<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE upgrade in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ise-upgrade/m-p/4726598#M1095279</link>
    <description>&lt;P&gt;Hi &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/132084"&gt;@asmlicense&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;In theory, yes, it would be easier to build new VMs and to do backup/restore. However, when building new VMs, new PID (like SN) gets generated, and license rehosting is required. Given that you are running ISE v2.0 which is EoL, I'm not sure that ou would be able to do rehosting (might be possible, but can't be sure), and I believe this is what &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/326046"&gt;@Marvin Rhoads&lt;/a&gt; mentioned.&lt;/P&gt;
&lt;P&gt;There was big change in ISE somewhere around v2.3 if I'm not mistaken, where Policy Sets were activated by default (if not activated before), and all configuration was migrated to new model. This usually means that you need to go and tweak policies and configuration, as ISE tends to mess it up, by addind bunch of unneeded configuration.&lt;/P&gt;
&lt;P&gt;There is possibility to export certain parts of ISE config (like users or network devices), but not all of it. For this, you could use API, but I can't tell to which extent, as I'm unfamiliar with API in v2.0.&lt;/P&gt;
&lt;P&gt;I would proceed with inline upgrade (with bunch of safety nets around it), untill I get to a supported version. You also need to bare in mind that you'll need to increase HW resources once on newer version, so count on that too. Finally, don't forget to ask for Cisco SKU upgrade, so you can actually purchase Cisco services, as I would assume this SKU is EoL, and would not be able to purchase support as of today.&lt;/P&gt;
&lt;P&gt;Kind regards,&lt;BR /&gt;Milos&lt;/P&gt;</description>
    <pubDate>Wed, 23 Nov 2022 13:20:59 GMT</pubDate>
    <dc:creator>Milos_Jovanovic</dc:creator>
    <dc:date>2022-11-23T13:20:59Z</dc:date>
    <item>
      <title>ISE upgrade</title>
      <link>https://community.cisco.com/t5/network-security/ise-upgrade/m-p/4726559#M1095274</link>
      <description>&lt;P&gt;Dears,&amp;nbsp;&lt;/P&gt;&lt;P&gt;For now we are using 2.0 version. As I know we have to do these steps in order to get 2.7 &lt;SPAN&gt;and higher&lt;/SPAN&gt; - 2.0--&amp;gt;2.2--&amp;gt;2.7&lt;/P&gt;&lt;P&gt;The question - is there any manipulations with licenses? I mean do we need to convert them to smart, or export and then import.&lt;/P&gt;&lt;P&gt;Maybe someone has detailed instruction or upgrade? We have only CLI access to server and the disk usage is 88%. Is there will be any problems with that?&lt;/P&gt;&lt;P&gt;I found this one:&lt;BR /&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/2-2/upgrade_guide/b_ise_upgrade_guide_22/b_ise_upgrade_guide_22_chapter_010.html" target="_blank" rel="noopener"&gt;https://www.cisco.com/c/en/us/td/docs/security/ise/2-2/upgrade_guide/b_ise_upgrade_guide_22/b_ise_upgrade_guide_22_chapter_010.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 23 Nov 2022 11:38:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ise-upgrade/m-p/4726559#M1095274</guid>
      <dc:creator>asmlicense</dc:creator>
      <dc:date>2022-11-23T11:38:18Z</dc:date>
    </item>
    <item>
      <title>Re: ISE upgrade</title>
      <link>https://community.cisco.com/t5/network-security/ise-upgrade/m-p/4726578#M1095275</link>
      <description>&lt;P&gt;What is your server - a VM or hardware appliance? There are restrictions on version support for older server hardware as well as changes in CPU and memory and disk requirements that affect your upgrade path.&lt;/P&gt;
&lt;P&gt;The 2.0 PAK-based licenses are still usable on 2.7 - Smart licenses are only required as of 3.0 or later. However, if you are moving to a new server you would need to have them rehosted which requires TAC support.&lt;/P&gt;</description>
      <pubDate>Wed, 23 Nov 2022 12:15:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ise-upgrade/m-p/4726578#M1095275</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2022-11-23T12:15:43Z</dc:date>
    </item>
    <item>
      <title>Re: ISE upgrade</title>
      <link>https://community.cisco.com/t5/network-security/ise-upgrade/m-p/4726584#M1095277</link>
      <description>&lt;P&gt;Hi Marvin,&lt;/P&gt;&lt;P&gt;We are using VM.&lt;/P&gt;&lt;P&gt;As I understand it is easier to up the new server because of different disk and CPU requirements.&lt;/P&gt;&lt;P&gt;Is there any tool to export configurations from 2.0 version (authentication rules, access lists, endpoint devices) and import them to a new 2.7 version?&lt;/P&gt;</description>
      <pubDate>Wed, 23 Nov 2022 12:29:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ise-upgrade/m-p/4726584#M1095277</guid>
      <dc:creator>asmlicense</dc:creator>
      <dc:date>2022-11-23T12:29:55Z</dc:date>
    </item>
    <item>
      <title>Re: ISE upgrade</title>
      <link>https://community.cisco.com/t5/network-security/ise-upgrade/m-p/4726598#M1095279</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/132084"&gt;@asmlicense&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;In theory, yes, it would be easier to build new VMs and to do backup/restore. However, when building new VMs, new PID (like SN) gets generated, and license rehosting is required. Given that you are running ISE v2.0 which is EoL, I'm not sure that ou would be able to do rehosting (might be possible, but can't be sure), and I believe this is what &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/326046"&gt;@Marvin Rhoads&lt;/a&gt; mentioned.&lt;/P&gt;
&lt;P&gt;There was big change in ISE somewhere around v2.3 if I'm not mistaken, where Policy Sets were activated by default (if not activated before), and all configuration was migrated to new model. This usually means that you need to go and tweak policies and configuration, as ISE tends to mess it up, by addind bunch of unneeded configuration.&lt;/P&gt;
&lt;P&gt;There is possibility to export certain parts of ISE config (like users or network devices), but not all of it. For this, you could use API, but I can't tell to which extent, as I'm unfamiliar with API in v2.0.&lt;/P&gt;
&lt;P&gt;I would proceed with inline upgrade (with bunch of safety nets around it), untill I get to a supported version. You also need to bare in mind that you'll need to increase HW resources once on newer version, so count on that too. Finally, don't forget to ask for Cisco SKU upgrade, so you can actually purchase Cisco services, as I would assume this SKU is EoL, and would not be able to purchase support as of today.&lt;/P&gt;
&lt;P&gt;Kind regards,&lt;BR /&gt;Milos&lt;/P&gt;</description>
      <pubDate>Wed, 23 Nov 2022 13:20:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ise-upgrade/m-p/4726598#M1095279</guid>
      <dc:creator>Milos_Jovanovic</dc:creator>
      <dc:date>2022-11-23T13:20:59Z</dc:date>
    </item>
    <item>
      <title>Re: ISE upgrade</title>
      <link>https://community.cisco.com/t5/network-security/ise-upgrade/m-p/4726632#M1095285</link>
      <description>&lt;P&gt;If you are starting with ISE 2.0, you would first need to upgrade to ISE 2.4 and then to 2.7. You would backup your ISE 2.0 configuration (easiest from the cli since 2.0 GUI uses Flash which is unsupported on all modern browsers) and restore it onto a new 2.4 VM.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/2-4/upgrade_guide/Upgrade_Journey/b_upgrade_overview_2_4.html#LicensingNew24" target="_blank" rel="noopener"&gt;https://www.cisco.com/c/en/us/td/docs/security/ise/2-4/upgrade_guide/Upgrade_Journey/b_upgrade_overview_2_4.html#LicensingNew24&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Then back the 2.4 ISE and restore onto a 2.7 VM. (Some people also recommend patch 2.4 before doing the backup.)&lt;/P&gt;
&lt;P&gt;Once you have restored on to the 2.7 VM, it should be patched to the latest patch (currently Patch 8).&lt;/P&gt;
&lt;P&gt;If you have a multi-node deployment, the instructions for the whole process are summarized here:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/2-7/upgrade_guide/Upgrade_Journey/HTML/b_upgrade_method_2_7.html#id_119627" target="_blank" rel="noopener"&gt;https://www.cisco.com/c/en/us/td/docs/security/ise/2-7/upgrade_guide/Upgrade_Journey/HTML/b_upgrade_method_2_7.html#id_119627&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;You will need to get Cisco TAC (licensing team) to issue your VM licenses. They will ask for your original PAK or Sales Order (SO) number to verify your entitlement.&lt;/P&gt;</description>
      <pubDate>Wed, 23 Nov 2022 14:23:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ise-upgrade/m-p/4726632#M1095285</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2022-11-23T14:23:26Z</dc:date>
    </item>
  </channel>
</rss>

