Security

 View Only
last person joined: 2 days ago 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Migrate the On-premise ClearPass to Azure

This thread has been viewed 13 times
  • 1.  Migrate the On-premise ClearPass to Azure

    Posted 2 days ago

    Hello AirHeads,

    One of our client decided to move their ClearPass from on-premise to Azure Cloud as they are moving their AD to Azure (Azure AD). So we need a clarity of the below things

    • Can we migrate the on-premise  ClearPass license to new Azure ClearPass ?
    • Can we backup the exiting on-premise ClearPass configuration and upload to Azure ClearPass ? (the existing service setup is EAP-TEAP with TLS for both user and machine)

    Many Thanks,



  • 2.  RE: Migrate the On-premise ClearPass to Azure
    Best Answer

    Posted 2 days ago

    Yes, you can move the license to the Azure ClearPass server, but you need to contact support to get i enabled for activation again. Except if you also at the same time migrate from an older version below 6.11 to 6.11 or 6.12.

    The backup can be restored on the server in Azure. An other option is to join the Azure server as a Subscriber to the on prem server, this will sync the configuration, except extension configuration.

    After this move the Publisher role to the server in Azure and drop the on prem server from the cluster



    ------------------------------
    Best Regards
    Jonas Hammarbäck
    MVP Guru 2024, ACEX, ACDX #1600, ACCX #1335, ACX-Network Security, Aruba SME, ACMP, ACSA
    Aranya AB
    If you find my answer useful, consider giving kudos and/or mark as solution
    ------------------------------



  • 3.  RE: Migrate the On-premise ClearPass to Azure

    Posted 2 days ago

    Hi Jonas,

    Thanks for the valuable feedback.

    The best and preferred option you recommended is that the clustering between both on-premise and Azure ClearPass

    But there is a challenge here, because the on-premise ClearPass is 6.10 and Azure will support from 6.11 onwards only.  So can we make cluster between these two different image version? 

    I noticed you recommended a workaround 

    https://community.arubanetworks.com/discussion/clearpass-611-cluster-versioning

    Reg,

    Shamz




  • 4.  RE: Migrate the On-premise ClearPass to Azure

    Posted 2 days ago

    With two different versions you have to follow the 6.11 upgrade path.

    It's not possible to cluster two different major versions.



    ------------------------------
    Best Regards
    Jonas Hammarbäck
    MVP Guru 2024, ACEX, ACDX #1600, ACCX #1335, ACX-Network Security, Aruba SME, ACMP, ACSA
    Aranya AB
    If you find my answer useful, consider giving kudos and/or mark as solution
    ------------------------------