cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2066
Views
6
Helpful
3
Replies

Changing Cisco ISE IP adress

Hi, 

 

I have imported Config backup from old node in a cluster, into new VM

I want to change the address IP of the VM but it ask me to break the cluster, and i have no access from the GUI.

How can i erase cluster configuration and change address ip from the CLI.

 

Regards

1 Accepted Solution

Accepted Solutions

Dinesh Moudgil
Cisco Employee
Cisco Employee

Hi Oussama,

 

For changing IP address on ISE, the prerequisite is:

"If the Cisco ISE node is part of a distributed deployment, you must first remove it from the deployment and ensure that it is a standalone node."

 

If you execute "application reset-config ise",  that resets all the GUI configuration (includes distributed deployment configuration) and retains CLI configuration.

 

Regards,

Dinesh Moudgil

P.S. Please rate helpful posts.

Cisco Network Security Channel - https://www.youtube.com/c/CiscoNetSec/

View solution in original post

3 Replies 3

Dinesh Moudgil
Cisco Employee
Cisco Employee

Hi Oussama,

 

For changing IP address on ISE, the prerequisite is:

"If the Cisco ISE node is part of a distributed deployment, you must first remove it from the deployment and ensure that it is a standalone node."

 

If you execute "application reset-config ise",  that resets all the GUI configuration (includes distributed deployment configuration) and retains CLI configuration.

 

Regards,

Dinesh Moudgil

P.S. Please rate helpful posts.

Cisco Network Security Channel - https://www.youtube.com/c/CiscoNetSec/

thank you for providing extra insight on this topic. i do have a follow up question on your post

1) when re-IPing in a clustered environment, is there a preferred order the nodes must be re-IPed in? meaning should the Primary admin node be re-IPed first and then the secondary admin node followed by the PSN? OR is it that the order doesnt matter? 

is part of the re-IPing process to issue the "reset config" command via cli?

for the certs, do you need to issue a newly generated cert to the node? OR can you re-use the previous cert before you re-IPed? 

Resurrecting a 2-year old + thread that has an accepted solution limits the number of people that will take a look at it. The best thing to do is to start a new thread.