

When you try to modify the key of AAA Server Self under Network Configuration the error message is

returned.

Correct Answer by Jagdeep Gambhir about 8 years 1 month ago

That is due to a known bug,


Symptom: 127.0.0.1 address appears in ACS and replication fails

Conditions:

Install S/W Acs version 4.2.0.124

*Disable Network Adapter

*Enable Network Adapter

*Navigate to Network Configuration page.

*Should see the AA server IP to be loop back one

Workaround:

For windows: remove the 127.0.0.1 entry

For appliance: backup the database, install ACS on windows, restore, remove

the entry, do a backup and restore it on the appliance



http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?caller=pluginredirector&method=fetchBugDetails&bugId=CSCso39795


Regards,

~JG


Do rate helpful posts

  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 5 (1 ratings)
Loading.

ACS does not support distributed deployments in a NAT environment. If a Primary or Secondary address is NAT-configured, the database replication file will indicate shared secret mismatch. Bidirectional replication, wherein an ACS sends database components to and receives database components from the same remote ACS, is not supported. Replication fails if an ACS is configured to replicate to and from the same ACS.


http://www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_server_for_windows/4.2/user/guide/SCAdv.html#wp755988



Correct Answer
Jagdeep Gambhir Fri, 05/22/2009 - 07:09
User Badges:
  • Red, 2250 points or more

That is due to a known bug,


Symptom: 127.0.0.1 address appears in ACS and replication fails

Conditions:

Install S/W Acs version 4.2.0.124

*Disable Network Adapter

*Enable Network Adapter

*Navigate to Network Configuration page.

*Should see the AA server IP to be loop back one

Workaround:

For windows: remove the 127.0.0.1 entry

For appliance: backup the database, install ACS on windows, restore, remove

the entry, do a backup and restore it on the appliance



http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?caller=pluginredirector&method=fetchBugDetails&bugId=CSCso39795


Regards,

~JG


Do rate helpful posts

w.iqbal Tue, 05/26/2009 - 06:03
User Badges:

if you want to give desired ip follow this.


1) Connect your acs cable with your system. like normal system connection , without connectivity i never found to change my ip.

2) in console enter

set ip (enter)

give ip ,subnet as it ask.



Done..


Bangash

pakistan

MarekVanco_2 Fri, 04/29/2011 - 10:55
User Badges:

did you manage to resolve his issue? I ahve the same problem? was it a bug as stated above?



This is the version I'm running:

Cisco Secure ACS4.2.0.124
Appliance Management Software4.2.0.124
Appliance Base Image4.2.0.107


Message was edited by: MarekVanco

Devashree Chakr... Mon, 05/02/2011 - 20:15
User Badges:
  • Bronze, 100 points or more

Hello Marek


Yes, there is a know bug. You need to follow the workaround :


Workaround:

For windows: remove the 127.0.0.1 entry

For appliance: backup the database, install ACS on windows, restore, remove

the entry, do a backup and restore it on the appliance


thanks

Devashree

Actions

This Discussion