ISE upgrade

 








































===== Backup and Restore method to upgrade ISE to 3.x====

Current Deployment: two ISE nodes
ISE01: Primary Admin Node, Secondary Monitoring Node.
ISE02: Primary Monitoring Node, Secondary Admin Node.


Upgrade steps:
1. Backup ISE configuration and optional operation data.
2. Export Certificates from both nodes (including private keys)
3. Export Running Configuration from both nodes into separate notepad files
4. Disconnect or shutdown ISE02
5. Build a new VM ISE3.x node with the same IP address, hostname, DNS, NTP, Domain Name and all other settings as ISE02 (all details are saved in the notepad file).
6. Restore backup to this new VM, this VM will be in standalone mode.
7. Import certificate and private key, install the patch to this new VM.
8. Make this new VM as Primary PAN/MnT, verify its functionality.
9. Disconnect or Shutdown ISE01
10. Build the 2nd new VM ISE3.x  with the same IP address, hostname, DNS, NTP, Domain Name and all other settings as ISE01 (all details are saved in the notepad file)
11. Import certificate and private key, install the latest patch to the 2nd new VM.
12. Join the 2nd new VM to the new deployment as the Secondary PAN.
13. Promote the 2nd new VM as  Primary PAN, verify its functionality.
14. Contact Cisco to convert Smart Licenses.


=======================





Comments

Popular posts from this blog

Firepower FMC and FTD troubleshooting

ASA IKEv1 VPN troubleshooting Steps and Tips

Firepower 2100/1100 FTD/ASA initial setup, reimage, upgrade.