<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE Restore Questions in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-restore-questions/m-p/5007442#M586809</link>
    <description>&lt;P&gt;Hello &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1588027"&gt;@ryanbess&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1. While the ISE restore process includes certificates, it's recommended to separately backup and store certificates. This is mainly for situations where you might need to restore ISE in a new environment or if you are not using the built-in CA for your certificates. Keeping a separate backup of certificates provides an extra layer of assurance and flexibility, especially in scenarios where you might need to migrate ISE to a different infrastructure.&lt;/P&gt;
&lt;P&gt;2. It's somewhat unexpected that you needed to rebind ISE to Active Directory after a restore. The restore process should ideally bring back all configurations, including AD bindings. If you find that AD bindings are not consistently restored, it's advisable to document the AD binding configurations separately and verify the restoration process in a controlled environment.&lt;/P&gt;
&lt;P&gt;3. The individual config backup for policies is indeed for a more granular restore process. This allows you to selectively restore policy configurations without affecting the entire ISE deployment. It can be beneficial in scenarios where a specific policy or set of policies needs to be rolled back or restored independently of other configurations.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sun, 28 Jan 2024 18:06:29 GMT</pubDate>
    <dc:creator>M02@rt37</dc:creator>
    <dc:date>2024-01-28T18:06:29Z</dc:date>
    <item>
      <title>ISE Restore Questions</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-restore-questions/m-p/5007415#M586808</link>
      <description>&lt;P&gt;Just did my first ISE retore based upon config backups.&amp;nbsp; Two things i noticed.&lt;/P&gt;&lt;P&gt;1. ISE restored all certs i added and properly assigned them appropriately which is good.&amp;nbsp; Given this behavior, why do they recommend to backup all ISE certs manually and store them some place safe given the restore via the config backups adds them back?&lt;/P&gt;&lt;P&gt;2. When ISE came back up, it had the AD binding configs, yet I needed to rebind ISE?&amp;nbsp; Is this expected?&lt;/P&gt;&lt;P&gt;3. All policies were also restored.&amp;nbsp; Again, which is good.&amp;nbsp; Why do they have an individual config to auto backup ISE policies outside of the ISE config backups?&amp;nbsp; I suspect this is so you can quickly restore just the policy configs without having to do a complete ISE restore.&amp;nbsp; Am i correct here?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 28 Jan 2024 15:47:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-restore-questions/m-p/5007415#M586808</guid>
      <dc:creator>ryanbess</dc:creator>
      <dc:date>2024-01-28T15:47:10Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Restore Questions</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-restore-questions/m-p/5007442#M586809</link>
      <description>&lt;P&gt;Hello &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1588027"&gt;@ryanbess&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1. While the ISE restore process includes certificates, it's recommended to separately backup and store certificates. This is mainly for situations where you might need to restore ISE in a new environment or if you are not using the built-in CA for your certificates. Keeping a separate backup of certificates provides an extra layer of assurance and flexibility, especially in scenarios where you might need to migrate ISE to a different infrastructure.&lt;/P&gt;
&lt;P&gt;2. It's somewhat unexpected that you needed to rebind ISE to Active Directory after a restore. The restore process should ideally bring back all configurations, including AD bindings. If you find that AD bindings are not consistently restored, it's advisable to document the AD binding configurations separately and verify the restoration process in a controlled environment.&lt;/P&gt;
&lt;P&gt;3. The individual config backup for policies is indeed for a more granular restore process. This allows you to selectively restore policy configurations without affecting the entire ISE deployment. It can be beneficial in scenarios where a specific policy or set of policies needs to be rolled back or restored independently of other configurations.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 28 Jan 2024 18:06:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-restore-questions/m-p/5007442#M586809</guid>
      <dc:creator>M02@rt37</dc:creator>
      <dc:date>2024-01-28T18:06:29Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Restore Questions</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-restore-questions/m-p/5007446#M586810</link>
      <description>&lt;P&gt;Thanks.&amp;nbsp; When you do the restore, it also had an ADE-OS restore checkbox.&amp;nbsp; What kinds of data would be in the ISE conifg backup that would be part of the ADE-OS?&lt;/P&gt;</description>
      <pubDate>Sun, 28 Jan 2024 18:28:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-restore-questions/m-p/5007446#M586810</guid>
      <dc:creator>ryanbess</dc:creator>
      <dc:date>2024-01-28T18:28:25Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Restore Questions</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-restore-questions/m-p/5007503#M586815</link>
      <description>&lt;P&gt;The ADE-OS is all the stuff you see in the CLI of the admin node (show running-config)&lt;/P&gt;</description>
      <pubDate>Mon, 29 Jan 2024 00:56:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-restore-questions/m-p/5007503#M586815</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2024-01-29T00:56:08Z</dc:date>
    </item>
    <item>
      <title>Re: ISE Restore Questions</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-restore-questions/m-p/5007505#M586816</link>
      <description>&lt;P&gt;Thanks for confirming my suspicions. &amp;nbsp;I can not think of any time when you would not want to check that box but I guess it’s good to have options.&lt;/P&gt;</description>
      <pubDate>Mon, 29 Jan 2024 01:07:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-restore-questions/m-p/5007505#M586816</guid>
      <dc:creator>ryanbess</dc:creator>
      <dc:date>2024-01-29T01:07:12Z</dc:date>
    </item>
  </channel>
</rss>

