Security

 View Only
  • 1.  Aruba C1000V Upgrade

    Posted Jan 30, 2025 03:56 AM

    We have Aruba CPPM C1000V running as standalone Radius server. It is currently running on version 6.10.3.18 installed on Hyper-V. We are planning to upgrade to version 6.12.3.

    To avoid minimal downtime, and to make rollback easy, here is our plan:

    1. Deploy a new VM and install 6.11.1.251304 on the machine. The IP address on the machine will be different from the current CPPM.
    2. Install temp licenses for Access and Onboard.
    3. Export the CPPM backup and certificates.
    4. Power off the current CPPM and install certificates and import backup.
    5. Upgrade the CPPN to version 6.12.0 and install patch to make it to 6.12.3.
    6. Test the new Setup for a few days.
    7. Transfer the licenses from old setup to the new CPPM.

    Is this the best/recommended upgrade plan when trying to upgrade CPPM VM? Also I would like to know if:
    1. The config is imported, will the IP addresses also be applied on the VM? Since Radius is pointing to the old CPPM IP address we want the same IP to be used.

    2. Do we need to import anything besides the Backup and certificates? CPPM is being used for Radius authentication for corporate users and Captive portal for Guest.



  • 2.  RE: Aruba C1000V Upgrade

    Posted Jan 30, 2025 06:09 AM

    Hi

    I would modify the process as follows to minimize downtime and also be able to do fast rollback.

    1. Deploy a new VM and install 6.12.0 on the machine. The IP address on the machine will be different from the current CPPM.
    2. Install the same licenses as on the current server. It's ok during the migration. Activate the licenses.
    3. Update to latest ClearPass 6.12 version.
    4. Export the CPPM backup and certificates.
    5. Install the certificates and restore the backup
    6. Remember that all configuration settings done under the Server Manager \ Server Configuration and the server such as Service Parameters and hardening must be done manually.
      Also any routing information added in CLI must be entered manually
    7. Disable the network interface in Hyper-V on the old server
    8. Add the old server IP as a VIP address on the new server
    9. Test the new Setup for a few days.
    10. Shut down and decommission the old server

    The IP address is not restored with the configuration.

    If you have any ClearPass extensions you may need to install and configure these as well.

    By using a different IP on the new server you can keep the old up for a longer time and just add the old IP as a VIP address. This will also make it easy to do a similar process in the future if you need to migrate to another VM or hardware for some reason.



    ------------------------------
    Best Regards
    Jonas Hammarbäck
    MVP Guru 2024, ACEX, ACDX #1600, ACCX #1335, ACX-Network Security, Aruba SME, ACMP, ACSA
    Aranya AB
    If you find my answer useful, consider giving kudos and/or mark as solution
    ------------------------------



  • 3.  RE: Aruba C1000V Upgrade

    Posted Jan 30, 2025 09:40 AM

    Don't activate the licenses until the new server is up, completely configured, and validated.  Saves hassle if the process goes bad and spinning up a new server is the quicker option to fix.



    ------------------------------
    Carson Hulcher, ACEX#110
    ------------------------------



  • 4.  RE: Aruba C1000V Upgrade

    Posted Jan 30, 2025 09:10 PM

    FYI here is the official procedure for moving to ClearPass 6.11

    and then upgrading to ClearPass 6.12



    ------------------------------
    If my post was useful accept solution and/or give kudos.
    Any opinions expressed here are solely my own and not necessarily that of HPE or Aruba.
    ------------------------------



  • 5.  RE: Aruba C1000V Upgrade

    Posted Feb 03, 2025 06:31 AM

    - prepare an AD account for rejoining to the Domain

    - update radius ip with the new vm on the controller