Cisco Support Community
Showing results for 
Search instead for 
Did you mean: 

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

Cisco ACS 5.4 patch 6

Hi Everyone,


I have a Primary Cisco ACS, called CiscoACS1, version 5.4 patch 6 with an IP address of and a Secondary ACS, called CiscoACS2, version 5.4 patch 6 with an IP address of

Connectivity between them is ok, same subnets.  I register CiscoACS2 with CiscoACS1 and everything is working fine, including Active Directory.  Both of these ACSes are used to authenticate my network devices.

Every time I use the webUI to log into the Secondary ACS (https://CiscoACS2), I can see that the CiscoACS2 is synced with CiscoACS1, the status is always "UPDATED"


However, if I webUI into the Primary ACS (https://CiscoACS1), I always see CiscoACS2 as "pending". 


I've tried to do "full replication" and eventually it will show up as "UPDATED" but a few hours later, it will show up as "PENDING".


Anyone knows why?  Is this a "bug"?


Thanks in advance.


Hi,If replication status on


If replication status on ACS1 GUI is showing pending then you know, full replication happens over the Sybase DB TCP port 2638, so your port need to be open in firewall.

New Member

Are you working for Cisco? 

Are you working for Cisco?  What do you mean by "port need to be open in firewall"?

Both CiscoACS1 and CiscoACS2 are sitting on the SAME subnet.  Why do I need to open ports on the firewall?