Avaya Identity Engines Ignition Server Software Release 7.0.0

Similar documents
OpenManage Integration for VMware vcenter Quick Install Guide for vsphere Client, Version 2.3.1

Avaya Identity Engines Release Notes Software Release 9.0.3

ClearPass Policy Manager 6.3

EventTracker: Virtual Appliance

EventTracker: Virtual Appliance

EventTracker: Virtual Appliance

Platform Compatibility... 1 Known Issues... 1 Resolved Issues... 2 Deploying the SRA Virtual Appliance... 3 Related Technical Documentation...

Backup and Restore System

OpenManage Integration for VMware vcenter Quick Install Guide for vsphere Client, Version 2.3

OpenManage Integration for VMware vcenter Using the vsphere Client Quick Install Guide Version 2.0

Visualization Performance & Fault Manager

OpenManage Integration for VMware vcenter Quick Install Guide for vsphere Client Version 3.0

akkadian Provisioning Manager Express

SonicWall SMA 8200v. Getting Started Guide

SRA Virtual Appliance Getting Started Guide

Avaya Identity Engines Release Notes Software Release 9.2.1

OpenManage Integration for VMware vcenter Quick Installation Guide for vsphere Web Client Version 3.2

SonicWall Secure Mobile Access SMA 500v Virtual Appliance 8.6. Getting Started Guide

OpenManage Integration for VMware vcenter Quick Installation Guide for vsphere Web Client Version 3.1

Cisco Prime Service Catalog Virtual Appliance Quick Start Guide 2

VMware vsphere with ESX 4.1 and vcenter 4.1

Installing the Cisco Virtual Network Management Center

Dell Storage Compellent Integration Tools for VMware

Global Management System (GMS) Virtual Appliance 6.0 Getting Started Guide

Avaya Identity Engines Release Notes Software Release 9.2.2

HP StoreOnce Recovery Manager Central for VMware User Guide

Quest VROOM Quick Setup Guide for Quest Rapid Recovery for Windows and Quest Foglight vapp Installers

VMware Mirage Web Manager Guide

Replace Single Server or Cluster

Using a Virtual Machine for Cisco IPICS on a Cisco UCS C-Series Server

EMC Smarts SAM, IP, ESM, MPLS, NPM, OTM, and VoIP Managers 9.5 Support Matrix

Upgrading the System

Quest VROOM Quick Setup Guide for Quest Rapid Recovery for Windows and Quest Foglight vapp Installers

WatchGuard Dimension v2.1.1 Update 3 Release Notes

WatchGuard Dimension v1.1 Update 1 Release Notes

CA Agile Central Administrator Guide. CA Agile Central On-Premises

Installing Cisco MSE in a VMware Virtual Machine

IPMI Configuration Guide

EMC Smarts SAM, IP, ESM, MPLS, NPM, OTM, and VoIP Managers Support Matrix

Installation and Upgrade

Dell Storage Compellent Integration Tools for VMware

Unified CVP Migration

dctrack Quick Setup Guide Virtual Machine Requirements Requirements Requirements Preparing to Install dctrack

HPE OneView Global Dashboard 1.40 User Guide

Configuring the SMA 500v Virtual Appliance

technical bulletin Updating E2 Controller Firmware Using Ultrasite32

HiveManager Virtual Appliance QuickStart

Storage Manager 2018 R1. Installation Guide

Quick Start Guide ViPR Controller & ViPR SolutionPack

SonicWall Security 9.0.6

Installing or Upgrading ANM Virtual Appliance

Dell Storage Integration Tools for VMware

Exam Name: VMware Certified Professional on vsphere 5 (Private Beta)

IBM/Lenovo BCS RSSM firmware Update

VMware ESX ESXi and vsphere. Installation Guide

How to Use a Tomcat Stack on vcloud to Develop Optimized Web Applications. A VMware Cloud Evaluation Reference Document

DSI Optimized Backup & Deduplication for VTL Installation & User Guide

"Charting the Course... VMware vsphere 6.7 Boot Camp. Course Summary

CA Agile Central Installation Guide On-Premises release

Administering vrealize Log Insight. 12-OCT-2017 vrealize Log Insight 4.5

By the end of the class, attendees will have learned the skills, and best practices of virtualization. Attendees

Avaya Identity Engines Ignition Server

Setup. About Window. About

Deploying Cisco UCS Central

Updating E2 Controller Firmware Using UltraSite32

SonicWALL Security Software

Release Notes for Avaya WLAN 9100 Software Patch Release WLAN Release Notes

Dell Server Management Pack Suite Version For Microsoft System Center Operations Manager And System Center Essentials Installation Guide

VMware Mirage Web Management Guide. VMware Mirage 5.9.1

Installing Cisco CMX in a VMware Virtual Machine

Release Notes. Network Resource Manager 1.0 NRM 1.0

akkadian Global Directory 3.0 System Administration Guide

Security Gateway Virtual Edition

All - In - One for Hyper- V

Installing on a Virtual Machine

Basic Configuration Installation Guide

VMware View Upgrade Guide

MARWATCH INSTALLATION AND UPGRADE GUIDE

Developing and Deploying vsphere Solutions, vservices, and ESX Agents. 17 APR 2018 vsphere Web Services SDK 6.7 vcenter Server 6.7 VMware ESXi 6.

Administering vrealize Log Insight. September 20, 2018 vrealize Log Insight 4.7


Gnostice StarDocs On-Premises API Virtual Appliance

VMware vsphere with ESX 6 and vcenter 6

RecoverPoint for Virtual Machines

Virtual Appliance Installation Guide

Setting Up the DR Series System on Veeam

UDS Enterprise Preparing Templates Windows 7 + RDP + UDS Actor

Network Security Platform 8.1

Installing Cisco Virtual Switch Update Manager

Cisco Emergency Responder Installation

WatchGuard Dimension v2.0 Update 2 Release Notes. Introducing New Dimension Command. Build Number Revision Date 13 August 2015

Developing and Deploying vsphere Solutions, vservices, and ESX Agents

IBM Hyper-Scale Manager as an Application Version 1.7. User Guide GC

Scrutinizer Virtual Appliance Deployment Guide Page i. Scrutinizer Virtual Appliance Deployment Guide. plixer

Preparing Virtual Machines for Cisco APIC-EM

Administering vrealize Log Insight. 05-SEP-2017 vrealize Log Insight 4.3

Preparing Virtual Machines for Cisco APIC-EM

Install ISE on a VMware Virtual Machine

VMware Mirage Getting Started Guide

Dell SonicWALL Security 8.1.1

Transcription:

Avaya Identity Engines Ignition Server Software Release 7.0.0 1. Release Summary Release Date: 03-Dec-2010 Purpose: Software major release to introduce new feature enhancements and to address customer found software issues. 2. Important Notes Before Upgrading to This Release AIEIS Software Upgrade Requirements: In order to maximize configuration compatibility during upgrade, Avaya does not recommend upgrading from release prior to 6.0.1. If you re using the software prior to 6.0.1, please upgrade to release 6.0.1 first and then proceed with upgrade to 7.0.0. Saved Configuration file compatibility In order to maximize configuration compatibility during upgrade, Avaya does not recommend config backup/restore from release prior to 6.0.1. 3. Platforms Supported VMware ESX Server version 3.5 VMware vsphere version 4.0 4. Notes for Upgrade Release 7.0.0 contains many features & enhancements to the Ignition Server as well as various components of the Identity Engines portfolio. Please read the special instructions given below before proceeding with the upgrade as outlined in the Avaya Identity Engines Ignition Server Administration guide. File Names For This Release File Name ESX_3.5/AIEIS_RHEL_5_5_LINUX- VM_07_00_00_020492_x86_64 ESX_4.0/AIEIS_RHEL_5_5_LINUX- VM_07_00_00_020492_x86_64 Module or File Type File Size (bytes) OVF files for ESX 3.5 environment 996566854 OVF files for vsphere 4.0 environment 996566912 LINUX-VM_07_00_00_020492.img Upgrade image 143517298 LINUX-VM_07_00_00_01_os_only_is6_to_is7.pkg OS Upgrade package 447061011 DashboardInstaller-7.0.0_020492.exe Dashboard Installer 49440413 2010 Avaya Inc. Rev: 01.02 (06-Dec-2010) Page 1 of 7

GuestManagerInstaller-7.0.0_020492.exe Guest Manager Installer 48342753 IgnitionAnalytics_7.0.exe Ignition Analytics Installer 281072726 5. Version of Previous Release Software version 6.0.1. 6. Compatibility This software release can only be managed with Avaya Ignition Dashboard release 7.0. All other components of the Identity Engines portfolio (Guest Manager, Ignition Analytics) should also be upgraded to release 7.0 to work with Ignition Server 7.0. 2010 Avaya Inc. Rev: 01.02 (06-Dec-2010) Page 2 of 7

7. Changes in This Release New Features in This Release Support for MS-NAP based posture checking The 7.0.0 release supports Microsoft s Network Access Protection (NAP) based posture checking. Network Access Protection (NAP) is a framework developed by Microsoft to provide a mechanism to authenticate and authorize users or devices requiring network access as well as necessary tools for network administrators to define security requirements & controls for managing the network access. NAP uses the Statement of Health to manage a computer's conformance with corporate security policies. Platform upgrade In the current model of the Ignition Server, it s not possible to upgrade the base operating system without upgrading the entire system. In release 7.0.0, a new feature called OS upgrade is introduced which supports upgrading the base operating system components without having to upgrade the entire system. Depending on the components being upgraded, the system can be upgraded in a hitless manner without actually needing a halt/reboot of the system. Please note that if the components being upgraded are critical (for example, a kernel upgrade) hitless upgrade may not be possible and that a reboot of the system would be required. How to upgrade OS from Dashboard To perform OS upgrade from the dashboard, first upload the package file by right click on Site -> Upgrade System -> Package -> Upload. Once the file is uploaded, select the file that s uploaded and click Verify Content to see what s included in the package and perform package integrity check. Once the package integrity check is passed, click on Activate to install the package. Identity Engines licensing enhancements Version enforcement Starting from 7.0.0 release, each BASE license includes a version field that indicates the software version for which the license is valid for. This means that a new license must be purchased while upgrading to a new major release. For those who are upgrading the Ignition Server from a previous release, the upgrade would be allowed and a 30- day grace period would be given to upgrade the license. Failing which, the Ignition Server would stop working. The remaining grace period status is actively shown whenever user login to the Dashboard as well as through periodic alert logs. FEATURE_NAP License A new type of license called FEATURE_NAP is introduced in release 7.0.0. This license is intended to control the Microsoft NAP Posture checking functionality being introduced in this release. 2010 Avaya Inc. Rev: 01.02 (06-Dec-2010) Page 3 of 7

2 flavors of FEATURE_NAP are introduced, called SMALL and LARGE. SMALL version of NAP license is intended for smaller deployments and supports up to 20 end points, while the LARGE is intended for large enterprise networks that can support up to 1,000,000 end points. Please note that the type of NAP license (SMALL or LARGE) should match with the type of BASE license installed on the system. A SMALL NAP license cannot be installed on a LARGE BASE system. Guest Manager Dynamic Activation of Guest User In the current model of Guest Manager, the validity of the guest manager starts based on the activate account on setting and valid until the max duration as defined in the policy. In release 7.0.0, a new enhancement called Dynamic activation is introduced. This feature would allow the administrator to create guest user accounts in advance of use and have the duration (example 8 hours) active on first logon. The duration the account is valid for from the time account is first used (i.e., when the guest user first logs in and not first created). Provisioning groups can be defined to create guest users based on time or based on first login. VMware vsphere 4.0 support Starting from release 7.0.0, Ignition Server can now be deployed on VMware vsphere 4.0 servers. The hardware requirements for VM deployment remain the same, i.e., a minimum of 1024 GB of memory, 30 GB of disk storage, 2 CPU's, at least 1 physical NIC card and 3 Logical NIC cards. OVF files for ESX 3.5 environment cannot be used to deploy Ignition Server on vsphere 4.0 environments. Download the appropriate OVF zip files as mentioned in the software list above. For those who d already deployed Ignition Server 6.0.1 on ESX 3.5 environment and looking to upgrade to vsphere 4.0 environments, the following two step process should be followed. First, upgrade the Ignition Server software from 6.0.1 to 7.0.0 as explained in upgrade procedure below Once all the Ignition Server components are successfully upgraded, upgrade the entire setup to the vsphere 4.0 environment using the VMware migration tools Note: The scope of the upgrade procedure explained below is limited to the procedure to be followed to upgrade the Ignition Server and its components alone. Migration from ESX 3.5 to vsphere 4.0 is outside the scope of this document. Refer to VMware documentation on how to migrate from ESX 3.5 to vsphere 4.0 environments. Ignition Analytics improvements Simplified installation procedure The current installation of Ignition Analytics requires a number of installation steps that could easily result in enduser error. The installation procedure has been greatly enhanced to provide a DEFAULT installation method in which most of the user inputs would have been eliminated and the software be installed with default settings. CUSTOM installation method is also provided in which the user can install the software based on his/her inputs. 2010 Avaya Inc. Rev: 01.02 (06-Dec-2010) Page 4 of 7

Old Features Removed From This Release None. Problems Resolved in This Release Work item Number wi00572228 wi00572310 wi00572309 Description Both HA nodes become secondary The event handling of HA has been improved in release 7.0 that now correctly handles the HA fail-over and Mast-Backup election scenarios. Default gateway not always restored after upgrade in a HA scenario During upgrade, the default gateway may not be restored properly in the kernel routing table although it s available in the configuration. In release 7.0, additional checks have been added to the configuration module which queries the kernel routing table to make sure the default route is properly added, if not retry the configuration. Upgrade process stalls when upgrading a HA system through Dashboard While performing firmware upgrade through Dashboard in a HA setup, the upgrade procedure sometimes stalls with the Dashboard dialog box showing the message as waiting for node to become primary. In release 7.0, the upgrade procedure handling has been corrected to set the node status correctly prior to the upgrade so that it correctly upgrades the backup first and then upgrades the primary. As the fix is available from release 7.0 onwards and users might experience this issue while upgrading from 6.0.1 to 7.0, please refer to known limitations section for a work around. Upgrade procedure Follow the instructions given below before proceeding with the upgrade. Contact Avaya technical support to order a new 7.0.0 BASE license Take a backup of entire VM using the VMware Backup & restore utility prior to the upgrade. o As release 7.0.0 includes major enhancements as well as upgrade to the base operating system, a downgrade from 7.0.0 to a previous release is not allowed. Hence its highly recommended to take a backup of entire 6.0.1 VM so that user can revert to the backed up VM, if needed Take a backup of the policy configuration data from the Dashboard From the Dashboard, upgrade the Ignition Server to release 7.0.0 as mentioned in the Ignition Server Administration Guide section Activating a firmware image 2010 Avaya Inc. Rev: 01.02 (06-Dec-2010) Page 5 of 7

Once the Server is upgraded, close the Dashboard and install 7.0.0 Dashboard o Ignition Server 7.0.0 cannot be managed from a 6.0.1 Dashboard. Hence the Dashboard must be upgraded to 7.0.0 o Also note that 7.0.0 Dashboard upgrades the Java platform to JRE release 6 update 20 Note that the release 7.0.0 includes new Avaya branded certificates. If you re installing the new 7.0.0 Dashboard over an existing dashboard, this could cause connectivity issues with the 7.0.0 Ignition Server. Dashboard keeps the key-store of these certificates at following locations: Windows: Application Data\Avaya or Application Data\Identity Engines Linux: /root/avaya or /root/identity Engines Delete these directories from your system before launching the new Dashboard Once the Ignition Server & Dashboard are upgraded, connect to the Dashboard and install a special package called LINUX-VM_07_00_00_01_os_only_is6_to_is7.pkg through platform upgrade procedure o This is a special package that upgrades the base operating system to Red Hat Enterprise Linux 5.5 and its mandatory Release 7.0.0 Ignition Software will not work with any previous versions of Guest Manager and Ignition Analytics software. All the associated components must be upgraded as well. Upgrade Guest Manager & Ignition Analytics to release 7.0.0 o Note that Guest Manager 7.0.0 will also install/upgrade the Apache Tomcat Web server 6.0.29 as well as the JRE release 6 update 20 If installing the 7.0.0 Guest Manager over an existing Guest Manager version or installing on a system where another instance of Tomcat web server is running, note that the GM 7.0.0 would install a new instance of Tomcat web server 6.0.29 o To avoid any conflicts while running multiple instances of web server on the same system, select a different port number while installing the Tomcat web server Once all the components are upgraded, connect to the Dashboard and install a new 7.0.0 license. If the new license is not installed, the Ignition Server continues to run for a grace period of 30 days after which the Ignition Server would stop running To configure and use the newly introduced Microsoft NAP based posture checking, order a SMALL or LARGE FEATURE_NAP license 8. Outstanding Issues NA. 9. Known Limitations Guest Manager: When changing the membership of a provisioner from a time based provisioning group to a first login based group or vice versa, the properties of existing guest users created by the provisoner are not changed. 2010 Avaya Inc. Rev: 01.02 (06-Dec-2010) Page 6 of 7

Only the new guest users that are created after the change in membership would have the new group membership attributes. Guest Manager: When a provisioner is a member of both time based as well as first login based provisioning group, the guest user type can be changed from a time based account to first login based account or vice-versa. However, this operation will not have any impact on the guest user accounts if the user is already logged in. In general, we do not recommend changing the individual guest user types once the user is created. Firmware upgrade: While upgrading from release 6.0.1 to 7.0, the upgrade may stall with the Dashboard dialog box showing waiting for <node> to become primary. To recover from this, while the Dashboard window is still continuing with the upgrade, reboot the node which is waiting to become primary. Once the node comes up, repeat the firmware activate to upgrade again. 10. Documentation For latest documentation and for details on other known issues, please download the product documentation available from the Avaya Technical Support web site at: https://support.avaya.com/css/products/p0622. Copyright 2010 Avaya Inc - All Rights Reserved. The information in this document is subject to change without notice. The statements, configurations, technical data, and recommendations in this document are believed to be accurate and reliable, but are presented without express or implied warranty. Users must take full responsibility for their applications of any products specified in this document. The information in this document is proprietary to Nortel. To access more technical documentation, search our knowledge base, or open a service request online, please visit Avaya Technical Support on the web at: http://www.avaya.com/support or for legacy products at: http://www.nortel.com/support. 2010 Avaya Inc. Rev: 01.02 (06-Dec-2010) Page 7 of 7