<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Cisco ISE 2.3 Migration Tool in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cisco-ise-2-3-migration-tool/m-p/3421328#M510898</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am currently migrating ACS 5.8 to ISE 2.3 using the migration tool.&amp;nbsp; Followed the prerequisites and did a clean export from ACS with no errors (only a few infos). I imported the ACS trusted certificates in to the settings and still getting "FQDN and ISE Host cannot be found" errors during the import to ISE process.&amp;nbsp; What am I missing?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 10 Apr 2018 17:30:53 GMT</pubDate>
    <dc:creator>nhkelley1</dc:creator>
    <dc:date>2018-04-10T17:30:53Z</dc:date>
    <item>
      <title>Cisco ISE 2.3 Migration Tool</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-2-3-migration-tool/m-p/3421328#M510898</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am currently migrating ACS 5.8 to ISE 2.3 using the migration tool.&amp;nbsp; Followed the prerequisites and did a clean export from ACS with no errors (only a few infos). I imported the ACS trusted certificates in to the settings and still getting "FQDN and ISE Host cannot be found" errors during the import to ISE process.&amp;nbsp; What am I missing?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 10 Apr 2018 17:30:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-2-3-migration-tool/m-p/3421328#M510898</guid>
      <dc:creator>nhkelley1</dc:creator>
      <dc:date>2018-04-10T17:30:53Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE 2.3 Migration Tool</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-2-3-migration-tool/m-p/3421329#M510899</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Ned,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please reach out to the TAC to investigate further.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;-Tim&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 10 Apr 2018 18:16:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-2-3-migration-tool/m-p/3421329#M510899</guid>
      <dc:creator>Timothy Abbott</dc:creator>
      <dc:date>2018-04-10T18:16:15Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE 2.3 Migration Tool</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-2-3-migration-tool/m-p/3421330#M510900</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 10 Apr 2018 18:20:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-2-3-migration-tool/m-p/3421330#M510900</guid>
      <dc:creator>nhkelley1</dc:creator>
      <dc:date>2018-04-10T18:20:35Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE 2.3 Migration Tool</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-2-3-migration-tool/m-p/3421331#M510901</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It's not clear whether you imported the ISE system certificate if self-signed or its root CA certificate if the system certificate issued by an external CA. If the correct certificate imported, then ensure using the FQDN of ISE in the migration tool to connect to ISE.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 11 Apr 2018 04:44:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-2-3-migration-tool/m-p/3421331#M510901</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2018-04-11T04:44:58Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE 2.3 Migration Tool</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-2-3-migration-tool/m-p/3421332#M510902</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you for your reply. I went back and inported the correct trusted certificates for both ACs and ISE. The export completed with out errors. The problem occurs when trying to "Import to ISE". DNS and FQDN issues appear after typing in the login credentials. Again, both trusted certificates contains the CN=host+FQDN. I am not sure what i am missing here.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Appreciate any help or feeback here. Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 Apr 2018 18:33:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-2-3-migration-tool/m-p/3421332#M510902</guid>
      <dc:creator>nhkelley1</dc:creator>
      <dc:date>2018-04-12T18:33:30Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE 2.3 Migration Tool</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-2-3-migration-tool/m-p/3421333#M510903</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If not already done, please review the info @ &lt;A _jive_internal="true" data-containerid="5319" data-containertype="14" data-objectid="65715" data-objecttype="102" href="https://community.cisco.com/docs/DOC-65715" style="font-size: 12px; font-family: arial; color: #0a63a7;"&gt;&lt;SPAN style="font-style: inherit; font-family: inherit;"&gt;&lt;STRONG&gt;How to Migrate ACS 5.x to ISE 2.x&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN style="font-size: 10pt;"&gt;. In particular, Step 16 in Page 23 says,&lt;/SPAN&gt;&lt;/P&gt;&lt;DIV class="section"&gt;&lt;DIV class="column"&gt;&lt;BLOCKQUOTE&gt;&lt;TABLE border="1"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;
&lt;P&gt;&lt;SPAN style="font-size: 11pt; font-family: Times;"&gt;Browse ISE 2.x UI and go to system certificate by going to&lt;/SPAN&gt;&lt;SPAN style="font-size: 11pt; font-family: 'Times,Bold';"&gt;Administration&lt;/SPAN&gt;&lt;SPAN style="font-size: 11pt; font-family: Wingdings;"&gt;&lt;/SPAN&gt;&lt;SPAN style="font-size: 11pt; font-family: 'Times,Bold';"&gt;System&lt;/SPAN&gt;&lt;SPAN style="font-size: 11pt; font-family: Wingdings;"&gt;&lt;/SPAN&gt;&lt;SPAN style="font-size: 11pt; font-family: 'Times,Bold';"&gt;Certificates&lt;/SPAN&gt;&lt;SPAN style="font-size: 11pt; font-family: Wingdings;"&gt;&lt;/SPAN&gt;&lt;SPAN style="font-size: 11pt; font-family: 'Times,Bold';"&gt;System Certificates&lt;/SPAN&gt;&lt;SPAN style="font-size: 11pt; font-family: Times;"&gt;. Observe the entry that has usage “admin”. This certificate need to be exported.&lt;/SPAN&gt;&lt;/P&gt;

&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/BLOCKQUOTE&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Verify the Windows PC running the migration tool is able to ping ISE by its FQDN as shown in the subject or the subject alternative name field in the certificate. If you are unable to add ISE FQDN in the DNS, you may add it to the "hosts" file locally on the Windows PC.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If none of the above helping, then it's best for you to engage TAC so TAC may have a WebEx meeting with you to check the issue directly.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 Apr 2018 18:57:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-2-3-migration-tool/m-p/3421333#M510903</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2018-04-12T18:57:10Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE 2.3 Migration Tool</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-2-3-migration-tool/m-p/3421334#M510904</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, I can ping the hostname, IP, and FQDN from both the ACS and ISE VM CLI to each other.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My windows workstation also pings both servers.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 Apr 2018 19:05:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-2-3-migration-tool/m-p/3421334#M510904</guid>
      <dc:creator>nhkelley1</dc:creator>
      <dc:date>2018-04-12T19:05:44Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE 2.3 Migration Tool</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-2-3-migration-tool/m-p/3421335#M510905</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Issue resolved;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Deleteted and re-installed new ISE certificates into the migration tool.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Previous certificates serial numbers did not match due to new VM rebuild.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you for your assistance and support.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;v/r;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ned&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 Apr 2018 20:24:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-2-3-migration-tool/m-p/3421335#M510905</guid>
      <dc:creator>nhkelley1</dc:creator>
      <dc:date>2018-04-12T20:24:54Z</dc:date>
    </item>
  </channel>
</rss>

