Installing a Clean Access Manager High Availability Pair
If using a CA-signed certificate for the HA pair:
This process assumes you have already generated a Certificate Signing Request and accompanying
Note
Private Key, submitted the request to your Certificate Authority, and have received your CA-signed
certificate. If you have not yet obtained a CA-signed certificate for the CAS, be sure to follow the
instructions in the "Manage CAM SSL Certificates" section of the
Manager Configuration Guide, Release 4.8(3)
Click Browse and navigate to the directory on your local machine containing the CA-signed
a.
certificate and Private Key.
Click Import. Note that you will need to import the same certificate later to the HA-Secondary
b.
CAS.
Go to Administration > CCA Manager and click the Failover tab. Choose the HA-Primary option
Step 2
from the Clear Access Manager Mode dropdown menu. The high availability settings appear:
Figure 4-5
Step 3
Copy the value from the IP Address field under Administration > CCA Manager > Network and enter
it in Service IP Address field. The Network Settings IP Address is the existing IP address of the primary
Clean Access Manager. The idea here is to turn this IP address, which the Clean Access Servers already
recognize, into the virtual Service IP address Clean Access Servers use for the Clean Access Manager
pair.
Change the IP address under Administration > CCA Manager > Network to an available address (for
Step 4
example x.x.x.121).
Cisco NAC Appliance Hardware Installation Guide
4-10
HA-Primary Clean Access Manager Failover Settings
Chapter 4
Cisco NAC Appliance - Clean Access
for details.
Configuring High Availability (HA)
OL-20326-01
Need help?
Do you have a question about the NAC3350-PROF-K9 - NAC Profiler Server and is the answer not in the manual?