<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Scripted ISE install? in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/scripted-ise-install/m-p/3591793#M526349</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This is an excellent question.&amp;nbsp; I have written my own guides for rebuilding an ISE "cluster" from scratch (as part of my customer's requirement to have this disaster recovery process documented).&amp;nbsp; It's a very lengthy document and after many iterations I have honed the process down to the correct sequence. &lt;/P&gt;&lt;P&gt;It would be nice to be able to build such a system using some automation tools (chef/puppet/Ansible etc).&amp;nbsp; I don't think an ISE node should be immutable like your typical web server running in a Docker container that gets spun up for 10 seconds and then killed again.&amp;nbsp; But if you're building a lot of these nodes, then it gets a bit long in the tooth.&amp;nbsp; I am not a fan of cloning and exporting/importing configs to "speed up" the process because that brings too much baggage with it.&amp;nbsp; Clean, quick build from scratch and with automation - that's what we're hearing all the time from the SDN folks.&amp;nbsp; Maybe something like a kickstart install for ISE would be nice.&amp;nbsp; One can create a file offline with all the settings you want, and then during install (.iso) one feeds that file (via tftp or whatever).&amp;nbsp; Sit back and watch your ISE node be built.&lt;/P&gt;&lt;P&gt;I'll get off my cloud now ... &lt;IMG src="https://community.cisco.com/legacyfs/online/emoticons/mischief.png" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 11 Oct 2017 23:21:37 GMT</pubDate>
    <dc:creator>Arne Bier</dc:creator>
    <dc:date>2017-10-11T23:21:37Z</dc:date>
    <item>
      <title>Scripted ISE install?</title>
      <link>https://community.cisco.com/t5/network-access-control/scripted-ise-install/m-p/3591791#M526347</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: Times New Roman; font-size: 12pt;"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: Calibri; font-size: 12pt;"&gt;Is there is a way to script the rebuild of the ISE environment so that they do not have to manually rebuild everything when doing a fresh install to get a clean database.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: Times New Roman; font-size: 12pt;"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 11 Oct 2017 17:51:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/scripted-ise-install/m-p/3591791#M526347</guid>
      <dc:creator>kkem07</dc:creator>
      <dc:date>2017-10-11T17:51:09Z</dc:date>
    </item>
    <item>
      <title>Re: Scripted ISE install?</title>
      <link>https://community.cisco.com/t5/network-access-control/scripted-ise-install/m-p/3591792#M526348</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;There is some stuff that can be exported, and re-imported, but not a lot.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What do you mean by a clean database? everything recreated in that version? Or, to remove the old logs?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you are not sure about old entrys, you could purge the current data and do a backup, then rebuild and restore the backup. This should keep everything except the logs.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 11 Oct 2017 18:22:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/scripted-ise-install/m-p/3591792#M526348</guid>
      <dc:creator>Dustin Anderson</dc:creator>
      <dc:date>2017-10-11T18:22:34Z</dc:date>
    </item>
    <item>
      <title>Re: Scripted ISE install?</title>
      <link>https://community.cisco.com/t5/network-access-control/scripted-ise-install/m-p/3591793#M526349</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This is an excellent question.&amp;nbsp; I have written my own guides for rebuilding an ISE "cluster" from scratch (as part of my customer's requirement to have this disaster recovery process documented).&amp;nbsp; It's a very lengthy document and after many iterations I have honed the process down to the correct sequence. &lt;/P&gt;&lt;P&gt;It would be nice to be able to build such a system using some automation tools (chef/puppet/Ansible etc).&amp;nbsp; I don't think an ISE node should be immutable like your typical web server running in a Docker container that gets spun up for 10 seconds and then killed again.&amp;nbsp; But if you're building a lot of these nodes, then it gets a bit long in the tooth.&amp;nbsp; I am not a fan of cloning and exporting/importing configs to "speed up" the process because that brings too much baggage with it.&amp;nbsp; Clean, quick build from scratch and with automation - that's what we're hearing all the time from the SDN folks.&amp;nbsp; Maybe something like a kickstart install for ISE would be nice.&amp;nbsp; One can create a file offline with all the settings you want, and then during install (.iso) one feeds that file (via tftp or whatever).&amp;nbsp; Sit back and watch your ISE node be built.&lt;/P&gt;&lt;P&gt;I'll get off my cloud now ... &lt;IMG src="https://community.cisco.com/legacyfs/online/emoticons/mischief.png" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 11 Oct 2017 23:21:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/scripted-ise-install/m-p/3591793#M526349</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2017-10-11T23:21:37Z</dc:date>
    </item>
    <item>
      <title>Re: Scripted ISE install?</title>
      <link>https://community.cisco.com/t5/network-access-control/scripted-ise-install/m-p/3591794#M526350</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This thread can take many turns (positive ones, actually), but this is not the proper forum to discuss what could be or coming.&amp;nbsp; I would suggest reaching out to account team for roadmap discussions and enhancement requests.&amp;nbsp; Short of it is that on this date in Oct 2017, there is no "sysprep" for ISE.&amp;nbsp;&amp;nbsp; It is possible to have dormant ISE nodes that have fresh install up to setup phase, or even fully configured at ADE-OS level and ready to be registered into deployment.&amp;nbsp; This could be used to augment existing VM or even hardware-based deployment.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Craig&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 Oct 2017 11:26:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/scripted-ise-install/m-p/3591794#M526350</guid>
      <dc:creator>Craig Hyps</dc:creator>
      <dc:date>2017-10-12T11:26:15Z</dc:date>
    </item>
  </channel>
</rss>

