Installing Secondary Access Manager Appliance

  1. Insert the CD containing the software.

    The installation process is almost same for a secondary appliance as for a primary. If this is a second or third appliance, Administration Console will be configured for the fault tolerance. Ensure that you perform the following actions while installing a secondary appliance:

    • Deselect Primary.

    • Specify the IP address of the primary Access Manager Appliance.

    • Specify the user name and password of the primary Access Manager Appliance.

    Installation of the secondary appliance becomes interactive after the installation of operating system in the following scenarios:

    • (Conditional) When this is the fourth appliance: The number of Administration Consoles in a cluster is restricted to three. If more appliances are added into the cluster, the system will ask whether you want to proceed with the installation of rest of the components other than Administration Console.

    • (Conditional) When the time is not synchronized between primary and secondary appliances: The system will prompt a message asking you to re-try the time synchronization or to proceed without synchronization.

    Configure the details on the Administration Console Configuration page as specified in step 9 in Installing Access Manager Appliancein the NetIQ Access Manager Appliance CE 24.2 (v5.1) Installation and Upgrade Guide.

  2. Continue with the installation process.

    Identity Server and Access Gateway from the secondary appliance are automatically clustered with the primary appliance. If this is second or third secondary appliance, the configuration store will be configured for the fault tolerance. Install at least one secondary appliance.

    After successful installation, the appliance points to the Access Manager Appliance's IP address for the web server, and Identity Server points to the local user store. If a cluster is configured for Access Manager Appliance and if primary appliance is down, you cannot authenticate because the user store is on primary and they cannot access the resources because it points to the web server on primary. Hence, it is advised to change the IP address of the web server configured in the master proxy service to point to your test or production web server, and change the Identity Server’s configuration to point to an external user store.