Security

last person joined: 5 hours ago 

Enterprise security using ClearPass Policy Management, ClearPass Security Exchange, IntroSpect, VIA, 360 Security Exchange, Extensions and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Cluster with two geographic locations?

  • 1.  Cluster with two geographic locations?

    Posted Oct 25, 2018 04:54 AM

    Hi there,

     

    I have two different locations that are connected by a VPN link.

    I want both locations to work even if the other side goes down.

    I'm unsure what should I do?

     

    # Publisher + Subscriber?

    Will subscriber authenticate users when publisher is down?

    Will OnGuard work? (requires health to be written to db?)

    Will [Machine Authenticated] work for new machines? (requires role to be written to db?)

     

    # Publisher + Standby Publisher?

    if the link goes down, both Publishers will become active. What happens when the link goes up again?

    Can I do automatic failback so that after the link comes up the promoted publisher gets back to standby?

     

    Another related question: 

    Will data that I insert to the database using appexternal also get replicated from Publisher to Subscribers?

     

    Thanks



  • 2.  RE: Cluster with two geographic locations?

    Posted Oct 26, 2018 11:57 AM

    Related:

     

    - Is it possible to have centralized accounting on the Publisher?

     

    Thanks



  • 3.  RE: Cluster with two geographic locations?

    Posted Oct 27, 2018 03:40 PM

    This interests me too. We have two separate locations too so can't have virtual IP for Clearpass servers.

    Wondering also if I should relay DHCP to both servers or will it mess up the profiling?



  • 4.  RE: Cluster with two geographic locations?

    Posted Nov 01, 2018 09:32 PM

    Hi,

     

    Please take a read of the following document.

    CPPM TechNote - Clustering Design Guidelines v1.2

     

    This should help you out with the information you are looking for.

     

    thanks,