Security

 View Only
Expand all | Collapse all

How to Upgrade ClearPass Cluster from C3000 (DL360 Gen9) to N3000 1G Hardware Appliance (Current Version 6.11)

This thread has been viewed 46 times
  • 1.  How to Upgrade ClearPass Cluster from C3000 (DL360 Gen9) to N3000 1G Hardware Appliance (Current Version 6.11)

    Posted Mar 17, 2025 05:10 AM

    Hello,

    I am looking to upgrade the ClearPass cluster from the current C3000 model (DL360 Gen9) to the new N3000 1G hardware appliance for one of our clients. The current version of ClearPass running is 6.11.

    Could someone guide me through the upgrade process or share any best practices to ensure a smooth migration to the new hardware?

    1. Are there any critical steps I should take before starting the upgrade?
    2. How should I handle migrating the data from the C3000 to the N3000 appliance?
    3. What are the key post-upgrade checks to ensure everything is functioning properly?
    4. Any important considerations regarding license transfer or activation on the new hardware?

    Any insights or documentation link would be greatly appreciated!

    Thanks in advance!



  • 2.  RE: How to Upgrade ClearPass Cluster from C3000 (DL360 Gen9) to N3000 1G Hardware Appliance (Current Version 6.11)

    Posted Mar 17, 2025 11:07 AM

    Easiest is to add the new appliance to the existing cluster as a subscriber, which will synchronize all of the ClearPass items to the new node.  You can then verify functionality on the new machine before moving over.  Once ready to move over, down the old machine and promote the new to Publisher.



    ------------------------------
    Carson Hulcher, ACEX#110
    ------------------------------



  • 3.  RE: How to Upgrade ClearPass Cluster from C3000 (DL360 Gen9) to N3000 1G Hardware Appliance (Current Version 6.11)

    Posted Mar 18, 2025 03:02 AM

    Thank you for your response. 

    What specific tests would you recommend to validate the functionality of the new subscriber before promoting it to Publisher? If possible, is there any knowledge base article or documentation?




  • 4.  RE: How to Upgrade ClearPass Cluster from C3000 (DL360 Gen9) to N3000 1G Hardware Appliance (Current Version 6.11)

    Posted Mar 18, 2025 06:41 AM

    You should test that all functionality that you use now, still works on that new appliances. When both are running side-by-side, you could move some switches/APs/devices to the new server and verify that all works as expected. If you have test/lab equipment you should ideally use that to avoid interference with the production environment.



    ------------------------------
    Herman Robers
    ------------------------
    If you have urgent issues, always contact your HPE Aruba Networking partner, distributor, or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact HPE Aruba Networking TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or HPE Aruba Networking.

    In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
    ------------------------------



  • 5.  RE: How to Upgrade ClearPass Cluster from C3000 (DL360 Gen9) to N3000 1G Hardware Appliance (Current Version 6.11)

    Posted Mar 19, 2025 05:38 AM

    Thank you for the guidance on testing and validating the new ClearPass appliance. I appreciate the suggestion to move a few devices to the new server and to use lab equipment for testing before full migration. This will definitely help in ensuring minimal impact on the production environment.

    I'll incorporate these steps into our migration plan.




  • 6.  RE: How to Upgrade ClearPass Cluster from C3000 (DL360 Gen9) to N3000 1G Hardware Appliance (Current Version 6.11)

    Posted Mar 19, 2025 06:03 AM

    Some configuration is not transferred to the new server by the cluster sync. This include any parameters under Server Manager \ Server Configuration for the servers. Like Service parameters, hardening under the Network tab, SNMP settings etc. These settings must be configured manually. As additional information, these settings are not included in the backups either.

    Any manually added routing information added in the CLI is host specific and will not be transferred, the same goes for certificates. They are installed on the specific server. If you are still using EAP-PEAP the servers must be joined to Active Directory. The AD join is done per server.

    Personally I prefer to have a VIP address for the RADIUS traffic for on prem ClearPass servers. This way I can very easily move the authentication traffic from one server to another without need to update DNS record or reconfigure switches and wireless infrastructure.

    Move the Publisher role from the old server to the new server before dropping that node from the cluster for decommission.



    ------------------------------
    Best Regards
    Jonas Hammarbäck
    MVP Guru, ACEX, ACDX #1600, ACCX #1335, ACX-Network Security, Aruba SME, ACMP, ACSA
    Aranya AB
    If you find my answer useful, consider giving kudos and/or mark as solution
    ------------------------------



  • 7.  RE: How to Upgrade ClearPass Cluster from C3000 (DL360 Gen9) to N3000 1G Hardware Appliance (Current Version 6.11)

    Posted Mar 19, 2025 06:23 AM

    Hi,

    Upgrading a ClearPass cluster from the C3000 (DL360 Gen9) to the N3000 1G hardware appliance running version 6.11 is a significant task, but with careful planning, it can be smooth. Since you're staying on 6.11, this is more of a hardware migration than a software upgrade, which simplifies some aspects. I'll walk you through the process, best practices, critical steps, data migration, post-upgrade checks, and license considerations based on general ClearPass migration principles and hardware swap workflows.

    Upgrade Process Overview

    The migration involves replacing the old C3000 appliances with new N3000 units while preserving your existing configuration, certificates, and data. Since ClearPass 6.11 on N3000 uses RHEL 8.x (same as C3000 on 6.11), there's no OS transition, but you'll need to reimage the N3000 appliances with 6.11, restore your configuration, and ensure cluster continuity. Here's a high-level process:

    1. Preparation: Backup everything, validate hardware, and plan downtime.

    2. Staged Migration: Build a parallel setup or replace nodes incrementally to minimize disruption.

    3. Data Migration: Transfer configuration, certificates, and optionally logs/Insight data.

    4. Cluster Reformation: Rejoin nodes to the cluster and validate replication.

    5. Post-Upgrade Validation: Confirm functionality and cluster health.

    Best Practices for a Smooth Migration

    • Minimize Downtime: If your cluster has multiple nodes (e.g., publisher and subscribers), upgrade subscribers first, keeping the publisher active to maintain service. Swap the publisher last.

    • Parallel Testing: If possible, set up the N3000 appliances with temporary IPs to test the restored config before cutting over.

    • Document Everything: Record IPs, hostnames, cluster roles, and certificate details from the C3000 cluster.

    • Engage Support: If you have an Aruba support contract, involve TAC or your SE for guidance, especially for licensing and unexpected hiccups.

    • Test Backups: Before starting, restore a backup to a VM (e.g., C1000V trial) to ensure it's viable.

    Critical Steps Before Starting

    1. Backup the Current Cluster:

      • On the publisher, go to Administration > Server Manager > Server Configuration > Backup.

      • Include configuration data (tipsdb, AppPlatform), Insight data (insightdb), and optionally session logs (tipsLogDb) if used in your workflows.

      • Export as a .bak file and store it securely off-cluster (e.g., SFTP or local drive).

    2. Export Certificates:

      • Navigate to Administration > Certificates > Certificate Store.

      • Export RADIUS, HTTPS, and any other service certificates as .p12 files with passwords. Each node might have unique certs, so check all.

    3. Record Licenses:

      • On the publisher, run show license in the CLI to list all application and platform keys. Save this output.

      • Note: Licenses are tied to hardware serial numbers, so you'll need to transfer them (more on this later).

    4. Check Cluster Health:

      • In Administration > Server Manager > Cluster Status, ensure all nodes are up and replication is healthy.

      • Fix any issues (e.g., DB sync errors) before proceeding.

    5. Validate N3000 Hardware:

      • Confirm the N3000 appliances are powered on, accessible via iLO, and have the right firmware (check HPE support for N3000 compatibility with 6.11).

      • Ensure network ports (mgmt, data) match your C3000 cabling plan.

    6. Disable Standby Publisher (if applicable):

      • In Administration > Server Manager > Cluster-Wide Parameters > Standby Publisher, remove any designated standby publisher. Restoring a backup with this enabled can break cluster formation on the new hardware.

    Migrating Data from C3000 to N3000

    Since you're moving hardware, you can't directly copy data disks-you'll rely on backups and manual restoration. Here's how:

    1. Prepare N3000 Appliances:

      • Use iLO to mount the ClearPass 6.11 ISO (download from Aruba Support Portal) and reimage each N3000 appliance.

      • During initial setup, assign temporary IPs and hostnames (you'll adjust these later to match the C3000 cluster).

    2. Restore Backup on the Publisher:

      • Log into the first N3000 (future publisher) via CLI or GUI.

      • Go to Administration > Server Manager > Server Configuration > Restore and upload the .bak file from the C3000 publisher.

      • Use the -s flag in CLI (system restore -s) if the backup includes a standby publisher config to avoid cluster join issues.

      • Reboot after restoration.

    3. Import Certificates:

      • In Administration > Certificates > Certificate Store, import the .p12 files for each service, matching the C3000 setup.

    4. Handle Subscribers:

      • Reimage additional N3000 nodes with 6.11, but don't restore the full backup yet.

      • Join them to the restored publisher via Administration > Server Manager > Server Configuration > Join Cluster, using the publisher's IP and cluster password.

      • The publisher will sync config data to subscribers automatically.

    5. Cutover IPs:

      • Once tested, power off the C3000 nodes and reassign the original IPs to the N3000 nodes to maintain network continuity.

    Key Post-Upgrade Checks

    1. Cluster Status:

      • In Administration > Server Manager > Cluster Status, verify all N3000 nodes are listed, online, and syncing (no red flags).

    2. Authentication Tests:

      • Test 802.1x (EAP-TLS) with a sample client device to confirm certificate-based auth works.

      • Check logs in Monitoring > Live Monitoring > Access Tracker for successful authentications.

    3. Service Functionality:

      • Validate RADIUS, TACACS+, Guest, Onboard, and OnGuard services (if used) against your policies.

    4. Database Replication:

      • Run show db-status in CLI on each node to ensure DB services (tipsdb, insightdb) are running and synced.

    5. Network Connectivity:

      • Confirm management and data interfaces are up (e.g., show interface in CLI) and reachable by switches/APs.

    6. Insight Reports:

      • If using Insight, generate a report to verify historical data restored correctly.

    License Transfer and Activation

    Licenses are tied to the hardware's Protected Access Credential (PAC) or serial number, so moving to N3000 requires reactivation:

    1. Retrieve Current Licenses:

      • You already have them from the show license output. They include platform (PAK) and application keys (Access, Onboard, etc.).

    2. Contact Aruba Support:

      • Submit a request via the Aruba Support Portal or your SE to transfer licenses from C3000 to N3000 serial numbers.

      • Provide old and new hardware serials (find N3000 serials via iLO or CLI: show hardware).

    3. Activate on N3000:

      • After restoration, go to Administration > Server Manager > Licensing on the publisher.

      • Enter the new platform key for the N3000 hardware and re-add application keys (they're cluster-wide and should still work if unchanged).

      • If offline, use the offline activation process with a generated request file.

    4. Verify:

      • Run show license again to confirm all licenses are active 

    • Important Considerations

      • Downtime: Plan a maintenance window-restoring and rejoining the cluster can take 1-2 hours per node, depending on DB size.
      • 6.11 Stability: Since 6.11.0 had issues (pulled by Aruba), ensure you're on a stable patch (e.g., 6.11.4 or later). Check release notes on the Aruba Support Portal.
      • Hardware Differences: N3000 (DL20 Gen10) is 1G-only vs. C3000's 10G capability. Ensure your network design aligns with 1G interfaces.
      • Fallback Plan: Keep C3000 appliances intact until the N3000 cluster is fully validated, so you can revert if needed.

      Documentation Links

      • ClearPass 6.11 Installation Guide: Check the "Moving to ClearPass 6.11" section for cluster migration details (Aruba Support Portal).
      • Release Notes: Review known issues and hardware support for 6.11 (Aruba Support Portal).
      • HPE N3000 Specs: Confirm hardware details on HPE's site (search "HPE ClearPass N3000").

      This should set you up for success. If you hit snags (e.g., DB replication failing or license woes), let me know the specifics, and I'll refine the guidance!




      Thanks 






  • 8.  RE: How to Upgrade ClearPass Cluster from C3000 (DL360 Gen9) to N3000 1G Hardware Appliance (Current Version 6.11)

    Posted Mar 21, 2025 05:45 AM
    Edited by nehabw Mar 21, 2025 06:50 AM

    Thanks a loads..! @rupkumm16

    We have 20+ servers (running on 6.11.10) in one cluster with one PUB (does not do any authentication), one STANDBY PUB and remaining are SUBSCRIBERS (authentications are load balanced)

    I think it will take at-least 4 months to get it done completed. 




  • 9.  RE: How to Upgrade ClearPass Cluster from C3000 (DL360 Gen9) to N3000 1G Hardware Appliance (Current Version 6.11)

    Posted Mar 21, 2025 07:18 AM
    Your welcome Neha





  • 10.  RE: How to Upgrade ClearPass Cluster from C3000 (DL360 Gen9) to N3000 1G Hardware Appliance (Current Version 6.11)
    Best Answer

    Posted Mar 21, 2025 08:25 AM
    Edited by nehabw Mar 24, 2025 01:58 PM

    Hi @nehabw

    Sorry to say it looks like the answer from @rupkumm16 is generated by AI as it has a lot of signs of AI generated stuff. Looks good at a first glance, but after a deeper reading it's found to be full of errors, non existing commands, technical buzzwords without meaning etc.

    For example the following commands mentioned in the post does not exists in ClearPass CLI:

    • system restore
    • show db-status
    • show interface
    • show hardware

    Basically, as you are already running on 6.11 you have two paths to follow.

    1. Keep old cluster, set up a new in parallel
    2. Join new nodes in the current cluster

    With the first option you are sure that no work done during the setup and configuration of the new servers can cause disturbances and downtime on the current authentication flow, but you have to move authentication to the new servers some where in the process. Also you will have two publishers to maintain during your migration project. Depending on number of configuration changes this may be a challenge to keep the two clusters in sync manually. Guest users will be a really big challenge.

    I would follow the second option , I have successfully replaced nodes in distributed clusters with servers in several countries with this method.

    If you doesn't already have VIP addresses, I think VIP is a good way to transfer the authentication load between servers. I usually configure one VIP address per server and utilize this address for authentication traffic instead of the interface IP on the server. This way I can very easily move the load to the new hardware server. Without need to change IP, update DNS or updating RADIUS configuration on your network equipment.

    As you have a quite large cluster you can add a few new nodes to the cluster, test them, transfer the production authentication to the new host and then decommission the old hardware. Then continue to the next round of servers. When you join the cluster all configuration is replicated, no need for backups and restores.
    I would start with some "less important" servers like the stand by publisher, and one subscriber close to your physical location. This way your testing may be easier to do as you don't need to contact local staff to perform test authentications.

    Test that would be good to do on subscribers are of course all types of authentication methods like 802.1x, MAC auth and guest authentication. If EAP-PEAP is still in use in your organization, all new servers must be joined to AD and you need to specify logon servers. In that case verify both the LDAP connection and the NTLM part during authentication.

    For the new server that will take over as publisher or stand by publisher, make extra verifications of port openings to and from all nodes in the cluster.

    Some information is done on each server. This is the configuration done on each server node under Administration\Server Manager\Server Configuration\<Server Name>.
    For example service parameters, SNMP configuration, network hardening etc.
    Also if you have any static routing entries added in CLI, this must be added on each server.

    I'm not sure about the maximum number of servers in a ClearPass 6.11 cluster. In previous version the upper limit was around 40. I think I have read that it's lower in 6.11 or 6.12, investigate this.

    Regarding the licenses, you need to move your application licenses like Access, Onguard and Onboard if you set up a new cluster in parallel. If you join the current cluster the licenses are already installed in the cluster and no need to do anything. The PAK licenses are bound to the hardware serial numbers, you will need to retrieve the new PAK licenses from the networking support portal for the new servers.

    When adding new servers to a cluster, remember to verify that all port openings between nodes on different subnets are in place, also check that there is enough IP addresses on each subnet for the new servers.

    During the planning, make sure to have detailed plans both for the execution and rollback. It's a big task to replace 20 ClearPass servers in production, but with good planning it's possible to do without disturbances for end users.

    Good luck!



    ------------------------------
    Best Regards
    Jonas Hammarbäck
    MVP Guru, ACEX, ACDX #1600, ACCX #1335, ACX-Network Security, Aruba SME, ACMP, ACSA
    Aranya AB
    If you find my answer useful, consider giving kudos and/or mark as solution
    ------------------------------



  • 11.  RE: How to Upgrade ClearPass Cluster from C3000 (DL360 Gen9) to N3000 1G Hardware Appliance (Current Version 6.11)

    Posted Mar 21, 2025 09:45 AM

    Maximum nodes in a cluster is 32.



    ------------------------------
    Carson Hulcher, ACEX#110
    ------------------------------



  • 12.  RE: How to Upgrade ClearPass Cluster from C3000 (DL360 Gen9) to N3000 1G Hardware Appliance (Current Version 6.11)

    Posted Mar 24, 2025 02:05 PM

    @jonas.hammarback Thanks for the heads-up..!

    "If EAP-PEAP is still in use in your organization, all new servers must be joined to AD and you need to specify logon servers." >> NOTED.

    We will consider every point while planning the upcoming migration and will be involving TAC as well. Thanks once again..!