ā03-12-2023 11:32 PM
Hi All,
Any Suggestions - Please help !
We are in planning stage of our ISE upgrade from 2.6 no Patch to 3.1, details are below in current and proposed setup. Can somebody please help me with the upgrade approach ? We plan to build a parallel setup and gradually migrate all the radius/TACCAS NADs.
Current Setup:
We have distributed deployment. with PAN/MNT/PxGrid/PSN on SNS-3595 in 1 DC as Primary & Secondary PAN/MNT/PxGrid/PSN on SNS-3595. We have 2x PSNs only deployed in a remote location. These are configured as a single deployment running on 2.6 with no patch.
Proposed Setup:
We plan to upgrade the primary PAN/MNT/PxGrid/PSN running on SNS-3595 to SNS-3755 in DC-1 and decouple the PSN from the existing node to dedicate a PSN only BOX at each DC. So we will have 4 Appliances (SNS-3755) rather that 2 in DC-1 and DC-2. we also have the dedicated remote 2x PSN only on 2x SNS-3655 appliances. We do not plan to upgrade these as these are not EOL soon.
Thanks in Advance
ā03-13-2023 01:17 AM
check this discussion recently user trying to do same or near by your kind of setup :
ā03-13-2023 02:21 AM
Thanks for directing me to the link - will go through and come back if required
ā03-13-2023 10:59 AM
Hi
I just checked the link - it seems to be more related to Licenses, i am clear off .
can you provide me with some insight regarding the the whole migration ? maybe a good document which covers all aspects of ISE 2.6 to 3.1 ISE migration like , existing certificates, ISE existing database , existing PSNs migration ?
Regards
ā03-15-2023 07:32 PM
Personally, I would install 3.1 fresh installation,s and Migrate the Data (offline ) and test it, and add them to the network.
or you can install on the new Kit 2.6 and upgrade to 3.1 as per below guide (make sure you do testings before you put them back in Live environment)
check below guides :
https://www.cisco.com/c/en/us/td/docs/security/ise/3-1/upgrade_guide/HTML/b_upgrade_method_3_1.html
ā03-16-2023 05:15 AM
@n_nmanzoor wrote:
Proposed Setup:
We plan to upgrade the primary PAN/MNT/PxGrid/PSN running on SNS-3595 to SNS-3755 in DC-1 and decouple the PSN from the existing node to dedicate a PSN only BOX at each DC. So we will have 4 Appliances (SNS-3755) rather that 2 in DC-1 and DC-2. we also have the dedicated remote 2x PSN only on 2x SNS-3655 appliances. We do not plan to upgrade these as these are not EOL soon.
Thanks in Advance
ā03-16-2023 12:55 PM
Maybe a small tip: don't forget to domain join your freshly installed nodes, or any authentication that uses AD groups will fail
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide