<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Correct procedure of restoring operational backup by CLI command  for distributed system in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/correct-procedure-of-restoring-operational-backup-by-cli-command/m-p/3691834#M508123</link>
    <description>&lt;P&gt;Thanks for sharing your experience, Ping.&lt;/P&gt;
&lt;P&gt;With your comment, I noticed the guide doesn't cover 2 node deployment. Now GUI covers standalone and distributed. I also want to know about that.&lt;/P&gt;</description>
    <pubDate>Tue, 21 Aug 2018 01:53:04 GMT</pubDate>
    <dc:creator>masyamad</dc:creator>
    <dc:date>2018-08-21T01:53:04Z</dc:date>
    <item>
      <title>Correct procedure of restoring operational backup by CLI command  for distributed system</title>
      <link>https://community.cisco.com/t5/network-access-control/correct-procedure-of-restoring-operational-backup-by-cli-command/m-p/3691082#M508114</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Administrator guide introduce different ways to restore operational backup for each deployment when using GUI.&amp;nbsp; It explains deregistering is required before performing restore.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;SECTION&gt;&lt;A class="link" href="https://www.cisco.com/c/en/us/td/docs/security/ise/2-4/admin_guide/b_ise_admin_guide_24/b_ise_admin_guide_24_new_chapter_01100.html#ID519" target="_blank"&gt;Restore a Monitoring (Operational) Backup in a Standalone Environment&lt;/A&gt;&lt;/SECTION&gt;
&lt;SECTION&gt;&lt;A class="link" href="https://www.cisco.com/c/en/us/td/docs/security/ise/2-4/admin_guide/b_ise_admin_guide_24/b_ise_admin_guide_24_new_chapter_01100.html#ID563" target="_blank"&gt;Restore a Monitoring Backup with Administration and Monitor Personas&lt;/A&gt;&lt;/SECTION&gt;
&lt;SECTION&gt;&lt;A class="link" href="https://www.cisco.com/c/en/us/td/docs/security/ise/2-4/admin_guide/b_ise_admin_guide_24/b_ise_admin_guide_24_new_chapter_01100.html#ID636" target="_blank"&gt;Restore a Monitoring Backup with a Monitoring Persona&lt;/A&gt;&lt;/SECTION&gt;
&lt;SECTION&gt;&lt;/SECTION&gt;
&lt;SECTION&gt;But for CLI operation, no explanation is provided for restoring for distributed system.&lt;/SECTION&gt;
&lt;SECTION&gt;&lt;/SECTION&gt;
&lt;SECTION&gt;&lt;A class="link" href="https://www.cisco.com/c/en/us/td/docs/security/ise/2-4/admin_guide/b_ise_admin_guide_24/b_ise_admin_guide_24_new_chapter_01100.html#ID358" target="_blank"&gt;Restoration of Configuration or Monitoring (Operational) Backup from the CLI&lt;/A&gt;&lt;/SECTION&gt;
&lt;SECTION&gt;
&lt;SECTION&gt;Does it mean deregistering is not required only when using CLI even for distributed system?&lt;/SECTION&gt;
&lt;SECTION&gt;Or something is missing about CLI restore steps?&lt;/SECTION&gt;
&lt;SECTION&gt;&lt;/SECTION&gt;
&lt;SECTION&gt;&lt;/SECTION&gt;
&lt;/SECTION&gt;
&lt;SECTION&gt;Deregistering is a not easy operation on production network. So my customer wants to use CLI restore if it doesn't require deregister/re-register. But I'm not sure why deregister/re-register is not required only when using CLI.&amp;nbsp;&lt;/SECTION&gt;</description>
      <pubDate>Sun, 19 Aug 2018 17:37:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/correct-procedure-of-restoring-operational-backup-by-cli-command/m-p/3691082#M508114</guid>
      <dc:creator>masyamad</dc:creator>
      <dc:date>2018-08-19T17:37:18Z</dc:date>
    </item>
    <item>
      <title>Re: Correct procedure of restoring operational backup by CLI command  for distributed system</title>
      <link>https://community.cisco.com/t5/network-access-control/correct-procedure-of-restoring-operational-backup-by-cli-command/m-p/3691095#M508118</link>
      <description>&lt;P&gt;Just to share my experience...&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I did restore on the Primary node via CLI from 1.4 Configuration Data to 2.0.1 on a 2-node deployment, without deregistering the nodes. At the end of it, the restore function completed successfully, confirmed by command output of show restore history. Then I logged into the Primary, found out it has been put to Standalone deployment.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;HTH.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 19 Aug 2018 19:19:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/correct-procedure-of-restoring-operational-backup-by-cli-command/m-p/3691095#M508118</guid>
      <dc:creator>Ping Zhou</dc:creator>
      <dc:date>2018-08-19T19:19:27Z</dc:date>
    </item>
    <item>
      <title>Re: Correct procedure of restoring operational backup by CLI command  for distributed system</title>
      <link>https://community.cisco.com/t5/network-access-control/correct-procedure-of-restoring-operational-backup-by-cli-command/m-p/3691667#M508120</link>
      <description>&lt;P&gt;It looks like CLI steps are missing the information on the distributed deployment, I will work with the doc team to address this.&amp;nbsp;I understand why the customer would want to avoid deregistration, but please follow the steps outlined on the GUI backup/restore procedure.&lt;/P&gt;</description>
      <pubDate>Mon, 20 Aug 2018 17:52:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/correct-procedure-of-restoring-operational-backup-by-cli-command/m-p/3691667#M508120</guid>
      <dc:creator>howon</dc:creator>
      <dc:date>2018-08-20T17:52:00Z</dc:date>
    </item>
    <item>
      <title>Re: Correct procedure of restoring operational backup by CLI command  for distributed system</title>
      <link>https://community.cisco.com/t5/network-access-control/correct-procedure-of-restoring-operational-backup-by-cli-command/m-p/3691834#M508123</link>
      <description>&lt;P&gt;Thanks for sharing your experience, Ping.&lt;/P&gt;
&lt;P&gt;With your comment, I noticed the guide doesn't cover 2 node deployment. Now GUI covers standalone and distributed. I also want to know about that.&lt;/P&gt;</description>
      <pubDate>Tue, 21 Aug 2018 01:53:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/correct-procedure-of-restoring-operational-backup-by-cli-command/m-p/3691834#M508123</guid>
      <dc:creator>masyamad</dc:creator>
      <dc:date>2018-08-21T01:53:04Z</dc:date>
    </item>
    <item>
      <title>Re: Correct procedure of restoring operational backup by CLI command  for distributed system</title>
      <link>https://community.cisco.com/t5/network-access-control/correct-procedure-of-restoring-operational-backup-by-cli-command/m-p/3691840#M508124</link>
      <description>Thanks howon. I look forward to the doc update. &lt;BR /&gt;BTW according to Ping's experience, restore worked well without deregistration for 2 node deployment. Is it expected result? &lt;BR /&gt;&lt;BR /&gt;And now the guide covers only following scenarios.&lt;BR /&gt;&lt;BR /&gt;No.1: In a Standalone Environment (=simple standalone)&lt;BR /&gt;No.2: Backup with Administration and Monitor Personas (=mid size distributed deployment)&lt;BR /&gt;No.3: Backup with a Monitoring Persona (=large size distributed deployment)&lt;BR /&gt;&lt;BR /&gt;But it seems not to cover "Backup with Administration, Monitor and  Policy Service Node personas (=2 node deployments)".&lt;BR /&gt;&lt;BR /&gt;Could you also tell us the scenario? Is the procedure for the scenario same as either of No.1~3?</description>
      <pubDate>Tue, 21 Aug 2018 01:59:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/correct-procedure-of-restoring-operational-backup-by-cli-command/m-p/3691840#M508124</guid>
      <dc:creator>masyamad</dc:creator>
      <dc:date>2018-08-21T01:59:39Z</dc:date>
    </item>
    <item>
      <title>Re: Correct procedure of restoring operational backup by CLI command  for distributed system</title>
      <link>https://community.cisco.com/t5/network-access-control/correct-procedure-of-restoring-operational-backup-by-cli-command/m-p/3691933#M508125</link>
      <description>&lt;P&gt;Hi Howon,&lt;BR /&gt;&lt;BR /&gt;I tried "Backup with Administration and Monitor Personas" scenario for 2 node deployment, but got abnormal result. &lt;BR /&gt;"Show details" on live log or report doesn't show actual information and only show following message. &lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="無題.png" style="width: 681px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/17201i76FAC82B4BA04E06/image-dimensions/681x79?v=v2" width="681" height="79" role="button" title="無題.png" alt="無題.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Does it mean "Backup with Administration and Monitor Personas" scenario can't be applied to 2 node deployment? Please tell me correct restore procedure for the deployment.&lt;BR /&gt;&lt;BR /&gt;My Test Environment.&lt;BR /&gt;- 2 node deployment&lt;BR /&gt;- Both ISE are VM appliances and running with 2.4 patch2&lt;BR /&gt;- At the beginning of the verification, ISE1 is primary PAN/primary MnT/active PSN. ISE2 is secondary PAN/secondary MnT/active PSN.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;My Test Steps.&lt;BR /&gt;Step1: On ISE1 (primary PAN/primary MnT/active PSN), collect Operational Backup via "Backup now" menu.&lt;BR /&gt;Step2: Purge all data via Purge data now.&lt;BR /&gt;Step3: Promote ISE2 (secondary PAN/secondary MnT/active PSN) to primary.&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; After that, ISE2 became primary PAN/secondary MnT/Active PSN.&lt;BR /&gt;Step4: Deregistered ISE1 from the 2 node deployment.&lt;BR /&gt;Step5: Restore operational data with backup collected at Step1.&lt;BR /&gt;Step6: Register ISE1 from ISE2 GUI.&lt;BR /&gt;Step7: Promote ISE1 to primary.&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; After that, ISE1 became primary PAN/secondary MnT/Active PSN.&lt;BR /&gt;Step8: See some report or live log and click details. But it didn't show information and only show "No Data available for this record. Either the data is purged or authentication for this session record happened a week ago.&lt;BR /&gt;Or if this is an 'PassiveID' or 'PassiveID Visibility' session, it will not have authentication details on ISE but only the session.&lt;BR /&gt;"&lt;BR /&gt;&lt;BR /&gt;From administration guide...&lt;BR /&gt;Before you begin&lt;BR /&gt;&amp;nbsp; &amp;nbsp; Purge the old monitoring data.&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Schedule a backup or perform an on-demand backup.&lt;BR /&gt;&lt;BR /&gt;Procedure&lt;BR /&gt;Step1 :&lt;BR /&gt;Prepare to promote another Cisco ISE node as the PAN, by synchronizing the node with the existing primary node you want to backup.&lt;BR /&gt;This ensures that the configuration of the Cisco ISE node you are going to promote is up to date.&lt;BR /&gt;Step2 :&lt;BR /&gt;Promote the newly synced Administration node to primary status.&lt;BR /&gt;Step3: &amp;nbsp;&amp;nbsp; &amp;nbsp;&lt;BR /&gt;Prepare to deregister the node to be backed up by assigning the Monitoring persona to another node in the deployment.&lt;BR /&gt;A deployment must have at least one functioning Monitoring node.&lt;BR /&gt;Step4:&amp;nbsp;&amp;nbsp; &amp;nbsp;&lt;BR /&gt;Deregister the node to be backed up.&lt;BR /&gt;Step5:&amp;nbsp;&amp;nbsp; &amp;nbsp;&lt;BR /&gt;Restore the Monitoring backup to the newly deregistered node.&lt;BR /&gt;Step6:&amp;nbsp;&amp;nbsp; &amp;nbsp;&lt;BR /&gt;Register the newly restored node with the current Administration node.&lt;BR /&gt;Step7:&amp;nbsp;&amp;nbsp; &amp;nbsp;&lt;BR /&gt;Promote the newly restored and registered node as the PAN. &lt;/P&gt;</description>
      <pubDate>Tue, 21 Aug 2018 07:12:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/correct-procedure-of-restoring-operational-backup-by-cli-command/m-p/3691933#M508125</guid>
      <dc:creator>masyamad</dc:creator>
      <dc:date>2018-08-21T07:12:17Z</dc:date>
    </item>
    <item>
      <title>Re: Correct procedure of restoring operational backup by CLI command  for distributed system</title>
      <link>https://community.cisco.com/t5/network-access-control/correct-procedure-of-restoring-operational-backup-by-cli-command/m-p/3692494#M508126</link>
      <description>&lt;P&gt;Looks to be defect. I filed&amp;nbsp;it but unicast me directly if defect ID is needed. howon@cisco.com&lt;/P&gt;</description>
      <pubDate>Tue, 21 Aug 2018 20:52:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/correct-procedure-of-restoring-operational-backup-by-cli-command/m-p/3692494#M508126</guid>
      <dc:creator>howon</dc:creator>
      <dc:date>2018-08-21T20:52:47Z</dc:date>
    </item>
    <item>
      <title>Re: Correct procedure of restoring operational backup by CLI command  for distributed system</title>
      <link>https://community.cisco.com/t5/network-access-control/correct-procedure-of-restoring-operational-backup-by-cli-command/m-p/3692581#M508127</link>
      <description>Thanks for filing defect. BTW how about the correct restore procedure for 2 node deployment?  The steps of "Restore a Monitoring Backup with Administration and Monitor Personas" should be applied to the 2 node deployment? &lt;BR /&gt;&lt;BR /&gt;Now the guide shows following 3 scenarios. &lt;BR /&gt;No1. Restore a Monitoring (Operational) Backup in a Standalone Environment&lt;BR /&gt;No2. Restore a Monitoring Backup with Administration and Monitor Personas&lt;BR /&gt;No3. Restore a Monitoring Backup with a Monitoring Persona&lt;BR /&gt;&lt;BR /&gt;When using 2 node deployment, No2 and No3 can be a candidate because all of 3 personas run on both node. Could you confirm not No.3 but No.2 is the correct procedure for the deployment?</description>
      <pubDate>Wed, 22 Aug 2018 00:50:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/correct-procedure-of-restoring-operational-backup-by-cli-command/m-p/3692581#M508127</guid>
      <dc:creator>masyamad</dc:creator>
      <dc:date>2018-08-22T00:50:46Z</dc:date>
    </item>
    <item>
      <title>Re: Correct procedure of restoring operational backup by CLI command  for distributed system</title>
      <link>https://community.cisco.com/t5/network-access-control/correct-procedure-of-restoring-operational-backup-by-cli-command/m-p/3692585#M508128</link>
      <description>&lt;P&gt;For sake of backup and restore PSN persona is irrelevant since backup is for Config (PAN) and Operations (MnT). For a node that has all three personas, #2 would be applicable.&lt;/P&gt;</description>
      <pubDate>Wed, 22 Aug 2018 01:12:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/correct-procedure-of-restoring-operational-backup-by-cli-command/m-p/3692585#M508128</guid>
      <dc:creator>howon</dc:creator>
      <dc:date>2018-08-22T01:12:04Z</dc:date>
    </item>
    <item>
      <title>Re: Correct procedure of restoring operational backup by CLI command  for distributed system</title>
      <link>https://community.cisco.com/t5/network-access-control/correct-procedure-of-restoring-operational-backup-by-cli-command/m-p/3692593#M508129</link>
      <description>Thanks. But it not so clear with current document. I hope the information will also be added to the guide.</description>
      <pubDate>Wed, 22 Aug 2018 01:24:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/correct-procedure-of-restoring-operational-backup-by-cli-command/m-p/3692593#M508129</guid>
      <dc:creator>masyamad</dc:creator>
      <dc:date>2018-08-22T01:24:14Z</dc:date>
    </item>
  </channel>
</rss>

