<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Upgrade ISE 2.3 to 2.4, new HW in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/upgrade-ise-2-3-to-2-4-new-hw/m-p/3956870#M455747</link>
    <description>&lt;P&gt;Hi team&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I planning the upgrade from ise 2.3 to ise 2.4 in a two nodes deployment to a new HW. Already read the upgrade document and I think this is the procedure.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ise01a = ise 2.3 primary node (3415)&lt;/P&gt;&lt;P&gt;ise02a = ise 2.3 secondary node&amp;nbsp;(3415)&lt;/P&gt;&lt;P&gt;ise01b = ise 2.4&amp;nbsp;(3655)&lt;/P&gt;&lt;P&gt;ise02b = ise 2.4&amp;nbsp;(3655)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1.- Take a configuration and operation backup from ise01a, also the show run from ise01a and ise02a&lt;/P&gt;&lt;P&gt;2.- Export the certificate from ise01a&lt;/P&gt;&lt;P&gt;3.- Deregister ise02a from 2.3 deployment.&lt;/P&gt;&lt;P&gt;4.- Shutdown&amp;nbsp;ise02a&lt;/P&gt;&lt;P&gt;5.- Power on ise02b (the appliance already have the version 2.4 patch 10 loaded)&lt;/P&gt;&lt;P&gt;6.- Load the show run from ise02a to ise02b&amp;nbsp;&lt;/P&gt;&lt;P&gt;7.- Restore the ise02b from configuration/operational backup from ise01a&lt;/P&gt;&lt;P&gt;8.- Importe the certificate from ise01a&lt;/P&gt;&lt;P&gt;9.- Assign at ise02b as primary node.&lt;/P&gt;&lt;P&gt;10.- Shutdown ise01a&lt;/P&gt;&lt;P&gt;11.-&amp;nbsp;Power on ise01b&amp;nbsp;(the appliance already have the version 2.4 patch 10 loaded)&lt;/P&gt;&lt;P&gt;10.-&amp;nbsp;Load the show run from ise01a to ise01b&amp;nbsp;&lt;/P&gt;&lt;P&gt;11.-&amp;nbsp;Restore the ise01b from configuration/operational backup from ise01a&lt;/P&gt;&lt;P&gt;12 .-&amp;nbsp;Assign at ise02b as secondary node.&lt;/P&gt;&lt;P&gt;13.- change the ise01b as primary and ise02b as secondary&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm ok with the procedure?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 11 Nov 2019 22:12:57 GMT</pubDate>
    <dc:creator>Servicio Tac</dc:creator>
    <dc:date>2019-11-11T22:12:57Z</dc:date>
    <item>
      <title>Upgrade ISE 2.3 to 2.4, new HW</title>
      <link>https://community.cisco.com/t5/network-access-control/upgrade-ise-2-3-to-2-4-new-hw/m-p/3956870#M455747</link>
      <description>&lt;P&gt;Hi team&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I planning the upgrade from ise 2.3 to ise 2.4 in a two nodes deployment to a new HW. Already read the upgrade document and I think this is the procedure.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ise01a = ise 2.3 primary node (3415)&lt;/P&gt;&lt;P&gt;ise02a = ise 2.3 secondary node&amp;nbsp;(3415)&lt;/P&gt;&lt;P&gt;ise01b = ise 2.4&amp;nbsp;(3655)&lt;/P&gt;&lt;P&gt;ise02b = ise 2.4&amp;nbsp;(3655)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1.- Take a configuration and operation backup from ise01a, also the show run from ise01a and ise02a&lt;/P&gt;&lt;P&gt;2.- Export the certificate from ise01a&lt;/P&gt;&lt;P&gt;3.- Deregister ise02a from 2.3 deployment.&lt;/P&gt;&lt;P&gt;4.- Shutdown&amp;nbsp;ise02a&lt;/P&gt;&lt;P&gt;5.- Power on ise02b (the appliance already have the version 2.4 patch 10 loaded)&lt;/P&gt;&lt;P&gt;6.- Load the show run from ise02a to ise02b&amp;nbsp;&lt;/P&gt;&lt;P&gt;7.- Restore the ise02b from configuration/operational backup from ise01a&lt;/P&gt;&lt;P&gt;8.- Importe the certificate from ise01a&lt;/P&gt;&lt;P&gt;9.- Assign at ise02b as primary node.&lt;/P&gt;&lt;P&gt;10.- Shutdown ise01a&lt;/P&gt;&lt;P&gt;11.-&amp;nbsp;Power on ise01b&amp;nbsp;(the appliance already have the version 2.4 patch 10 loaded)&lt;/P&gt;&lt;P&gt;10.-&amp;nbsp;Load the show run from ise01a to ise01b&amp;nbsp;&lt;/P&gt;&lt;P&gt;11.-&amp;nbsp;Restore the ise01b from configuration/operational backup from ise01a&lt;/P&gt;&lt;P&gt;12 .-&amp;nbsp;Assign at ise02b as secondary node.&lt;/P&gt;&lt;P&gt;13.- change the ise01b as primary and ise02b as secondary&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm ok with the procedure?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Nov 2019 22:12:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/upgrade-ise-2-3-to-2-4-new-hw/m-p/3956870#M455747</guid>
      <dc:creator>Servicio Tac</dc:creator>
      <dc:date>2019-11-11T22:12:57Z</dc:date>
    </item>
    <item>
      <title>Re: Upgrade ISE 2.3 to 2.4, new HW</title>
      <link>https://community.cisco.com/t5/network-access-control/upgrade-ise-2-3-to-2-4-new-hw/m-p/3956906#M455749</link>
      <description>&lt;P&gt;I think you may face an issue with&lt;/P&gt;
&lt;P&gt;7.- Restore the ise02b from configuration/operational backup from ise01a&lt;/P&gt;
&lt;P&gt;8.- Importe the certificate from ise01a&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When you restore the config backup onto ise02b, then the node should also get the certificate that you had on ise02a, and not ise01a - the FQDN on ise02b must match the Subject Common name of the Admin cert (or ... unless you have a wildcard cert or Multi-Domain Cert, then ignore what I have said - but check you Admin cert to ensure it will match the node's FQDN)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Step 11 is not correct&lt;/P&gt;
&lt;P&gt;11.-&amp;nbsp;Restore the ise01b from configuration/operational backup from ise01a&lt;/P&gt;
&lt;P&gt;You don't restore the config - you need to register the secondary node to the primary. Once done, the Secondary sync's up with the Primary.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This step happens during the registration phase.&lt;/P&gt;
&lt;P&gt;12 .-&amp;nbsp;Assign at ise02b as secondary node.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So I would say steps 11 and 12 would look like this&lt;/P&gt;
&lt;P&gt;11. Install Cert Chain (Trusted Certs) for the Admin cert you're going to use. Then import the Admin cert from ise01a&lt;/P&gt;
&lt;P&gt;12. From ise02b Register the new node ise02a and assign it the Secondary roles (Admin/MnT) and all the other stuff like Policy etc.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This is a very condensed version. There are many moving parts but you're on the right track.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I normally don't migrate certs from old system to new system. I would create a CSR on each node and have new certs created.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Nov 2019 00:32:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/upgrade-ise-2-3-to-2-4-new-hw/m-p/3956906#M455749</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2019-11-12T00:32:01Z</dc:date>
    </item>
    <item>
      <title>Re: Upgrade ISE 2.3 to 2.4, new HW</title>
      <link>https://community.cisco.com/t5/network-access-control/upgrade-ise-2-3-to-2-4-new-hw/m-p/3957279#M455751</link>
      <description>&lt;P&gt;Thanks for your anwser&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The idea it's have the lowest impact to the end user, that why we want export the certificates to the 2.3 to 2.4&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Your are right with the Certificate and FQDN... May be an option start with the procedure with the node ise01a to ise01b&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Nov 2019 14:23:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/upgrade-ise-2-3-to-2-4-new-hw/m-p/3957279#M455751</guid>
      <dc:creator>Servicio Tac</dc:creator>
      <dc:date>2019-11-12T14:23:43Z</dc:date>
    </item>
  </channel>
</rss>

