Security

 View Only
  • 1.  ClearPass Upgrade: Physical to Virtual – Onguard Agent Concerns

    Posted Jun 13, 2025 03:01 AM

    Hi All,

    I'm planning to upgrade our ClearPass deployment from a physical appliance(6.10.8)  to a virtual machine(6.11.*). As part of this upgrade, I have a question regarding the Onguard Agent installed on user machines.

    Since we're currently using the persistent Onguard Agent, I'd like to understand what steps (if any) need to be taken on the client side when we migrate ClearPass. Specifically:

    • Will the existing agents automatically connect to the new virtual ClearPass server?

    • Do we need to update the agent configuration on each machine (e.g., IP or hostname)?

    • Is there a recommended approach for minimizing disruption during this transition?

    Appreciate any insights or best practices from those who have performed a similar migration.



  • 2.  RE: ClearPass Upgrade: Physical to Virtual – Onguard Agent Concerns

    Posted Jun 13, 2025 03:11 AM

    Hi @Mithran

    Just add VM to the cluster as subscriber, promote it to standby publisher, define VIP address and make sure that clients are connecting via VIP address. Then you can shutdown old publisher and VM will become publisher and clients will connect over VIP address.

    Best, Gorazd



    ------------------------------
    Gorazd Kikelj
    MVP Guru 2025
    ------------------------------



  • 3.  RE: ClearPass Upgrade: Physical to Virtual – Onguard Agent Concerns

    Posted Jun 15, 2025 07:25 PM

    @GorazdKikelj is this actually possible ? Joining a 6.11.x or later node to an existing 6.10.x cluster I thought is not supported as I thought they must be the same major version.

    @Mithran any reason you're choosing 6.11 and not 6.12? I'm in the same boat myself and curious. 




  • 4.  RE: ClearPass Upgrade: Physical to Virtual – Onguard Agent Concerns

    Posted Jun 15, 2025 10:34 PM
    Edited by GorazdKikelj Jun 15, 2025 10:36 PM

    Hi Brendan.

    No. You can't mix different versions. My comment was just on moving existing phy appliance to vm. To move from 6.10 to 6.11 or higher you need to create a new vm with 6.11 image and migrate config via backup/restore procedure as described in documentation.

    Having vip address will help minimize disruptions on the network when you migrate vip address from old node to new one after or before migration. 

    6.11 is LSR version and 6.12 is SSR version. Usually in production you preffere LSR version except if you really need features from short version.

    Best, Gorazd



    ------------------------------
    Gorazd Kikelj
    MVP Guru 2025
    ------------------------------



  • 5.  RE: ClearPass Upgrade: Physical to Virtual – Onguard Agent Concerns

    Posted Jun 16, 2025 09:22 AM

    .. for 6.12 specific, if you are doing anything with Azure/EntraID/Intune, go for 6.12 as it has big improvements.



    ------------------------------
    Herman Robers
    ------------------------
    If you have urgent issues, always contact your HPE Aruba Networking partner, distributor, or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact HPE Aruba Networking TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or HPE Aruba Networking.

    In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
    ------------------------------