<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Hello Charles, thank you very in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/best-practise-for-rebooting-ise-nodes/m-p/2592770#M72357</link>
    <description>&lt;P&gt;Hello Charles,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thank you very much.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kind regards&lt;/P&gt;&lt;P&gt;Benjamin&lt;/P&gt;</description>
    <pubDate>Thu, 30 Oct 2014 13:56:31 GMT</pubDate>
    <dc:creator>Benjamin Lehner</dc:creator>
    <dc:date>2014-10-30T13:56:31Z</dc:date>
    <item>
      <title>Best Practise for rebooting ISE Nodes?</title>
      <link>https://community.cisco.com/t5/network-access-control/best-practise-for-rebooting-ise-nodes/m-p/2592766#M72329</link>
      <description>&lt;P&gt;Hello Community,&lt;/P&gt;&lt;P&gt;I administer an ISE installation with two nodes (I am not an ISE Specialist, my job is just to manage the user/mac-adresses... but now I have to move my ISE Nodes from one VMWare Cluster to another VMWare Cluster.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;(Both VMWare environments are connected to our enterprise network, but are different environments. vMotion not possible)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would shutdown ISE02, move it to our new VMWare environment and start it again.&lt;/P&gt;&lt;P&gt;Than I would do this with our ISE01 Node...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Are there any best practises for doing this? (Shutdown application first, stopl replikation etc)?&lt;/P&gt;&lt;P&gt;Can I really simply reboot an ISE Node - or have I consider something bevor I doing this? After I doing this?&lt;/P&gt;&lt;P&gt;Any tasks after reboot?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for any answer!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ISE01&amp;nbsp;&amp;nbsp; &amp;nbsp;&lt;BR /&gt;Administration, Monitoring, Policy Service&amp;nbsp;&amp;nbsp; &amp;nbsp;&lt;BR /&gt;PRI(A), SEC(M)&lt;/P&gt;&lt;P&gt;ISE02&amp;nbsp;&amp;nbsp; &amp;nbsp;&lt;BR /&gt;Administration, Monitoring, Policy Service&amp;nbsp;&amp;nbsp; &amp;nbsp;&lt;BR /&gt;SEC(A), PRI(M)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 05:09:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/best-practise-for-rebooting-ise-nodes/m-p/2592766#M72329</guid>
      <dc:creator>Benjamin Lehner</dc:creator>
      <dc:date>2019-03-11T05:09:23Z</dc:date>
    </item>
    <item>
      <title>There is a lot to consider</title>
      <link>https://community.cisco.com/t5/network-access-control/best-practise-for-rebooting-ise-nodes/m-p/2592767#M72338</link>
      <description>&lt;P&gt;There is a lot to consider here.&amp;nbsp; If changing environments means changing IP Address and IP Scopes, then your policies, profiles, and dACLs would also have to change among other things.&amp;nbsp; If this is the case, create a new ISE VM in the new environment using the built in evaluation license and recreate the deployment from the old environment using the addressing scheme of the new environment.&amp;nbsp; Then spin-up a new Secondary node and register it on the Primary.&amp;nbsp; Once this is done, you can re-host the license from your old environment onto your new environment.&amp;nbsp; You can use this tool to re-host:&lt;/P&gt;&lt;P&gt;&lt;A href="https://tools.cisco.com/SWIFT/LicensingUI/loadDemoLicensee?FormId=3999"&gt;https://tools.cisco.com/SWIFT/LicensingUI/loadDemoLicensee?FormId=3999&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If IP Addressing is to remain the same, it gets simpler.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;First, and always, perform a configuration and operational backup.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;If downtime is not an issue, or if you have a maintenance window of an hour or so: Simply shut down both nodes.&amp;nbsp; Transfer them to the New Environment and turn them on, Primary Node first, of course.&lt;/P&gt;&lt;P&gt;If downtime is an issue, shut down the Secondary Node and transfer it to the New Environment.&amp;nbsp; Start the Secondary Node and when it is up, shut down the Primary Node.&amp;nbsp; Once services on the primary node have stopped, promote the Secondary Node to Primary Node.&lt;/P&gt;&lt;P&gt;Transfer the OLD Primary Node to the New Environment and turn it on.&amp;nbsp; It should assume the role of Secondary Node.&amp;nbsp; If it does not, assign that role through the GUI.&lt;/P&gt;&lt;P&gt;Remember, the correct way to shut down an ISE node is:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;application stop ise&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;halt&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;By using these commands, the risk of database corruption decreases by about 90% (Remember to always backup).&lt;/P&gt;&lt;P&gt;Please Rate Helpful posts and mark this question as answered if, in fact, this does answer your question.&amp;nbsp; Otherwise, feel free to post follow-up questions.&lt;/P&gt;&lt;P&gt;Charles Moreton&lt;/P&gt;</description>
      <pubDate>Thu, 30 Oct 2014 13:26:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/best-practise-for-rebooting-ise-nodes/m-p/2592767#M72338</guid>
      <dc:creator>Charlie Moreton</dc:creator>
      <dc:date>2014-10-30T13:26:46Z</dc:date>
    </item>
    <item>
      <title>Hello Charles, thanks for</title>
      <link>https://community.cisco.com/t5/network-access-control/best-practise-for-rebooting-ise-nodes/m-p/2592768#M72343</link>
      <description>&lt;P&gt;Hello Charles,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks for your reply. The network addresses dont changes.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;So, just few further questions:&lt;/P&gt;&lt;P&gt;How to promote the secondary to primary node? (Do you got an Link for me?)&lt;/P&gt;&lt;P&gt;Can I do the movment without changeing the primary/secondary roles?&lt;/P&gt;&lt;P&gt;What will happen if I dont promote the secondary to primary? If node01 comes up - it will be the primary again if there is no other primary?&lt;/P&gt;</description>
      <pubDate>Thu, 30 Oct 2014 13:37:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/best-practise-for-rebooting-ise-nodes/m-p/2592768#M72343</guid>
      <dc:creator>Benjamin Lehner</dc:creator>
      <dc:date>2014-10-30T13:37:06Z</dc:date>
    </item>
    <item>
      <title> How to promote the secondary</title>
      <link>https://community.cisco.com/t5/network-access-control/best-practise-for-rebooting-ise-nodes/m-p/2592769#M72349</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How to promote the secondary to primary node? (Do you got an Link for me?)&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Here is the link to show how to promote the node:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;A href="http://www.cisco.com/c/en/us/td/docs/security/ise/1-2/user_guide/ise_user_guide/ise_dis_deploy.html#pgfId-1128454"&gt;http://www.cisco.com/c/en/us/td/docs/security/ise/1-2/user_guide/ise_user_guide/ise_dis_deploy.html#pgfId-1128454&lt;/A&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Can I do the movment without changeing the primary/secondary roles?&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;If you can schedule the move with expected downtime, then yes.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;What will happen if I dont promote the secondary to primary? If node01 comes up - it will be the primary again if there is no other primary?&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;True, and that is the reason for having a Secondary Node, however, if there is an extended amount of time between moving the Primary Node, other anomalies may occur.&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 30 Oct 2014 13:51:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/best-practise-for-rebooting-ise-nodes/m-p/2592769#M72349</guid>
      <dc:creator>Charlie Moreton</dc:creator>
      <dc:date>2014-10-30T13:51:50Z</dc:date>
    </item>
    <item>
      <title>Hello Charles, thank you very</title>
      <link>https://community.cisco.com/t5/network-access-control/best-practise-for-rebooting-ise-nodes/m-p/2592770#M72357</link>
      <description>&lt;P&gt;Hello Charles,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thank you very much.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kind regards&lt;/P&gt;&lt;P&gt;Benjamin&lt;/P&gt;</description>
      <pubDate>Thu, 30 Oct 2014 13:56:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/best-practise-for-rebooting-ise-nodes/m-p/2592770#M72357</guid>
      <dc:creator>Benjamin Lehner</dc:creator>
      <dc:date>2014-10-30T13:56:31Z</dc:date>
    </item>
    <item>
      <title>Happy to help.Good luck with</title>
      <link>https://community.cisco.com/t5/network-access-control/best-practise-for-rebooting-ise-nodes/m-p/2592771#M72364</link>
      <description>&lt;P&gt;Happy to help.&lt;/P&gt;&lt;P&gt;Good luck with your ISE move.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Charles Moreton&lt;/P&gt;</description>
      <pubDate>Thu, 30 Oct 2014 14:16:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/best-practise-for-rebooting-ise-nodes/m-p/2592771#M72364</guid>
      <dc:creator>Charlie Moreton</dc:creator>
      <dc:date>2014-10-30T14:16:13Z</dc:date>
    </item>
    <item>
      <title>Hello Charly,one more further</title>
      <link>https://community.cisco.com/t5/network-access-control/best-practise-for-rebooting-ise-nodes/m-p/2592772#M72369</link>
      <description>&lt;P&gt;Hello Charly,&lt;/P&gt;&lt;P&gt;one more further question about changing primary/secondary role:&lt;/P&gt;&lt;P&gt;My installation:&lt;/P&gt;&lt;P&gt;node01&lt;/P&gt;&lt;P&gt;- Admin, Policy&lt;/P&gt;&lt;P&gt;node02&lt;/P&gt;&lt;P&gt;- Monitoring, Policy&lt;/P&gt;&lt;P&gt;In your link I read:&lt;/P&gt;&lt;P&gt;"You can only promote a secondary Administration node to become a primary Administration node. Cisco ISE nodes that assume only the Policy Service or Monitoring persona, or both, cannot be promoted to a primary Administration node."&lt;/P&gt;&lt;P&gt;So it is not possible to promote this node to primary admin node?&lt;/P&gt;&lt;P&gt;--&amp;gt; I dont got an Option like " &lt;B class="cBold"&gt; Promote to Primary&lt;/B&gt; ." in the edit page of my noedes... what dos this mean?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 30 Oct 2014 15:47:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/best-practise-for-rebooting-ise-nodes/m-p/2592772#M72369</guid>
      <dc:creator>Benjamin Lehner</dc:creator>
      <dc:date>2014-10-30T15:47:30Z</dc:date>
    </item>
    <item>
      <title>Add the secondary Admin Node</title>
      <link>https://community.cisco.com/t5/network-access-control/best-practise-for-rebooting-ise-nodes/m-p/2592773#M72372</link>
      <description>&lt;P&gt;Add the secondary Admin Node persona to the Secondary Node before moving the VM&lt;/P&gt;</description>
      <pubDate>Thu, 30 Oct 2014 16:12:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/best-practise-for-rebooting-ise-nodes/m-p/2592773#M72372</guid>
      <dc:creator>Charlie Moreton</dc:creator>
      <dc:date>2014-10-30T16:12:15Z</dc:date>
    </item>
  </channel>
</rss>

