<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ISE 3.1 deployment migration - Small PSN on Medium PAN in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-3-1-deployment-migration-small-psn-on-medium-pan/m-p/4912047#M583662</link>
    <description>&lt;DIV class=""&gt;&lt;P class=""&gt;Hi All,&lt;/P&gt;&lt;P class=""&gt;I'll soon be needing to move away from our two-node small ISE VM deployment (currently running 3.1) in favour of a medium deployment (Still on 3.1 for now). I believe I have an understanding of the actual migration process once the new VMs have been built (thanks to the very helpful information from&amp;nbsp;&lt;A href="https://community.cisco.com/t5/user/viewprofilepage/user-id/330320" target="_blank" rel="noopener"&gt;@Milos_Jovanovic&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;found here&amp;nbsp;&lt;A href="http://&amp;nbsp;https://community.cisco.com/t5/network-access-control/move-from-small-2-node-ise-deployment-to-medium-large-deployment/td-p/4486348" target="_self"&gt;&amp;nbsp;https://community.cisco.com/t5/network-access-control/move-from-small-2-node-ise-deployment-to-medium-large-deployment/td-p/4486348&lt;/A&gt;&amp;nbsp;&amp;nbsp;), but have listed steps here for verification in case my understanding is incorrect:&lt;/P&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;1. Install ISE on two standalone nodes using Medium VM OVA - ensure PKI certs in place&lt;DIV class=""&gt;2. From existing deployment remove Admin and MnT roles from secondary PAN (leaving PSN in place)&lt;/DIV&gt;&lt;DIV class=""&gt;3. Join one of the new nodes to the existing deployment as a secondary PAN running Admin an MnT&lt;/DIV&gt;&lt;DIV class=""&gt;4. Join (new) secondary node to AD&lt;/DIV&gt;&lt;DIV class=""&gt;5. Promote (new) secondary to primary PAN&lt;/DIV&gt;&lt;DIV class=""&gt;6. Remove Admin and MnT roles from what is now the secondary PAN (leaving PSN in place)&lt;/DIV&gt;&lt;DIV class=""&gt;7. Join the second of the new standalone nodes as a secondary PAN and MnT&lt;/DIV&gt;&lt;DIV class=""&gt;8. Join the new secondary PAN to AD&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;My questions are:&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;Should I be restoring config/operational backups to the new node before joining it back to the existing deployment? (e.g between steps 2 and 3) - I've only ever done ISE upgrades, where this has been a necessary step. I presume because the new node/s is re-joining the same deployment (initially as a secondary PAN) it will simply sync up and therefore isn't required?&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;The PSN's left from the existing deployment were built with a small/medium (600Gb) OVA, but the "Small" option was selected in VMWare, do these need to be re-imaged and built specifically with the Medium VM option to be properly part of the deployment (and function correctly), or will the PSN's be fine as they are?&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;Thanks&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;</description>
    <pubDate>Fri, 25 Aug 2023 14:04:27 GMT</pubDate>
    <dc:creator>stubush</dc:creator>
    <dc:date>2023-08-25T14:04:27Z</dc:date>
    <item>
      <title>ISE 3.1 deployment migration - Small PSN on Medium PAN</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-3-1-deployment-migration-small-psn-on-medium-pan/m-p/4912047#M583662</link>
      <description>&lt;DIV class=""&gt;&lt;P class=""&gt;Hi All,&lt;/P&gt;&lt;P class=""&gt;I'll soon be needing to move away from our two-node small ISE VM deployment (currently running 3.1) in favour of a medium deployment (Still on 3.1 for now). I believe I have an understanding of the actual migration process once the new VMs have been built (thanks to the very helpful information from&amp;nbsp;&lt;A href="https://community.cisco.com/t5/user/viewprofilepage/user-id/330320" target="_blank" rel="noopener"&gt;@Milos_Jovanovic&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;found here&amp;nbsp;&lt;A href="http://&amp;nbsp;https://community.cisco.com/t5/network-access-control/move-from-small-2-node-ise-deployment-to-medium-large-deployment/td-p/4486348" target="_self"&gt;&amp;nbsp;https://community.cisco.com/t5/network-access-control/move-from-small-2-node-ise-deployment-to-medium-large-deployment/td-p/4486348&lt;/A&gt;&amp;nbsp;&amp;nbsp;), but have listed steps here for verification in case my understanding is incorrect:&lt;/P&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;1. Install ISE on two standalone nodes using Medium VM OVA - ensure PKI certs in place&lt;DIV class=""&gt;2. From existing deployment remove Admin and MnT roles from secondary PAN (leaving PSN in place)&lt;/DIV&gt;&lt;DIV class=""&gt;3. Join one of the new nodes to the existing deployment as a secondary PAN running Admin an MnT&lt;/DIV&gt;&lt;DIV class=""&gt;4. Join (new) secondary node to AD&lt;/DIV&gt;&lt;DIV class=""&gt;5. Promote (new) secondary to primary PAN&lt;/DIV&gt;&lt;DIV class=""&gt;6. Remove Admin and MnT roles from what is now the secondary PAN (leaving PSN in place)&lt;/DIV&gt;&lt;DIV class=""&gt;7. Join the second of the new standalone nodes as a secondary PAN and MnT&lt;/DIV&gt;&lt;DIV class=""&gt;8. Join the new secondary PAN to AD&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;My questions are:&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;Should I be restoring config/operational backups to the new node before joining it back to the existing deployment? (e.g between steps 2 and 3) - I've only ever done ISE upgrades, where this has been a necessary step. I presume because the new node/s is re-joining the same deployment (initially as a secondary PAN) it will simply sync up and therefore isn't required?&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;The PSN's left from the existing deployment were built with a small/medium (600Gb) OVA, but the "Small" option was selected in VMWare, do these need to be re-imaged and built specifically with the Medium VM option to be properly part of the deployment (and function correctly), or will the PSN's be fine as they are?&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;Thanks&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Fri, 25 Aug 2023 14:04:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-3-1-deployment-migration-small-psn-on-medium-pan/m-p/4912047#M583662</guid>
      <dc:creator>stubush</dc:creator>
      <dc:date>2023-08-25T14:04:27Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 3.1 deployment migration - Small PSN on Medium PAN</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-3-1-deployment-migration-small-psn-on-medium-pan/m-p/4912414#M583678</link>
      <description>&lt;P&gt;It helps to have a picture of your final state noting which nodes were the originals.&lt;/P&gt;
&lt;P&gt;If you had a load balancer(s), you could simply add 2 PSNs to your existing deployment, redirect the RADIUS requests to the new PSNs and turn off PSN services on your original 2 nodes. But it doesn't sound like you have load balancer(s) &lt;EM&gt;and&lt;/EM&gt; you want to preserve the existing PSN IPs because you do not want to update the AAA server IPs on all of your network devices. That is the real issue making this more complicated because you need to move the roles around.&lt;/P&gt;
&lt;P&gt;You do not need to perform a backup+restore although you should definitely make a backup just in case! When you elect your new node as the secondary (step 3) ISE will synchronize the configuration with it so no restore should be necessary. Just wait for the sync to complete before continuing.&lt;/P&gt;
&lt;P&gt;The Small/Medium OVA is fine for either. The issue is not disk space (600GB) but CPU &amp;amp; RAM. After moving to your Medium deployment, your PSNs will be Smalls. That may be fine depending on your scale because you have not provided any details about &lt;EM&gt;Why&lt;/EM&gt; you are moving to a Medium-sized deployment with respect to your &lt;EM&gt;Scale&lt;/EM&gt; needs. See &lt;A href="https://cs.co/ise-scale" target="_blank"&gt;https://cs.co/ise-scale&lt;/A&gt; for Small vs Medium PSN performance/scale. If you do want to update from Small to Medium you should be able to shutdown each PSN, adjust the VM sizing in VMware and power on and you will have the increased CPU and RAM for your ISE node.&lt;/P&gt;</description>
      <pubDate>Sat, 26 Aug 2023 13:51:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-3-1-deployment-migration-small-psn-on-medium-pan/m-p/4912414#M583678</guid>
      <dc:creator>thomas</dc:creator>
      <dc:date>2023-08-26T13:51:34Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 3.1 deployment migration - Small PSN on Medium PAN</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-3-1-deployment-migration-small-psn-on-medium-pan/m-p/4913619#M583699</link>
      <description>&lt;P&gt;Thomas, thanks for the reply.&lt;/P&gt;&lt;P&gt;Unfortunately no load balancer in the environment currently, we only have the two nodes which are both running all roles. By the end of the migration these two original nodes will be the PSNs. As you have mentioned, wanted to take this approach as all our NAD's are currently pointing at these nodes&lt;/P&gt;&lt;P&gt;The reason for the the move to a medium deployment is to accommodate an office in another country, which will get its own local PSN. So the actual amount of requests, or load on the current PSNs in the UK will remain the same as it is currently. I had no idea you could just change the VM size by shutting it down and amending, that's a helpful tip&lt;/P&gt;</description>
      <pubDate>Tue, 29 Aug 2023 08:10:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-3-1-deployment-migration-small-psn-on-medium-pan/m-p/4913619#M583699</guid>
      <dc:creator>stubush</dc:creator>
      <dc:date>2023-08-29T08:10:50Z</dc:date>
    </item>
  </channel>
</rss>

