11-19-2017 07:05 PM
My customer planned to migrate ACS 5.4 to ISE 2.2 . , so we created a config backup on the ACS 5.4 and load it in a new ACS 5.5 , started to migrate using the tool .
The ACS is running as device administration.
Authorization policy migration is not successful with below reason , Other elements is successful like ( devices, shell profile/command set etc ),
“Failed to create authorization policy of policy set Rule-2. Specified resource already exists
An error has occurred while migrating the policy configuration. The policy configuration has been reverted back to the version that existed prior to the migration processing.”
My customer is using external resource (one-time authentication server ) for most user authentication , does it affect all authentication policy ?
And internal user migration is not successful neither, not sure if we need to upgrade ACS 5.8 and do migration again.
Info Type: WARN
> 2017.11.19 21:33:11'313 : 'Description' :Specified resource already exists: InternalUser
Any comments is appreciated
thanks
Qingguo
Solved! Go to Solution.
11-20-2017 12:17 PM
We do support migration from ACS 5.5+ to ISE 2.1+.
The migration tool identifies the issues including name overlaps ete. Some of them are benign since if the name exists and the rules are the same in ISE you can ignore the issue.
Please take a look at the how to migrate from ACS to ISE guide where I have detailed tables that speaks about naming differences and what to do with it. I also have step by step instructions how to migrate.
http://cs.co/acstoise will have videos showing migration from ACS to ISE. You can use these resources for migration.
As Hsing said, if you encounter further issues please call TAC.
-Krishnan
11-19-2017 07:42 PM
If the migration tool fails to copy certain rules or objects, then we would need configuring them manually, after the run. Please perform a sanity check afterwards.
How to Migrate ACS 5.x to ISE 2.x suggests
Even though ACS 5.6 to 5.8 all supported to migrate to ISE 2.3, ACS to ISE migration shows ACS 5.8 doing it better.
For further help, please contact Cisco TAC.
11-20-2017 12:17 PM
We do support migration from ACS 5.5+ to ISE 2.1+.
The migration tool identifies the issues including name overlaps ete. Some of them are benign since if the name exists and the rules are the same in ISE you can ignore the issue.
Please take a look at the how to migrate from ACS to ISE guide where I have detailed tables that speaks about naming differences and what to do with it. I also have step by step instructions how to migrate.
http://cs.co/acstoise will have videos showing migration from ACS to ISE. You can use these resources for migration.
As Hsing said, if you encounter further issues please call TAC.
-Krishnan
04-23-2018 04:07 AM
Hi Sir,
I am migrating cisco acs 5.8 to ISE 2.2 using migration tool.
My all objects gets migrated but only access policy is not getting migrating.
In policy gap report it is showing that Authorization policy is unsupported.
What would be the issue?
Can you please suggest here...
Regards,
Ravin L
08-02-2018 08:04 AM
08-02-2018 09:22 AM
08-13-2018 01:22 PM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide