PSA to ISA Migration

Introduction

This document describes about the guidelines and procedure for successfully migrating the ICS/IPS configurations from PSA Appliance to ISA Appliance. The ISA Appliance is the new next generation Secure Access Gateway with enhanced security and improved performance.

The recommended way to transfer the configuration and settings is through the export of binary configurations from PSA Appliance to ISA Appliance.

Follow the steps in this document to ensure successful configuration migration to next generation ISA devices.

Assumptions

According to the guidelines in this document, it is assumed that you would migrate to the new environment concurrently and switching over to this once the migration steps have been completed. This method offers flexibility and allows for easy adoption of the new solution with minimal impact to existing production environments.

The following should be noted if the Administrator decides to migrate with the same network settings and certificates.

When you migrate a cluster as-is, ensure that you form the new environment with the same cluster name and port definitions before importing the exported XML. Otherwise, , import will fail due to clashes in ports in use, existing cluster name on the same network and node hostnames.

If you are using Active Directory or ACE authentication servers, there may be a need to recreate the computer objects. For ACE, there may also be a need to regenerate or re-import the SDCONF.REC file to the devices if authentication fails after import.

Please note that if the target environment is standalone, all cluster-related steps can simply be ignored.