[ Pobierz całość w formacie PDF ]
Step 2 Log onto the primary Cisco NAM console and ping the Ethernet 0 interface on the
secondary Cisco NAM: 172.16.1.13.
Note For more configuration information, see the Cisco NAC Appliance Cabling table located in
Appendix A of this document.
Activity Verification
You have completed this task when you attain this result:
The output confirms that the line is operational, that the correct protocol has been used, and
that this line is in the same VLAN as the Ethernet 0 interface on the primary Cisco NAM.
Task 2: Export an SSL Private Key and an SSL Temporary
Certificate
In this task, you will export an SSL private key and an SSL temporary certificate for the
secondary Cisco NAM to use.
Activity Procedure
Complete these steps:
Step 1 Open the Cisco NAM administration console for the primary Cisco NAM.
Step 2 Choose Administration > CCA Manager > SSL Certificate.
Step 3 Choose Export CSR/Private Key/Certificate from the Choose an Action drop-
down menu.
Step 4 Click the Export button next to the Currently Installed Private Key field to export
the SSL private key.
Step 5 Save the key file to the desktop on the manager machine.
Step 6 Click the Export button next to the Currently Installed Certificate field to export the
SSL temporary certificate key.
Step 7 Save the certificate file to the desktop on the manager machine.
Activity Verification
You have completed this task when you attain this result:
The task completes with no warnings.
Task 3: Configure the Primary Cisco NAM Network and Failover
Settings
In this task, you will configure the primary network and failover settings of the primary Cisco
NAM.
Activity Procedure
Complete these steps:
Step 1 Go to the Administration > CCA Manager > Network & Failover tab.
Step 2 Select the HA-Primary option from the High-Availability Mode drop-down menu.
Step 3 Copy the value in the IP Address field that is under Network Settings and paste it
into the Service IP Address field found in the Failover Settings column.
36 Implementing Cisco NAC Appliance (CANAC) v2.1 © 2007 Cisco Systems, Inc.
The PDF files and any printed representation for this material are the property of Cisco Systems, Inc.,
for the sole use by Cisco employees for personal study. The files or printed representations may not be
used in commercial training, and may not be distributed for purposes other than individual self-study.
Step 4 Change the IP address under the Network Settings column to the IP address assigned
to the Primary Cisco NAM of your pod. For example:
172.16.1.12
Step 5 Enter the hostname of the primary Cisco NAM in the Host Name field under
Network Settings.
Step 6 Enter the hostname of the secondary Cisco NAM in the Peer Host Name field in the
Failover Settings column.
Caution The Host Name and Peer Host Name fields are case-sensitive. You will need to enter the
exact primary Cisco NAM hostname when you configure the secondary Cisco NAM.
Step 7 Enter 10.100.100 for the crossover network field.
Step 8 Click the Update button to update the database on the primary Cisco NAM.
Step 9 Click the Reboot button to enable the changes on the primary Cisco NAM.
Activity Verification
You have completed this task when you attain this result:
The task completes with no warnings.
Task 4: Import an SSL Private Key and an SSL Temporary
Certificate into the Secondary Cisco NAM
In this task, you will import an SSL private key and an SSL temporary certificate into the
secondary Cisco NAM.
Activity Procedure
Complete these steps:
Step 1 Open the Cisco NAM administrator console for the secondary Cisco NAM.
Step 2 Click the Yes button on all Security Alert dialog boxes. This includes accepting the
Cisco NAM temporary certificate. The Cisco NAM license key web page should
open.
Step 3 In the PAK section of the window, click the Browse button and navigate to where
your instructor has put the license keys for your pod
Step 4 Enter the high-availability (failover) license key for your pod in the Enter Product
License field.
Tip Your instructor will provide you with the license keys.
Step 5 Click the Yes button on all Security Alert dialog boxes that appear. This includes
accepting the Cisco NAM temporary certificate. The Cisco NAM web-based
administration console should open.
Step 6 In the SSL Certificate tab, choose Import Certificate from the Choose an Action
drop-down menu.
[ Pobierz całość w formacie PDF ]