Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

ACS Replication !

Hello All

I know that the ACS replicates the entire database from primary to secondary, and not vice-versa.. My scenario is:

primary ACS goes down, and the secondary takes over.. now, all user addition etc, is done on the secondary ACS.. now, when the primary comes back again, will it overwrite the secondary database and should we recreate the configs ? or is it that the secondary ACS replicates its data to primary ? its kinda confusing !

I'm gonna do ACS replication in a few days, and wanted to be really sure of this.

Raj

1 ACCEPTED SOLUTION

Accepted Solutions

Re: ACS Replication !

Hi,

So you configure a redudant ACS server as secondary.

All the database from the primary will be replicated to secondary.

As you said what happes if secondary takes over and configuration is done on the secondary.

It will be reflected on primary. depends how you configure it.

check it has the option for send and recive.

this link will be very helpful for you.

http://www.cisco.com/en/US/products/sw/secursw/ps2086/prod_configuration_examples_list.html

6 REPLIES

Re: ACS Replication !

Hi,

So you configure a redudant ACS server as secondary.

All the database from the primary will be replicated to secondary.

As you said what happes if secondary takes over and configuration is done on the secondary.

It will be reflected on primary. depends how you configure it.

check it has the option for send and recive.

this link will be very helpful for you.

http://www.cisco.com/en/US/products/sw/secursw/ps2086/prod_configuration_examples_list.html

Re: ACS Replication !

attached

Re: ACS Replication !

Raj,

ACS performs only one way replication ie from primary to secondary and not other way.

So if you have made changes in secondary acs , it will not be replicated, You need to manually add the changes in primary acs.

Regards,

~JG

Do rate helpful posts

Re: ACS Replication !

Right JG.. Just wanted to confirm on this ! Doesnt it look like a flaw :) There should have been something like HSRP or pre-empt concept here, but i know it is really tough to manage from NAD point of view..

Thanks

Silver

Re: ACS Replication !

The *only* safe way to manage this is to have a config master onto which all management is done.

Have this replicate to master and slave servers which service actual authentication traffic.

Since admin changes rarely cause ACS crashes its unlikely the primary would ever be unavailable for more than a few seconds (during initial stage of outbound replication, or someone clicks submit+restart)

Re: ACS Replication !

Thanks for the reply..

Raj

301
Views
7
Helpful
6
Replies