11-29-2021 01:03 AM - edited 11-29-2021 02:32 AM
i want to change my devices from acs to ISE doing it remotely without getting disconnected by changing the configs,
do you recommend tftping download the config to the devices and save it as startup config?
am guessing if i delete aaa commands while SSHing , i will get locked out of the device, so what are your recommendations?
i don't want to use migration tool
Should i do the configurations on ISE first then add the aaa template commands on all devices?
thanks in advance.
Solved! Go to Solution.
11-29-2021 02:39 AM
First make sure you have Local account Fall back before you lock out yourself.
second i will add ISE as secondary server, Primary as ACS.
On ACS Side, the device you like to Migrate to ISE, Remove the Key , try to Login, this time (if the config is good) it fall back to ISE and get authenticated, if that success, you remove ACS config and save config).
make sense ?
If that is tested 1 or 2 devices, you can use any scripting or any tools to make this automated and test it.
You still have Local account in case any failures to recovery.
11-29-2021 02:39 AM
First make sure you have Local account Fall back before you lock out yourself.
second i will add ISE as secondary server, Primary as ACS.
On ACS Side, the device you like to Migrate to ISE, Remove the Key , try to Login, this time (if the config is good) it fall back to ISE and get authenticated, if that success, you remove ACS config and save config).
make sense ?
If that is tested 1 or 2 devices, you can use any scripting or any tools to make this automated and test it.
You still have Local account in case any failures to recovery.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide