cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
295
Views
0
Helpful
2
Replies

Cisco ACS 5.4 patch 6

cciesec2011
Level 3
Level 3

Hi Everyone,

 

I have a Primary Cisco ACS, called CiscoACS1, version 5.4 patch 6 with an IP address of 1.1.1.1/24 and a Secondary ACS, called CiscoACS2, version 5.4 patch 6 with an IP address of 1.1.1.2/24.

Connectivity between them is ok, same subnets.  I register CiscoACS2 with CiscoACS1 and everything is working fine, including Active Directory.  Both of these ACSes are used to authenticate my network devices.

Every time I use the webUI to log into the Secondary ACS (https://CiscoACS2), I can see that the CiscoACS2 is synced with CiscoACS1, the status is always "UPDATED"

 

However, if I webUI into the Primary ACS (https://CiscoACS1), I always see CiscoACS2 as "pending". 

 

I've tried to do "full replication" and eventually it will show up as "UPDATED" but a few hours later, it will show up as "PENDING".

 

Anyone knows why?  Is this a "bug"?

 

Thanks in advance.

2 Replies 2

abwahid
Level 4
Level 4

Hi,

If replication status on ACS1 GUI is showing pending then you know, full replication happens over the Sybase DB TCP port 2638, so your port need to be open in firewall.

Are you working for Cisco?  What do you mean by "port need to be open in firewall"?

Both CiscoACS1 and CiscoACS2 are sitting on the SAME subnet.  Why do I need to open ports on the firewall?