<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Upgrade from SNS-3595-K9 to SNS-3795-K9 in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/upgrade-from-sns-3595-k9-to-sns-3795-k9/m-p/5217274#M592814</link>
    <description>&lt;P&gt;Hello, Me again.&lt;/P&gt;
&lt;P&gt;I have another upgrade.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am thinking instead of the approach above, I am thinking of using a DR approach.&lt;/P&gt;
&lt;P&gt;These are my steps which should cut down the migration time and have a good rollback option.&lt;/P&gt;
&lt;P&gt;Pre-Reqs&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Take backups of config and operational DBs&lt;/LI&gt;
&lt;LI&gt;Take backups of policy set and certificates.&lt;/LI&gt;
&lt;LI&gt;Build new appliances in lab, same IP, same ISE version and patch level.&lt;/LI&gt;
&lt;LI&gt;Restore config and operation DBs&lt;/LI&gt;
&lt;LI&gt;Check policy set and certificates.&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;Make sure appliances in lab are identical to live environment.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;Migration:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Power down old appliances&lt;/LI&gt;
&lt;LI&gt;Move network cables&lt;/LI&gt;
&lt;LI&gt;Power up new appliances&lt;/LI&gt;
&lt;LI&gt;Make sure deployment is in sync (this is a two mode deployment)&lt;/LI&gt;
&lt;LI&gt;&amp;nbsp;Review live logs, alarms, health check&lt;/LI&gt;
&lt;LI&gt;Test.&lt;/LI&gt;
&lt;LI&gt;Failover to secondary&lt;/LI&gt;
&lt;LI&gt;Test&lt;/LI&gt;
&lt;LI&gt;Failback to primary&lt;/LI&gt;
&lt;LI&gt;Test.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;If there is a big issues, power down, move cables back to old appliances and power up.&lt;/P&gt;
&lt;P&gt;Can you forsee any issues with this method?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;Anthony.&lt;/P&gt;</description>
    <pubDate>Wed, 30 Oct 2024 10:15:55 GMT</pubDate>
    <dc:creator>Anthony O'Reilly</dc:creator>
    <dc:date>2024-10-30T10:15:55Z</dc:date>
    <item>
      <title>Upgrade from SNS-3595-K9 to SNS-3795-K9</title>
      <link>https://community.cisco.com/t5/network-access-control/upgrade-from-sns-3595-k9-to-sns-3795-k9/m-p/5050913#M588394</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;I have two ISE 3595 (3.2 Patch 3) physical appliances, one in each Data Centre. They will be end-of-life in a few months. They are currently used for Wired NAC with Posturing, Wireless NAC (corporate, BYOD and Guest and Hotspot). It is also used for TACACS+.&lt;/P&gt;
&lt;P&gt;They are being replaced with two&amp;nbsp;&lt;SPAN&gt;SNS-3795 physical appliances.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;My aim is to build both of these in a lab by backing up the config and operation databases on the 3595 and restoring on the 3795. The new appliance will have the same IP address, same hostname, same OS version and same patch level.&lt;/P&gt;
&lt;P&gt;On the night of migration, I will move the current network cables from the current 3595 to the new 3795 in the hope of completing this in one clean swoop. I can roll back to the 3595s easily if necessary.&lt;/P&gt;
&lt;P&gt;Is there anything I need to be aware of:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;join to AD domain&lt;/LI&gt;
&lt;LI&gt;certificate migration&lt;/LI&gt;
&lt;LI&gt;licensing&lt;/LI&gt;
&lt;LI&gt;anything else.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Thanks Anthony.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 26 Mar 2024 15:57:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/upgrade-from-sns-3595-k9-to-sns-3795-k9/m-p/5050913#M588394</guid>
      <dc:creator>Anthony O'Reilly</dc:creator>
      <dc:date>2024-03-26T15:57:17Z</dc:date>
    </item>
    <item>
      <title>Re: Upgrade from SNS-3595-K9 to SNS-3795-K9</title>
      <link>https://community.cisco.com/t5/network-access-control/upgrade-from-sns-3595-k9-to-sns-3795-k9/m-p/5050951#M588398</link>
      <description>&lt;P&gt;I thought SNS-3595 was more than upgraded by going to an SNS-3655 or SNS-3755 level device&amp;nbsp; For a 2-node deployment, I'd think going to a pair of SNS-3795's was overkill.&amp;nbsp; Does anyone from Cisco want to chime in?&lt;/P&gt;</description>
      <pubDate>Tue, 26 Mar 2024 17:17:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/upgrade-from-sns-3595-k9-to-sns-3795-k9/m-p/5050951#M588398</guid>
      <dc:creator>davidgfriedman</dc:creator>
      <dc:date>2024-03-26T17:17:40Z</dc:date>
    </item>
    <item>
      <title>Re: Upgrade from SNS-3595-K9 to SNS-3795-K9</title>
      <link>https://community.cisco.com/t5/network-access-control/upgrade-from-sns-3595-k9-to-sns-3795-k9/m-p/5050985#M588399</link>
      <description>&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/performance_and_scalability/b_ise_perf_and_scale.html" target="_blank" rel="noopener"&gt;https://www.cisco.com/c/en/us/td/docs/security/ise/performance_and_scalability/b_ise_perf_and_scale.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;You will need to re-join to AD.&amp;nbsp; You will need to export/import the certificates.&amp;nbsp; Keep an eye on DNS changes needed as well.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 26 Mar 2024 18:31:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/upgrade-from-sns-3595-k9-to-sns-3795-k9/m-p/5050985#M588399</guid>
      <dc:creator>ahollifield</dc:creator>
      <dc:date>2024-03-26T18:31:07Z</dc:date>
    </item>
    <item>
      <title>Re: Upgrade from SNS-3595-K9 to SNS-3795-K9</title>
      <link>https://community.cisco.com/t5/network-access-control/upgrade-from-sns-3595-k9-to-sns-3795-k9/m-p/5051599#M588443</link>
      <description>&lt;P&gt;Thanks for this.&lt;/P&gt;
&lt;P&gt;I was thinking of this method, it is probably not recommended.&lt;/P&gt;
&lt;P&gt;Could you do this?&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Build both new ISE 3795 appliances with the same OS and Patch (3.2 Patch 3) in the lab.&lt;/LI&gt;
&lt;LI&gt;Move the Admin and MnT mode to the ISE01&lt;/LI&gt;
&lt;LI&gt;Remove the old secondary ISE appliance. (ISE02)&lt;/LI&gt;
&lt;LI&gt;Join the new ISE appliance, let them sync. With this the primary will be 3595 and the secondary will be 3795&lt;/LI&gt;
&lt;LI&gt;Failover admin and MnT to the secondary. (New-ISE02)&lt;/LI&gt;
&lt;LI&gt;Remove the old primary, join the new ISE and let them sync, now both appliance will be 3795&lt;/LI&gt;
&lt;LI&gt;Then at the end the following will be running:&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;ISE01 - Primary Admin, Secondary MnT&lt;/P&gt;
&lt;P&gt;ISE02 - Secondary Admin, Primary MnT&lt;/P&gt;
&lt;P&gt;Is this lazy way possible?&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;Anthony&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 27 Mar 2024 17:38:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/upgrade-from-sns-3595-k9-to-sns-3795-k9/m-p/5051599#M588443</guid>
      <dc:creator>Anthony O'Reilly</dc:creator>
      <dc:date>2024-03-27T17:38:02Z</dc:date>
    </item>
    <item>
      <title>Re: Upgrade from SNS-3595-K9 to SNS-3795-K9</title>
      <link>https://community.cisco.com/t5/network-access-control/upgrade-from-sns-3595-k9-to-sns-3795-k9/m-p/5051679#M588446</link>
      <description>&lt;P&gt;Yeah this should work.&amp;nbsp; As long as you are ok with the redundancy concerns.&lt;/P&gt;</description>
      <pubDate>Wed, 27 Mar 2024 19:31:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/upgrade-from-sns-3595-k9-to-sns-3795-k9/m-p/5051679#M588446</guid>
      <dc:creator>ahollifield</dc:creator>
      <dc:date>2024-03-27T19:31:03Z</dc:date>
    </item>
    <item>
      <title>Re: Upgrade from SNS-3595-K9 to SNS-3795-K9</title>
      <link>https://community.cisco.com/t5/network-access-control/upgrade-from-sns-3595-k9-to-sns-3795-k9/m-p/5051741#M588452</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;When you say redundancy concerns, are you referring to the time when both ISE appliance are not in sync and the Admin and MnT personas running on the same node?&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;Anthony.&lt;/P&gt;</description>
      <pubDate>Wed, 27 Mar 2024 22:12:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/upgrade-from-sns-3595-k9-to-sns-3795-k9/m-p/5051741#M588452</guid>
      <dc:creator>Anthony O'Reilly</dc:creator>
      <dc:date>2024-03-27T22:12:25Z</dc:date>
    </item>
    <item>
      <title>Re: Upgrade from SNS-3595-K9 to SNS-3795-K9</title>
      <link>https://community.cisco.com/t5/network-access-control/upgrade-from-sns-3595-k9-to-sns-3795-k9/m-p/5051748#M588454</link>
      <description>No when you only have a single ISE node online at a time.  This is a small deployment with only two nodes correct?&lt;BR /&gt;</description>
      <pubDate>Wed, 27 Mar 2024 22:36:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/upgrade-from-sns-3595-k9-to-sns-3795-k9/m-p/5051748#M588454</guid>
      <dc:creator>ahollifield</dc:creator>
      <dc:date>2024-03-27T22:36:46Z</dc:date>
    </item>
    <item>
      <title>Re: Upgrade from SNS-3595-K9 to SNS-3795-K9</title>
      <link>https://community.cisco.com/t5/network-access-control/upgrade-from-sns-3595-k9-to-sns-3795-k9/m-p/5051954#M588460</link>
      <description>&lt;P&gt;Yes, it is only a two-mode deployment.&lt;/P&gt;
&lt;P&gt;Can you have a two node deployment where two node have different physical hardware. e.g 3595 and a 3795?&lt;/P&gt;</description>
      <pubDate>Thu, 28 Mar 2024 09:52:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/upgrade-from-sns-3595-k9-to-sns-3795-k9/m-p/5051954#M588460</guid>
      <dc:creator>Anthony O'Reilly</dc:creator>
      <dc:date>2024-03-28T09:52:13Z</dc:date>
    </item>
    <item>
      <title>Re: Upgrade from SNS-3595-K9 to SNS-3795-K9</title>
      <link>https://community.cisco.com/t5/network-access-control/upgrade-from-sns-3595-k9-to-sns-3795-k9/m-p/5051972#M588461</link>
      <description>It should be fine for the purposes of the migration. Its nothing you want to leave for very long though as you will have mismatched scale.&lt;BR /&gt;</description>
      <pubDate>Thu, 28 Mar 2024 10:29:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/upgrade-from-sns-3595-k9-to-sns-3795-k9/m-p/5051972#M588461</guid>
      <dc:creator>ahollifield</dc:creator>
      <dc:date>2024-03-28T10:29:57Z</dc:date>
    </item>
    <item>
      <title>Re: Upgrade from SNS-3595-K9 to SNS-3795-K9</title>
      <link>https://community.cisco.com/t5/network-access-control/upgrade-from-sns-3595-k9-to-sns-3795-k9/m-p/5051980#M588463</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;I had a typo, the new ISE appliance will be a SNS-3755-K9 not a SNS-3795-K9. Does this impact my plan above?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 28 Mar 2024 10:42:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/upgrade-from-sns-3595-k9-to-sns-3795-k9/m-p/5051980#M588463</guid>
      <dc:creator>Anthony O'Reilly</dc:creator>
      <dc:date>2024-03-28T10:42:04Z</dc:date>
    </item>
    <item>
      <title>Re: Upgrade from SNS-3595-K9 to SNS-3795-K9</title>
      <link>https://community.cisco.com/t5/network-access-control/upgrade-from-sns-3595-k9-to-sns-3795-k9/m-p/5051986#M588464</link>
      <description>Nope&lt;BR /&gt;</description>
      <pubDate>Thu, 28 Mar 2024 10:50:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/upgrade-from-sns-3595-k9-to-sns-3795-k9/m-p/5051986#M588464</guid>
      <dc:creator>ahollifield</dc:creator>
      <dc:date>2024-03-28T10:50:57Z</dc:date>
    </item>
    <item>
      <title>Re: Upgrade from SNS-3595-K9 to SNS-3795-K9</title>
      <link>https://community.cisco.com/t5/network-access-control/upgrade-from-sns-3595-k9-to-sns-3795-k9/m-p/5217274#M592814</link>
      <description>&lt;P&gt;Hello, Me again.&lt;/P&gt;
&lt;P&gt;I have another upgrade.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am thinking instead of the approach above, I am thinking of using a DR approach.&lt;/P&gt;
&lt;P&gt;These are my steps which should cut down the migration time and have a good rollback option.&lt;/P&gt;
&lt;P&gt;Pre-Reqs&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Take backups of config and operational DBs&lt;/LI&gt;
&lt;LI&gt;Take backups of policy set and certificates.&lt;/LI&gt;
&lt;LI&gt;Build new appliances in lab, same IP, same ISE version and patch level.&lt;/LI&gt;
&lt;LI&gt;Restore config and operation DBs&lt;/LI&gt;
&lt;LI&gt;Check policy set and certificates.&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;Make sure appliances in lab are identical to live environment.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;Migration:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Power down old appliances&lt;/LI&gt;
&lt;LI&gt;Move network cables&lt;/LI&gt;
&lt;LI&gt;Power up new appliances&lt;/LI&gt;
&lt;LI&gt;Make sure deployment is in sync (this is a two mode deployment)&lt;/LI&gt;
&lt;LI&gt;&amp;nbsp;Review live logs, alarms, health check&lt;/LI&gt;
&lt;LI&gt;Test.&lt;/LI&gt;
&lt;LI&gt;Failover to secondary&lt;/LI&gt;
&lt;LI&gt;Test&lt;/LI&gt;
&lt;LI&gt;Failback to primary&lt;/LI&gt;
&lt;LI&gt;Test.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;If there is a big issues, power down, move cables back to old appliances and power up.&lt;/P&gt;
&lt;P&gt;Can you forsee any issues with this method?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;Anthony.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Oct 2024 10:15:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/upgrade-from-sns-3595-k9-to-sns-3795-k9/m-p/5217274#M592814</guid>
      <dc:creator>Anthony O'Reilly</dc:creator>
      <dc:date>2024-10-30T10:15:55Z</dc:date>
    </item>
    <item>
      <title>Re: Upgrade from SNS-3595-K9 to SNS-3795-K9</title>
      <link>https://community.cisco.com/t5/network-access-control/upgrade-from-sns-3595-k9-to-sns-3795-k9/m-p/5217317#M592821</link>
      <description>&lt;P&gt;I wouldn't bother with an operational backup.&amp;nbsp; Those are can be quite large and do you really need that data?&amp;nbsp; How can you spin up nodes in a lab with the same IP?&amp;nbsp; I assume the lab is fully disconnected from production?&lt;/P&gt;</description>
      <pubDate>Wed, 30 Oct 2024 11:04:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/upgrade-from-sns-3595-k9-to-sns-3795-k9/m-p/5217317#M592821</guid>
      <dc:creator>ahollifield</dc:creator>
      <dc:date>2024-10-30T11:04:09Z</dc:date>
    </item>
    <item>
      <title>Re: Upgrade from SNS-3595-K9 to SNS-3795-K9</title>
      <link>https://community.cisco.com/t5/network-access-control/upgrade-from-sns-3595-k9-to-sns-3795-k9/m-p/5217332#M592824</link>
      <description>&lt;P&gt;Yes, the lab is completely isolated. It is not even on the customer site.&lt;/P&gt;
&lt;P&gt;I was just going to restore the operational DB as this doesn't take much time and less chances of having any issues.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Oct 2024 11:22:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/upgrade-from-sns-3595-k9-to-sns-3795-k9/m-p/5217332#M592824</guid>
      <dc:creator>Anthony O'Reilly</dc:creator>
      <dc:date>2024-10-30T11:22:30Z</dc:date>
    </item>
  </channel>
</rss>

