<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE upgrade question in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-upgrade-question/m-p/4862136#M582474</link>
    <description>&lt;P&gt;one small addition, your base license which is perpetual (permanent) now will change to essential (term based) and that term expires on oct 31 2023 I think, and you may need to invest in your license term renewal. verify that with licensing before hand and make sure you account of upcoming cost before upgrade. you may want to keep your cisco AM/SE involved.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 26 Jun 2023 04:41:37 GMT</pubDate>
    <dc:creator>Ambuj M</dc:creator>
    <dc:date>2023-06-26T04:41:37Z</dc:date>
    <item>
      <title>ISE upgrade question</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-upgrade-question/m-p/4861429#M582431</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I have 2 clusters, with two nodes each (PAN, MNT, PSN) in version 2.6 and I will upgrade it to version 3.1 using Backup and Restore method, smart licensing is currently in use.&lt;BR /&gt;the licenses are:&lt;BR /&gt;cluster1: Tacacs (2), VM Small (2)&lt;BR /&gt;cluster2: VM Small (2)&lt;/P&gt;&lt;P&gt;I read the solution proposed by &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/158532"&gt;@Arne Bier&lt;/a&gt;&amp;nbsp;, very clear thanks &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;BR /&gt;&lt;A href="https://community.cisco.com/t5/network-access-control/easiest-way-to-upgrade-a-two-node-deployment-2-4-to-3-0/td-p/4596302" target="_blank"&gt;https://community.cisco.com/t5/network-access-control/easiest-way-to-upgrade-a-two-node-deployment-2-4-to-3-0/td-p/4596302&lt;/A&gt;&lt;/P&gt;&lt;P&gt;My questions :&lt;BR /&gt;a- should I use the ISE-3.1.0.518b-virtual-SNS3615-SNS3655-600.ova (for Small or Medium) ova?&lt;BR /&gt;b- can I install the other ova, example: for Medium or Large, or for Large? or am I limited by the VM Small license?&lt;BR /&gt;c- once the installation is complete, is there an action to do so that the licenses work or is it automatically recognized?&lt;/P&gt;&lt;P&gt;Many thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 23 Jun 2023 13:48:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-upgrade-question/m-p/4861429#M582431</guid>
      <dc:creator>cisco.13</dc:creator>
      <dc:date>2023-06-23T13:48:08Z</dc:date>
    </item>
    <item>
      <title>Re: ISE upgrade question</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-upgrade-question/m-p/4861618#M582440</link>
      <description>&lt;P&gt;The -600.ova is a good choice for a small or medium all in one node type. It creates a 600GB thick provisioned disk. The ova import will also guide you and prompt you. Unless you have a very long log retention policy, 600GB should be fine.&amp;nbsp;&lt;BR /&gt;The VM licensing is based on the SNS type you selected when you import the ova. The wizard will ask you. After install you have 90 day eval license.&amp;nbsp;&lt;BR /&gt;You have to configure smart licensing in the ISE gui and paste in a key from the smart licensing portal. That activates Smart Licensing.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 23 Jun 2023 20:57:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-upgrade-question/m-p/4861618#M582440</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2023-06-23T20:57:44Z</dc:date>
    </item>
    <item>
      <title>Re: ISE upgrade question</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-upgrade-question/m-p/4861621#M582441</link>
      <description>&lt;P&gt;Thank you &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/158532"&gt;@Arne Bier&lt;/a&gt;&lt;/P&gt;&lt;P&gt;SNS type, it's what ? do you have documentation please?&lt;BR /&gt;so I can activate the licenses (Tacacs, VM) before the shutdown of the old VM?&lt;/P&gt;&lt;P&gt;Thanks a lot&lt;/P&gt;</description>
      <pubDate>Fri, 23 Jun 2023 21:25:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-upgrade-question/m-p/4861621#M582441</guid>
      <dc:creator>cisco.13</dc:creator>
      <dc:date>2023-06-23T21:25:31Z</dc:date>
    </item>
    <item>
      <title>Re: ISE upgrade question</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-upgrade-question/m-p/4861657#M582442</link>
      <description>&lt;P&gt;SNS stands for Secure Network Server and it refers to ISE hardware appliances. Each appliance model has a different resources set. The .ova images are based on those hardware appliances, check out this link please:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/sns3600hig/b_sns_3600_install/b_sns_3600_install_chapter_00.html" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/ise/sns3600hig/b_sns_3600_install/b_sns_3600_install_chapter_00.html&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;Regarding the smart licenses, you have to work with Cisco licensing team asking them to convert the existing licenses to the new licenses model which is required for ISE 3.1. The conversion would affect the existing base, plus, and apex licenses, TACACS licenses don't need to be converted. The licenses conversion can be done in advance or after the upgrade is completed, the recommendation would be to raise the case with Cisco ahead of the upgrade and let them know when you need the licenses to be converted, you can also call them right after the upgrade is done to convert the licenses.&lt;/P&gt;
&lt;P&gt;You would need to do the same for the VM licenses, the new model is now called VM Common which doesn't look at the VM size anymore.&lt;/P&gt;
&lt;P&gt;Not doing the VM licenses conversion in time wouldn't affect the deployment functionality, you would only get some warnings about it, however the features licenses will. Although you might run your deployment in eval mode which give you 90 days, but I think that is still gonna be for 100 nodes only.&lt;/P&gt;</description>
      <pubDate>Sat, 24 Jun 2023 01:52:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-upgrade-question/m-p/4861657#M582442</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2023-06-24T01:52:13Z</dc:date>
    </item>
    <item>
      <title>Re: ISE upgrade question</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-upgrade-question/m-p/4861849#M582461</link>
      <description>&lt;P&gt;&lt;SPAN class=""&gt;Hello,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;Thank you &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/158532"&gt;@Arne Bier&lt;/a&gt;&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/284594"&gt;@Aref Alsouqi&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;So if I understood, when installing the ova: ISE-3.1.0.518b-virtual-SNS3615-&lt;STRONG&gt;SNS3655&lt;/STRONG&gt;-600.ova, I can choose &lt;STRONG&gt;SNS3655&lt;/STRONG&gt; if the resources of my ESX (CPU, RAM, Disk ..) allows it? &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;Ok for my licenses? t&lt;/SPAN&gt;&lt;SPAN class=""&gt;he resource of 3615 which corresponds to the Small model, and t&lt;/SPAN&gt;&lt;SPAN class=""&gt;he resources of SNS 3655 corresponds to the Medium model&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;Table 2. OVA Template Reservations: &lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/3-1/install_guide/b_ise_InstallationGuide31/b_ise_InstallationGuide31_chapter_2.html#vmwarevmrequirements" target="_blank" rel="noopener"&gt;https://www.cisco.com/c/en/us/td/docs/security/ise/3-1/install_guide/b_ise_InstallationGuide31/b_ise_InstallationGuide31_chapter_2.html#vmwarevmrequirements&lt;/A&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;Cisco ISE Hardware Appliances: &lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/performance_and_scalability/b_ise_perf_and_scale.html#reference_mry_drh_m5b" target="_blank" rel="noopener"&gt;https://www.cisco.com/c/en/us/td/docs/security/ise/performance_and_scalability/b_ise_perf_and_scale.html#reference_mry_drh_m5b&lt;/A&gt; Thank you.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;Thank you&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 24 Jun 2023 18:38:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-upgrade-question/m-p/4861849#M582461</guid>
      <dc:creator>cisco.13</dc:creator>
      <dc:date>2023-06-24T18:38:12Z</dc:date>
    </item>
    <item>
      <title>Re: ISE upgrade question</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-upgrade-question/m-p/4861867#M582462</link>
      <description>&lt;P&gt;If you ask Cisco licensing team to convert your existing VM licenses to the new model (VM Common) then you can use them on a small, medium, or large VM, in the other words the new VM licenses don't look at the VM resources any longer.&lt;/P&gt;</description>
      <pubDate>Sat, 24 Jun 2023 20:36:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-upgrade-question/m-p/4861867#M582462</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2023-06-24T20:36:48Z</dc:date>
    </item>
    <item>
      <title>Re: ISE upgrade question</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-upgrade-question/m-p/4861879#M582463</link>
      <description>&lt;P&gt;Hello,&amp;nbsp;&lt;/P&gt;&lt;P&gt;In this case I will choose SNS3655 (better performance) since I have the required resources on my ESX&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 24 Jun 2023 21:21:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-upgrade-question/m-p/4861879#M582463</guid>
      <dc:creator>cisco.13</dc:creator>
      <dc:date>2023-06-24T21:21:52Z</dc:date>
    </item>
    <item>
      <title>Re: ISE upgrade question</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-upgrade-question/m-p/4862087#M582468</link>
      <description>&lt;P&gt;That makes sense.&lt;/P&gt;</description>
      <pubDate>Sun, 25 Jun 2023 23:54:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-upgrade-question/m-p/4862087#M582468</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2023-06-25T23:54:39Z</dc:date>
    </item>
    <item>
      <title>Re: ISE upgrade question</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-upgrade-question/m-p/4862128#M582472</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Regarding the upgrade "Backup and Restore method" should I generate a backup file on the secondary node (when I deregister my secondary node) and restore it on the future secondary node or I use the backup primary one for both nodes?&lt;/P&gt;&lt;P&gt;at the beginning of the operation to avoid IP address duplication, you use a temporary IP?&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 26 Jun 2023 03:49:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-upgrade-question/m-p/4862128#M582472</guid>
      <dc:creator>cisco.13</dc:creator>
      <dc:date>2023-06-26T03:49:15Z</dc:date>
    </item>
    <item>
      <title>Re: ISE upgrade question</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-upgrade-question/m-p/4862136#M582474</link>
      <description>&lt;P&gt;one small addition, your base license which is perpetual (permanent) now will change to essential (term based) and that term expires on oct 31 2023 I think, and you may need to invest in your license term renewal. verify that with licensing before hand and make sure you account of upcoming cost before upgrade. you may want to keep your cisco AM/SE involved.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 26 Jun 2023 04:41:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-upgrade-question/m-p/4862136#M582474</guid>
      <dc:creator>Ambuj M</dc:creator>
      <dc:date>2023-06-26T04:41:37Z</dc:date>
    </item>
    <item>
      <title>Re: ISE upgrade question</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-upgrade-question/m-p/4862219#M582479</link>
      <description>&lt;P&gt;Yes you would deploy the new nodes with different IP addresses, and then you would restore the configuration from the normal primary configuration backup. If you restore the backup without including the "include-adeos" option ISE will only restore the application configuration backup, so it won't restore the hostname, IP addresses etc. However, if you want to restore everything including those low level configs then you can drop "include-adeos" at the very end of the restore command line. In that case you would need to shut down or disconnect the old node that you are restoring from the network before the restore to avoid duplicated IP addresses on the network.&lt;/P&gt;</description>
      <pubDate>Mon, 26 Jun 2023 08:44:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-upgrade-question/m-p/4862219#M582479</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2023-06-26T08:44:32Z</dc:date>
    </item>
    <item>
      <title>Re: ISE upgrade question</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-upgrade-question/m-p/4862251#M582480</link>
      <description>&lt;P&gt;Thank you very much for your help&lt;/P&gt;</description>
      <pubDate>Mon, 26 Jun 2023 09:45:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-upgrade-question/m-p/4862251#M582480</guid>
      <dc:creator>cisco.13</dc:creator>
      <dc:date>2023-06-26T09:45:27Z</dc:date>
    </item>
    <item>
      <title>Re: ISE upgrade question</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-upgrade-question/m-p/4862662#M582497</link>
      <description>&lt;P&gt;Hi, &lt;SPAN class=""&gt;it's me again &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;when did I choose SNS3655? &lt;/SPAN&gt;&lt;SPAN class=""&gt;I just imported the ova: ISE-3.1.0.518b-virtual-SNS3615-SNS3655-600.ova, and I see "Small" or "Medium", &lt;/SPAN&gt;&lt;SPAN class=""&gt;is it "Medium"? &lt;/SPAN&gt;&lt;SPAN class=""&gt;or do I have to choose when configuring&amp;nbsp;the basic parameters in CLI? &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;No problem when I import a configuration sns3615 (old deployment) in new deployment sns3655 ?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;Thank you !&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 26 Jun 2023 16:55:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-upgrade-question/m-p/4862662#M582497</guid>
      <dc:creator>cisco.13</dc:creator>
      <dc:date>2023-06-26T16:55:18Z</dc:date>
    </item>
    <item>
      <title>Re: ISE upgrade question</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-upgrade-question/m-p/4862679#M582499</link>
      <description>&lt;P&gt;That will depend on how many vCPUs and RAM you will be assigning. The small deployment recommendation would be 16x vCPU with 32 GB of RAM, and the medium is 24x vCPU with 96 GB of RAM. The hard disk requirement changes based on the roles that ISE will be running and how many endpoints that node will be serving. One thing I would keep in mind is that the hard disk size can't be changed after ISE is deployed, and to increase it you have to redeploy the image from the scratch. For the backup restore you should be good to go to restore the old backup on the new deployment.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ArefAlsouqi_0-1687800119139.png" style="width: 983px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/188630i4D753C8879F37A9E/image-dimensions/983x253?v=v2" width="983" height="253" role="button" title="ArefAlsouqi_0-1687800119139.png" alt="ArefAlsouqi_0-1687800119139.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ArefAlsouqi_1-1687800145468.png" style="width: 971px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/188631i2C5A3F748CBCC331/image-dimensions/971x182?v=v2" width="971" height="182" role="button" title="ArefAlsouqi_1-1687800145468.png" alt="ArefAlsouqi_1-1687800145468.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/3-1/install_guide/b_ise_InstallationGuide31/b_ise_InstallationGuide31_chapter_2.html" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/ise/3-1/install_guide/b_ise_InstallationGuide31/b_ise_InstallationGuide31_chapter_2.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 26 Jun 2023 17:26:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-upgrade-question/m-p/4862679#M582499</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2023-06-26T17:26:23Z</dc:date>
    </item>
  </channel>
</rss>

