<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco ISE 2.2 moving personas Administration and Monitoring to a new node in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cisco-ise-2-2-moving-personas-administration-and-monitoring-to-a/m-p/3188472#M555573</link>
    <description>&lt;P&gt;I don't think you should have to do any restore operations. Of course starting the whole process with a current backup is a recommended step no matter what path you follow.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I would add the 2 new servers to the deployment as PSNs first. I'd remove the non-PSN roles for the current ISE02 first. Then add a new VM to the deployment and make it secondary PAN and MnT. Once it is all synced, promote it to primary. Then remove the non-PSN roles from ISE01. Finally add the second new VM in the role of Secondary PAN and MnT.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You may need to re-issue your certs with additional SANs to accommodate the new servers.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You might consider putting the whole deployment on ISE 2.3. It's being seen as less buggy than ISE 2.2.&lt;/P&gt;</description>
    <pubDate>Sat, 23 Sep 2017 14:42:59 GMT</pubDate>
    <dc:creator>Marvin Rhoads</dc:creator>
    <dc:date>2017-09-23T14:42:59Z</dc:date>
    <item>
      <title>Cisco ISE 2.2 moving personas Administration and Monitoring to a new node</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-2-2-moving-personas-administration-and-monitoring-to-a/m-p/3188420#M555570</link>
      <description>&lt;P&gt;Hi All,&amp;nbsp;&lt;/P&gt;&lt;P&gt;The company I work for is growing very fast and our ISE infrastructure is not adapted any more&amp;nbsp;so I d'l like to review totally the design&amp;nbsp;of it and I'd like to know which is the best approach&amp;nbsp;for implementing it.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My current ISE Distributed deployment of nodes &amp;nbsp;is as follow :&amp;nbsp;&lt;/P&gt;&lt;P&gt;Note : No PAN active&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2 Cisco ISE 2.2.0.407 servers running on VM's &amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ISE01 : Primary Admin/monitoring and PSN role&lt;/P&gt;&lt;P&gt;ISE02 : Secondary Admin/Monitoring and PSN role&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Today , I'd like to move the Admin and Monitoring personas to 2 new servers (VM)and keep the PSN on the actual servers&amp;nbsp;,&amp;nbsp;the idea behind is to unload actual servers of Monitoring and admin tasks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My ISE deployment will look as follow:&amp;nbsp;&lt;/P&gt;&lt;P&gt;ISE New 1 : Primary Admin , secondary Monitoring&lt;/P&gt;&lt;P&gt;ISE New 2 : Secondary Admin, Primary Monitoring&amp;nbsp;&lt;/P&gt;&lt;P&gt;ISE01 : PSN&lt;/P&gt;&lt;P&gt;ISE02 : PSN&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I already have my two new servers running in standalone with the same ISE version (Hostname and IP are not the same) .&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now I'm not sure what is the best approach to migrate the Admin and Monitoring services to the new servers :&amp;nbsp;&lt;/P&gt;&lt;P&gt;My first idea is :&lt;/P&gt;&lt;P&gt;1. restore first a backup of the old server 1/2 to the new servers&lt;/P&gt;&lt;P&gt;(make sure I have the Admin certificates of each nodes on all servers)&lt;/P&gt;&lt;P&gt;2. On actual ISE02(Secondary)&amp;nbsp;server remove the Admin/monitoring services&amp;nbsp;&lt;/P&gt;&lt;P&gt;3. register ISE New 1&amp;nbsp;as secondary server of ISE01 for Admin/monitoring to the ISE deployment and do a sync between Primary and Secondary&lt;/P&gt;&lt;P&gt;4. Promote ISE New 1&amp;nbsp;as Primary node for Admin /Monitoring services &amp;nbsp;sync&amp;nbsp;&lt;/P&gt;&lt;P&gt;5. remove Admin/monitoring on ISE01&amp;nbsp;(keep only PSN)&lt;/P&gt;&lt;P&gt;6, register ISE new 2 as secondary server for Admin/Monitoring services , SYNC&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Other things :&amp;nbsp;&lt;/P&gt;&lt;P&gt;What will happen when I will remove the Admin/Monitoring Services of the actual ISE02 servers , will both ISE will restart ?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If someone has a best way to do it &amp;nbsp;or any suggestions, it will be very appreciated .&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best regards&amp;nbsp;&lt;/P&gt;&lt;P&gt;Marc&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 18:34:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-2-2-moving-personas-administration-and-monitoring-to-a/m-p/3188420#M555570</guid>
      <dc:creator>maissiat</dc:creator>
      <dc:date>2020-02-21T18:34:38Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE 2.2 moving personas Administration and Monitoring to a new node</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-2-2-moving-personas-administration-and-monitoring-to-a/m-p/3188472#M555573</link>
      <description>&lt;P&gt;I don't think you should have to do any restore operations. Of course starting the whole process with a current backup is a recommended step no matter what path you follow.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I would add the 2 new servers to the deployment as PSNs first. I'd remove the non-PSN roles for the current ISE02 first. Then add a new VM to the deployment and make it secondary PAN and MnT. Once it is all synced, promote it to primary. Then remove the non-PSN roles from ISE01. Finally add the second new VM in the role of Secondary PAN and MnT.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You may need to re-issue your certs with additional SANs to accommodate the new servers.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You might consider putting the whole deployment on ISE 2.3. It's being seen as less buggy than ISE 2.2.&lt;/P&gt;</description>
      <pubDate>Sat, 23 Sep 2017 14:42:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-2-2-moving-personas-administration-and-monitoring-to-a/m-p/3188472#M555573</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2017-09-23T14:42:59Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE 2.2 moving personas Administration and Monitoring to a new node</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-2-2-moving-personas-administration-and-monitoring-to-a/m-p/3188509#M555574</link>
      <description>&lt;P&gt;Dear Marvin,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Sound's very good approach , I will follow it .&amp;nbsp;&lt;/P&gt;&lt;P&gt;I will update my post with the result of my migration&lt;/P&gt;&lt;P&gt;Thank you very much&lt;/P&gt;&lt;P&gt;Marc&lt;/P&gt;</description>
      <pubDate>Sat, 23 Sep 2017 17:45:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-2-2-moving-personas-administration-and-monitoring-to-a/m-p/3188509#M555574</guid>
      <dc:creator>maissiat</dc:creator>
      <dc:date>2017-09-23T17:45:20Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE 2.2 moving personas Administration and Monitoring to a new node</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-2-2-moving-personas-administration-and-monitoring-to-a/m-p/3344627#M555583</link>
      <description>&lt;P&gt;Marc, did it go smoothly?&lt;/P&gt;</description>
      <pubDate>Thu, 08 Mar 2018 07:49:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-2-2-moving-personas-administration-and-monitoring-to-a/m-p/3344627#M555583</guid>
      <dc:creator>Peter Koltl</dc:creator>
      <dc:date>2018-03-08T07:49:44Z</dc:date>
    </item>
  </channel>
</rss>

