Network Access Control

 View Only
Expand all | Collapse all

Not connect enforcer with 2 SEP Manager

Migration User

Migration UserFeb 01, 2009 08:58 PM

  • 1.  Not connect enforcer with 2 SEP Manager

    Posted Jan 09, 2009 05:37 AM

    Hi, all!

     

    I can't use spm command connect Lan enforcer with 2 SEP manager. Please help me.

     

    Thanks!

     

    ThangPN.



  • 2.  RE: Not connect enforcer with 2 SEP Manager

    Posted Jan 12, 2009 12:45 PM
    I am not sure what you are trying to achieve. LAN enforcer can only connect to 1 SEPM server at a time. Are you trying to do replication?


  • 3.  RE: Not connect enforcer with 2 SEP Manager

    Posted Jan 12, 2009 09:50 PM

    Hi, Mandy Pang!

     

    Thank you for reply.

     

    I want high available for my system. I have 2 radius running ACS 4.2, 1 Lan enforcer and 2 SEPM.

     

    I want replicate 2 SEPM but I have 1 Lan enforcer. Please help me for this.

     

    ThangPN.

     

     



  • 4.  RE: Not connect enforcer with 2 SEP Manager

    Posted Jan 13, 2009 07:50 PM

    You can setup replication between the 2 SEPM so that when 1 SEPM fails, the enforcer will communicate with the other SEPM.

     

    RADIUS failover is supported by the Enforcer. On the enforcer settings on SEPM, you can input both of your ACS RADIUS servers into 1 RADIUS group and assign to the enforcer. The order of the ACS radius matters. The enforcer will first try to connect to the 1st ACS RADIUS on the list, if there is no response, it will try the 2nd one.

     

    For LAN enforcer failover, it's done on the switch level. Since you only have 1 LAN enforcer, you can setup on the switch radius group such that LAN enforcer is 1st on the list, and your ACS radius is 2nd on the list. This way, if the LAN enforcer fails, the switch will contact your ACS for user authentication. 



  • 5.  RE: Not connect enforcer with 2 SEP Manager

    Posted Jan 13, 2009 08:43 PM

    Hi, Mandy Pang!

     

    As you tell me: "You can setup replication between the 2 SEPM so that when 1 SEPM fails, the enforcer will communicate with the other SEPM.", but I am not sure when 1 SEPM fails, the enforcer will auto communicate with the other SEPM. I think the enforcer will manual communicate with the other SEPM when I use SPM commmand again with that.

     

    ThangPN.



  • 6.  RE: Not connect enforcer with 2 SEP Manager

    Posted Jan 16, 2009 02:12 PM
    You can setup 2 SEPMs on the same server list on the SEPM server, then apply that server list to the enforcer.


  • 7.  RE: Not connect enforcer with 2 SEP Manager

    Posted Jan 22, 2009 02:15 AM

    Hi, Mr Pang.

     

    I don't understand your idea. I don't know "setup 2 SEPMs on the same server list on the SEPM server". You want tell that you will install an additional management server to an existing site. I tried but it don't install for Embeded databate, It only apply for SQL database.

     

    ThangPN.



  • 8.  RE: Not connect enforcer with 2 SEP Manager

    Posted Jan 22, 2009 01:35 PM
    Yes, with embedded DB, you cannot add additional site. If you want to setup SEPM failover for enforcer, you can setup another SEPM independent with the 1st one, put them to be replication partner. Then on the SEPM console, go to Policies -> Policy components -> Management Server List to create a new server list with both SEPM servers. Then go to enforcer settings on SEPM and make sure you select the server list you just created. This way, the enforcer will failover to the 2nd SEPM when the 1st fails.


  • 9.  RE: Not connect enforcer with 2 SEP Manager

    Posted Jan 22, 2009 10:35 PM

    Hi, Mr Pang!

     

    Enforcer SPM with SEPM 1st. Enforcer setting only appear on SEPM 1st. When SEPM 1st die. Enforcer setting not appear on SEPM 2nd because enforcer not SPM with SEPM 2nd. That time, Does is SEPM 2nd communicate with enforcer?.

     

    ThangPN.



  • 10.  RE: Not connect enforcer with 2 SEP Manager

    Posted Jan 26, 2009 12:54 PM
    It should if you set the 2 SEPM in the same management server list.


  • 11.  RE: Not connect enforcer with 2 SEP Manager

    Posted Jan 28, 2009 09:12 PM

    On the Enforcer, I must SPM to SEPM 1st, SEPM 2nd, server list management or when SEPM 1st die I must SPM to SEPM 2nd again.

     

    ThangPN.



  • 12.  RE: Not connect enforcer with 2 SEP Manager

    Posted Jan 28, 2009 09:46 PM
    If you put SEPM1 and SEPM2 in the same server list, then when you connect enforcer to SEPM1, it will download the profile from SEPM1 which contains both SEPM1 and SEPM2. When SEPM1 dies, and enforcer cannot contact SEPM1, it will then try to connect to SEPM2.


  • 13.  RE: Not connect enforcer with 2 SEP Manager

    Posted Feb 01, 2009 08:58 PM

    Thank for your support!

     

    ThangPN.