Thanks once again for uploading this video! I got a quick question/request : Would you be able to demonstrate on how do we make subscriber a standby publisher so in circumtances when currently active publisher fails, the standby publlisher promotes itself as new active publisher? Many Thanks, Mehul Patel
@AirheadsBroadcasting7 жыл бұрын
Let me see if I can create a video on publisher failover, however, I think I'd like to get other videos in the series out before. If you want to check out yourself, go into the Server Configuration (Administration » Server Manager » Server Configuration) to the Cluster-Wide Parameters, then to the Standby Publisher tab. There you can enable the automatic failover and select a designated standby publisher.
@jzeeee4 жыл бұрын
Excellent
@satheeshkumar37556 ай бұрын
Hi Herman, Just to check with you can Publisher and subscribers run in different firmware version
@hermanrobers6 ай бұрын
No, publisher and subscribers should run the same software version. During an upgrade, that temporarily is not the case, and subscribers will run standalone as long as their version does not match the publisher, and (seamlessly) sync again as soon versions match.
@satheeshkumar37556 ай бұрын
@hermanrobers Noted with thanks Herman. As we are planning to upgrade from 6.9 to 6.11. Is there any order to follow upgrade as we have many subscribers and publisher
@hermanrobers6 ай бұрын
@@satheeshkumar3755 The 6.11 'upgrade' is basically a reinstall. First reinstall your subscriber as otherwise you can't really reinstall your subscribers. If your publisher is a VM, I would install the new publisher in parallel, so you can still manager your 6.9 cluster from the original subscriber. If you are in doubt, it may be best to work with your Aruba partner and/or support to plan your upgrade.
@satheeshkumar37556 ай бұрын
Noted with thanks Herman👍👍👍
@xximpxx5 жыл бұрын
Thank you very much. This has been very helpful.
@MartinVisser7 жыл бұрын
Small correction (if someone was confused) at 1:25 you mentioned you were joining the domain, but of course you meant you were joining the cluster.
@hermanrobers6 жыл бұрын
Thanks for that. Unfortunately, I cannot edit the video and upload it again to change that. Hope this note will take care of the confusion.
@ratao199811 ай бұрын
Herman, how are you? Today I only have one clearpass working. And now I'm going to add another 3 in different subnets, but they talk to each other. I would like 1/3 to be my new publisher. How should I proceed with this so that I still maintain the same settings I have running today?
@chanceschraeder24564 жыл бұрын
Great stuff!
@sureshhkumar9555 жыл бұрын
how server speaks within themselves and how zone wise , load balancing will work...
@hermanrobers5 жыл бұрын
That can be pretty technical. High-level there are database syncs between publisher and subscribers and you load balance your switches, controllers, APs manually over the available cluster nodes. The more detailed technical story is in the CPPM TechNote - Clustering Design Guidelines v1.2, which can be found at support.arubanetworks.com/Documentation/tabid/77/DMXModule/512/EntryId/33093/Default.aspx
@haoyang49363 жыл бұрын
hi, Robert how many subscribers supported ?
@hermanrobers3 жыл бұрын
I think the official number is 30. It depends a bit on the load though, and how you use zones to reduce the synchronization load between the different nodes. If you plan to deploy more than a few subscribers, it may be good to work with your partner/Aruba SE as they can assist in optimizing your cluster.
@ibrahimsawy6 жыл бұрын
if we have only 2 clearpass and i want to operate it in main and backup setup, considering that we are configuring url redirection on aruba WLC to redirect the guest to registration page of the clearpass. will published/subscriber with configuring virtual ip address will achieve our need without using external load balancing node?
@hermanrobers6 жыл бұрын
If your ClearPass servers are in the same (L2) subnet, and you can use a virtual IP, yes that can be used for redundancy. If your ClearPass servers are in different sites, and you have either L3 (routed) or limited bandwidth, it may be better to use network or DNS load balancers.
@bootcd Жыл бұрын
How did you create a subscriber without a certificate? Do I need a certificate if I have a Publisher cluster and want to implement a new subscriber custer?
@hermanrobers Жыл бұрын
There is an updated video on this topic: kzbin.info/www/bejne/r4a3i5Z6rMZ4rK8 . To answer the question, it's recommended to have your certificates properly setup on the publisher before joining a subscriber; you can then through the publisher manage the certificates for the subscriber. No need to have a cert on the subscriber before joining, but it will be retained if you have it installed already.
@mattsimeone466 жыл бұрын
I've got four CPPM servers in a cluster in the same subnet. Would a Virtual IP be the recommended configuration and to point the NADs to this VIP?
@hermanrobers6 жыл бұрын
It depends on your architecture and intended use. If you have 4 equal ClearPass servers, the preferred method is to use an external Network Load Balancer (NLB) with service checks to offer a single ClearPass IP to the network. If you don't have that, I would create indeed 4 VIPs on 1-2 2-3 3-4 4-1 and point your network equipment to two of them that don't share the same appliances. In that case you have the VIP for fast failover if an appliance fails, and the fallback RADIUS in case a cluster fails. With a NLB, all redundancy is arranged in there. There is a TechNote on how to use F5 LTM for that purpose, if you have a different load balancer, the high level steps will probably be similar.
@noreenchannel4444 жыл бұрын
How to setup ip for another interface which connected to router?
@hermanrobers4 жыл бұрын
I'm not sure what you are trying to achieve. I would recommend to stay away from using multiple interfaces on ClearPass. In order to reach subscribers to reach the publisher, just set up IP connectivity through the default gateway of the management network. Don't use the data interface, just management. If you really can't avoid using the data interface, read carefully and understand the ClearPass Services Routing Technote. If your question is not answered, can you try to explain in different wording what you try to do?