4-33
Cisco NAC Appliance Hardware Installation Guide
OL-20326-01
Chapter 4 Configuring High Availability (HA)
Installing a Clean Access Server High Availability Pair
8.
Perform one of the following procedures, depending on whether you intend to use a temporary,
self-signed certificate or a CA-signed certificate:
If using a temporary certificate for the HA pair:
a.
Click
Generate Temporary Certificate
, enter information for all of the fields in the form, and
click
Generate
. The certificate must be associated with the Service IP addresses of the HA pair.
b.
When finished generating the temporary certificate, click the checkboxes for the certificate and
Private Key to highlight them in the table.
c.
Click
Export
to save the certificate and Private Key to your local machine. You must import the
certificate and Private Key later when configuring the HA-Secondary CAS.
If using a CA-signed certificate for the HA pair:
Note
This process assumes you have already generated a Certificate Signing Request and accompanying
Private Key, submitted the request to your Certificate Authority, and have received your CA-signed
certificate. If you have not yet obtained a CA-signed certificate for the CAS, be sure to follow the
instructions in the “Manage CAS SSL Certificates” section of the
Cisco NAC Appliance - Clean Access
Server Configuration Guide, Release 4.8(3)
.
a.
Click
Browse
and navigate to the directory on your local machine containing the CA-signed
certificate and Private Key.
b.
Click
Import
. Note that you will need to import the same certificate later to the HA-Secondary
CAS.
Note
The CA-signed certificate must either be based on the Service IP or a host name/domain name resolvable
to the Service IP through DNS.
e. Reboot the HA-Primary CAS
9.
Reboot
the Clean Access Server from either the CAS direct access interface (
Network Settings >
Failover > General > Reboot
button) or from the CAM web console (
Administration > CCA
Manager > Network > Reboot
button).
f. Add the CAS to the CAM Using the Service IP
10.
In the CAM web console, go to
Device Management > CCA Servers > New Server
, and add the
CAS to the CAM using the Service IP for the pair (10.201.2.112) as the
Server IP
address.
11.
Configure any other settings desired, such as DHCP settings, to control the runtime behavior of the
CAS.
12.
Test the configuration by trying to log into the untrusted (managed) network from a computer
connected to the untrusted interface of the Clean Access Server. Proceed to the next step only if you
can successfully access the network.
Содержание NAC-3310
Страница 8: ...Contents 6 Cisco NAC Appliance Hardware Installation Guide OL 20326 01 ...
Страница 172: ...A 4 Cisco NAC Appliance Hardware Installation Guide OL 20326 01 Appendix A Open Source License Acknowledgements Notices ...
Страница 176: ...Index IN 4 Cisco NAC Appliance Hardware Installation Guide OL 20326 01 ...