cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
613
Views
0
Helpful
2
Replies

ISE Standalone to Distributed deployment - PSN IP Addressing

jsanz
Cisco Employee
Cisco Employee

Hi,

Is there any recommendation of moving from ISE standalone to distributed deployment and deploying new PSN for avoiding reconfiguring all NAD with new Radius server Ip Address? Starting with LB in the Standalone deployment would help with this, is there any other option?

Thanks

1 Accepted Solution

Accepted Solutions

If you think you can pull off turning the current node IP into a VIP you could do the following with no down time until the end:

 

Build a brand new distributed deployment.  New Admin/M&Ts backing each other up.  New PSNs behind the load balancer.  Restore the backup of your current environment to the distributed environment.  Rehost licensing or enabled smart licensing.  Build a new VIP on the load balancer pointing to the PSNs and test your rule set with test network devices.

 

During a cutover window, shut down current standalone ISE node and change the VIP on the load balancer to the IP that was on the standalone ISE node.

 

If the conversion fails then change the VIP back to the IP you used for testing and power back on the standalone ISE node. 

View solution in original post

2 Replies 2

Jason Kunst
Cisco Employee
Cisco Employee
Perhaps try making a new PAN/MNT as a secondary. then promoting to primary and removing those services from the original IP?

If you think you can pull off turning the current node IP into a VIP you could do the following with no down time until the end:

 

Build a brand new distributed deployment.  New Admin/M&Ts backing each other up.  New PSNs behind the load balancer.  Restore the backup of your current environment to the distributed environment.  Rehost licensing or enabled smart licensing.  Build a new VIP on the load balancer pointing to the PSNs and test your rule set with test network devices.

 

During a cutover window, shut down current standalone ISE node and change the VIP on the load balancer to the IP that was on the standalone ISE node.

 

If the conversion fails then change the VIP back to the IP you used for testing and power back on the standalone ISE node.