Hi @Mithran
Sorry for late reply, maybe you have sorted this out already.
Before you do something with the current subscriber like changing IP or dropping, you need to remove the server from the VIP configuration.
If you change the IP addresses without dropping the node from the cluster you may get a lot of error messages and the server may come out of sync in the cluster. I would recommend to drop the node first and after that change the IP.
In ClearPass 6.11 and later a change of the management IP address will also update the database certificate with the new IP in the SAN field. This may take "some time", or you can update the certificate manually. Otherwise the server will start to give error messages related to not being able to read internal databases.
------------------------------
Best Regards
Jonas Hammarbäck
MVP Guru, ACEX, ACDX #1600, ACCX #1335, ACX-Network Security, Aruba SME, ACMP, ACSA
Aranya AB
If you find my answer useful, consider giving kudos and/or mark as solution
------------------------------
Original Message:
Sent: Feb 05, 2025 11:30 AM
From: Mithran
Subject: Publisher(VMware) and Subscriber(KVM)
Hi @jonas.hammarback ,
I plan to first power off the existing subscriber, then change its IP address to that of the new subscriber and add it to the current publisher. However, I'm unsure whether we should power off the subscriber first or drop it from the cluster before shutting it down. Also, do we need to remove the subscriber's IP address from the VIP before making the changes?
Original Message:
Sent: Jan 27, 2025 08:19 AM
From: jonas.hammarback
Subject: Publisher(VMware) and Subscriber(KVM)
Hi
When I move to a new server within the cluster and have VIP addresses configured I prefer to configure the new server on a new IP, patch the server to the same level as the current servers and make the new server a subscriber in the cluster and as a final task move VIP address(es) as needed.
After this just drop the old server from the cluster and decommission.
If you would like to keep the same IP you have to shut down the old server before bringing the new server up with the same IP. But the process is more or less the same.
As you move the license from one instance of ClearPass to another you need to contact Aruba support and ask them to enable the license for Activation again.
Remember that service parameters, routing entries added in CLI, hardening of subnets that can access admin pages etc isn't included in the cluster configuration nor backupfiles. Thus all settings under the server object in Server Manager that have been changed from default must be updated manually.
------------------------------
Best Regards
Jonas Hammarbäck
MVP Guru 2024, ACEX, ACDX #1600, ACCX #1335, ACX-Network Security, Aruba SME, ACMP, ACSA
Aranya AB
If you find my answer useful, consider giving kudos and/or mark as solution
Original Message:
Sent: Jan 27, 2025 07:46 AM
From: Mithran
Subject: Publisher(VMware) and Subscriber(KVM)
Hello All, We currently have two ClearPass appliances in a cluster setup (1 Publisher and 1 Subscriber) installed in VMware. We are planning to migrate the Subscriber to a KVM-based virtual machine, while maintaining the same IP address.
Could you please advise if there will be any impact on the following during the migration:
Cluster Synchronization
Virtual IP (VIP) Handling –
If you have any guidance or best practices to ensure a smooth migration process without disrupting the cluster sync or VIP functionality, that would be greatly appreciated.
Looking forward to your input.