<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Change ISE personas without configuration loss in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/change-ise-personas-without-configuration-loss/m-p/4811524#M581054</link>
    <description>&lt;P&gt;Hi Marcelo Morais,&lt;/P&gt;
&lt;P&gt;Thank you so much for your advice. We use ISE 3.1 so as per document we can have up to 6 PSNs for medium deployment. After your step 6 I can freely add any more PSN up to 6, is that correct ?&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;An&lt;/P&gt;</description>
    <pubDate>Tue, 11 Apr 2023 01:47:02 GMT</pubDate>
    <dc:creator>nupagazi</dc:creator>
    <dc:date>2023-04-11T01:47:02Z</dc:date>
    <item>
      <title>Change ISE personas without configuration loss</title>
      <link>https://community.cisco.com/t5/network-access-control/change-ise-personas-without-configuration-loss/m-p/4810068#M581011</link>
      <description>&lt;P&gt;Hello Team,&lt;/P&gt;
&lt;P&gt;We currently deploy 2 ISE appliances 3615 with HA as in the attache image. Now we want to move to distributed deployment by adding 4 ISE VMs: 2 of VMs act as the PAN &amp;amp; Mnt (HA), 2 VMs act as PSN together with current 2 x 3615 i.e change personas from PAN, Mnt &amp;amp; PSN to PSN only (attached image). We want to minimize the effort for changing by following steps:&lt;/P&gt;
&lt;P&gt;1. Shutdown the secondary appliance&lt;/P&gt;
&lt;P&gt;2. Add first VM as secondary PAN to the current primary appliance PAN+MnT+PSN&lt;/P&gt;
&lt;P&gt;3. add second VM as PSN to current group of primary appliance PAN+MnT+PSN&lt;/P&gt;
&lt;P&gt;4. Change the current primary appliance PAN+MnT+PSN to PSN only&lt;/P&gt;
&lt;P&gt;5. Add third VM as secondary PAN&lt;/P&gt;
&lt;P&gt;6. Add 4th VM as PSN only to the psn group&lt;BR /&gt;7. Turn on the secondary appliance and change it to PSN only and join current psn group&lt;/P&gt;
&lt;P&gt;Would you please advise the above steps works and all policies are remained as before moving ?&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;An&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 07 Apr 2023 10:37:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/change-ise-personas-without-configuration-loss/m-p/4810068#M581011</guid>
      <dc:creator>nupagazi</dc:creator>
      <dc:date>2023-04-07T10:37:14Z</dc:date>
    </item>
    <item>
      <title>Re: Change ISE personas without configuration loss</title>
      <link>https://community.cisco.com/t5/network-access-control/change-ise-personas-without-configuration-loss/m-p/4810071#M581012</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="nupagazi_0-1680863879841.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/181160iBC4303622C43CE1D/image-size/medium?v=v2&amp;amp;px=400" role="button" title="nupagazi_0-1680863879841.png" alt="nupagazi_0-1680863879841.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 07 Apr 2023 10:38:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/change-ise-personas-without-configuration-loss/m-p/4810071#M581012</guid>
      <dc:creator>nupagazi</dc:creator>
      <dc:date>2023-04-07T10:38:07Z</dc:date>
    </item>
    <item>
      <title>Re: Change ISE personas without configuration loss</title>
      <link>https://community.cisco.com/t5/network-access-control/change-ise-personas-without-configuration-loss/m-p/4810180#M581017</link>
      <description>&lt;P&gt;Before you turn off the secondary appliance in step one, change it from PAN + MNT + PSN to PSN only. No need to turn off this appliance and turn it back on.&lt;BR /&gt;Only concern in your way is once you completed step 5, Deployment will not let you perform Step 7 as distributed ISE deployments will only allow 2 PAN's and 2 MNT's&lt;/P&gt;</description>
      <pubDate>Fri, 07 Apr 2023 14:49:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/change-ise-personas-without-configuration-loss/m-p/4810180#M581017</guid>
      <dc:creator>Sri Harsha Dasari</dc:creator>
      <dc:date>2023-04-07T14:49:34Z</dc:date>
    </item>
    <item>
      <title>Re: Change ISE personas without configuration loss</title>
      <link>https://community.cisco.com/t5/network-access-control/change-ise-personas-without-configuration-loss/m-p/4810897#M581032</link>
      <description>&lt;P&gt;Hi Sri Harsha Dasari,&lt;/P&gt;
&lt;P&gt;Thank you for your comment.&amp;nbsp; I think for distrbuted deployment we can have 5 PSN (attached), am I correct ?&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="nupagazi_0-1681091454378.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/181320i077C01636C834625/image-size/medium?v=v2&amp;amp;px=400" role="button" title="nupagazi_0-1681091454378.png" alt="nupagazi_0-1681091454378.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;An&lt;/P&gt;</description>
      <pubDate>Mon, 10 Apr 2023 01:51:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/change-ise-personas-without-configuration-loss/m-p/4810897#M581032</guid>
      <dc:creator>nupagazi</dc:creator>
      <dc:date>2023-04-10T01:51:09Z</dc:date>
    </item>
    <item>
      <title>Re: Change ISE personas without configuration loss</title>
      <link>https://community.cisco.com/t5/network-access-control/change-ise-personas-without-configuration-loss/m-p/4811202#M581045</link>
      <description>&lt;P class="lia-align-justify"&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1044427"&gt;@nupagazi&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;please take a look at:&amp;nbsp;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/performance_and_scalability/b_ise_perf_and_scale.html" target="_blank" rel="noopener"&gt;Performance and Scalability Guide for Cisco Identity Services Engine&lt;/A&gt;., search for &lt;STRONG&gt;Different Types of Cisco ISE Deployment&lt;/STRONG&gt;, in your case you have a &lt;STRONG&gt;Small Deployment&lt;/STRONG&gt; and want to go to a &lt;STRONG&gt;Medium Deployment&lt;/STRONG&gt; (up to &lt;STRONG&gt;6x PSNs&lt;/STRONG&gt; for &lt;STRONG&gt;ISE 3.0+&lt;/STRONG&gt;).&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;Note: about the steps you can:&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;1. generate a &lt;STRONG&gt;Backup: Config&lt;/STRONG&gt; and &lt;STRONG&gt;Oper&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;2. remove the &lt;STRONG&gt;SPAN &amp;amp; SMnT&lt;/STRONG&gt;&amp;nbsp;from the &lt;STRONG&gt;Secondary Appliance&lt;/STRONG&gt;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;3. add the &lt;STRONG&gt;1st VM&lt;/STRONG&gt; as &lt;STRONG&gt;SPAN &amp;amp; SMnT&lt;/STRONG&gt;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;4. at &lt;STRONG&gt;1st VM&lt;/STRONG&gt;&amp;nbsp;"promote" the &lt;STRONG&gt;SPAN &amp;amp; SMnT&lt;/STRONG&gt; to &lt;STRONG&gt;PPAN &amp;amp; PMnT&lt;/STRONG&gt;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;5. remove the &lt;STRONG&gt;SPAN &amp;amp; SMnT&lt;/STRONG&gt; from the &lt;STRONG&gt;Primary Appliance&lt;/STRONG&gt;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;6. add the &lt;STRONG&gt;2nd VM&lt;/STRONG&gt; as &lt;STRONG&gt;SPAN &amp;amp; SMnT&lt;/STRONG&gt;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;At the end of the day:&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&lt;STRONG&gt;Primary Appliance: PSN&lt;/STRONG&gt;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&lt;STRONG&gt;Secondary Appliance: PSN&lt;/STRONG&gt;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&lt;STRONG&gt;1st VM: PPAN &amp;amp; PMnT&lt;/STRONG&gt;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&lt;STRONG&gt;2nd VM: SPAN &amp;amp; SMnT&lt;/STRONG&gt;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;Hope this helps !!!&lt;/P&gt;</description>
      <pubDate>Mon, 10 Apr 2023 14:02:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/change-ise-personas-without-configuration-loss/m-p/4811202#M581045</guid>
      <dc:creator>Marcelo Morais</dc:creator>
      <dc:date>2023-04-10T14:02:42Z</dc:date>
    </item>
    <item>
      <title>Re: Change ISE personas without configuration loss</title>
      <link>https://community.cisco.com/t5/network-access-control/change-ise-personas-without-configuration-loss/m-p/4811524#M581054</link>
      <description>&lt;P&gt;Hi Marcelo Morais,&lt;/P&gt;
&lt;P&gt;Thank you so much for your advice. We use ISE 3.1 so as per document we can have up to 6 PSNs for medium deployment. After your step 6 I can freely add any more PSN up to 6, is that correct ?&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;An&lt;/P&gt;</description>
      <pubDate>Tue, 11 Apr 2023 01:47:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/change-ise-personas-without-configuration-loss/m-p/4811524#M581054</guid>
      <dc:creator>nupagazi</dc:creator>
      <dc:date>2023-04-11T01:47:02Z</dc:date>
    </item>
    <item>
      <title>Re: Change ISE personas without configuration loss</title>
      <link>https://community.cisco.com/t5/network-access-control/change-ise-personas-without-configuration-loss/m-p/4811951#M581074</link>
      <description>&lt;P class="lia-align-justify"&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1044427"&gt;@nupagazi&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;yes, that's correct ... after &lt;STRONG&gt;Step 6&lt;/STRONG&gt;, you can add up to &lt;STRONG&gt;6x PSNs&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;Hope this helps !!!&lt;/P&gt;</description>
      <pubDate>Tue, 11 Apr 2023 14:34:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/change-ise-personas-without-configuration-loss/m-p/4811951#M581074</guid>
      <dc:creator>Marcelo Morais</dc:creator>
      <dc:date>2023-04-11T14:34:52Z</dc:date>
    </item>
    <item>
      <title>Re: Change ISE personas without configuration loss</title>
      <link>https://community.cisco.com/t5/network-access-control/change-ise-personas-without-configuration-loss/m-p/4816372#M581227</link>
      <description>&lt;P&gt;Hi Marcelo Morais,&lt;/P&gt;
&lt;P&gt;Thank you so much for your advice.&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;An&lt;/P&gt;</description>
      <pubDate>Tue, 18 Apr 2023 01:25:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/change-ise-personas-without-configuration-loss/m-p/4816372#M581227</guid>
      <dc:creator>nupagazi</dc:creator>
      <dc:date>2023-04-18T01:25:07Z</dc:date>
    </item>
  </channel>
</rss>

