Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Failover issue in clear pass?

This thread has been viewed 1 times
  • 1.  Failover issue in clear pass?

    Posted Aug 25, 2014 07:00 AM
    Now I have configure VIP between the 2 nodes and my publisher failed and the subscriber became publisher but when the old publisher returned back online it remain subscriber? What causes this issue


  • 2.  RE: Failover issue in clear pass?

    EMPLOYEE
    Posted Aug 25, 2014 09:00 AM

    This is as expected.  Please see these steps to re-join a failed publisher to the cluster. 

     

    1. Original Publisher becomes reachable. A message is shown to the logged in user:
    image001.png


    Suppose a VIP is configured between Original publisher and standby publisher/other subscriber nodes, with Primary node as Original Publisher, then VIP is not released to this Node.

    2. Drop the subscriber nodes (Remove VIP and Standby Publisher settings if configured for that subscriber node). This takes few seconds for each of the node.  Ex: It takes nearly 20sec (in our test bed.. may be a max of 1min) for each of the nodes to get dropped. We should see the following error as well "ERROR - A.A.A.A: - Ignore drop node request from unknown publisher".


    NOTE: Drop subscriber will not work if there are warnings, while dropping nodes, that are participating in Standby publisher operation or any VIP config. Please remove the same and perform Drop subscriber..

    3. Refresh the Original publisher after dropping the subscriber nodes, and revisit Server Configuration screen [Administration » Server Manager » Server Configuration] to join this node to the cluster. Make subscriber operation starts here.

    4. Original publisher is added back to the cluster as subscriber.

     



  • 3.  RE: Failover issue in clear pass?

    Posted Aug 25, 2014 09:39 AM

    Thank you for your replayI know that  but my issue is to make thr faild publisher became publishr again when it is back online (Automatically) can I achive this?



  • 4.  RE: Failover issue in clear pass?

    EMPLOYEE
    Posted Aug 25, 2014 09:44 AM
    This is not possible today