<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ACS 5.4 to ISE 2.2 in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/acs-5-4-to-ise-2-2/m-p/3687472#M519718</link>
    <description>My authorization policies are Device Admin Authorization Policies instead of Network Access does this make a difference? When migrating for the first time my TACACS Policies did not migrate I had to manually input them.</description>
    <pubDate>Mon, 13 Aug 2018 20:22:57 GMT</pubDate>
    <dc:creator>kamwalke</dc:creator>
    <dc:date>2018-08-13T20:22:57Z</dc:date>
    <item>
      <title>ACS 5.4 to ISE 2.2</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-4-to-ise-2-2/m-p/3538522#M519710</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.0pt;"&gt;My customer planned to migrate ACS 5.4 to ISE 2.2 .&amp;nbsp;&amp;nbsp;&amp;nbsp; ,&amp;nbsp; so we created a config backup on the ACS 5.4&amp;nbsp; and load it in a new ACS 5.5 ,&amp;nbsp; started to migrate using the tool . &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.0pt;"&gt;The ACS is running as device administration.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.0pt;"&gt;Authorization policy migration is not successful with below reason ,&amp;nbsp; Other elements is successful like ( devices, shell profile/command set etc ),&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.0pt;"&gt;“Failed to create authorization policy of policy set Rule-2. Specified resource already exists&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.0pt;"&gt;An error has occurred while migrating the policy configuration. The policy configuration has been reverted back to the version that existed prior to the migration processing.”&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.0pt;"&gt;My customer is using external resource (one-time authentication server ) for most user authentication ,&amp;nbsp; does it affect all authentication policy ?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.0pt;"&gt;And internal user migration is not successful neither, not sure if we need to upgrade ACS 5.8 and do migration again. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.0pt;"&gt;Info Type: WARN&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.0pt;"&gt;&amp;gt; 2017.11.19 21:33:11'313 : 'Description' :Specified resource already exists: InternalUser&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.0pt;"&gt;Any comments is appreciated&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.0pt;"&gt;thanks&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.0pt;"&gt;Qingguo&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 20 Nov 2017 03:05:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-4-to-ise-2-2/m-p/3538522#M519710</guid>
      <dc:creator>Qingguo Zhang</dc:creator>
      <dc:date>2017-11-20T03:05:28Z</dc:date>
    </item>
    <item>
      <title>Re: ACS 5.4 to ISE 2.2</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-4-to-ise-2-2/m-p/3538523#M519711</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If the migration tool fails to copy certain rules or objects, then we would need configuring them manually, after the run. Please perform a sanity check afterwards.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" href="https://community.cisco.com/docs/DOC-65715"&gt;How to Migrate ACS 5.x to ISE 2.x&lt;/A&gt;&lt;SPAN style="font-size: 10pt;"&gt; suggests&lt;/SPAN&gt;&lt;/P&gt;&lt;DIV class="section" style="background-color: rgb(100.000000%, 100.000000%, 100.000000%);"&gt;&lt;DIV class="column"&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN style="font-size: 11.000000pt; font-family: 'Times'; color: rgb(32.900000%, 55.300000%, 83.100000%);"&gt;ACS 5.4&lt;/SPAN&gt;&lt;SPAN style="font-size: 11.000000pt; font-family: 'Wingdings'; color: rgb(32.900000%, 55.300000%, 83.100000%);"&gt;&lt;/SPAN&gt;&lt;SPAN style="font-size: 11.000000pt; font-family: 'Times';"&gt;ACS 5.6&lt;/SPAN&gt;&lt;SPAN style="font-size: 11.000000pt; font-family: 'Wingdings';"&gt;&lt;/SPAN&gt;&lt;SPAN style="font-size: 11.000000pt; font-family: 'Times';"&gt;ACS 5.7 or ACS 5.8 &lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Even though ACS 5.6 to 5.8 all supported to migrate to ISE 2.3, &lt;A _jive_internal="true" href="https://community.cisco.com/thread/87194" style="font-size: 12px; font-family: arial; color: #0a63a7;"&gt;ACS to ISE migration&lt;/A&gt;&lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt; shows ACS 5.8 doing it better.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;For further help, please contact Cisco TAC.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 20 Nov 2017 03:42:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-4-to-ise-2-2/m-p/3538523#M519711</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2017-11-20T03:42:52Z</dc:date>
    </item>
    <item>
      <title>Re: ACS 5.4 to ISE 2.2</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-4-to-ise-2-2/m-p/3538524#M519712</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We do support migration from ACS 5.5+ to ISE 2.1+.&lt;/P&gt;&lt;P&gt;The migration tool identifies the issues including name overlaps ete. Some of them are benign since if the name exists and the rules are the same in ISE you can ignore the issue.&lt;/P&gt;&lt;P&gt;Please take a look at the how to migrate from ACS to ISE guide where I have detailed tables that speaks about naming differences and what to do with it. I also have step by step instructions how to migrate.&lt;/P&gt;&lt;P&gt;http://cs.co/acstoise will have videos showing migration from ACS to ISE. You can use these resources for migration.&lt;/P&gt;&lt;P&gt;As Hsing said, if you encounter further issues please call TAC.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Krishnan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 20 Nov 2017 20:17:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-4-to-ise-2-2/m-p/3538524#M519712</guid>
      <dc:creator>kthiruve</dc:creator>
      <dc:date>2017-11-20T20:17:40Z</dc:date>
    </item>
    <item>
      <title>Re: ACS 5.4 to ISE 2.2</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-4-to-ise-2-2/m-p/3538525#M519715</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Sir,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am migrating cisco acs 5.8 to ISE 2.2 using migration tool.&lt;/P&gt;&lt;P&gt;My all objects gets migrated but only access policy is not getting migrating.&lt;/P&gt;&lt;P&gt;In policy gap report it is showing that Authorization policy is unsupported.&lt;/P&gt;&lt;P&gt;What would be the issue?&lt;/P&gt;&lt;P&gt;Can you please suggest here...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Ravin L&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 23 Apr 2018 11:07:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-4-to-ise-2-2/m-p/3538525#M519715</guid>
      <dc:creator>csawest.dc</dc:creator>
      <dc:date>2018-04-23T11:07:28Z</dc:date>
    </item>
    <item>
      <title>Re: ACS 5.4 to ISE 2.2</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-4-to-ise-2-2/m-p/3680135#M519716</link>
      <description>I am having the same issue. I am migrating from ACS 5.8 to ISE 2.3 and my authorization policies did not migrate.</description>
      <pubDate>Thu, 02 Aug 2018 15:04:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-4-to-ise-2-2/m-p/3680135#M519716</guid>
      <dc:creator>kamwalke</dc:creator>
      <dc:date>2018-08-02T15:04:40Z</dc:date>
    </item>
    <item>
      <title>Re: ACS 5.4 to ISE 2.2</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-4-to-ise-2-2/m-p/3680211#M519717</link>
      <description>In the migration tool folder, there will be a "migration.log" file.  Confirm if "Authorization Policy Rule" lists that one of your authz rules was exported successfully and then search for the authz policy name and you should also see it imported. &lt;BR /&gt;&lt;BR /&gt;I've done a few 5.8 to 2.3 migrations with the tool and it worked "ok" for me.  The migrated authz rules logic have always required clean up and modification after.</description>
      <pubDate>Thu, 02 Aug 2018 16:22:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-4-to-ise-2-2/m-p/3680211#M519717</guid>
      <dc:creator>Damien Miller</dc:creator>
      <dc:date>2018-08-02T16:22:18Z</dc:date>
    </item>
    <item>
      <title>Re: ACS 5.4 to ISE 2.2</title>
      <link>https://community.cisco.com/t5/network-access-control/acs-5-4-to-ise-2-2/m-p/3687472#M519718</link>
      <description>My authorization policies are Device Admin Authorization Policies instead of Network Access does this make a difference? When migrating for the first time my TACACS Policies did not migrate I had to manually input them.</description>
      <pubDate>Mon, 13 Aug 2018 20:22:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs-5-4-to-ise-2-2/m-p/3687472#M519718</guid>
      <dc:creator>kamwalke</dc:creator>
      <dc:date>2018-08-13T20:22:57Z</dc:date>
    </item>
  </channel>
</rss>

