Cisco ACS 1113 v4.0.1.44 possibilities of reproduction have 1120 and 2nd 1113

Hello

We currently have 1 ACS SE 1113 running the 4.0.1.44 version that we are unable to take the Live service and we want to install a 2nd one for replication and resilience (and have the resilient pair running the 4.2.0.124 version).

We had the following put at our disposal for this purpose an ACS SE 1113 and a CSACS 1120 times 4.2.0.124 the version currently running.

Could you please tell if the following downgrade/upgrade process is valid (I see that the CSACS1120 does not suppot version 4.0 or 4.1).

1. the downgrade 2nd ACS SE 1113 to version 4.0.1.44

2. the replication between the 1113 establishment is so we now have our on-line data on both boxes.

3. take the primary ACS out of service and confirm secondary now handles all requests.

3. switch to level our primary ACS to version 4.1, then to the 4.2.0.124 version

4. bring the ACS primary in-service and see works then take secondary ACS decommissioned for upgrade to version 4.1 and 4.2.0.124

5 confirm replication now working at the 4.2.0124 version.

Are there other methods possible to migrate our existing data directly from our existing of 1113 to one of the other devices (1113 and 1120) 4.2.0.124 running without going through the process of decommissioning/updated above.

Thanks in advance for your help.

Jim.

Hi Jim,.

I understand that you have 3 devices - 2 ACS ACS 1113 and 1120 1.

ACS1 - 1113 4.0.1.44 - running in production.

ACS2 - 1113 4.2.0.124 - lab running.

ACS3 - 1120 4.2.0.124 - running in the laboratory.

You want to configure the replication in the production environment and the transfer of the backup of the ACS1 to 4.2.0.124.

The path mentioned in the post is correct.

You can try to do the following:

take backup of the ACS1. Install ACS for windows 4.0.1.44 in the laboratory. Restore the backup of the ACS1. Upgrade the windows of the ACS to 4.1.1.24 and then to 4.2.0.124 in maintaining the database.

Restore the database on ACS2 and ACS3. Configure replication for ACS2 and ACS3.

Take a time out and replace ACS1 with the pair of replication of ACS2 and ACS3.

I hope this helps.

Kind regards

Anisha

P.S.: Please mark this message as answered if you feel that your query is resolved. Note the useful messages.

Tags: Cisco Security

Similar Questions

  • Cisco ACS 1113 appliance v4.1 - integration of RSA Securid v6.1

    The Windows of Cisco ACS version seems to have the ability of integration with RSA Securid its listed in external databases. It can also support the SDI Protocol if you install the agent on the Windows ACS platform. I need to use a Cisco ACS 1113 but RSA Securid does not appear in the section external databases. This mean that I won't be able to use the SDI Protocol only available RADIUS.

    And Yes you are right,

    With ACS, we need to configure using RADIUS, on ACS SE it won't work with SDI.

    Kind regards

    Prem

  • Does Cisco ACS 1113 v4.2 device work with Windows 2008

    Hello

    I have a wireless currently in production infrastructure. All my Cisco LWAP is managed by Cisco WLC. Authentication is done via RADIUS through my device Cisco ACS 1113 running on version 4.2. The Cisco ACS 1113 device communicates with my Windows 2003 Active Directory. Everything is good now.

    Next month, we plan to update Active Directory from Windows 2003 to Windows 2008? Will be all fine and good, or will it be questions? Please advice kindly.

    I saw another post in this community that the States https://supportforums.cisco.com/thread/1003597?tstart=0. I am now confused. Help, please.

    Kind regards

    RAM

    + 60122918870

    ACS 4.2 does not work with Windows 2008R2.  I had a case of TAC open about this, and basically, they told me that I had to switch to 5.2 ACS.   I've been doing demonstrations there and it authenticates with Windows2008R2 very well.

  • Cisco ACS 5.3 selection of service needs for RADIUS PEAP wireless and 802. 1 x Port Auth

    I use ACS 5.3.0.40.8 with GANYMEDE + maintenance device AAA and RADIUS maintenance the Cisco Wireless to access user AD environment. How can I implement 802. 1 x with the current implementation of RADIUS with users without distracting current thread or am I prevented due to the EAP - GTC used with PEAP via RADIUS?

    Sent by Cisco Support technique iPad App

    In general the EAP type is determined by the supplicant and the server

    so if you have configured for EAP TLS and client cable configured wireless client

    for PEAP MSCHAP v2, you shouldn't have any problems if you have access

    RADIUS service and handling the two types of active EAP and identity

    political as well as the authorization is right to the same target and the level of access.

    See you soon

    -------------------------------------------------------------------------------------------------------------------------

    Please don't forget to rate correct answers

  • RADIUS does not not on Cisco ACS SE v4.1 (1)

    Hello

    I have a CiscoSecure ACS version 4.1 (1) build 23.

    I can't configure the Cisco ACS for granular control of access router. I have a Netopia Router that is configured to use RADIUS to authenticate remotely for a telnet connection. The router sends the request to access the Cisco ACS SE RADIUS and a sniff on the side of the ACS shows the application of GBA, but I see no response from the ACS. RADIUS authentication to work with a Windows 2003 server.

    I configured an AAA client and a user of the ACS and use the default group. I use IETF RADIUS. Should what attributes I configure. In Windows, I use Service Type framed and Framed-Protocol PPP. This does not work with the Cisco ACS SE. Nothing shows up in the newspapers. It shouldn't be so difficult, but for some reason I can't make it work.

    Thanks for any help.

    Jutta Kullmann

    Jutta,

    Good to know it works very well. Please mark this thread as solved so other can benefit from.

    Kind regards

    ~ JG

  • Cisco ACS 4.2 1113 Recovery DVD

    Nice day!

    We have CSACSE-1113-k9 Cisco ACS 4.2 device 1113. And we need to reimage (restore the device to its original state). Can enyone help me with the correct link software.cisco.com image recovery DVDs?

    I'm trying to find it, but I can't see recovery dvd:

    Hello

    As far as I know, you don't have the possibility to download cisco.com ACS recovery DVDs. You can contact Cisco TAC and they can publish the software for you.

    Note If useful...

    Kind regards

    Kush

  • Replacement of Cisco ACS Solutions 4.2 engine

    Hello

    Our ACS (Cisco 1113) is dead and it is not cost-effective to replace because it will serve only until the end of this year.

    Is it possible to get the Ganymede software to install on a Windows Server? How can I go on the procurement software as the original documentation is no longer available? The fact that I have a dead unit will be sufficient evidence for a copy of the software? We are currently running v4.1

    Thank you.

    Here's a path to download the Eval of ACS 4.2 windows.

    Cisco.com > downloads Home > Products > Security > access control and

    Policies > policy and access management > Cisco Secure Access Control

    Server for Windows > Cisco Secure ACS for Windows 4.2 > secure access

    Control (ACS) server for Windows - 4.2.0.124 > scroll down

    and you will see a file named

    ACS v4.2.0.124 90-Days Evaluation Software

    EVAL-ACS - 4.2.0.124 - SW.zip

    ACS installation under windows

    http://www.Cisco.com/en/us/docs/net_mgmt/cisco_secure_access_control_server_for_windows/4.2/installation/guide/Windows/install.html

    Once installed, you can restore the previous backup on windows server.

    Restore from a backup ACS file

    http://www.Cisco.com/en/us/docs/net_mgmt/cisco_secure_access_control_server_for_windows/4.2.1/User_Guide/SCBasic.html#wp222758

    Jatin kone

    -Does the rate of useful messages-

  • Integration appliance ACS 1113 with RSA-Urgent

    Hi Experts,

    I got the following steps to install the fix on ACS 1113 V 4.0 Box.

    Instructions on how to install the patch

    ========================================

    1 extract the ACS CSAuth.exe - 4.0.1 - RSA - SW -CSCsc12614- CSCsd41866.zip

    2 stop the CSAuth service

    3. locate \bin and save a copy of the current CSAuth.exe

    4. copy the extracted the zip to \bin CSAuth.exe new

    5 start the CSAuth service

    In step 3, it was mentioned that locate \bin and save a copy of the current CSAuth.exe (i.e. on device ACS 1113). Could someone help me with the steps to locate the ACS ACS 1113 unit dir.

    Thank you

    Smail

    Satish,

    These steps are for windows-based acs. For the steps of the device are different. You need patch for the device.

    Steps to download for device attached is patch

    You can download the patch from the unit of

    http://www.Cisco.com/cgi-bin/tablebuild.pl/ACS-Soleng-3DES

    Please note if assistance

    Kind regards

    ~ JG

  • Problem with certifcate on Cisco ACS

    We want to authenticate our internal wireless users using our Cisco ACS running 5.3.  GBA questions our Active Directory environment for the user name and password provided.  I created a CSR on GBA and it provided to Entrust.  They gave me a root certificate, string and server.  I've linked the server certificate to the CSR under System Administration > Local Server Certificates > local certificates.  I then added the chain and the root certificates to the users of the site and identity stores > autorit├⌐s.  When I try to connect to a laptop client he asks a user name and password, but after entering this information, I am presented with the warning on this certificate below.  This certificate is to Entrust and I see the certificate root in the root store on the laptop.  Any ideas what would cause this.  TAC does not seem to have all the answers.  They say it's a problem of the client machine.

    In case you want to check your configuration settings.

    http://www.Cisco.com/en/us/products/ps10315/products_configuration_example09186a0080bd1100.shtml

    ~ BR
    Jatin kone

    * Does the rate of useful messages *.

  • Cisco ACS server

    Hello

    I currently have a Cisco ACS 3.3 Server. I want to upgrade the server to the latest version and cluster with one another so that we can have a redundant infrastructure because if one fails it also includes...

    Can provide you a solution for this?

    Thank you

    Hello

    The latest version is 4.1 ACS. You can upgrade 3.3.3 build 11 directly to 4.1.

    Then, you can install an another ACS 4.1 on a different machine and replication configuration between these two. In this way, you will need to make changes to only one that ACS and the secondary will be automatically updated.

    Once these two are defined, you can set both of these servers as a server Radius/Ganymede on devices and there will be a redundancy.

    Kind regards

    Vivek

  • How can I use Cisco ACS to save Shell commands

    Hi guys, pleeeease how can I configure Cisco ACS to do command authorization on my Cisco 3660 router. I get the accounting logs and authentication but no newspaper that show orders issued by users - shell and it's the most important paper that I need. I read materails and download articles on the site of Cisco... but the thing is still does not give me the papers.

    I have these lines on my router:

    ...

    AAA authorization config-commands

    AAA authorization exec default group Ganymede +.

    AAA authorization commands 15 default authenticated if

    AAA authorization network default group Ganymede +.

    ...

    It's funny, when I turn on debugging of the authorization of the AAA on the router, it shows me every command being sent by the user on the debug log. But nothing shows under Administration TACAC + on the Cisco Secure ACS. What is responsible for this?

    *****************************************************

    I installed the trial version of the Cisco ACS 90 days and made all necessary settings and I have to say I like what I see already. I'm opening moves to recommend the product to purchase. Thank you guys, I got about the features of this ACS software through this forum, keep up the good work. I recommend the software for those who need to have adapted to the management reports Security Audit logs.

    If I understand what you're asking correctly, the answer is not in the authorization, that it is in accounting. I set up on my routers and send to ACS orders that level 15 privilege users enter on the router.

    orders accounting AAA 15 by default start-stop Ganymede group.

  • Cisco ACS appliance takes long to start after initial config

    Hello

    I'll put up 2 ACS (1113 HW, SW 4.1) devices. After the initial configuration (IP address, admin pass etc.) and reboot, the devices do not seem to start or close the login prompt (even after a start of the night).

    What could be the problem with the device or my patience?

    Hello

    If you get something like from console windows,

    Then, make sure that you use less than 15 characters without spaces unit name.

    Kind regards

    Prem

  • Problem with Cisco ACS and different areas

    Hello

    We are conducting currently a problem with Cisco ACS that we put in place, and I'll try to describe:

    We have ACS related directory AD areas, where we have 2 domains and appropriate group mappings.

    Then we have our Cisco switches with the following configuration,

    AAA new-model

    AAA-authentication failure message ^ CCCC

    Failled to authenticate!

    Please IT networks Contact Group for more information.

    ^ C

    AAA authentication login default group Ganymede + local

    AAA authorization exec default group Ganymede + local

    AAA authorization network default group Ganymede + local

    AAA accounting exec default start-stop Ganymede group.

    orders accounting AAA 15 by default start-stop Ganymede group.

    !

    AAA - the id of the joint session

    But the problem is that with the users in a domain, we can authenticate, but not the other. Basically, the question is that when we check on the past of authentication, two authentications are passage and the display of 'Authentic OK', but on the side of the switch, there is a power failure.

    There may be something wrong with the ACS?

    Thank you

    Jorge

    Try increasing the timeout on IOS device using radius-server timeout 10.

    Do we not have journaling enabled on the ACS server remotely?

    -Philou

  • Cisco ACS 5.8 CLI admin account lockout

    Hi all

    We recently deployed device Cisco ACS 3495 and running on a version 5.8.

    Everything seems well while our for the CLI admin account was locked out.

    Found a bug in Cisco for the same problem with version 5.5, but no solution yet...

    ACS 5.5 CLI Admin account locked and no Log Message
    Someone out there who might have encountered the same issue and can help advise?
    Thank you and best regards,
    NDA

    Hello

    Unfortunately, the only solution for this is the DVD of password recovery.

    Once fixed, you can increase the car locked out amounted to something greater than the default value of Cisco.

  • 5.4 double certificate option Cisco ACS

    Hello Experts

    I wonder if anyone knows if I can get two certificates on my Cisco ACS 5.4 server. The documentation says I can have it as long they have different 'from' and 'to' dates with a same name CN. However, this is a production server and wanted to if sure before I make changes. I currently have a certificate installed and everything works well but need to add a second for migration purposes.

    Hovsep Armeni
    LAN, UK

    A certificate can be linked to these two services (HTTP and EAP), however, each service can only be associated with a single certificate. Thus, for example, you cannot have two certificates that are related to the EAP process.

    Thank you for evaluating useful messages!

Maybe you are looking for

  • Re: After installing Bitdefender cannot access F8 at startup to recover the system.

    Bidefender installed on a Satellite L755 out-of-the box. When the Starter have 2 options:Recovery of BitDefender or Windows 7. Any option is selected, the laptop stuck. Wanted to use F8 to access recovery and reset the machine to factory default. Hit

  • Save picture in the image control

    Hello world The labview picture control has a context menu that includes the option so save the image. I found that it works very well in the development environment. If I click on it, a dialog box opens that allows me to choose where to save the ima

  • Cannot install Kb976098

    Auto update and computer will not install update Kb976098 WHY?

  • Windows 7 - Windows Live essential 2011 upgrade

    Problems with Windows Live essential 2011 (KB2434419) installation.  He always tells me that I have an upgrade to install and after I start the installation, he informs me that he could not install because I already have a taste of different construc

  • Why Windows XP Mode a Terminal Server (Bus network)?

    A Bus network is based in airports, train stations, subways and bus stations, but not businesses. Why Windows XP Mode is a Bus network? A Terminal Server is a service of a bus network.