Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

User and Group Database Migration

I am installing SecureACS 4.1 from scratch on a new Server. Is there a way for me to migrate the user and groups from a previous 2.4 and 3.0 vs install? there has to be an easier way to create all those groups and users?

4 REPLIES
Silver

Re: User and Group Database Migration

Someone at Cisco decided that from 4.0 onwards they wouldnt upgrade from every previous version any more.

I think this means you'd have to upgrade the existing server to 3.1 then create a backup.

NExt install 3.1 on the new server and restore the backup.

Lastly upgrade the new server to 4.1 and cross your fingers it upgrades smoothly!

An easier (but less complete) method is simply to run csutil -d on the first server, copy the dump file to the new one and then use csutil -l. HOWEVER... this can cause problems if you're group/user config uses NDGs (eg NDG->DCS command authorisation) because only NDG indexes are in the dump file.

When you re-create the NDGs on the new server the indexes are likely all be different.

So in summary only use the csutil route if your just moving very simple groups or users.

BTW there is an option for csutil to load just the users from a dump file leaving groups untouched (run csutil -x to find out more)

Darran

ps we're seeing more people installing ACS (and aaa-reports!) under VMWare - which then makes hardware upgrades a non-issue.

New Member

Re: User and Group Database Migration

Its always safe to follow CISCO recommended procedures as it will be trustworthy.

ACS 4.1 supports the following upgrade paths.

These paths have been tested and are supported:

Cisco Secure ACS for Windows, release 3.3.3 to ACS 4.1

Cisco Secure ACS for Windows, release 4.0 to ACS 4.1

For releases of ACS prior to ACS 3.3.3, you must first upgrade to ACS 3.3.3, then upgrade to ACS 4.1.

Cisco Employee

Re: User and Group Database Migration

Hi,

I think the path would be :-

2.4->2.6.4->3.0.4->3.3.3->4.1

Regards,

Vivek

New Member

Re: User and Group Database Migration

Update - i created a TAC Case and the Engineer took my backup and updated it to 4.1 vs for me. I guess that's the price you pay for being so far back on revision?

126
Views
0
Helpful
4
Replies
CreatePlease login to create content