Cisco ACS 4.2 Solutions Engine replacement advice

Hi everyone,
I am hoping to get some advice on an upcoming upgrade.  We currently have a Cisco ACS 4.2 Solutions Engine.  (That's the physical appliance).  It is coming to end of support and we are looking to replace.  Here is what we use it for today:
1. TACACS+ AAA for all routers and switches.  Gives us great reporting.
2. PEAP Authentication for our wireless network off of a 5508 Wireless Controller.
3. Machine Access Restrictions for our Wireless network.  (Basically Machine Authentication)
I believe that is all we use it for today.  That said, hoping to get some of your opinions on a replacement.
Any advice or opinions are greatly appreciated.
Thanks,
Josh

Hi Josh,
  To add up to the above post, You will have to undergo the migration process from going to ACS 4.2 to ACS 5.4.
Here is the migration guide:
http://www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_system/5.4/migration/guide/Migration_support.html
Regards
Minakshi
(Do rate the helpful posts )

Similar Messages

  • Cisco ACS 4.2 Solutions Engine replacement

    Hi,
    Our ACS appliance (Cisco 1113) has died and it is not cost effective to get it replaced as it will only be used until the end of this year.
    Is it possible to get the tacacs software to install on a Windows server? How do I go about sourcing the software as the original documentation is no longer available? Will the fact that I have a defunct appliance be sufficient proof to get a copy of the software? We are currently running v4.1
    Thanks.

    Here is a path to download the Eval version of ACS 4.2 windows.
    Cisco.com > Downloads Home > Products >  Security > Access Control and
    Policy > Policy and Access Management > Cisco Secure Access Control
    Server for Windows > Cisco Secure ACS 4.2 for Windows > Secure Access
    Control Server (ACS) for Windows-4.2.0.124 > scroll down to the bottom
    and you will see a file named
    ACS v4.2.0.124 90-Days Evaluation Software
    eval-ACS-4.2.0.124-SW.zip
    Installing ACS on windows
    http://www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_server_for_windows/4.2/installation/guide/windows/install.html
    Once installed you can restore the previous backup on the windows server.
    Restoring ACS from a backup file
    http://www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_server_for_windows/4.2.1/User_Guide/SCBasic.html#wp222758
    Jatin Katyal
    - Do rate helpful posts -

  • Upgrade path for Cisco Secure ACS 4.X Solution Engine 1113 Appliance.

    Hello,
    I am having Cisco Secure ACS 4.X Solution Engine 1113 Appliance, and is running on version Cisco Secure ACS Release 4.1(1) Build 23 and now want to upgarde it to the latest version. Need to know the upgrade path for the same. As per my information ACS 4.1(1) runs on windows server and releases post to 5.X uses Linux. Please guide how can i upgrade Appliance 1113 from 4.1 to 5.x

    Hi,
    Cisco ACS 1113 appliance doesn't support ACS 5.x version. 1113 appliance supports till ACS 4.2.1 version.
    Cisco ACS SE 1120/1121 appliance models are required for ACS 5.x
    The upgrade path for ACS 4.1 to 4.2.1 version can be found in the following link :
    http://www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_server_for_solution_engine/4.2.1/Installation_Guide/solution_engine/upgap.html#wp1237189
    Regards,
    Karthik Chandran
    *kindly rate helpful post*

  • Cisco Secure ACS 4.0 Solution engine problem

    Hi,
    I have a probleme with a Cisco Secure ACS 4.0 Solution Engine (CSACSE-1113-K9).
    I try to power up the engine, but the light in the power button stay blinking all the time. Anyone have a idea why ?
    Last week, I boot it for the first time (It's brand new), every things goes fine.
    I made " shutdown " then wait the message to press 4 seconds power button to turn it off. This morning, nothing come up.
    I see one thing in the console "Press <SpaceBar> to update BIOS." after that, blank. No bios detection, no harddrive dectection, no windows boot.
    Any idea ?
    Thank you

    No, I'm sur.
    Then we have version 1113 of ACS.
    See: http://www.cisco.com/application/pdf/en/us/guest/products/ps6731/c2001/ccmigration_09186a008068f7bd.pdf
    Page 32(1-8) #2.
    I let the engine off about 6hours after my first post, then I try back. The engine start.
    What can cause this problem ?

  • ACS 4.2 Solution Engine - Most current?

    We have two Cisco ACS 1113 4.2 "Solution Engines" running Windows. They are in test. Is this the most current software base for the 1113? My memory is telling me there was a Linux-based version in the works. Is that true? Is that available?

    Thanks! That pretty much ansers my question. ;-) At http://www.cisco.com/go/acs I read:
    "ACS 5.0 currently supports many but not all access scenarios. ACS 4.2 will continue to be available for customers that require it"
    That puts the fear in me that an upgrade may be a requirement in the future - and will involve a complete appliance swap-out. Hopefully the 1113's with 4.2 have a few years in them?

  • ACS 5.2 Solution Engine Patches and Installs

    Hi
    Im trying to upload the 5.2 patches to the ACS Solution Engine so i can install the updates.
    Does anyone know how to do this or know the links that show how to do this??
    The User Guide documentation isnt very helpful.
    Thanks
    Marco

    Hi Marco,
    Here is the link for downloading ACS5.2 patches :
    http://www.cisco.com/cisco/software/release.html?mdfid=283107438&flowid=18604&softwareid=282766937&release=5.2.0.26&relind=AVAILABLE&rellifecycle=&reltype=latest
    Downlaod  any patch  and place in the   FTP/SFTP  server in your enviroment
    Login to the ACS CLI :
    Create a repository:
    acs/admin(config)# repository myrepository
    acs/admin(config-Repository)# url sftp://starwars.test.com/repository/system1
    acs/admin(config-Repository)# user luke password skywalker
    acs/admin(config-Repository)# exit
    after that run this command :
    acs patch install patch-name.tar.gpg repository repository-nameInstalling an ACS patch requires a restart of ACS services.Would you like to continue? yes/no
    once done you can do a sh version and see the acs5.2 with the new patch.
    Also when you download the patch there is also read me with similar instructions.
    Herre is the link for acs5.2 patch 5 read me link :
    http://www.cisco.com/web/software/282766937/37718/Acs-5-2-0-26-5-Readme.txt
    Thanks
    Waris Hussain

  • Adding Users on Cisco Secure ACS Solution Engine 3.3

    We have a large block of userids we need to add to our ACS 3.3 Solution Engine into the CiscoSecure User Database. When using the web-based GUI, it looks like you can only add one user at a time. Is there anyway to add users as a block with some type of command line, or is there a utility that will add users and also copy user options? It would be helpful if in the Add/Edit user panel, there was the ability to copy settings from a previously installed user definition.

    I'm not sure that csutil would setup all the parameters I need, so I would have to choose CSDBSync. Tacacs is used and not Radius. I need the user to initially be configured disabled, specify his/her real name and description, assign the user to a group, assign a PAP password and confirmation, use group settings for callback, client ip address assignment, and max sessions, establish a date to automatically disable the account, provide no enable privileges, and set a Tacacs+ Outbound password.

  • Manage a Cisco Secure ACS Solution Engine?

    Hello,
    how can i manage/observe a 'Cisco Secure ACS Solution Engine'? Ich found no things like SNMP etc.
    regards
    Karsten

    Hi,
    you have no chance to control the ACS SE with snmp. We have one router, access via ACS and uses a script roboter to control the access to the router. If the access fails, we send us an email
    Bye Michael

  • Cisco 5.0 ACS Solution engine

    Hi,
    Just installed and finished intail setup of ACS version 5.0 Sol. engine. Next i'm not able to acces solution engine over internet explorer. Even not able to telnet port 2002.
    Do i need to configure anything else for enabling gui in version 5.0?
    Please assist.
    Thanks!
    Kamal
    [email protected]

    ACS 5.x doesn't work on PORT 2002 like ACS 4.2, it works on https-443 so in order to use ACS 5.x, you should URL
    https://
    To log in to the GUI, you must use the predefined username ACSAdmin and password default. When you access the GUI for the first time, you will be prompted to change the predefined password for the administrator. You can also define access privileges for other administrators who will access the GUI application.
    Rgds, Jatin
    Do rate helpful posts~

  • Cisco Secure Access Control Server Solution Engine OR Cisco Secure Access Server ?

    Which product is really affected, the Cisco Secure Access Control Server Solution Engine which is a hardware applliance with software from 3.2 to 4.2 or the Cisco Secure Access Control Server Software appliance available for installing as a virtual machine into VMware ESX/ESXi 5.0 with 5.X software ?
    Thank you for clarifying
    Best regards
    Marco

    Hi Thomas,
    You can download ACS for windows 4.1 or 4.2 from the below listed link:
    http://www.cisco.com/cgi-bin/tablebuild.pl/acs-win-eval
    For ACS 5.x, please visit cisco.com
    Download software > Security  > Cisco Secure Access Control System 5.x  > Secure Access Control System Software
    HTH
    Regards,
    Jatin
    Plz rate helpful posts-

  • ACS Solution Engine TACACS+ and Radius

    I have an ACS Solutions Engine that is performing TACACS authentication for remote access to Switches and now want to add 802.1X support for port based access control against the ACS server also.  For some reason this is not working for me at all.  Does anyone have a document that will guide me in this.

    http://cisco.biz/en/US/prod/collateral/iosswrel/ps6537/ps6586/ps6638/guide_c07-627531.pdf
    There is a lot of reading on the topic. Maybe you could precise what is not working as expected ?
    what EAP method are you doing ? how is your switchport configured ? Is there an error message on ACS ?

  • Cisco ACS Engine appliance 1120 software upgrade

    I want to upgrade my Cisco ACS Engine appliance 1120 from software version 3.3 to the latest version (5.x). How do I go about this? Someone should help please.

    It is highly suspicious that you would have a 1120 appliance that is running 3.3
    ACS 3.3 was with the ACS solution engine 1111, 1112 and 1113.
    ACS 5 requires the appliance 1120/1121 so it requires an appliance change. I'm puzzled about how you could be running 3.3 for 1120 since there is no installation DVD for that.
    As a general thing, one has to follow the ACS 5 migration guide on cisco.com that explains the process quite well. You need to go to acs 4.1/4.2 to migrate to 5.
    http://www.cisco.com/en/US/partner/docs/net_mgmt/cisco_secure_access_control_system/5.1/user/guide/migrate.html
    Nicolas

  • ACS 1113 Solution Engine console enter CURRENT password

    I have a ACS 1113 Solution Engine, when I plug into console after BIOS bootup sequence I get Enter CURRENT Password:
    We don't have the password, can I download the ACS Recovery CD from CCO? I didn't see the recovery image on CCO.

    CSCsl70457
    Symptom Some ACS 1113 appliances that ship from RMA depots, come with a bootup password of 'acs1113'.
    Conditions Appliance comes with a BIOS Password.
    Workaround On boot, enter the BIOS password of 'acs1113'.
    http://www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_server_for_windows/4.2/release/notes/ACS42_RN.html

  • Maximum users on ACS Solution Engine 3.3

    Hello,
    I need to know the maximum supported number of users in the local database of the CiscoSecure ACS Solution Engine 3.3 (the appliance) ?
    Is there a document about this ?
    Thank you !
    Patrice

    The client version of Mac OS X supports a maximum of 10 AFP clients. It's always been that way.
    If you want more than 10 AFP clients you need to move to Mac OS X Server (unlimited) which can support any number of concurrent users.

  • Extra server on cisco ACS engine

    I'm a bit curious about the way the cisco ACS engine (the cisco-built hardware) sets up servers initially. Most of the documentation I have is for windows, so I was a bit confused when, after the initial configuration there were two "AAA Servers" shown in the configuration, one called "Self" with the IP address I defined, and the other with the name I defined and a different address.
    Has anyone else encountered this? Will it cause problems? and is there a way to get rid of it?
    Thanks

    That is a known issue with acs appliance, but nothing to worry about. Make sure you have this setting in acs,
    acs--->network configuration--->Proxy dis table---> Bring Deleverance1 in the fwd to box and your server name in the left box.
    Incase you dont see proxy dis table , then you need to enable it
    Interface configuration---> Advance option ---> Put a check in distribution table.
    Regards,
    ~JG
    Please do rate helpful posts

Maybe you are looking for