<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Virtual ISE - Vmotion in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/virtual-ise-vmotion/m-p/5369065#M599766</link>
    <description>&lt;P&gt;Hello all,&lt;/P&gt;&lt;P&gt;We are entertaining virtual cisco ISE as a PSN for one of our remote sites.&amp;nbsp; It seems like all the live/hot vmotion problems have been fixed.&amp;nbsp; Is anyone using virtual ISE and can validate the vmotion concerns are no longer there?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/3-4/install_guide/b_ise_installationGuide34/b_ise_InstallationGuide_chapter_2.html" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/ise/3-4/install_guide/b_ise_installationGuide34/b_ise_InstallationGuide_chapter_2.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;VMware virtual machine requirements&lt;BR /&gt;You can use the VMware migration feature to migrate VM instances (running any persona) between hosts. Cisco ISE supports both hot and cold migration.&lt;/P&gt;&lt;P&gt;Hot migration is also called live migration or vMotion. You do not need to shut down or power off Cisco ISE during hot migration. You can migrate the Cisco ISE VM without any interruption in its availability.&lt;/P&gt;&lt;P&gt;Cisco ISE must be shutdown and powered off for cold migration. Cisco ISE does not allow to stop or pause the database operations during cold migration. Hence, ensure that Cisco ISE is not running and active during the cold migration.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 10 Feb 2026 14:49:39 GMT</pubDate>
    <dc:creator>ryanmbess</dc:creator>
    <dc:date>2026-02-10T14:49:39Z</dc:date>
    <item>
      <title>Virtual ISE - Vmotion</title>
      <link>https://community.cisco.com/t5/network-access-control/virtual-ise-vmotion/m-p/5369065#M599766</link>
      <description>&lt;P&gt;Hello all,&lt;/P&gt;&lt;P&gt;We are entertaining virtual cisco ISE as a PSN for one of our remote sites.&amp;nbsp; It seems like all the live/hot vmotion problems have been fixed.&amp;nbsp; Is anyone using virtual ISE and can validate the vmotion concerns are no longer there?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/3-4/install_guide/b_ise_installationGuide34/b_ise_InstallationGuide_chapter_2.html" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/ise/3-4/install_guide/b_ise_installationGuide34/b_ise_InstallationGuide_chapter_2.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;VMware virtual machine requirements&lt;BR /&gt;You can use the VMware migration feature to migrate VM instances (running any persona) between hosts. Cisco ISE supports both hot and cold migration.&lt;/P&gt;&lt;P&gt;Hot migration is also called live migration or vMotion. You do not need to shut down or power off Cisco ISE during hot migration. You can migrate the Cisco ISE VM without any interruption in its availability.&lt;/P&gt;&lt;P&gt;Cisco ISE must be shutdown and powered off for cold migration. Cisco ISE does not allow to stop or pause the database operations during cold migration. Hence, ensure that Cisco ISE is not running and active during the cold migration.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 10 Feb 2026 14:49:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/virtual-ise-vmotion/m-p/5369065#M599766</guid>
      <dc:creator>ryanmbess</dc:creator>
      <dc:date>2026-02-10T14:49:39Z</dc:date>
    </item>
    <item>
      <title>Re: Virtual ISE - Vmotion</title>
      <link>https://community.cisco.com/t5/network-access-control/virtual-ise-vmotion/m-p/5369097#M599771</link>
      <description>&lt;P&gt;Live vMotion (Hot Migration)&amp;nbsp;is now fully supported.&lt;/P&gt;
&lt;P&gt;what is your average round-trip latency? (ISE is sensitive to anything over&amp;nbsp;300ms&amp;nbsp;for database replication)&lt;/P&gt;</description>
      <pubDate>Tue, 10 Feb 2026 16:05:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/virtual-ise-vmotion/m-p/5369097#M599771</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2026-02-10T16:05:58Z</dc:date>
    </item>
    <item>
      <title>Re: Virtual ISE - Vmotion</title>
      <link>https://community.cisco.com/t5/network-access-control/virtual-ise-vmotion/m-p/5369152#M599775</link>
      <description>&lt;P&gt;I have been using live vMotion since ISE 3.3 and never noticed any issues as a result of using it. In my customer scenarios they don't tend to include ISE in DRS groups (as far as I know) but I know that they will deliberately vacate VMs (including ISE) to upgrade/patch the ESXi hosts.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I would trust that VMWare have done a reliable job in ensuring there is no data loss or corruption.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;There is more chance of breaking your ISE by doing a sanctioned ISE patch or upgrade.&lt;/P&gt;</description>
      <pubDate>Tue, 10 Feb 2026 20:27:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/virtual-ise-vmotion/m-p/5369152#M599775</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2026-02-10T20:27:35Z</dc:date>
    </item>
    <item>
      <title>Re: Virtual ISE - Vmotion</title>
      <link>https://community.cisco.com/t5/network-access-control/virtual-ise-vmotion/m-p/5369789#M599792</link>
      <description>&lt;P class="lia-align-justify"&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1243902"&gt;@ryanmbess&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&lt;STRONG&gt;&amp;nbsp;vMotion&lt;/STRONG&gt; is supported since &lt;STRONG&gt;ISE 3.1&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;My preferences for a&amp;nbsp;&lt;STRONG&gt;vMotion&lt;/STRONG&gt; are:&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;1st&lt;/STRONG&gt; Cold vMotion&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;STRONG&gt;ISE Nodes&lt;/STRONG&gt; shutdown:&lt;/P&gt;
&lt;PRE class="lia-indent-padding-left-30px"&gt;ise/admin# &lt;FONT color="#3366FF"&gt;halt&lt;/FONT&gt;&lt;/PRE&gt;
&lt;P&gt;&lt;STRONG&gt;2nd&lt;/STRONG&gt; "Cold vMotion"&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;STRONG&gt;ISE Nodes&lt;/STRONG&gt; with "application stop":&lt;/P&gt;
&lt;PRE class="lia-indent-padding-left-30px"&gt;ise/admin# &lt;FONT color="#3366FF"&gt;application stop ise&lt;/FONT&gt;&lt;/PRE&gt;
&lt;P&gt;&lt;STRONG&gt;3rd&lt;/STRONG&gt; Hot vMotion&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;STRONG&gt;ISE Nodes&lt;/STRONG&gt; up and running&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;Tested since &lt;STRONG&gt;ISE 3.3 P4&lt;/STRONG&gt; !&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;Hope this helps !&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 13 Feb 2026 02:51:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/virtual-ise-vmotion/m-p/5369789#M599792</guid>
      <dc:creator>Marcelo Morais</dc:creator>
      <dc:date>2026-02-13T02:51:36Z</dc:date>
    </item>
    <item>
      <title>Re: Virtual ISE - Vmotion</title>
      <link>https://community.cisco.com/t5/network-access-control/virtual-ise-vmotion/m-p/5369827#M599793</link>
      <description>&lt;P&gt;So none of the 3 options causes data loss. To my knowledge, (never had a virtual environment though for ISE)&lt;/P&gt;
&lt;P&gt;Once I had a bad experience due to VM resources - ISE had a performance issue, so I prefer physical somehow.&lt;/P&gt;</description>
      <pubDate>Fri, 13 Feb 2026 07:53:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/virtual-ise-vmotion/m-p/5369827#M599793</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2026-02-13T07:53:18Z</dc:date>
    </item>
    <item>
      <title>Re: Virtual ISE - Vmotion</title>
      <link>https://community.cisco.com/t5/network-access-control/virtual-ise-vmotion/m-p/5369866#M599799</link>
      <description>&lt;P&gt;Thanks.&amp;nbsp; It's encouraging to hear that you've had success with live vMotions.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 13 Feb 2026 12:04:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/virtual-ise-vmotion/m-p/5369866#M599799</guid>
      <dc:creator>ryanmbess</dc:creator>
      <dc:date>2026-02-13T12:04:26Z</dc:date>
    </item>
    <item>
      <title>Re: Virtual ISE - Vmotion</title>
      <link>https://community.cisco.com/t5/network-access-control/virtual-ise-vmotion/m-p/5369877#M599800</link>
      <description>&lt;P class="lia-align-justify"&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/286878"&gt;@balaji.bandi&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;yes, none of the 3 options causes Data Loss&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;PS: what I prefer about &lt;STRONG&gt;VM&lt;/STRONG&gt; over the &lt;STRONG&gt;SNS&lt;/STRONG&gt; is that t&lt;SPAN&gt;he&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;SNS Appliance&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;supports the&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;UEFI&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;(&lt;/SPAN&gt;&lt;STRONG&gt;Unified Extensible Firmware Interface&lt;/STRONG&gt;&lt;SPAN&gt;)&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Secure Boot feature&lt;/STRONG&gt;&lt;SPAN&gt;, which ensures that&amp;nbsp;&lt;/SPAN&gt;&lt;U&gt;only a signed&lt;/U&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Cisco ISE&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;U&gt;image&lt;/U&gt;&lt;SPAN&gt;&amp;nbsp;can be installed, in other words, although the&amp;nbsp;&lt;STRONG&gt;SNS &lt;/STRONG&gt;is a&amp;nbsp;&lt;STRONG&gt;Cisco UCS C&lt;/STRONG&gt;, the&amp;nbsp;&lt;STRONG&gt;SNS Appliance&lt;/STRONG&gt;&amp;nbsp;are a&amp;nbsp;&lt;U&gt;dedicated&lt;/U&gt;&amp;nbsp;&lt;STRONG&gt;Appliance&lt;/STRONG&gt;&amp;nbsp;ONLY for&amp;nbsp;&lt;STRONG&gt;Cisco ISE&lt;/STRONG&gt;, and cannot be repurposed ... p&lt;/SPAN&gt;lease take a look at:&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&lt;A href="https://community.cisco.com/t5/security-knowledge-base/ise-what-we-need-to-know-about-sns-vm/ta-p/5274022" target="_blank" rel="noopener"&gt;ISE - What we need to know about SNS / VM&lt;/A&gt;&amp;nbsp;.&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 13 Feb 2026 12:44:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/virtual-ise-vmotion/m-p/5369877#M599800</guid>
      <dc:creator>Marcelo Morais</dc:creator>
      <dc:date>2026-02-13T12:44:41Z</dc:date>
    </item>
  </channel>
</rss>

