Security

 View Only
last person joined: 6 hours ago 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Couple of questions about migrating from 6.10.8 to 6.11

This thread has been viewed 74 times
  • 1.  Couple of questions about migrating from 6.10.8 to 6.11

    Posted Feb 14, 2024 02:49 PM

    Hi,

    I'm getting ready to install and migrate to 6.11 from 6.10.8 C2000V on ESXi

    1. I downloaded the 6.11.1 version of the OVA.  I was planing on also installing hotfix and patches to get it to 6.11.7 BEFORE I restore my configuration and certificates.  Is this correct?
    2. I was also planning on using the same hostname and IP address for the new server.  So in a maintenance window, I'll shutdown and deactivate the license of the old server before I start the Clearpass setup in the ESXI console.  Is that what other people are doing?

    Thanks



  • 2.  RE: Couple of questions about migrating from 6.10.8 to 6.11

    Posted Feb 14, 2024 04:28 PM

    Sounds like you will have a complete Maintenace window, which is not as common of a scenario. 

    If that's the case the series of events is less critical:

    I would get all nodes installed and updated before restoring the configuration or setting up publisher/subscriber relationship. This will ensure a stable OS and will be faster than a cluster update. 

    For Licensing - do you have your licensing registered in ASP/LMS with a support contract?



    ------------------------------
    If my post was useful, please Accept Solution and Give Kudos.
    ------------------------------
    Zak Chalupka
    Principal Engineer - HPE Aruba
    ACDX | ACMP | ACSP | ACCP
    wifizak@hpe.com
    ------------------------------
    Ideas expressed here are solely my own and not necessarily that of HPE Aruba.
    ------------------------------



  • 3.  RE: Couple of questions about migrating from 6.10.8 to 6.11

    Posted Feb 14, 2024 04:55 PM

    Thanks.  We just have a standalone Clearpass.  It was just recommended to me to make a backup or cluster.  I haven't looked at licensing for that yet.

    I was planning on having all the backups ready from the 6.10 server, I'll have the new server installed and configured in ESXi, then I'll power on the new server for the first time and start working. We're a school so I can do this weekend and I'll start early.  Plan for 4 hours maybe.

    Yes I already contacted Aruba and verified our license is attached to our support contract.

    So you think it's more common to use a new IP address on the new server?




  • 4.  RE: Couple of questions about migrating from 6.10.8 to 6.11

    Posted Feb 15, 2024 04:15 AM

    Hi

    Regarding the license you do not need to ask Aruba to enable it for activation again, as the 6.11 activation will work also if the license have been activated in 6.10. If you need to reactivate the license in the future, you have to contact Aruba TAC to enable the license for activation again, as we are used to do.

    In most of the cases where I have migrated customers to 6.11 I have opted for new IP addresses on the 6.11 servers. This way I can complete all the updates, restore procedures, clustering etc before the active 6.10 nodes are taken offline.

    Ofcourse this will lead to some additional work related to port openings, som new DNS records etc. But from my point it's almost always worth this extra tasks.

    In addition most of the environments I work with we have VIP addresses for the authentication traffic. This way when it's time to change from 6.10 to 6.11 the only work is to remove the VIP addresses from the 6.10 cluster to the 6.11 cluster. If the old cluster doesn't have a VIP I usually take the old servers IP addresses as VIP addresses in the 6.11 cluster. By this I do not need to update any of the network equipment with new IP addresses or DNS namnes for Radius and TACACS+.

    Another benefit with separate IP and server names is if you have a Active Directory domain join, you will join the 6.11 server under a new name. Thius way the 6.10 server will not lose it's domain join.

    If you keep your initial plan to shut down the 6.10 host and start to work on the 6.11 I recommend to practice the restore process in a lab before hand. I have done the restore process with a customer under 4 hours but it's not optimal.



    ------------------------------
    Best Regards
    Jonas Hammarbäck
    MVP Guru 2024, ACEX, ACDX #1600, ACCX #1335, ACX-Network Security, Aruba SME, ACMP, ACSA
    Aranya AB
    If you find my answer useful, consider giving kudos and/or mark as solution
    ------------------------------



  • 5.  RE: Couple of questions about migrating from 6.10.8 to 6.11

    Posted Feb 15, 2024 08:12 AM

    @ Jonas: When you have two clusters running in parallel, the new 6.11 cluster is updated, licensed and ready.  When restoring the backup from 6.10 does the IP address restore?  I am afraid two clusters have the same IP address when finish restoring.

      




  • 6.  RE: Couple of questions about migrating from 6.10.8 to 6.11

    Posted Feb 15, 2024 08:15 AM

    Hi

    No, IP addresses are not restored. In fact no settings at all done under the specific server objects are restored from the backup. So all customizations of service parameters and settings under the Network tab must be entered manually.

    During the restore VIP configuration will be restored, but not enabled, if you have VIP addresses in the old cluster.



    ------------------------------
    Best Regards
    Jonas Hammarbäck
    MVP Guru 2024, ACEX, ACDX #1600, ACCX #1335, ACX-Network Security, Aruba SME, ACMP, ACSA
    Aranya AB
    If you find my answer useful, consider giving kudos and/or mark as solution
    ------------------------------



  • 7.  RE: Couple of questions about migrating from 6.10.8 to 6.11

    MVP
    Posted Feb 15, 2024 08:24 AM

    How did you handle the update activation delay? I have condfigured several 6.11.x servers and needed to wait close to 24 hours before being able to patch.

    From past experiences working with RMA replacements I would not attempt to change an ip address after configuring the server wither.



    ------------------------------
    Bruce Osborne ACCP ACMP
    Liberty University

    The views expressed here are my personal views and not those of my employer
    ------------------------------



  • 8.  RE: Couple of questions about migrating from 6.10.8 to 6.11

    EMPLOYEE
    Posted Feb 15, 2024 10:57 AM

    I think that support check delay was resolved in the 6.11.1image, which is why there is an updated image. This should no longer be an issue.



    ------------------------------
    Herman Robers
    ------------------------
    If you have urgent issues, always contact your Aruba partner, distributor, or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact Aruba TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.

    In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
    ------------------------------



  • 9.  RE: Couple of questions about migrating from 6.10.8 to 6.11

    MVP
    Posted Feb 15, 2024 11:02 AM

    i have been using the 6.11.1VMWare  VM image for quite a while, most recently, last month. the delay was still there at that time. My SE even saw it.



    ------------------------------
    Bruce Osborne ACCP ACMP
    Liberty University

    The views expressed here are my personal views and not those of my employer
    ------------------------------



  • 10.  RE: Couple of questions about migrating from 6.10.8 to 6.11

    EMPLOYEE
    Posted Feb 16, 2024 03:58 AM

    This is the information that I got. There is a warning in 6.11.1 but if you ignore that you can upgrade.



    ------------------------------
    Herman Robers
    ------------------------
    If you have urgent issues, always contact your Aruba partner, distributor, or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact Aruba TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.

    In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
    ------------------------------



  • 11.  RE: Couple of questions about migrating from 6.10.8 to 6.11

    Posted Feb 20, 2024 03:59 PM
    We have a two node cluster running on VMs and built new systems with the same IP addresses on an isolated network. We used a management station with interfaces on production and the isolated network to move configs and updates between the networks. We were able to install updates manually before going live. When we went live, we shut the old systems down and changed the new servers to be on the production network, joined the domain, built the cluster, set VIPs, activated licenses, etc. TAC reset the update stuff and it appears to be working OK.

    Robert







  • 12.  RE: Couple of questions about migrating from 6.10.8 to 6.11

    Posted Feb 15, 2024 09:21 AM

    Hi Jonas.  That's a good idea.  Couldn't I setup my 6.11 standalone server with a new IP address then when I'm ready to switch, make a VIP of the old server IP address? 




  • 13.  RE: Couple of questions about migrating from 6.10.8 to 6.11

    MVP
    Posted Feb 15, 2024 10:08 AM

    If I recall correctly, the VIP needs to be in the same subnet as the server.  we do not use VIPs currently.



    ------------------------------
    Bruce Osborne ACCP ACMP
    Liberty University

    The views expressed here are my personal views and not those of my employer
    ------------------------------



  • 14.  RE: Couple of questions about migrating from 6.10.8 to 6.11

    Posted Feb 15, 2024 10:27 AM

    @OESTech you can set up the new 6.11 server on the same subnet as the old 6.10 server and then move the server IP to the 6.11 server as a VIP. As mentioned the IP addresses must be on the same IP subnet.

    @bosborn, I don't know if there is a difference in behavior when installing updates if you are a customer or a partner. But as a partner at least it's possible to download the update from ASP and upload to the ClearPass hosts and install before the 24 hours have passed.



    ------------------------------
    Best Regards
    Jonas Hammarbäck
    MVP Guru 2024, ACEX, ACDX #1600, ACCX #1335, ACX-Network Security, Aruba SME, ACMP, ACSA
    Aranya AB
    If you find my answer useful, consider giving kudos and/or mark as solution
    ------------------------------



  • 15.  RE: Couple of questions about migrating from 6.10.8 to 6.11

    Posted 17 days ago

    Hi Jonas, 

    Have you experienced any anomalies by building in parallel a cluster of 6.11? I just built my first 6.11 vm using an IP that belong to current cluster 6.10 (but it was dropped), I did a restore and migrated the DB (everything came as expected), removed the vips just a a precaution and I noticed one webauth for onguard.  Now I'm second guessing if restoring the DB was a good idea but I wasn't expecting any auth come to the new 6.11 since everything is pointing to the vips.  



    ------------------------------
    MLG
    ------------------------------



  • 16.  RE: Couple of questions about migrating from 6.10.8 to 6.11

    MVP
    Posted Feb 15, 2024 08:05 AM

    From my testing experience you cannot do everything in 4 hours. After you license the 6.11 VM wou usually need to wait about 24 hours before it realized you have a support contract. You need to wait before you can patch.

    In our case we are setting up a new 6.11 cluster & migrating our many services over to it.



    ------------------------------
    Bruce Osborne ACCP ACMP
    Liberty University

    The views expressed here are my personal views and not those of my employer
    ------------------------------