Chapter 4
Configuring High Availability (HA)
2.
3.
Figure 4-17
4.
5.
Failing Over an HA-CAS Pair
To test your HA system, use the following steps:
1.
2.
3.
4.
Note
5.
6.
7.
8.
OL-20326-01
Open the Clean Access Manager administration console.
Go to Device Management > CCA Servers > List of Servers. The Active CAS of a
high-availability pair is displayed in brackets next to the Service IP for the pair, as shown in
Figure
4-17. Since the HA-Primary CAS is turned off, the IP address of the HA-Secondary CAS
should appear in brackets in the List of Servers with a status of Connected.
Active CAS in an HA-Pair
Click the Manage button for the pair. The management pages of the HA-Secondary CAS (now the
Active CAS) should appear.
From a client computer connected to the Clean Access Server's untrusted interface, test the
configuration by trying to log on to the untrusted (managed) network as an authorized user. If
successful, remain logged on and proceed to the next step.
Turn on the HA-Primary CAS machine. Make sure that the CAS is fully started and functioning
before proceeding.
From the client computer, log off the user's session and try to log onto the untrusted (managed)
network again as the user.
The HA-Secondary CAS should still be active and providing services for the user.
Shut down the HA-Secondary CAS machine.
Cisco recommends "shutdown" or "reboot" on the machine to test failover, or, if a CLI command
is preferred,
service perfigo stop
use
service perfigo maintenance
network connectivity to the management VLAN. See
for details.
After about 15 seconds, you should be able to continue browsing, with the HA-Primary CAS
becoming the Active server and providing the service.
Turn on the HA-Secondary CAS machine (the standby server).
Check the event log on the Clean Access Manager. It should correctly indicate the status of the Clean
Access Servers (e.g.,
"rjcas_1 is dead. rjcas_2 is up
Testing of the high availability configuration is now complete.
Installing a Clean Access Server High Availability Pair
and
service perfigo start
instead to bring the CAS to maintenance mode and allow
Useful CLI Commands for HA, page 4-43
")
.
Cisco NAC Appliance Hardware Installation Guide
. For a Virtual Gateway CAS,
4-39
Need help?
Do you have a question about the NAC3350-PROF-K9 - NAC Profiler Server and is the answer not in the manual?