Ironport ESA Cluster

 1. What is ESA cluster

A cluster consists of a set of machines with common configuration information.  Within each cluster, the appliances can be further divided into machine groups, where a single machine can be a member of only one group at a time. 

Clusters are implemented in a peer-to-peer architecture - with no primary/secondary relationship.  You may log into any machine to control and administer the entire cluster or group.  This allows the administrator to configure different elements of the system on a cluster-wide, group-wide, or per-machine basis, based on their own logical groupings.

2.Requirement

2.1 Must same version
2.2 Cluster communication can use on port 22 (SSH) or 2222 (CCS)

3. Create the Cluster

3.1 On the first appliance
ironport.lab> clusterconfig
choose "Create a new cluster", give cluster a name, choose SSH on management interface or 2222 (CCS) on other interface.


3.2 On the second appliance
ironport.lab> clusterconfig
Choose join an existing cluster over SSH or CCS, enter the first appliance IP, admin/password. For CSS, need run "clusterconfig" --> "prepjoin" on the active appliance first.


4.Configure Groups

In certain scenarios, there may be a requirement that few ESAs in the Cluster work in a particular way than the rest. For achieving this, rather than creating a new cluster we can proceed with creation of Groups. 
The configurations that are made at Group level, takes precedence over the Cluster level configuration.

ironport.lab> clusterconfig


https://www.cisco.com/c/en/us/support/docs/security/email-security-appliance/200885-ESA-Cluster-Requirements-and-Setup.html

Comments

Popular posts from this blog

Firepower FMC and FTD troubleshooting

ASA IKEv1 VPN troubleshooting Steps and Tips

Firepower 2100/1100 FTD/ASA initial setup, reimage, upgrade.