<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco ISE v2.4 to Cisco ISE on AWS v3.x in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cisco-ise-v2-4-to-cisco-ise-on-aws-v3-x/m-p/4971032#M585518</link>
    <description>&lt;P&gt;Hi Marvin,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Always appreciate your prompt advise.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Yea that is what I think too. Backup restore will be more direct when come to migration. Let me sum up:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1) Backup existing data and operation config, cert and keys from PAN (No deregister is required)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2) Restore the backup config to staging ise v3.0 single node&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;3) Backup config data, cert and key from node v3.0&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;4) Restore above to v3.3 (different hostname and IP - the node will initially be standalone, before configuring to be PAN), add secondary node by register it&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;5) NAD and T&lt;SPAN&gt;est&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 04 Dec 2023 15:11:13 GMT</pubDate>
    <dc:creator>wayne loh</dc:creator>
    <dc:date>2023-12-04T15:11:13Z</dc:date>
    <item>
      <title>Cisco ISE v2.4 to Cisco ISE on AWS v3.x</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-v2-4-to-cisco-ise-on-aws-v3-x/m-p/4963444#M585314</link>
      <description>&lt;P&gt;Hi Guys,&lt;/P&gt;
&lt;P&gt;Does anyone has experience on the Cisco ISE v2.4 (On prem - virtual) to Cisco ISE v3.x on AWS? Existing ISE is configured to be 802.1x authentication both wired and wireless. Is there migration tool/steps possible or it has to be new setup and re-configure all the policies and settings?&lt;/P&gt;
&lt;P&gt;Any advise would be appreciated!&lt;/P&gt;
&lt;P&gt;Many thanks.&lt;/P&gt;</description>
      <pubDate>Tue, 21 Nov 2023 05:53:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-v2-4-to-cisco-ise-on-aws-v3-x/m-p/4963444#M585314</guid>
      <dc:creator>wayne loh</dc:creator>
      <dc:date>2023-11-21T05:53:52Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE v2.4 to Cisco ISE on AWS v3.x</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-v2-4-to-cisco-ise-on-aws-v3-x/m-p/4963606#M585320</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;- FYI :&amp;nbsp;&lt;A href="https://community.cisco.com/t5/network-access-control/aws-and-ise-and-upgrades/m-p/4567645#M573351" target="_blank"&gt;https://community.cisco.com/t5/network-access-control/aws-and-ise-and-upgrades/m-p/4567645#M573351&lt;/A&gt;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;But from 2.4 you can only go to 3.0 with backup restore method ,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;M.&lt;/P&gt;</description>
      <pubDate>Tue, 21 Nov 2023 10:04:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-v2-4-to-cisco-ise-on-aws-v3-x/m-p/4963606#M585320</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2023-11-21T10:04:16Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE v2.4 to Cisco ISE on AWS v3.x</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-v2-4-to-cisco-ise-on-aws-v3-x/m-p/4963738#M585324</link>
      <description>&lt;P&gt;Spin up an ISE 3.0 VM as a staging system. Restore the backup from your current 2.4 system onto it. Then take a backup from 3.0 and restore it onto the 3.x (currently recommended 3.2 patch 4) system in AWS. Be sure to include backup of your system certificates and keys (assuming you are using CA-issued certificates). Adjust DNS accordingly to resolve the server name(s) to the new IP address(es). Of course your NADs need to point to the new PSN address(es).&lt;/P&gt;</description>
      <pubDate>Tue, 21 Nov 2023 14:07:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-v2-4-to-cisco-ise-on-aws-v3-x/m-p/4963738#M585324</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2023-11-21T14:07:29Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE v2.4 to Cisco ISE on AWS v3.x</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-v2-4-to-cisco-ise-on-aws-v3-x/m-p/4964190#M585343</link>
      <description>&lt;P&gt;Appreciate the reply.&lt;/P&gt;
&lt;P&gt;Will try out the approach above mentioned. How about your experience on any of the Cisco ISE cluster on AWS? I saw some aws cloud transformation (CF) to automate the 2 node across 2 availability zones with other components, to trigger and alert the failover. It doesnt seems like the traditional way of HA and failover (with hearthbeat) it seems complex. Is there a guide to setup the minimum to be HA on aws?&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 22 Nov 2023 01:55:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-v2-4-to-cisco-ise-on-aws-v3-x/m-p/4964190#M585343</guid>
      <dc:creator>wayne loh</dc:creator>
      <dc:date>2023-11-22T01:55:31Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE v2.4 to Cisco ISE on AWS v3.x</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-v2-4-to-cisco-ise-on-aws-v3-x/m-p/4964705#M585352</link>
      <description>&lt;P&gt;There is no difference in the way an ISE cluster handles redundancy and high-availability regardless of whether it is deployed in on-prem, private cloud, or public cloud environments (or across any combination). See the &lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/3-2/admin_guide/b_ise_admin_3_2/b_ISE_admin_32_deployment.html" target="_blank" rel="noopener"&gt;Admin Guide&lt;/A&gt; for information on Distributed ISE Deployments.&lt;/P&gt;</description>
      <pubDate>Wed, 22 Nov 2023 21:56:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-v2-4-to-cisco-ise-on-aws-v3-x/m-p/4964705#M585352</guid>
      <dc:creator>Greg Gibbs</dc:creator>
      <dc:date>2023-11-22T21:56:27Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE v2.4 to Cisco ISE on AWS v3.x</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-v2-4-to-cisco-ise-on-aws-v3-x/m-p/4970845#M585509</link>
      <description>&lt;P&gt;Hi Marvin,&lt;/P&gt;
&lt;P&gt;Basically we have 2 full ise node in the environment, running active and passive. For the staging system, do we need to have 2 full ise node v3.0 as well？Do we need to de-register the existing secondary node and do the backup of primary?&lt;/P&gt;
&lt;P&gt;Thanks.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 04 Dec 2023 09:01:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-v2-4-to-cisco-ise-on-aws-v3-x/m-p/4970845#M585509</guid>
      <dc:creator>wayne loh</dc:creator>
      <dc:date>2023-12-04T09:01:57Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE v2.4 to Cisco ISE on AWS v3.x</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-v2-4-to-cisco-ise-on-aws-v3-x/m-p/4970928#M585512</link>
      <description>&lt;P&gt;No need to de-register before taking a backup. The staging node can be standalone.&lt;/P&gt;</description>
      <pubDate>Mon, 04 Dec 2023 12:32:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-v2-4-to-cisco-ise-on-aws-v3-x/m-p/4970928#M585512</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2023-12-04T12:32:34Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE v2.4 to Cisco ISE on AWS v3.x</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-v2-4-to-cisco-ise-on-aws-v3-x/m-p/4970994#M585516</link>
      <description>&lt;P&gt;Hi Marvin,&lt;/P&gt;
&lt;P&gt;Well noted. As second opinion, do you think I should use the backup restore method or I should just setup from scratches, meaning build the new v3.3 and configure wireless with 802.1x. Which one to be more seemless looking at the short windows of period.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 04 Dec 2023 14:26:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-v2-4-to-cisco-ise-on-aws-v3-x/m-p/4970994#M585516</guid>
      <dc:creator>wayne loh</dc:creator>
      <dc:date>2023-12-04T14:26:24Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE v2.4 to Cisco ISE on AWS v3.x</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-v2-4-to-cisco-ise-on-aws-v3-x/m-p/4971005#M585517</link>
      <description>&lt;P&gt;It depends on a couple of things, mostly not directly ISE capability-wise. Like how comfortable are you with the existing configurations, how "clean" the existing configuration is, are you able to troubleshoot everything that might go wrong if you rebuild from new install etc.&lt;/P&gt;
&lt;P&gt;Most people elect to backup and restore unless the current setup is very messy and not something they want to preserve.&lt;/P&gt;</description>
      <pubDate>Mon, 04 Dec 2023 14:38:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-v2-4-to-cisco-ise-on-aws-v3-x/m-p/4971005#M585517</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2023-12-04T14:38:55Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE v2.4 to Cisco ISE on AWS v3.x</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-v2-4-to-cisco-ise-on-aws-v3-x/m-p/4971032#M585518</link>
      <description>&lt;P&gt;Hi Marvin,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Always appreciate your prompt advise.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Yea that is what I think too. Backup restore will be more direct when come to migration. Let me sum up:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1) Backup existing data and operation config, cert and keys from PAN (No deregister is required)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2) Restore the backup config to staging ise v3.0 single node&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;3) Backup config data, cert and key from node v3.0&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;4) Restore above to v3.3 (different hostname and IP - the node will initially be standalone, before configuring to be PAN), add secondary node by register it&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;5) NAD and T&lt;SPAN&gt;est&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 04 Dec 2023 15:11:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-v2-4-to-cisco-ise-on-aws-v3-x/m-p/4971032#M585518</guid>
      <dc:creator>wayne loh</dc:creator>
      <dc:date>2023-12-04T15:11:13Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE v2.4 to Cisco ISE on AWS v3.x</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-v2-4-to-cisco-ise-on-aws-v3-x/m-p/4971037#M585519</link>
      <description>&lt;P&gt;Correct summary.&lt;/P&gt;
&lt;P&gt;Be sure to have new hostnames and IPs in your configured DNS (forward A records and reverse lookup PTR records). Your NADs will then have to point to the new addresses.&lt;/P&gt;</description>
      <pubDate>Mon, 04 Dec 2023 15:22:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-v2-4-to-cisco-ise-on-aws-v3-x/m-p/4971037#M585519</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2023-12-04T15:22:43Z</dc:date>
    </item>
  </channel>
</rss>

