ACS 5.2 design issues

Is it possible to have my managed network ACS Appliance (CSACS-1121-K9) 5.2 as primary and an ACS Server 5.2 VMWare (CSACS - 5.2 - VM - K9) as secondary? I have problems with basic license?

Otherwise if I plan to run servers ACS 5.2 VMWare are my primary and secondary. Should I buy 1 or 2 VMWare Software (s) (CSACS - 5.2 - VM - K9)?

We currently have a device of 4.2 ACS on a platform of 1113, is there any option for ACS 5.2 upgrade device or ACS 5.2 VMWare Server? The ordering Guide indicates that he's upgraded options like, CSACS-1121-UP-K9 & CSACS-5.2 - VM-UP-K9 to upgrade from previous versions. But the Migration Document, said that the ACS4.x device must be restored to a windows ACS4.x server before migration and backup. This does not seem like an easy migration. Is there another solution?

http://www.Cisco.com/en/us/docs/net_mgmt/cisco_secure_access_control_system/5.2/migration/guide/Migration_support.html#wp1016086

Is the new ISE product better for AAA / GANYMEDE + or I should have a separate ACS for AAA?

Thanks in advance.

Jenny,

Here's the answer to your questions:

Is it possible to have my managed network ACS Appliance (CSACS-1121-K9) 5.2 as primary and an ACS Server 5.2 VMWare (CSACS - 5.2 - VM - K9) as secondary?

Yes

I have problems with basic license?

NO.

Otherwise if I plan to run servers ACS 5.2 VMWare are my primary and secondary. Should I buy 1 or 2 VMWare Software (s) (CSACS - 5.2 - VM - K9)?

This is just sku which included another license that you purchase. You don't buy the software from us, license only. You can download more likey the software from cisco website.

We currently have a device of 4.2 ACS on a platform of 1113, is there any option for ACS 5.2 upgrade device or ACS 5.2 VMWare Server?

You answered your question on this one, there are an involved migration process that converts your old base of 4.2 to 5.2, take into account the fact that migration migrates only the hard parts such as: groups of network devices, internal users, ldap database configurations, network devices, sets of shell commands, to name a few. You will need to reconfigure the authorization policies since acs 5.2 takes on a different model of acs 4.x.

But the Migration Document, said that the ACS4.x device must be restored to a windows ACS4.x server before migration and backup. This does not seem like an easy migration. Is there another solution?

This isn't a bad solution, all you have to do is to deploy another server windows just to run acs for windows on, and then you use vnc to walk through the migration process. You will need to open a folder of tac for a person to publish the installation files and patches to put you on the same version.

Is the new ISE product better for AAA / GANYMEDE + or I should have a separate ACS for AAA?

ISE is a new product that migrates only 5.x databases. Right now ISE 1.0 not Ganymede support.

Tags: Cisco Security

Similar Questions

  • LAN/WAN design issues: redundant network core design and equipment

    Dear all,

    I have a growing network that has inherited the reliability and scalability issues:

    (Example from my existing network)

    We pop connected with us through lines of CF, that LSPS are connected to our CF traverse on persistent organic pollutants.

    Now, it is necessary to make the core of switching (switch with "?" mark) redundant

    because this is the point of concentration of all connections outside.

    I got an appointment in order to study new equipment (now it's just Catalyst 3560) for this network block.

    Unfortunately, the budget is pretty low.

    I have the following considerations:

    I think that the main problem is that most of the connections is L2 trunk links and it is difficult to prevent this.

    It seems that I need to duplicate all the links to LSP FC, pop and branches (this seems doable) and rely on STP! (this seems bad)

    with all of these links.

    Currently, I have two options for the basic block:

    1. two Catalyst 3750 have duplicated links. (CSW1 LSP1, CSW2-LSP1) and rely on STP

    2. a switch Catalyst 4500 series with two redundant supervisors (probably, they allow to buy if there are strong arguments) have reproduced links and rely on STP.

    These two options do not look good because I have to rely on STP with LSP.

    I would use redundancy features and L3 protocols, but do not know how to avoid trunks

    I have no experience with the material of fantasy as a Catalyst 4500/6500 series.

    Could someone please advice me alternatives for options of design and of the hardware and confirmation or withdrawal of my options.

    Also, I would be grateful if someone could help me find strong arguments for the acquisition of Catalyst 4500 series light up the core.

    Thank you much in advance.

    Best regards

    Max

    Hi Max,.

    in the diagram and description that you provided the switch, you need to replace is a dashboard device that works only for the moment, in L2

    If you plan to go L3 communications in this device, you should review your design to the whole of the network and also review/discuss with MS how that can be converted into L3 communications

    If you want to keep the same as L2 and introduce it into the device or devices for redundancy, I'd rather have two redundant devices of a redundant chassis that I mean pair of 3750 is more reliable chassis 4500 with equipment redundant as soup, UPE however its a reliable option as well and again for sure

    If you rely on STP for redundancy, what is the problem here? It is time of convergence or what is your concern?

    hope this helps

  • In design issue - CC will not save PDF & TIFF images are missing

    My indesign file, I've worked on over the past two months suddenly will not save the pdf out. Before this problem with the economy that happened... The last page of the circular page 8.5 x 11 20, is gray/50% the whole page in gray? And the background image that has been placed in the document and left behind an empty "images box" disappeared (or so I thought). I'm going to place the background image in once again, assuming that I deleted it. I am also having the same problem with the other images on other pages where the images have disappeared leaving behind empty boxes that may not have the images replaced them as NDS. They will not be displayed.

    I went to check the display in inDesign aka he changed the overprint preview and the "greying" box covered now all layers on this page only. How design is very organized, so everything is on layers (of exodus's images, shapes, text, background, guides). Guides have disappeared, and this gray effect (almost like when you're in illustrator and isolate a form any other work turned a shade darker) is there with once again the empty boxes without the content that I placed in them.

    I therefore decided to close the file and reopen. nothing has changed. I tried to save out as a PDF, so I can make sure that the file is safe... it out will now save all and tasks from bottom says "Impossible to export the PDF file." That's all. No other explanation.

    Does all this sound familiar to anyone? Or did happen? Help.

    Post edited by: Elisha Bencich

    UPDATE:

    I deleted a page that was giving me trouble and copy and paste new content... which seems a sort of solve the problem for now. I have to register again the whole document into a new document, I hope that works... I wish that this form could let me post a screenshot of the issue, I'm sure it would give someone a understanding of what's going on.

    See remove minor corruption by exporting

  • Database design issues

    Y at - it a forum that deals with issues of General database design, such as the definition of primary keys, unique constraints, Check constraints, indexes, etc.?
    I searched but could not find it. Maybe I missed it. Thank you.

    General, database or SQL/PLSQL:

    http://forums.Oracle.com/forums/category.jspa?categoryID=18

  • Display of design issues

    Hello

    I downloaded the Dreamweaver 8 and I am taking a few online tutorials to improve my almost non-existent skills. I have changed something during my careless exploration on demand. The problems that I'll have all involved the design view.

    1. If I create a layer in the lower part of the page, it automatically goes to the top left corner, but when I view in a browser it is still exactly where I placed it in design mode.
    2. If I change the text using a css style it will show changes in the browser view, but not in design mode.
    3. can I change the position of a layer if I change the HTML code but I do not get a handle when I mouse over the upper left corner of the layer. When I change the position of the layer in the code it still doesn't move the top left corner in design mode, but it does not change in the browser view. (I have to change the position in the code because when I click on the layer only layer properties that are available and class layer)
    4. last but far from least only page properties that are available to me are appearance, title/encoding and Image Tracing

    It's the trial version of Dreamweaver 8 and the same downloaded test works fine on my laptop. Both machines are addition to the XP Home with SP2.

    I worked on the issue for about a week. (Please don't laugh) I deleted and reinstalled the app... twice.

    Anyhelp would be greatly appreciated

    Make sure that CSS Style rendering do not turn off:

    View > Style made > display Styles

    It is a part of menu toggle, she should have a check mark next to it
    When ON.

    HTH,
    Randy

    > 2. If I changed the text using a css style it will show changes in the browser
    > view but not in Design view.

  • ACS 4.1 evaluation issues

    I have problems with the ACS 4.1 on a Windows 2003 SP1 / SP2 server.

    I can't add additional administrators to connect to the ACS. Error code in Internet Explorer: "error on page". I tried other machines, the problem remains the same...

    Also, after a few seconds (30), the session hangs and I have to reconnect back... Error: "cannot display page". Is this a known problem and what can I do about it?

    Thank you

    Remco

    First of all, make sure that you have JAVA Sun JRE 1.4.2_04 installed on the system with the browser. It is documented at:

    http://www.Cisco.com/en/us/docs/net_mgmt/cisco_secure_access_control_server_for_windows/4.1/installation/guide/Windows/install.html

  • The ISE Solution design issues?

    Is it possible to configure ISE in the following way:

    3 locations: main campus, 1 Site (Recovery Site) & Site2

    4 devices ISE.

    Main campus: 2 devices:

    Unit 1: PAN (P) + dem (P) + PSN (Just for backup, will be configured as a second ray on all of n)

    Unit 2: PSN (will be configured as the first Radius Server on Campus n main)

    Site 1 (DR Site): 1 unit

    Unit 1: PAN (S) + PSN (the Radius Server first for local NADs, third Ray on all other n), MnT (S)

    Box 2: 1 site

    Unit 1: PSN (the Radius Server first for local DNA)

    Due to some constraints, I'm not able to test this configuration in the laboratory and by looking at the document, although not mentioned specifically theoretically it seems possible to implement this way ISE, comments of support or support is much appreciated.

    Thanks for the info Maury. Overall, your design is OK for the number of endpoints that you have decided to run. Ideally, in a distributed deployment, you would 2 x ISE servers for Admin/M & T personas and then 2 x ISE for the Services of personal politics. You can also make one of the nodes in the primary for the Admin, but backup for M & T and vice versa for a better distribution of the load. So in your situation, you might do:

    Site A:

    ISE Server #1 - Admin main and secondary M & T

    ISE Server #1 - primary PSN secondary PSN for Site B to Site A

    Site b:

    ISE Server #1 - Admin secondary and primary M & T

    ISE Server #1 - primary PSN for Site B and secondary PSN for Site has

    Yet once, you won't have that many points of concurrent endpoints so you'll be OK going with the design that you have described. However, if you want to follow the guide Cisco design and future-proof your architecture and then I would follow my suggestion :)

    I hope this helps!

    Thank you for evaluating useful messages!

  • Failover of the ACS 5.1 Design

    How ACS 5.1 channel failover?  You need two devices of GBA?

    In terms of configuration on the network device, it's the same. Note that in ACS 5.1 configuration changes must be made on the main server and get replicated to all secondary servers. If the primary fails high school can continue to operate. However, in order to perform other configuration operations, you need to promote high school to play the main role and then continue Setup operations

  • ACS 5.1 - Ganymede + issue witch 'network access' access services

    Hello world

    can someone explain why Ganymede + cannot be used with the network access services?

    I know that Ganymede is mainly intended command authorization, but as I remember with ACS 4.2 it is possible. For example for the purpose of PPP.

    THX and regards

    Przemek

    GANYMEDE + applications cannot be managed by access with the Service Type «Peripheral Administration» services

    If the type is NetworkAccess, it will fail. Please check the Service Type defined for the Access Service 'VPM-access '.

  • General design issue task flows/MVC

    Hello

    I have a general question about the design of workflow without violating the MVC pattern.

    The question is simply: can business logic goes into workflow code tasks (which means the beans in the viewController project) rather than the model project?

    I know that, to meet the logic MVC design model business should be kept in the model project (generally in the application module class) and not in the controller layer (where the TF Pond in the ADF applications). This generally provides the security and reuse for the enterprise features.

    But what happens if this logic was complicated and involves the intervention of the user? If this logic be keept in the model project but split in 'functions' more small and separately called the TF according to decisions by the user through the process? But will these "very unitary", insignificant and useless functions without the calling workflow and so hardly reusable.

    On the other hand, workflows are reusable and securable components completely independent and are designed to deal with such cases. So why can't put us the logic in any case in there?  Is always considered as a violation of the MVC design pattern in a merger of ADF application?

    To summarize, if the business logic is coded in the model layer, so the question is how to handle the case of the long process involving interactions with the user and decisions through the whole process. On the other hand, the code put this logic in the TF will solve this problem but will be a violation of MVC design model.

    Any ideas or links to this topic?

    Thank you

    Elias.

    Hello

    Yes. Still you would write them in the model layer. By writing your business logic in the model layer, you expose only the necessary things in the view layer. By that I mean is, the view / controller layer does not necessarily bother on how the business logic is in the model layer. All of this has to do is just to call the exposed API (Client Interfaces) and display the result of it.

    Now, your question to place your business logic in the view layer. Suppose that your application must support the other platform (say mobile - MAF or office - ADFdi) in the future. What would you do with business logic written in your view layer of ADF Faces? You re - write them again according to the customer? Consider this scenario and reread my previous response, which would give you a better idea.

    Arun-

  • Basic design issues

    I want to design an icon for an Android application in CS5 and there are a lot of design guidelines that must be met, and there are a few that I am unclear:

    1.), they must be cartoonish in nature - how do you interpret this? What does that mean?

    (2.) with very little perspective - how do you interpret this? Closes this means that they must be flat?

    Sorry, English is not my first language.

    Thanks for your comments.

    You may say that the guidelines suggest your doing something which, in addition to be simplistic, is striking and thus has an immediate impact; something that can anser the question by Emily Eden: what's new and exciting?

  • Single column supporting different FK of various tables [Design issue]

    What would be a good design for a table with a column that can be worth a few different tables FK.
    The Fk constraint doesn't have to be applied.

    My thought is to simply make an int with another column in the table that defines the origin of the value.

    Is there a better way to do it?

    Thank you

    If the FK column in this table must exist in the table of a parent or another? Hmmm. As FK relationships must be able to be provided by the database to be useful, maybe...

    Create two columns, one for the FK to one parent and one for the FK to parent b. You can then declare the FK relationship in the database so that it can enforce and make profit in the optimization of queries. Then add a check constraint to the table to assert that none of the columns is null, and only one of then has a value (while the other is null). Outer join to both tables parent with a DECODING on the query returns the appropriate parent (research) value of the result set.


    SELECT c.col_a,
    DECODE( p1.col_b, NULL, p2.col_c, p1.col_b )
    FROM child c,
    parent_a p1,
    parent_b p2
    WHERE c.id = p1.c_id (+)
    AND c.id = p2.cid (+);

  • RPD design issues

    Dear all,

    I did the RPD made 2 and 3 dimensions as

    1-> fact 1 dimension <-size 2

    2-> 2 fact dimension

    (The join is made on the physical layer)

    When you create the Web Analytics, put the axis 1 and 2 dimension so that the two facts, only made 2 will have figures. I think that the reason behind should be of that size 2 there was no link with fact 1

    However, we would like to show figure 1 made with axis 1 and 2, is possible to do? Or should I move the join of the physical layer to layer MDB?

    Rajesh Raoul - BI - are you serious? 1 = 1 is the last option, you need to think because this is the worst of possible solutions for a simple and direct question that asked the OP.

    Content levels LTS is the way to go. Honestly, if you reference presentation Jeffs, then make sure that you've read more than just slide #12 which he immediately pointed out that the first * option * and slide #13 puts explicitly * ATTENTION *.

    Move from a slide after slide #14 and it presents the solution of content LTS levels! In all seriousness, these destroyers 'tips' and then begging for points gets on my nerves and is more counterproductive because he leads the OP on a completely wrong tangent!

    Vulliez-so please do the smart thing and reproduce this correctly in your RPD.

  • Button design issue

    I am new to Flash - I was hoping to do this in the fires of artifice, but because nested buttons, it does not seem possible.

    That's what I'm trying to do.  I'm looking for general advice on how to set up - I'm reading "Learning Flash CS4 Professional" and doing tutorials, but what I'm asking is a little different than what is in the book, and I do not have the knowledge necessary to make me jump.

    On the stage, I want 3 buttons on the side.  When you click each of these buttons, it's respective image appears in the middle of the scene (3 buttons, 3 images).  Then, you can hover over each of these images that are labeled, and when you move th emouse on the label, the different text label changes.  That's a rudimentary virtual microscope with each button corresponds to 4 x, 10 x, 40 x magnification, images are the images on the slide, and labels are things like cell phones, chromatin bodies, etc. The aim is that the student can click on each magnification, see the image of the slide with labels, and when it will fly over the labels, they change text identifying the part of the cell.

    Thanks in advance for any advice!

    I have CS4, so I wouldn't be able to open your file.  Here is a link to a crude example that I did for you what I tried to explain... demos dig in and explore.

    http://www.nedwebs.com/Flash/AS3_Select_Image.fla

  • Login page design need help!

    Hello

    This is my second thread about this, I am new to the blackberry development.

    I developed a form with two fields, a field and field a password. which I use as login page.

    I wonder how I can configure these two fields in the center of the shape and I can put background image.

    The EditField user = new EditField ("User ID:","", 10, EditField.FIELD_HCENTER | ") EditField.FIELD_VCENTER);
    PasswordEditField password = new PasswordEditField("Password:","",10,PasswordEditField.FIELD_VCENTER);

    FIELD. FIELD_VCENTRE AND HCENTRE do not work in my case

    I use jde 4.2.

    All of the suggestions.

    My application is ready, but waiting for complete some design issues.

    I installed the jde 4.7 and used the package decoration classes to get the solution req...

    Thanks anyway!

Maybe you are looking for