8-11
User Guide for Cisco Secure ACS for Windows Server
78-14696-01, Version 3.1
Chapter 8 Establishing Cisco Secure ACS System Configuration
CiscoSecure Database Replication
With regard to database replication, we make the following distinctions about
Cisco Secure ACSes:
•
Primary Cisco Secure ACS—A Cisco Secure ACS that sends replicated
CiscoSecure database components to other Cisco Secure ACSes.
•
Secondary Cisco Secure ACS—A Cisco Secure ACS that receives
replicated CiscoSecure database components from a primary
Cisco Secure ACS. In the HTML interface, these are identified as replication
partners.
A Cisco Secure ACS can be both a primary Cisco Secure ACS and a secondary
Cisco Secure ACS, provided that it is not configured to be a secondary
Cisco Secure ACS to a Cisco Secure ACS for which it performs as a primary
Cisco Secure ACS.
Note
Bidirectional replication, wherein an Cisco Secure ACS both sends database
components to and receives database components from the same remote
Cisco Secure ACS, is not supported. Replication fails if an Cisco Secure ACS is
configured to replicate to and from the same Cisco Secure ACS.
Note
All Cisco Secure ACSes involved in replication must run the same release of the
Cisco Secure ACS software. For example, if the primary Cisco Secure ACS is
running Cisco Secure ACS version 3.0, all secondary Cisco Secure ACSes should
be running Cisco Secure ACS version 3.0. Because patch releases can introduce
significant changes to the CiscoSecure database, we strongly recommend that
Cisco Secure ACSes involved in replication use the same patch level, too.