Security

 View Only
last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Strategy to upgrade physical Clearpass servers

This thread has been viewed 16 times
  • 1.  Strategy to upgrade physical Clearpass servers

    Posted Jan 07, 2022 09:24 AM
    Hi everyone,

    Our old CPPM servers are going EOL in April so we purchased new ones to upgrade them.  I'm wondering what the best or simplest approach is to swap the existing gear out.  We have to keep the same IP addressing scheme as the current ones so that limits us to having a parallel environment of any kind.

    My thoughts were to stage each one in our lab with just login credentials and the same IP address.  Then we would unplug the old one, plug the new one into the switch and then complete any finishing touches before joining it to the cluster.

    If the above makes sense, is there a process to doing this like upgrading the subscribers first and then the publisher or doing the publisher first (by promoting another subscriber to become publisher first)?  

    Thanks for any suggestions or tips.


    ------------------------------
    Jose Robles
    ------------------------------


  • 2.  RE: Strategy to upgrade physical Clearpass servers

    MVP EXPERT
    Posted Jan 08, 2022 04:51 AM
    What I do is build new server up to same release
    Assign IP address
    Unbind old one and power down
    Connect new server to prod net
    Bind into cluster

    Pretty much what you’ve suggested :-)
    A




  • 3.  RE: Strategy to upgrade physical Clearpass servers

    Posted Jan 08, 2022 11:43 AM
    Thanks @alexs-nd for the confirmation.  What about the publisher node?  Does what I suggested make sense?​

    ------------------------------
    Jose Robles
    ------------------------------



  • 4.  RE: Strategy to upgrade physical Clearpass servers

    MVP EXPERT
    Posted Jan 10, 2022 01:50 AM
    As your jut upgrading hardware and not a cppm version,. Yes, once you’ve upgraded one of your subscribers, promote it to being the publisher and then upgrade original publisher
    A




  • 5.  RE: Strategy to upgrade physical Clearpass servers

    Posted Jan 10, 2022 08:07 AM
    Thanks for the confirmation. 

    Cheers!

    ------------------------------
    Jose Robles
    ------------------------------



  • 6.  RE: Strategy to upgrade physical Clearpass servers

    MVP EXPERT
    Posted Jan 10, 2022 08:13 AM
    remember you’ll need to add all your certs to the new boxes

    A




  • 7.  RE: Strategy to upgrade physical Clearpass servers

    Posted Jan 14, 2022 03:41 PM

    Great timing.  I logged in to ask this exact same question.  We're getting ready to upgrade our existing physical servers that are going EOL to virtual servers.

    Our plan is to:

    Give the two new servers a new IP
    Upgrade to the same release as the existing servers (6.9.4)
    Install certs on new servers
    Break the virtual IP for the two physical servers in the cluster
    Drop server from cluster and shutdown subscriber server
    Change new virtual server to IP of old subscriber and power on
    Join cluster, once synced promote new virtual to Publisher
    Do the same with second virtual
    Finally setup virtual IP.

    Then we'll probably wait a week or so and then do an upgrade to 6.10

    Sound about right?  Any issues with licensing and changing IP addresses?

    Thanks
    Andy



    ------------------------------
    Andy Jezierski
    ------------------------------