<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Split ISE distributed design to two separate deployments in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/split-ise-distributed-design-to-two-separate-deployments/m-p/4318786#M566600</link>
    <description>&lt;P&gt;Can some one please advise what is the best approach to achieve this ?&lt;/P&gt;
&lt;P&gt;1. Network 2 above must use existing configuration, certificates from Network 1 to avoid configuring everything from scratch&lt;/P&gt;
&lt;P&gt;Here is a rough overview of steps I have taken to migrate from one cluster to another (note: hosts were VMs, and used the same hostnames):&lt;/P&gt;
&lt;P&gt;Generate config backup from network 1 (old) setup PAN*&lt;/P&gt;
&lt;P&gt;Old cluster:&lt;/P&gt;
&lt;P&gt;disabled pan failover&lt;BR /&gt;promoted pan2 to primary&lt;BR /&gt;unjoined pan1 from AD&lt;BR /&gt;exported certificates&lt;BR /&gt;deregistered pan1 from cluster&lt;/P&gt;
&lt;P&gt;enabled nic on new pan1 in 2.7 cluster&lt;BR /&gt;shut nics on old pan1 in 2.4 cluster&lt;BR /&gt;changed IP address on new pan on nic 1 (services restart)&lt;BR /&gt;added nic 2 and added underlay ip address (services restart)&lt;BR /&gt;added static routes via CLI for additional nic &lt;BR /&gt;started system restore&amp;nbsp;&lt;BR /&gt;kicked off restore &amp;amp; successfully worked ~35 minutes for this instance&lt;BR /&gt;re-joined node to AD&lt;BR /&gt;setup node as primary node with right personas&lt;/P&gt;
&lt;P&gt;started psn1 migration&lt;BR /&gt;exported certs&lt;BR /&gt;unjoined ad&lt;BR /&gt;deregistered from old cluster&lt;BR /&gt;shut nics&lt;BR /&gt;added nics to new psn1&lt;BR /&gt;changed ip addresses and added appropriate static routes&lt;BR /&gt;registered with new pan&lt;BR /&gt;setup proper personas&lt;BR /&gt;synced with new pan&lt;BR /&gt;joined to AD&lt;BR /&gt;*verified radius live logs to determine it is servicing clients&lt;/P&gt;
&lt;P&gt;...and continue process for additional PSNs &amp;amp; lastly move 2nd PAN (now new primary of old cluster)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2. Reduce any downtime or minimal impact during migration or split.&lt;/P&gt;
&lt;P&gt;PSN x 8; I want to split the current network and want to take out 4 PSN from this setup&lt;/P&gt;
&lt;P&gt;-As long as your NADs have entries and the ability to talk to all 8 PSNs for AAA purposes you should have no issues de-registering 4 PSNs from network 1 setup.&amp;nbsp; If you are concerned here are a couple of options that will aide in eliminating downtime:&lt;/P&gt;
&lt;P&gt;You can setup a AAA server group and put the 4 PSNs that will stay at the top (highest priorities), and the 4 you will remove at the bottom.&amp;nbsp;&amp;nbsp;See here for more: &lt;A href="https://www.cisco.com/c/en/us/support/docs/security-vpn/remote-authentication-dial-user-service-radius/200403-AAA-Server-Priority-explained-with-new-R.html" target="_blank"&gt;AAA Server Priority explained with New Radius Server Command Line - Cisco&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Another option is you could implement a long reauth timer/window via Authz profiles to ensure during the cutover that clients are not re-auth'ing inside your cutover window.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Few things to note:&amp;nbsp;&lt;/P&gt;
&lt;P&gt;every ip change restarts services&lt;BR /&gt;changing personas restarts services&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I would suggest engaging TAC too to ensure you are covered if you hit any bumps during the migration.&amp;nbsp; Good luck &amp;amp; HTH!&lt;/P&gt;</description>
    <pubDate>Mon, 05 Apr 2021 17:00:01 GMT</pubDate>
    <dc:creator>Mike.Cifelli</dc:creator>
    <dc:date>2021-04-05T17:00:01Z</dc:date>
    <item>
      <title>Split ISE distributed design to two separate deployments</title>
      <link>https://community.cisco.com/t5/network-access-control/split-ise-distributed-design-to-two-separate-deployments/m-p/4318058#M566581</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have ISE 2.7 distributed design deployed and working fine with PSN split in two time zones:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;PAN x 2&lt;/P&gt;&lt;P&gt;MnT x 2&lt;/P&gt;&lt;P&gt;PSN x 8&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I want to split the current network and want to take out 4 PSN from this setup and want to administer these four PSN by deploying 2 new PAN and MnT nodes. So the final ISE network design will have following two separate ISE entities:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Network 1 (old)&lt;/P&gt;&lt;P&gt;#########&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;PAN x 2&amp;nbsp;&lt;/P&gt;&lt;P&gt;MnT x 2&lt;/P&gt;&lt;P&gt;PSN x 4&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Network 2 (new)&lt;/P&gt;&lt;P&gt;###########&lt;/P&gt;&lt;P&gt;PAN x 2 (new ip address and license)&lt;/P&gt;&lt;P&gt;MnT x 2 ( new ip address and license&lt;/P&gt;&lt;P&gt;PSN x 4 ( using old ip address and license)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Key goal here is that:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1. Network 2 above must use existing configuration, certificates from Network 1 to avoid configuring everything from scratch&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2. Reduce any downtime or minimal impact during migration or split.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can some one please advise what is the best approach to achieve this ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 02 Apr 2021 23:14:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/split-ise-distributed-design-to-two-separate-deployments/m-p/4318058#M566581</guid>
      <dc:creator>Muli</dc:creator>
      <dc:date>2021-04-02T23:14:26Z</dc:date>
    </item>
    <item>
      <title>Re: Split ISE distributed design to two separate deployments</title>
      <link>https://community.cisco.com/t5/network-access-control/split-ise-distributed-design-to-two-separate-deployments/m-p/4318061#M566582</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1162359"&gt;@Muli&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;my suggestion:&lt;/P&gt;&lt;PRE&gt;1. backup your &lt;STRONG&gt;ISE Cube 01&lt;/STRONG&gt; (12x Nodes)&lt;BR /&gt;2. export the &lt;STRONG&gt;Certificate&lt;/STRONG&gt;&lt;BR /&gt;3. de-register your &lt;STRONG&gt;PSN 08&lt;/STRONG&gt;&lt;BR /&gt;Note: at this point &lt;STRONG&gt;PSN 08&lt;/STRONG&gt; has all the configuration of&amp;nbsp; your &lt;STRONG&gt;ISE Cube 01&lt;/STRONG&gt; and is a &lt;STRONG&gt;Standalone&lt;/STRONG&gt;&lt;BR /&gt;4. install the &lt;STRONG&gt;new Nodes&lt;/STRONG&gt; (8x Nodes) on the &lt;STRONG&gt;new Site&lt;/STRONG&gt;&lt;BR /&gt;5. register the &lt;STRONG&gt;new Nodes&lt;/STRONG&gt; to &lt;STRONG&gt;PSN 08&lt;/STRONG&gt;&lt;BR /&gt;Note: at this point &lt;STRONG&gt;PSN 08&lt;/STRONG&gt; is the &lt;STRONG&gt;Primary PAN&lt;/STRONG&gt; of the &lt;STRONG&gt;ISE Cube 02&lt;/STRONG&gt;&lt;BR /&gt;6. promote one of the &lt;STRONG&gt;new Nodes&lt;/STRONG&gt; to &lt;STRONG&gt;Primary PAN&lt;/STRONG&gt;&lt;BR /&gt;7. install &lt;STRONG&gt;certificates&lt;/STRONG&gt;&lt;BR /&gt;8. backup the &lt;STRONG&gt;ISE Cube 02&lt;/STRONG&gt;&lt;BR /&gt;9. start de-register &lt;STRONG&gt;PSNs&lt;/STRONG&gt; from &lt;STRONG&gt;ISE Cube 01&lt;/STRONG&gt; (05, 06 and 07)&lt;BR /&gt;10. backup the &lt;STRONG&gt;ISE CUBE 01&lt;/STRONG&gt;&lt;/PRE&gt;&lt;P&gt;&lt;BR /&gt;Hope this helps !!!&lt;/P&gt;</description>
      <pubDate>Fri, 02 Apr 2021 23:55:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/split-ise-distributed-design-to-two-separate-deployments/m-p/4318061#M566582</guid>
      <dc:creator>Marcelo Morais</dc:creator>
      <dc:date>2021-04-02T23:55:32Z</dc:date>
    </item>
    <item>
      <title>Re: Split ISE distributed design to two separate deployments</title>
      <link>https://community.cisco.com/t5/network-access-control/split-ise-distributed-design-to-two-separate-deployments/m-p/4318786#M566600</link>
      <description>&lt;P&gt;Can some one please advise what is the best approach to achieve this ?&lt;/P&gt;
&lt;P&gt;1. Network 2 above must use existing configuration, certificates from Network 1 to avoid configuring everything from scratch&lt;/P&gt;
&lt;P&gt;Here is a rough overview of steps I have taken to migrate from one cluster to another (note: hosts were VMs, and used the same hostnames):&lt;/P&gt;
&lt;P&gt;Generate config backup from network 1 (old) setup PAN*&lt;/P&gt;
&lt;P&gt;Old cluster:&lt;/P&gt;
&lt;P&gt;disabled pan failover&lt;BR /&gt;promoted pan2 to primary&lt;BR /&gt;unjoined pan1 from AD&lt;BR /&gt;exported certificates&lt;BR /&gt;deregistered pan1 from cluster&lt;/P&gt;
&lt;P&gt;enabled nic on new pan1 in 2.7 cluster&lt;BR /&gt;shut nics on old pan1 in 2.4 cluster&lt;BR /&gt;changed IP address on new pan on nic 1 (services restart)&lt;BR /&gt;added nic 2 and added underlay ip address (services restart)&lt;BR /&gt;added static routes via CLI for additional nic &lt;BR /&gt;started system restore&amp;nbsp;&lt;BR /&gt;kicked off restore &amp;amp; successfully worked ~35 minutes for this instance&lt;BR /&gt;re-joined node to AD&lt;BR /&gt;setup node as primary node with right personas&lt;/P&gt;
&lt;P&gt;started psn1 migration&lt;BR /&gt;exported certs&lt;BR /&gt;unjoined ad&lt;BR /&gt;deregistered from old cluster&lt;BR /&gt;shut nics&lt;BR /&gt;added nics to new psn1&lt;BR /&gt;changed ip addresses and added appropriate static routes&lt;BR /&gt;registered with new pan&lt;BR /&gt;setup proper personas&lt;BR /&gt;synced with new pan&lt;BR /&gt;joined to AD&lt;BR /&gt;*verified radius live logs to determine it is servicing clients&lt;/P&gt;
&lt;P&gt;...and continue process for additional PSNs &amp;amp; lastly move 2nd PAN (now new primary of old cluster)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2. Reduce any downtime or minimal impact during migration or split.&lt;/P&gt;
&lt;P&gt;PSN x 8; I want to split the current network and want to take out 4 PSN from this setup&lt;/P&gt;
&lt;P&gt;-As long as your NADs have entries and the ability to talk to all 8 PSNs for AAA purposes you should have no issues de-registering 4 PSNs from network 1 setup.&amp;nbsp; If you are concerned here are a couple of options that will aide in eliminating downtime:&lt;/P&gt;
&lt;P&gt;You can setup a AAA server group and put the 4 PSNs that will stay at the top (highest priorities), and the 4 you will remove at the bottom.&amp;nbsp;&amp;nbsp;See here for more: &lt;A href="https://www.cisco.com/c/en/us/support/docs/security-vpn/remote-authentication-dial-user-service-radius/200403-AAA-Server-Priority-explained-with-new-R.html" target="_blank"&gt;AAA Server Priority explained with New Radius Server Command Line - Cisco&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Another option is you could implement a long reauth timer/window via Authz profiles to ensure during the cutover that clients are not re-auth'ing inside your cutover window.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Few things to note:&amp;nbsp;&lt;/P&gt;
&lt;P&gt;every ip change restarts services&lt;BR /&gt;changing personas restarts services&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I would suggest engaging TAC too to ensure you are covered if you hit any bumps during the migration.&amp;nbsp; Good luck &amp;amp; HTH!&lt;/P&gt;</description>
      <pubDate>Mon, 05 Apr 2021 17:00:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/split-ise-distributed-design-to-two-separate-deployments/m-p/4318786#M566600</guid>
      <dc:creator>Mike.Cifelli</dc:creator>
      <dc:date>2021-04-05T17:00:01Z</dc:date>
    </item>
  </channel>
</rss>

