Cisco Cisco Clean Access 3.5

Seite von 196
 
12-8
Cisco Clean Access Server Installation and Administration Guide
OL-7045-01
Chapter 12      Implement High Availability (HA) Mode
Configure High Availability
  –
[Standby] Peer MAC Address (untrusted-side interface): This is the peer MAC address from 
the untrusted (eth1) side of the standby CAS. 
  –
Heartbeat UDP Interface: Options are N/A, eth0, eth2, eth3, eth4. If a dedicated Ethernet 
connection is not available, it is recommended to use eth0 for the Heartbeat UDP interface when 
configuring a Clean Access Server in HA mode.
  –
[Standby] Heartbeat IP Address: The IP address of the trusted interface (eth0) of the standby 
CAS (in the sample, 172.16.1.3). 
Note
Prior to 3.5.4, the “[Standby] Heartbeat IP Address” field was called “[Standby] Peer IP 
Address.”
  –
Heartbeat Serial Interface: Select the COM port for the serial connection. It is recommended 
to use both serial and UDP connections for the Heartbeat interface.
  –
Heartbeat Timeout (seconds): Choose a value greater than 10 seconds. 
  –
Enable Serial Login: Serial login is disabled by default when HA mode is selected. To 
re-enable the serial console (ttyS0), click the Enable button at this stage (after Update and 
before Reboot).
  –
Update: Click to update the HA configuration information for the CAS without rebooting it.
  –
Reboot: This is used to reboot the CAS at the end of HA-Primary CAS configuration. (Do not 
click Reboot at this point.)
d. Configure the SSL Certificate
7.
Now configure the SSL certificate for the primary CAS. Click the SSL Certificate link from the 
Administration menu. The Generate Temporary Certificate form appears.