ACS Server hardware build for NAC/TACACS deployment

Hi,
We are in the pilot stage of a NAC v2 Framework rollout for our 4000 seat network and have funding available to purchase a high spec server to be deployed as the primary ACS box. The server will also handle our TACACS requirements for accessing network devices. I know I could simply go with the Cisco recommended build, however with a view to the future of managing NAC requests for 4000 PCs, I am keen to over spec the box where this would be useful. I have options to increase RAM, Processors and Disk configuration. Which of these will be advantageous?
Cheers, SteveK.

Enforce your organization's security policies on all devices seeking network access. Cisco Network Admission Control (NAC) allows only compliant and trusted endpoint devices, such as PCs, servers, and PDAs, onto the network, restricting the access of noncompliant devices and thereby limiting the potential damage from emerging security threats and risks. Cisco NAC gives organizations a powerful, roles-based method of preventing unauthorized access and improving network resiliencyhttp://www.cisco.com/en/US/products/sw/secursw/ps2086/index.html.

Similar Messages

  • How to Custom Report using sql server report builder for SCCM 2012 SP1

    Hi ,
    I am new to database, if i want to create a manual report using sql server report builder for SCCM 2012 SP1, what step should i take.
    i want to create a report in which computer name, total disk space, physical disk serial no come together. i already added class (physical disk serial no.) in hardware inventory classes. refer snapshot

    Hi,
    Here is a guide on how to create custom reports in Configuration Manager 2012, it is a great place to start, change to the data you want to display instead.
    http://sccmgeekdiary.wordpress.com/2012/10/29/sccm-2012-reporting-for-dummies-creating-your-own-ssrs-reports/
    Regards,
    Jörgen
    -- My System Center blog ccmexec.com -- Twitter
    @ccmexec

  • Hardware Build for CS6 Production Premium

    First: Thank you for all of the information in this forum. I've done a bunch of reading and there is lots of good information about a many issues.
    Second: I am looking for advice on a build for CS6 Production Premium. I don't want top of the line, but a decent midgrade setup. I've done a bunch of reading and I think that I have a reasonable system, but would appreciate some advice. The last time I built a computer was the 1990s when we still had to set DMA and IRQ channels, so I'm a bit rusty.
    Case: Cooler Master Cosmos II Ultra Tower RC-1200-KKN1
    Motherboard: Asus Z9PE-D8 WS Dual LGA 2011 Intel C602
    Two - Intel Xeon E5-2630 V2 Ivy Bridge 2.6GHz six core processors.
    Two - Intel STS200C CPU heat sinks.
    240 Pin 1600 MHz DDR 3 RAM. 16 GB adequate or 32 GB for a good balance on this system? (Don't really want to goto 64GB, but will if necessary.) Is it better to fill all 8 slots on the mother board or better to have more GB per card and run with 4 empty slots on the mother board?
    Crucial M4 256GB SSD SATA boot disk CT256M4SSD2.
    Six: 2 TB 7200 RPM SATA 6Gb/S Seagate Barracuda ST2000DM001 hard drives in a RAID 3 configuration with five drives in service and one in standby. (The SSD plugged into the 6GB/s SATA plug and the six 2TB plugged into the C602 SATA 3GB/S plugs? Nothing plugged into the Marvell SATA plugs?
    The mother board doesn't support RAID 3 and I have no RAID experience, so I'm guessing that I need a dedicated RAID controller for this? If so, is an Areca ARC-1224-8I a good fit, or is there a better choice?
    Pioneer BDR-2208 blu-ray burner.
    Rosewill 1300 watt 80 plus gold power supply.
    Soundblaster ZxR PCIe sound card.
    Windows 7 Professional Service Pack 1
    Two - Dell UltraSharp U2413 24" LED LCD monitors.
    Now the $3 question: Video card(s). Is a single GeForce GTX690 adequate to run the various applications in Production Premium? A GTX Titan? Quadro K4000? I don't really want to go to the Quadro K5000, but will if forced.
    The only software on the computer will be Windows 7, Adobe CS6, and either McAfee or Norton, along with whatever drivers are needed for the systems. I'll stay away from quicktime as it seems to gum up the works according to some advisers on this forum.
    Is there anything that I am missing, hardware wise or installation pointers?
    Thank you for any assistance!

    I am considering a similar build for heavy Photoshop and Lightroom use.  Currently on and older i7-1358 pin 3.0Ghz XEON cpu, I'm considering either a new i7-4930 or dual Xeons as you are. The reason for the Xeons is ability to use ECC memory and add more cores.  This is a production system in daily use so I'd probably not be overclocking.
    Interested in your and others views on this. Previous to my current system, I'v always had dual socket Pentiums, Athalons or Opterons, someof which are still in service but in a reduced roll.
    I typically use fast drives, some SAS, 15K & 10K (SSDs now where it makes sense) and RAID where necessary, especially for SWAP drives in Photoshop along with lots of memory..
    Thanks for any input here.  Basically ECC vs non ECC (I know there is a speed hit with ECC, but really - how much?).  Overclock (i7-4930) or non overclocking (Xeons)
    I should also mention, Culch, that I am considering the same CPUs and MB as you.
    Thanks for reading.
    Doug A

  • Using LabVIEW RTE vs. LabVIEW ActiveX Automation Server (TestStand LVRTS) for a TestStand Deployment and experience​ing Unabel to Launch LabVIEW.Ap​plication ActiveX Automation Server Error 18001

    I am developing in TestStand 4.2.1 and LabVIEW 2009, I have accomplished the following:
    1. Deployment package is built and deployed on PC
    2. PC has activated TestStand Deployment License
    3. LabVIEW 2009 RTE was selected as the adapter for the sequence and thus I believe the deployed testexec.ini contains this.
    I  am experiencing the following error: "see attachment".
    Is the LabVIEW RTE the right selection?
    Is there something I may have missed in building the deployment?
    Do I need to register the ActiveX server.
    THere seems to be conflicing solutions based on Version of TestStand and LabVIEW!!
    Thanks!!
    Attachments:
    TS_LV ActiveX Error.doc ‏77 KB

    Howdy mobiux,
    Please consider KnowledgeBase 4V58058Z: -18001 Errors in TestStand. If you're using Vista or Windows 7, then this may apply as well. You might also consider ensuring you have the proper LV version active in the TS Adapter Options.
    Warm regards,
    pBerg

  • Care to share your server/hardware config for Spatial?

    Hi there - we're in the early stages of planning for a new spatial system (geocoding a large volume of existing address data), and we'd like to get a sense of what different organisations might be using by way of server architecture for a high-availability, large volume dataset GIS where your typical spatial query is a within-polygon or buffer-type search of geocoded address data, and you might need to support several thousand of these per hour... (for example).
    Would you share your platform/CPU/OS/memory/storage config comments as they relate to a dedicated Oracle Spatial 10g DBMS?
    Or perhaps just suggest what you had to do in addition to the baseline 10gDBMS requirements to give Spatial room to perform well...
    Any comments are accepted with humble thanks.
    Kind regards
    Dennis

    Dennis,
    Several thousand, say 3000 per hour is less than one a second. I'm not sure how much data you have (define large), but in general I'd try to keep all, or most of the data in RAM to get the best performance possible. A Linux box with say, 512GB of RAM is entirely resonable to use. If your seach patter is geographicly time sensitive (moves based on time of day), you could also effectively use partition prunning to reduce the amount of data to be searched.
    This is will give you a single, fast, db. For HA you need at least two, depending on what you define HA as.
    Bryan

  • Need hardware configuration for server

    Hi All,
    Need server hardware configuration for deploying and maintaining SSAS cube. Consider OLTP size as 100 GB
    Thanks,
    ATRSAMS

    Hi Atrsams,
    According to your description, you need some hardware recommendations for deploying and maintaining a SQL Server Analysis Services cube, right?
    Though this isn't a sizing recommendation, I'd encourage you to buy as much memory as you can afford. This is generally the choke point I've seen on servers, especially when using SSAS. For the detail information about it, please refer to the links below.
    http://sqlblog.com/blogs/marco_russo/archive/2013/02/12/hardware-sizing-guide-for-ssas-tabular.aspx
    http://www.experts-exchange.com/Hardware/Microsoft_Hardware/Q_27781248.html
    Regards,
    Charlie Liao
    TechNet Community Support

  • JBOD controller for iSCSI storage server DIY build

    Hi,
    I'm starting planning of an iSCSI storage server DIY build for my LAB setup to provide iSCSI CSV storage to my LAB Hyper-V cluster.
    I'm looking for a JBOD controller that i can use without any additional RAID controller as i will be using storage spaces for "RAID". I will be using SATA drives and SFF8087 to SATA fan-out cables.
    What cheap cards can i use for this (looking on ebay/amazon)?
    This posting is provided "AS IS" with no warranties or guarantees and confers no rights

    Hi Sir,
    >>I'm starting planning of an iSCSI storage server DIY build for my LAB setup to provide iSCSI CSV storage to my LAB Hyper-V cluster.
    In my lab , I used 3 disks one for OS the other two were used for storage space then I created a mirrored disk for ISCSI CSV storage (it works well for my two nodes cluster LAB).
    Actually , it depends on your need to choose  raid configuration and hardware card .
    Best Regards
    Elton Ji
    We
    are trying to better understand customer views on social support experience, so your participation in this
    interview project would be greatly appreciated if you have time.
    Thanks for helping make community forums a great place.

  • Migrating server hardware replacement oes11 to oes11sp2

    This summer I will be replacing server hardware at one of my schools. Currently it has sles11sp1 / oes11 -- put in in 2012. The patches are up to date for this version, but I have not upgraded/migrated it to a newer version yet. I have played in a test environment with the yast2 wagon migration from sles11sp1/oes11 to sles11sp2/oes11sp1 -- no problems. However trying to find notes on how to do a migration and identity transfer from source server hardware to new target server hardware. Found oes11sp2 migration tool administration guide. I haven't found anything telling me how to setup sles on the target server box ie server name etc. Once I have the target sles server setup, I realize I need to install OES and select the "Novell pre-migration server" option during this installation.
    Current source server = sles11sp1/oes11 and has iPrint, Nss and netstorage installed. Installed in tree with oes11 and oes11sp1 servers.
    The main tree server has sles11sp2/oes11sp1 on it. We will need to upgrade it to sles11sp3/oes11sp2 this summer. I'm fine with doing the yast2 wagon migration on that server. We just haven't done server hardware replacements for OES-L yet.
    Looking for some good (step by step) instructions. ;-)
    Thanks
    Patty

    Originally Posted by amdsbnovell
    Thanks Thomas. Just printed the document now. If my current sles11sp1/oes11 server is called testfs for instance, then I need to install the new target server as a sles11sp3 server called tempfs. Then install oes11sp2 into the tree in a temporary location in the tree as a premigration server (for the installation). Then I should be able to follow the instructions. When I do the identity transfer, I'm assuming it renames the sles11sp3 server from tempfs to testfs as well (as that is where oes gets the file server name from)?
    Um, sorta. Let's pretend your server name is: OLD and the new one is NEW (temporary NEW name and temporary NEW IP)
    OLD: OES11
    NEW: OES11 SP2 (assuming you want latest stuff).
    Do all your data transfer/consolidations/etc
    Then when you do the ID transfer, it will literally transfer the eDir databases (well copy is more correct) from OLD to NEW, you shut off OLD, I think it restarts NEW and renames/changes the servername and IP to what OLD had.
    You can choose to install the NEW server with the .ISO separately (ie: Install SLES11 SP3, then after you're done, Add On the OES11 SP2 .ISO), or you may choose to use the integrated DVD and do it all at once, or use the 2 separate ISO and do them at once (but depending upon your installation method, you may not be able to do the 2 separate ISO).
    I hope that helps.
    I'm about halfway through editing my docs for OES11 SP1 (of course, SP2 is out now) for migrations from OES2 SP3, but the same setup steps basically apply. I think the only things that changed from NW To OES (ie: OES2 to OES11) are DHCP and iPrint migration procedures.
    --Kevin

  • Server & Desktop Setup for a New IT Organisation

    Hello Team,
    I got opportunity to IT setup of a new Organization which is also IT based so can anyone Guide  me which Microsoft server version(Professional or Enterprise or any other) is need to choose & which hardware Firewall is the best.
    Requirements are as below,
    1.DC,DNS & DHCP
    2.Exchange Server
    3.Application Server
    4.File Server
    5.Hardware Firewall
    Please suggest the Best Desktop Server Hardware Configuration for HYPER-V Server.
    Thanks In Advance

    Hello Team,
    I got opportunity to IT setup of a new Organization which is also IT based so can anyone Guide  me which Microsoft server version(Professional or Enterprise or any other) is need to choose & which hardware Firewall is the best.
    Requirements are as below,
    1.DC,DNS & DHCP
    2.Exchange Server
    3.Application Server
    4.File Server
    5.Hardware Firewall
    Please suggest the Best Desktop Server Hardware Configuration for HYPER-V Server.
    Thanks In Advance

  • ACS Server MAC Authentication with Windows Database

    Has anyone setup an ACS Server 3.2 for MAC authentication using Windows as the authentication. The documentation I found shows how to set it up using the CiscoSecure database. Any help would be appreciated.

    Here is the link for setting up MAC authentication using CisoSecure database. There may not be a solution for my setup, but maybe I'll keep hacking away at it and find a resolution.
    http://www.cisco.com/en/US/products/hw/wireless/ps430/products_white_paper09186a00800b3d27.shtml

  • With Cisco Secure ACS For Windows TACACS+, authentication fails with AD

      I am setting up a Cisco Secure ACS 4.2 server to act as a TACACS server for Switches and Routers  I am using Windows 2003 server for the ACS,
    and a Windows 2003 Active Directory server.  The AD server is fine, as it is used for many other things.
    I have set up ACS as defined nit he installation guide, including all the steps in the 'Member Server' section of the install guide
    when using AD as an external database (i.e. setting up the services to run with a domain admin account, setting up a machine called 'CISCO'
    on the domain etc).
    I've set the unknown user policy to use the Windows database if the internal database doesn;t contain the user details.
    If I add a user to the internal database, the authentication goes through fine, with an entry in the 'Passed Authentications' log,
    02/24/2010,05:07:03,Authen failed,eXXXX,Network Administrators(NDG) ,X.X.X.X,(Default),Internal error,,(geting error message as INternal Error)
    I've scoured google etc, and just cannot come up with any reason why this should be happening.
      I've followed all the install guides to the letter.  I need to get this up and running as soon as possible,
    so am looking forward to finding out if anyone can help me with this one!
    THanks and regards
    Sharan

    Hi  Jesse,
    Thasts a great answer and Soution.
    My previous version was 4.2 and it was installed on 64 bit machine hence getting internal Error.
    After this answer i have upgraded it to ACS4.2.1 and its started working fine
    Thanks very much for the help
    Dipu

  • Hardware Config for MI server!

    Hi All,
    I need information regarding the hardware configuration for the MI server which should deploy SAP Netweaver Mobile 7.1 and support xMAU 3.0 SP5.
    Can anyone throw some light on this.
    Thanks in advance!
    Kanwar

    Hi Kanwar,
    Check this link in SMP for MAU specific information.
    https://websmp105.sap-ag.de/~form/sapnet?_SCENARIO=01100035870000000202&_SHORTKEY=01100035870000694050
    For general MI queries, please check the MI FAQ section https://www.sdn.sap.com/irj/servlet/prt/portal/prtroot/docs/library/uuid/cc489997-0901-0010-b3a3-c27a7208e20a
    Regards
    Ajith

  • ACS server with NAC feature

    Hi,
    I have ACS 3.3 version and i have seen the it has network admission control feature in it. I have cisco switches 3750G and windows servers 2003. Currently i am running machine/user authentication over EAP-PEAP and it seems running ok in my network. I have now a new requirement. we want to authorize the machine only when the machine has latest antivirus running on it. we have symantic antivirus on our machines.
    I am new to network admission control and don't know much.
    Can i do it with cisco ACS server? is we have to buy any equipment/software to accomplish this?  your help in this matter will be highly appriciated.
    Regards

    This is called NAC framework, and as far as I know this might be possible but you might find some limitations, see the following link for guides:
    http://www.cisco.com/en/US/netsol/ns617/networking_solutions_sub_solution_home.html
    On the other hand the current NAC solution "Cisco Clean Access" Will allow you to play with it as desired, see:
    http://www.cisco.com/en/US/prod/collateral/vpndevc/ps5707/ps8418/ps6128/product_data_sheet0900aecd802da1b5.html
    hth
    Ivan

  • Antivirus deployment on ACS server

    Hi All,
    We have Kaspersky total Space Security with version 6.0.4.1424 for Windows server and we need to deploy it on ACS server (version 4.2 on windows 2000) so I need to know if it will negatively affect the performance or the functionality of ACS??
    Thanks in advance!

    can anyone help me please?1

  • Recommended Hardware Config for huge OLAP Cube build

    Hi David ,
    Can you please provide the recommended hardware config for cube having billions of data under fact table . We ran a cube with 0.1 billion of data took around 7 hours to process. What could be the key areas to gain the performance benefit ? ansd also what could be the CPU , RAM (server) , RAM (Oracle DB) to gain much more perf benefit in such configurations ?
    Also we have 32 bit windows 2003 server .Can we get better result if we switch to 64 bit ?
    Thanks in advance,
    DxP.

    Hi!
    Well, I would definitely recommend you to proceed with a consultant because I feel that you have some lack of methodology and experience together with time constraints for your project.
    Regarding hardware, unfortunately, I would not be able to give you any precise figures because I have no supporting information. What you should bear in mind that your system must be balanced. You (better with consultant) need to find a right balance between all the factors you consider as important while building a pile of hardware:
    - cost
    - architecture
    - speed
    - availability
    - load scenarios
    etc...
    Regarding architecture point bear in mind that today finding right balance between processing power and storage processing capacity is a challenge. Put attention to this.
    Regards,
    Kirill

Maybe you are looking for

  • A field of the table in sql server db can't be updated with the db adapter

    Hi all, I am using db adapter to update data in bpel. The database is sql server. But on the running time, i find a field which named 'JDBCT1' can't be updated. all the other fields of this table can be updated properly. For the operation type, i hav

  • Screenshot copyright question?

    I have no idea what forum I'd ask this question, so if my question can't be answered here, please advise where to post. I'd like to put a screenshot of a Numbers spreadsheet on my website to demo something, but I don't know if there are any copyright

  • Creating a new trasport request

    Hi, When we are making changes to a program/report when to create a new request and when should we save in the same request? Does it make any difference? Thanks, Kaavya

  • Any recommendations for A3 colour  printer for small studio?

    Need a printer to do A3 or A3+ printouts for client mockups in small studio. Can anyone recommend one? Needs to be networked with 3 people using it.

  • Key Event Windows dialog box

    I have executed a windows program using Runtime = Runtime.getRuntime( ); Process proc = rt.exec(command);However the program brings up an " an ok message dialog box" which needs click in order for the program to run. I have used the Robot class to si