Failover problem Manager HA of the NAC

Hi all

I have a high availability manager high availability server of the NAC and NAC. When I try to active failover primary NAC Manager to secondary NAC Manager, NAC Server is not able to connect to the secondary NAC Manager. I don't know that ip connectivity is not a problem. When I try to do the NAC Manager primary such as active, the NAC server can connect to the main Manager of NAC. It seems that NAC Server cannot connect to the secondary NAC Manager.

Does anyone have an idea?

Thank you.

have you checked certificates between them?

you export the certificate of the secondary primary NAC NAC?

Tags: Cisco Security

Similar Questions

  • "The [ComputerName] has no installed feature of failover clustering. Use Server Manager to install the feature on this computer. "

    Hello

    I got this error message prompt to try to add the first node, by which I already have installed in the node 1 and node 2 failover function. I am running windows server 2008 standard version at the moment and have all the grouping necessary setting such as: joined the domain, shared disk and etc. Facing this problem when trying to run/validate configurations "failover cluster management.
    Kindly, advice
    Boonlep coulibaly

    Hello

    Your question of Windows 7 is more complex than what is generally answered in the Microsoft Answers forums. It is better suited for the IT Pro TechNet public. Please post your question in the TechNet Forum. You can follow the link to your question:
    http://social.technet.Microsoft.com/forums/en-us/w7itpronetworking/threads

  • Problem of the NAC plugins & Nessus

    Hi all!

    I have a problem with the installation of the Nessus plugin. ((

    After reading Installation Guides I have not a clear understanding what files should I download. So I have 2 files:

    Nessus-plugins - 2.2.10.tar.gz (6507 KB)

    Nessus-plugins-GPL - 2.2.10.tar.gz (1071 KB)

    of http://www.nessus.org/download/index.php

    After renaming, I tried to download each of them turning the cam under updates of the Plugin. CAM said "Upload successful" and has always some plugins (Scan Setup-> Plugins).

    So I don't understand what the problem... ((

    Can someone share file plugins.tar.gz correct, please...?

    Concerning

    You must download and install the Nessus appropriate for your PC.

    After downloading the latest plugins on the site of Nessus, in the directory (for a Windows installation) c:/Program Files / sustainable / Nessus / Plugins, you will have a file 'plugin.tar.gz '. You can rename or copy this into "plugins.tar.gz".

    Then in the console the NAC Manager, under ACCESS OWN-> NETWORK SCANNER-> Plugin updates, go to the same folder and choose the file "plugins.tar.gz". It MUST be named exactly as described - with the S - to work. Complete the DOWNLOAD. When finished go to the Configuration of Scan tab and select all in the show _ Plugins dropdown. You should hae about 20,000 of them.

    HTH.

    Jim

  • I had some problems with my pc, since then when I close Firefox it would not reopen unless I go to Task Manager and end the process for FF.

    I had some problems with my pc, since then when I close Firefox it would not reopen unless I go to Task Manager and end the process for FF. I uninstalled FF and re-installed and no change.
    Walt

    I have a same problem.

  • When I try to download an audiobook, I get the following error Message: error 0xC00D2711 - a problem has occurred in the digital rights management component. Contact the technical application support. Can someone help?

    I try to download OverDrive Media Console to sync with the ipod of the omega software.

    Jmcarroll,

    Thank you for your question.

    What version of Media Player do you use?

    This problem may occur when the following conditions are met:

    ·         The file you are trying to play is a protected requiring an individualization of digital rights (DRM) of management 2.5.

    ·         You use the Player Windows Media 7.1 on a Microsoft Windows 2000-based computer.

    Player Windows Media 7.1 on a Microsoft Windows 2000-based computer does not support DRM 2.5 individualization.

    You can download the latest version of Windows Media Player which is the Download of Windows Media Center.

    I hope this helps!

    Lisa
    Microsoft Answers Support Engineer
    Visit our Microsoft answers feedback Forum and let us know what you think.

  • Problem of the NAC - Agent is a disconnect

    Hello

    We have a problem with the NAC in mode virtual outofband.

    AD SSO, sanitation, everything is working, but the strange things happening: after awhile, when downloading large files, Agent connects to the formula of network users, and the registration process is restarted.

    I disabled the pulsation clocks and timers, session, but we still have a problem.

    Also, while sniffing traffic on the switch port, I noticed that after have correctly connected you to the own Cisco Agent network always send traffic to UDP Port 8905. Is this a normal behavior?

    I noticed problems with this version of the agent causing connections to give up intermittently. I would upgrade to agent v4.1.3.1.

  • Someone at - it problems experienced installation PS 14 items on their Mac?  I managed to download the program after the purchase, but he continues to fail during installation.

    Someone at - it problems experienced installation PS 14 items on their Mac?  I managed to download the program after the purchase, but he continues to fail during installation.

    Frustrating.  I spent hours with 4-5 customer representatives Adobe tries to 'fix' my problem.  Finally, I just ask for a refund.  I was told 5 to 7 days until the refund appears on my cc.  I was considering buying the disc, but with your comment, I think I'll look for something else.

  • Problem of the NAC in the virtual tape gateway VPN SSO

    Hello

    I've implemented a NAC solution for remote users. The unit of CASE mode configured in the gateway enVirtual Strip.

    I followed all the steps listed in http://www.cisco.com/en/US/products/ps6128/products_configuration_example09186a008074d641.shtml

    Remote users can connect succeffuly using the cisco vpn software and they can ping the SIN, but not the DNS (the ASA offers IP @ but not the DNS I do not know why).

    When I access the NAS, I can download the NAC Agent but VPN SSO is not executed and the Agent asks me to connect using LOCAL DB.

    Any help please,.

    Kind regards

    Larson,

    For VPN SSO work, you must send the accounting package to the CAs. The CASE can in turn send for the ACS if you need accounting also be done on GBA, but for authentication ONLY work, the accountant must reach the CASE.

    HTH,

    Faisal

  • Activation of the NAC HA puts several hosts and ASA with processor clocked at 100%

    I installed a NAC Manager and a NAC server in OOB without any problems, but when I configured the AP (high availability) with another server, my ASA and several guests in my network started work ant 100% of the cpu.

    I tried to configure each interface of the NAC on a single DMZ and the problem stops there.

    -That someone had this problem (NAC version 4.7)

    TKX

    Miguel Amaral

    Hello Miguel.

    When I started a NAC InBand HA solution I had a similar problem that I solved the heart rate HA configuration to use ETH0 just instead use ETH0 and ETH1.

    Best regards

    Luciano Carvalho

  • Profiler in the NAC 2.1 to 3.1 upgrade

    Hi guys,.

    I'm setting up a Profiler from the NAC that accompanies 2.1 installed. I upgraded to 3.1, prayed and installed the license without any problems, but I always get this message: "ERROR: [2010-12-08 09:25:01 (main: 668)] valid no key not found [no such file or directory]" "

    The license file exists, and on the interface Web Profiler from the NAC, the State of the license is OK.

    A single line in the license file gives me this information: 'cisco 2.1 INCREMENT CCA-MANAGER countless Permanent '.

    Does anyone know if the license is linked with the version of Profiler?

    The upgrade from 2.1 to 3.1 is allowed or it is necessary to purchase a new license 3.1?

    Best regards

    Hello

    So I guess you spotted the problem here...

    You have a collector's license?

    You need 2 licenses: 1 to the server profile, and one for the collector.

    Basically, the mac address you provide is the same (eth0 ot Server Profiler), but you need a PAK Server Profiler to generate the license Server Profiler (the one you already have) and a PAK for license collector (which is missing).

    You have the collector PAK?

    If Yes, then just go to the license page and submit this PAK and the mac address.

    HTH,
    Tiago

    --

    If this helps you or answers to your question if it you please mark it as 'responded' or write it down, if other users can easily find it.

  • The NAC - OOB L2 authentication login page - does not appear!

    Hi all

    We have 2 managers of the NAC and NAC 2 servers. We have a failover solution. Our deployment is OOB layer 2 virtual Central Passage. We have successfully added the SIN in NAM and we did the requirements in NAM as a mapping setup VLAN (starting at vlan no reliable 913 to the vlan trust 910), adding managed subnet, change profile, profile, adding switches (cisco 3560) to NAM, the roles configuration on the user, the local users and also port user login page.
    Then, we tested it by connecting the PC to port controlled on the switch.
    The controlled port configuration was VLAN 910 and after connecting the PC, it is converted to 913 VLAN then we have successfully obtained an IP address from dhcp that is configured on the switch but the authentication login page appeared! and also, when disconnect us from the PC of this port, the configuration is not passed to vlan 913 to vlan 910 then manually change each time to do our tests.

    Do so that the login page appears and also automatically NAM to change the configuration of the port after having disconnected from the PC?

    Thanks in advance.

    AD SSO is supported with the Windows 2003, but with 2008, only single server is supported and which should also be 32-bit. 64-bit servers are not yet supported.

    HTH,

    Faisal

  • Agent of the NAC this SSL error

    Running

    CAM: 4.5.0 lite

    Current Windows clean access Agent Version: 4.5.0.0

    Current Windows clean access Agent Patch Version: 4.5.0.0

    Agent Macintosh's own access current version: 4.5.0.0

    Course Cisco NAC Web Agent Version: 4.5.0

    (Clean access windows agent installed on the host (Vista Business) is version 4.5.1.0)

    CAS mode: L2 virtual OOB GW

    The installation program is in conditions of laboratory for a proof of concept.

    The following scenario occurs each time a new authentication is attempted from a vista host running the agent access.

    -------------

    I plug the host on the controlled NAC switch port

    I get an ip address although my pool of vlan and dhcp auth

    Agent of Cisco clean access is displayed on the screen according to the normal

    I enter my user and pass and click login

    I get a "security alert" pop up indicating "the revocation information of the certificate for this site is not available. Do you want to continue? »

    There are 3 buttons to choose: Yes, no, display certificates

    I click Yes, but the error message does not disappear,... no matter how many times you click on Yes,... the error remains on the screen, keep you from making the connection.

    If I click on no.

    The clean access agent then says "network error!, detail: Certificate SSL REV failed [12057]."

    My only option is to click on the "Close" button so I don't

    This closes the agent clean access, but the agent instantly appears buck on my screen asking again user them and pass.

    I enter the right user and pass and click login

    I receive a new security alert pop up stating "this page requires a secure connection which includes server authentication." "The issuer of certificate for this site is unknown or unreliable, making you go?

    My click Options, Yes, no, view the certificate or more information

    I click on Yes, the security alert disappears and own access now States that I managed to connect to the network.

    It refreshes my IP address and puts me in the vlan correct based on the role of my user name.

    -------------

    I checked the event logs, all my access attempts are accepted, (on the 2nd try of course), but there is no errors in the cam on this SSL problem.

    However, I get a warning red text on the summary page of the cam, which stipulates the following, which I do not know if it has any impact on my problem.

    "WARNING: the end-entity certificate issued by"www.perfigo.com"is suitable for laboratory environments only." You must import a certificate of third party entity end for your own Access Manager and own access servers before the Cisco NAC Appliance deployment in a production environment. Please check your own access servers and ensures Clean Access Manager for similar messages.

    WARNING: The current "www.perfigo.com" trusted certification authority is suitable for laboratory environments only. Cisco recommends to import a third-party certification authority. Please check your own access servers and ensures Clean Access Manager for similar messages. »

    My questions are,

    -Why used the CAA accepts the first authentication attempt?

    -How can I remove the first security alert?

    -How can I set the CCA so that I login just once without having to click on no and wait for CAA to appear a 2nd time?

    Thank you all

    The fundamental problem is that the customer is unable to check the root certificate for your CASE.

    I guess that since you have always the perfigo warning that you have not installed a certificate valid on the job. If you did, you must remove the certificate of perfigo. If you install a valid certificate, you must remove the Perfigo cert.

    Once you have a valid cert installed, make sure that the client can access the certificate server root of the AUTH VLAN. That should get rid of these two messages.

    If you cannot provide access to the certificate server, then you cannot get rid of the second message, but you can get rid of the first message (the one that sticks you in a loop).

    This message (the first one) is due because the check certificate revocation in Internet Explorer has been enabled. This option has been disabled by default in XP, but is enabled by default in Vista. The option is disabled in Internet Options > Advanced tab > check the CRL.

  • Cannot run command to config the NAC perfigo service

    I have a new Server Manager of the NAC for a deployment costs. I logged in using the root with a connection password set on the server.

    I can't be able to run the 'service perfigo config' command to perform the initial configuration of the CAM.

    [[email protected] / * / /] # start service perfigo

    perfigo: unrecognized service

    [[email protected] / * / /] #.

    No idea what could be the problem?

    Thanks in advance.

    Have you installed the CAM software on it, or it was already installed?

    If it was already, I recommend you the image with the DVD.

  • I have 22 SPSS for Mac.  Since I upgraded to El Capitan, I have a number of problems.  I checked the Web sites of IBM, but they only mention fixes for SPSS 23.  Any thoughts would be greatly appreciated.  Thank you.

    I have 22 SPSS for Mac.  Since I upgraded to El Capitan, I have a number of problems.  I checked the Web sites of IBM, but they only mention fixes for SPSS 23.  Any thoughts would be greatly appreciated.  Thank you.

    I am running SPSS 23.0

    You can upgrade to 23.0?

    Also, have you looked here

    http://www-933.IBM.com/support/fixcentral/SWG/selectFixes?parent=SPSS & Product = IB m / + Information Management / SPSS + statistical...

  • Problems galore after installing the Vista SP2

    Once I installed SP2 on my Acer 6920 g, my sound card no longer works. I followed the "Fix It" solution and update its drivers, which solved the problem and his return. When I stopped the machine, he started rebotting, begin a strange "xp" mode, before launching Acer Arcade Deluxe, a media programme. This problem for about two hours, stop, reboot in this program can close again in a loop on and on. Through to hold the power button on the laptop, I managed finally to get the machine to stay 'off '. The following day, when I turned on the laptop I found that repairing the system has been launched, but could not solve the problem, telling me that the problem was the following;

    Event problem name: StartupRepairV2
    Problem signature 01: AutoFailover
    Problem signature 02: 6.0.6000.16386.6.6001.18000
    Problem signature 03:6
    Problem signature 04:524296
    Problem signature 05: 0xf4
    Problem signature 06: 0xf4
    Problem signature 07:0
    Problem signature 08:2
    Problem signature 09: WrpRepair
    Problem signature 10:16385
    OS version: 6.0.6000.2.0.0.256.1
    Locale ID: 1033

    Can anyone help? I have an option for 'Complete restoration of Windows', but want to this only as a last resort because I do not have a backup of my files.

    Thank you

    Try this first before reinstalling.

    If it fails, see below, data recovery before reinstalling.

    Restore point:

    Try typing F8 at startup and in the list of Boot selections, select Mode safe using ARROW top to go there > and then press ENTER.

    Try a restore of the system once, to choose a Restore Point prior to your problem...

    Click Start > programs > Accessories > system tools > system restore > choose another time > next > etc.

    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

    If the above does not work, try to make a Bootable ERD to do a Startup Repair:

    As is the case with most computers/laptops these days, they do not come with good Vista disc to repair only the recovery disks.

    As your grave in the category above, download the ISO on the provided link and do a repair of the disc.

    Go to your Bios/Setup, or the Boot Menu at startup and change the Boot order to make the DVD/CD drive 1st in the boot order, then reboot with the disk in the drive.

    At the startup/power on you should see at the bottom of the screen either F2 or DELETE, go to Setup/Bios or F12 for the Boot Menu.

    When you have changed that, insert the Bootable disk you did in the drive and reboot.

    You can make a tool to restart system, System Restore, etc. with it.

    Read all the info on the website on how to create and use it.

    http://NeoSmart.net/blog/2008/Windows-Vista-recovery-disc-download/

    ISO Burner: http://www.snapfiles.com/get/active-isoburner.html

    It's a very good Vista repair disc.

    You can do a system restart tool, system, etc it restore.

    There is not a disk of resettlement.

    And the 32-bit is what normally comes on a computer, unless 64-bit.

    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

    Data recovery:

    1. slave of your hard drive in another computer and read/save your data out there.

    2. put your Hard drive in a USB hard drive case, plug it into another computer and read/save from there.

    3 Alternatively, use Knoppix Live CD to recover data:

    http://www.Knopper.NET/Knoppix/index-en.html

    Download/save the file Knoppix Live CD ISO above.

    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

    http://isorecorder.alexfeinman.com/isorecorder.htm

    Download the Vista software from the link above.

    After installing above ISO burning software, right click on the Knoppix ISO file > copy the Image to a CD.

    Knoppix is not installed on your PC; use only the resources of your PC, RAM, graphics etc.

    Change the boot order in YOUR computer/laptop to the CD/DVD Drive 1 in the boot order.

    Plug a Flash Drive/Memory Stick, BOOT with the Live CD, and you should be able to read the hard drive.

    When the desktop loads, you will see at least two drive hard icons on the desktop (one for your hard drive) and one for the USB key.

    Click on the icons of hard drive to open and to understand which drive is which.

    Click the icon for the USB drive and click on "Actions > Change the read/write mode" so you can write to disk (it is read-only by default for security reasons).

    Now to find the files you want to back up, just drag and drop them on the USB. When you're done, shut down the system and remove the USB key.

    See you soon.

    Mick Murphy - Microsoft partner

Maybe you are looking for

  • 01/07/13 KB6270838 Microsoft update causes Firefox to crash. Only works in safe mode. Fix inside.

    How to fix: Uninstall Microsoft Update KB6270838 by going to control panelClick on Windows UpdateClick view update historyClick on installed updatesAccess to the area called Microsoft Windows and find the KB6270838 updateDoubleClick and select uninst

  • Tecra A10 - left key of the mouse on the touchpad is "locked".

    Dear forumLeft click Mouse touchpad is a little distorted. I had a peek inside the palmrest, and there is a white plastic stand thing that broke. It seems to happen this way with a large number of these particular models. Please do you know is there

  • Satellite L650 (PSK1EA) new installation - how?

    Hello my hard drive in the recently broken L650 (PSK1EA).I intend to buy a new one and replace only snag is that I never backed up my old one. I know I have to buy windows again, but what other things do I need.where can I get and when I install (bef

  • HP Officejet 4630: Cannot print photos on paper 4 x 6

    I am trying to print a photo 4 x 6 and I get a message saying "HP Officejet 4630 (network) has a problem that requires your intervention.  If I put a picture on the printer to copy, it prints a copy but will not let me print a photo stored on my comp

  • HP Deskjet F2480: printer does not print

    My printer has a paper jam and the paper was pulled out of the front (wrong way). The printer feeds through but does not actually print. Is this fixable or is the garbage bin of the printer? I believe that when the book was pulled he screwed up somet