
Chapter 8 Establishing Cisco Secure ACS System Configuration
CiscoSecure Database Replication
8-16
User Guide for Cisco Secure ACS for Windows Server
78-14696-01, Version 3.1
•
Cisco Secure ACS does not support bidirectional database replication. The
secondary Cisco Secure ACS receiving the replicated components verifies
that the primary Cisco Secure ACS is not on its Replication list. If not, the
secondary Cisco Secure ACS accepts the replicated components. If so, it
rejects the components.
•
To replicate user-defined RADIUS vendor and vendor-specific attribute
(VSA) configurations, user-defined RADIUS vendor and VSA definitions to
be replicated must be identical on primary and secondary
Cisco Secure ACSes, including the RADIUS vendor slots that the
user-defined RADIUS vendors occupy. For more information about
user-defined RADIUS vendors and VSAs, see
Custom RADIUS Vendors and
VSAs, page 8-33
.
Database Replication Versus Database Backup
Do not confuse database replication with system backup. Database replication
does not replace System Backup. While both features protect against partial or
complete server loss, each feature addresses the issue in a different way.
System Backup archives data into a format that you can later use to restore the
configuration if the system fails or the data becomes corrupted. The backup data
is stored on the local hard drive and can be copied and removed from the system
for long-term storage. You can store several generations of database backup files.
CiscoSecure Database Replication enables you to copy various components of the
CiscoSecure database to other Cisco Secure ACSes. This can help you plan a
failover AAA architecture and can reduce the complexity of your configuration
and maintenance tasks. While it is unlikely, it is possible that CiscoSecure
Database Replication can propagate a corrupted database to the
Cisco Secure ACSes that generate your backup files.
Caution
Because the possibility of replicating a corrupted database always exists, we
strongly recommend that you implement a backup plan, especially in
mission-critical environments. For more information about backing up
Cisco Secure ACS or the CiscoSecure database, see
Cisco Secure ACS Backup,
page 8-47
, and
Appendix D, “Cisco Secure ACS Command-Line Database
Utility.”