Migration from PSA to ISA
On the existing PSA platform. Log in to the standalone device or the primary node of the cluster (where the cluster was first formed) and export its binary configs (system.cfg and user.cfg), and the XML Network settings configurations.
- To export the binary configurations from the PSA Gateway:
- From the PSA Gateway Admin UI, select Maintenance > Import/Export > Configuration.
- Under Export, enter a password if you’d like to password-protect the configuration file.
- Click Save Config As to save the file. The default filename is system.cfg.
- Select Maintenance > Import/Export > User Accounts.
- Under Export, enter a password if you’d like to password-protect the configuration file.
- Click Save Config As to save the file. The default filename is users.cfg.
- To export the XML Network configuration:
- Select Maintenance > Import/Export > XML Import/Export.
- Under Export, expand System Settings and select Network > All.
- Click Export and save the XML file.
Make notes of all the local settings for both nodes (if not yet done during preparation stage): IP information, clustering, virtual ports, VLANs, hosts, routes, DNS settings, SNMP (if configured), Syslog.
Importing existing PSA configurations to ISA
- To import the configurations to ISA Gateway:
- From the ISA Gateway Admin UI, select Maintenance > Import/Export > Configuration.
- Select Import Everything except network settings, cluster settings, and licenses to import all configurations except network, cluster and license settings.
- Browse to the configuration file, system.cfg. Enter the password if specified.
- Click Import Config ***When importing the PSA configurations to ISA all the system configurations will be imported. (Configurations related to deprecated features such as SDP, Sensors and Pulse One will be removed).
- Select Maintenance > Import/Export > User Accounts and browse to the users.cfg file.
- Click Import Config ***When importing the PSA configurations to ISA all the user configurations user configs like realms, sign-in policies, host checker, policies, roles, devices, users will be imported. (Configurations related to deprecated features such as Citrix web interface/JICA, Citrix StoreFront, Microsoft OWA 2000, 2003,2007 will be removed).
- For XML import, select Maintenance > Import/Export > XML Import/Export and import the config file. After importing XML, system and user.cfg files, check and/or modify/add remaining local settings and other settings such as:
- Network > Overview settings (set in cluster or individual nodes)
- Network > Routes (for internal, external and other ports)
- Network > Hosts (set in cluster or individual nodes)
- Network > Internal Port/ External Port>Virtual Ports (if clustered, set this up in cluster “Entire Cluster”)
- Network > VLANs (if clustered, set this up in cluster “Entire Cluster”)
- Network > VPN Tunneling (set in cluster or individual nodes)
- Log/Monitoring > SNMP (set in cluster or individual nodes)
- Configuration > Certificates > Device Certificates (and its ports bindings)
- Resource Policies > VPN Tunneling > Connection Profiles (if configured)
- Configuration > Licensing - License client-server settings (if used as license client in Enterprise Licensing Server environment), proper licenses installed
8. Check cluster status (if clustered) and test operation by logging in to the cluster VIPs (or the standalone PSA device IP).
***Configurations related to the unsupported features will be removed from the imported configuration as part of the migration.
***Policies referring to unsupported features will also be deleted after the migration.
***The admin can view them under the event logs in the 21.x ICS Gateway.For more information, please check the PSA to ISA migration guide