cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
574
Views
1
Helpful
1
Replies

About ISE CLI Backup and Restore

Translator
Community Manager
Community Manager

For ISE CLI backups and restores, the backup command can only be run on the primary side. For primary/secondary redundancy, can I create backup files for restore on the primary side? Or do you need to create backup files for both primary and secondary?

If the backup file was created on the primary side, will the settings be restored on both the primary and secondary sides when the restore command is run on the primary side? I would also like to ask you about failover and reboot operations at that time.

1 Reply 1

There's a section in the administrator guide that covers parts of this:
https://www.cisco.com/c/en/us/td/docs/security/ise/3-4/admin_guide/b_ise_admin_3_4/b_ISE_admin_maintain_monitor.html#ID312

You will only create a backup from the primary administration node, and you will only restore to the primary administration node.

After you restore the primary node, you need to re-synchronize secondary nodes to the primary.
Or alternatively you could also either remove and re-join the secondary node to the deployment to get the config sync from the restored primary.

If a secondary node fails, you can just re-deploy a new secondary, install certificates and re-join to the deployment, and it will sync config from the primary, so no backup/restore method is required here.

---
Please mark helpful answers & solutions
---