HP (Hewlett-Packard) 700wl Series Switch User Manual


 
Using the 700wl Series System
Figure 2-12. Access Controller Redirect Page
Enterprise Class Redundancy
The 700wl Series system supports Access Control Server redundancy and failover. Access Control
Server failover provides high availability operation for clients in case of system outages, network
failures, or other disruptions. The primary Access Control Server functions as a normal Access Control
Server, servicing the connected Access Controllers’ requests for authentication, rights administration,
and other functions. The redundant Access Control Server is synchronized with the primary Access
Control Server through a combination of database replication, message and state replication, and
configuration replication, and is kept synchronized via incremental SQL updates.
To set up a redundant Access Control Server, the following is required:
Two peer Access Control Servers, each running version 4.0 or later software, must exist on the
network and be mutually reachable. Integrated Access Managers cannot be used as redundant
peers.
One of these Access Control Servers must have the
Preferred Primary Access Control Server option
checked as part of the Access Control Server setup under the System Components tab of the
Network pages. Only one of the peer Access Control Servers may have this option checked.
Both Access Control Servers, and all Access Controllers, must be configured with the same shared
secret in order to communicate with each other.
As Access Controllers are installed on the network, they are configured with the IP address of the
Preferred Primary Access Control Server. Access Controllers in a system with redundant Access
Control Servers receive the address of the secondary Access Control Server from the Primary Access
Control Server.
See Configuring Failover with Redundant Access Control Servers on page 6-15 in Chapter 6 for details on
configuring redundant Access Control Servers.
How Access Control Server Failover Works
When a redundant relationship is established, the primary Access Control Server initially replicates its
configuration state and database on the secondary Access Control Server. From then on, SQL updates
will keep the secondary Access Control Server synchronized with the primary Access Control Server. A
“heartbeat” message between the primary and secondary is used to keep the secondary Access Control
Server informed that the primary is functioning.
2-18 HP ProCurve Secure Access 700wl Series Management and Configuration Guide