
Chapter 2 Deploying Cisco Secure ACS
Basic Deployment Factors for Cisco Secure ACS
2-6
User Guide for Cisco Secure ACS for Windows Server
78-14696-01, Version 3.1
In the small LAN environment, see
Figure 2-1
, network architects typically place
a single Cisco Secure ACS internal to the AAA client, protected from outside
access by means of a firewall and the AAA client. In this environment, the user
database is usually small, there are few devices that require access to the
Cisco Secure ACS for AAA, and any database replication is limited to a
secondary Cisco Secure ACS as a backup.
Figure 2-1
Small Dial-up Network
In a larger dial-in environment, a single Cisco Secure ACS installation with a
backup may be suitable, too. The suitability of this configuration depends on
network and server access latency.
Figure 2-2
shows an example of a large dial-in
arrangement. In this scenario the addition of a backup Cisco Secure ACS is a
recommended addition.
Network
Cisco Secure
Access Control
Server
63486
Server-based
dial access
PSTN
Modem