Best way to migrate AnyConnect users to a new device

Hi!
We have an existing ASA5540 that serves a bunch of AnyConnect 2.5 clients.  For example purposes call it oldvpn.domain.com.  I have stood up a new device at vpn.domain.com.  The name change is purposeful and not just for moving to a new device.  Both new and old have signed SSL certs in place.  We want to migrate clients to the new device and shut down the old one.  What is the easiest/cleanest way to do this (and preferably with no user input)?  A couple thoughts...
On cutover day I could make oldvpn.domain.com resolve to the same IP of vpn.domain.com.  I believe that would lead to cert errors for the old clients though.  Can the new connection profile somehow have certs for both domains?
Or could I push a new client profile to users logging into the old service, which would point their client to the new ASA?
Has anyone done this type of move before and how did you do it?
Thanks!
Mark

Hi!
We have an existing ASA5540 that serves a bunch of AnyConnect 2.5 clients.  For example purposes call it oldvpn.domain.com.  I have stood up a new device at vpn.domain.com.  The name change is purposeful and not just for moving to a new device.  Both new and old have signed SSL certs in place.  We want to migrate clients to the new device and shut down the old one.  What is the easiest/cleanest way to do this (and preferably with no user input)?  A couple thoughts...
On cutover day I could make oldvpn.domain.com resolve to the same IP of vpn.domain.com.  I believe that would lead to cert errors for the old clients though.  Can the new connection profile somehow have certs for both domains?
Or could I push a new client profile to users logging into the old service, which would point their client to the new ASA?
Has anyone done this type of move before and how did you do it?
Thanks!
Mark

Similar Messages

  • What is the best way to migrate PSE6 Catalog (Wxp) to new computer W7, PSE11?

    What is the best way to migrate PSE6 Catalog (Wxp) to new computer W7, PSE11?  Previous PSE6 recovery (Wxp) after a failed HD resulted in pictures showing but not opening due to connection issues.  Had to restore pictures from backup and rebuild the catalog and albums.  Found a third party fix afterwards that has no support past PSE8.  Trying to make this migration to PSE11 painless.

    William47 wrote:
    What is the best way to migrate PSE6 Catalog (Wxp) to new computer W7, PSE11?  Previous PSE6 recovery (Wxp) after a failed HD resulted in pictures showing but not opening due to connection issues.  Had to restore pictures from backup and rebuild the catalog and albums.  Found a third party fix afterwards that has no support past PSE8.  Trying to make this migration to PSE11 painless.
    That's a very common and classical situation :
    http://helpx.adobe.com/photoshop-elements/kb/backup-restore-move-catalog-photoshop.html
    Just make sure that your backup to the external drive is ok : you should find a 'backup.tly' file in the folder.
    Use the PSE11 organizer to restore from the PSE7 backup : the first step restores all your media files, the second automatically does a catalog conversion to the PSE11 format.
    Read the note in the above link about restoring from XP to ulterior Win OS. You can also restore to a 'custom' location. For instance in a 'C:\My new library' folder. Make sure that master folder is accessible to all users, and if you want, you can move the catalog (database) itself from that location to the default location : catalog manager, option to move catalogs to location accessible to all users.

  • Best way to migrate iTunes and iPod to new hard drive

    Currently, my iTunes Library is referencing music files that sit on my music data drive (E:drive). My Library is actually on another data drive (D: drive), while my OS and apps are on the C: drive. I also have a networked Network Attached Storage (NAS) drive that has a duplicate copy of all of my music files.
    One of the reasons I have the NAS is to have 24/7 access to my music files through a Sonos Zone Player system (highly recommend this) hooked up to my stereo. The Sonos player is able to pickup all of my playlists but because iTunes creates the plalists thinking that all of the songs reside on my E:drive, they are broken links as far as Sonos is concerned.
    So my quesion is, what is the best way to redirect my iTunes Library so that it pulls the songs from the NAS rather than my internal E:drive? Since the NAS is always on, I don't care that when I want to play songs on my computer, it pulls them off of the NAS. In "migrating" the music file links, I'd like to maintain all of my rankings, play counts, and playlists. Is this possible?
    If not, then at a minimum, I'll be swapping out my E:drive for a larger one and need to know the best way to migrate the music files. It would be simple to just take out my current music file drive, swap in the new drive, and copy the files from the NAS drive onto the new drive. Do I need to de-authorize my computer at the start so iTunes doesn't think I'm giving permission to a new computer? Will my play counts, ratings, and playlists still show up? Regarding the latter, I'm guessing yes since the Music Library isn't being touched (on the D: drive).
    Hope this makes sense to someone.
    Thanks in advance,
    Steve
      Windows XP Pro  

    Well, you'll need to reinstall iTunes and the iPod updater.
    Did you happen to save the iTunes library file?
    What are the iTunes library files?

  • Best way to migrate local users to the network - move home folders?

    Hi everyone,
    I am about to set up my Mac mini server (Snow Leopard Server). I have one iMac with three user account on it (local), another iMac that we just bought and my MacBook Pro with my admin account on it (Snow Leopard). So all have Snow Leopard.
    What would be the best way to move the three local accounts AND their home folders to the server?
    What would be the best way to make my portable user account into a mobile user account on the server?
    I am planning to create all users on the server (with the same username and passwords etc.) then move the local home folders from the iMac to the server through some direct wired connection. My concern is with this move - will there be permissions mismatch issue? I am sure there will be as the UID would be different for the same accounts (pre-existing and newly created, eventhough their username and passwords are the same).
    Any best practices? strategies?
    Does Apple have any documentation on this specific topic? - that is moving local user accounts and their corresponding home folders onto the server?
    Thanks much!
    Kenneth

    Hi again,
    I haven't gotten round to it - but may have an alternative route in the mean time: the brand new 27" iMac just arrived, and rather than doing a full 'migration assistant' setup, I am going to try the following:
    1. on the new iMac: only create a local Admin account, user name totally unrelated with any other account name;
    2. on the server: settle all the network user account settings, portable home directories, managed preferences etc. for each user;
    3. on another computer: log on under the corresponding local user account, and copy one's home folder entirely to an external drive - do not use this machine again under this user account;
    4. on the new iMac: log in as a network user, make sure the home folder and library syncing works as desired, set some preferences (and check that this gets synced to the server drive); copy the parts of the home folder & library for this user from the external drive - wait until it all gets synced back and forth - and check any permissions, preferences whatever issue (the local account on the other computer is available for cross-checking, just don't change any documents or settings on that one)
    5. if all works well on the new iMac: delete this local user account on the other computer.
    6. repeat steps 3-5 for each other computer where this user has a local account (one 'old' iMac, one 13" MB) - will also allow to check and filter any duplicate documents which have accumulated over the different machines.
    7. create the network accounts for this user on the other computers, and check the syncing etc.
    8. repeat for each user (4 in total for us).
    I think this might just work, since the new iMac at present has no accounts - so no possible issues with similar account names & passwords etc - and you keep the 'old' local account on the other machine as a safeguard anyway.
    Any particular thoughts or comments on this proposed process??
    How about permissions: does the copying to an external disk, and then back onto another computers disk solve that??

  • Best way to migrate from old MBP to new iMac

    Hi,
    I'm currently working on an old MBP (2009, 17" unibody, to be exact) running Lion.
    Long story short, I decided to switch to a new iMac because it's slowly dying.
    I'm currently making daily clones of my computer (using SuperDuper) but I just realized that the new computer will be running Mountain Lion.
    It would seem counter-intuitive to restore my whole clone on the new computer as the OS is more recent on the new computer.
    Does anyone know the best way to painlessly transfer all my files (or, preferably, my whole current working setup) to the new iMac?
    The 2 ways I tought about were to upgrade my MBP to ML (though it'll cost me for ML even though I'll have it pre-installed on the new computer). The other would be to transfer my documents only and take the opportunity to do a spring cleaning in the process.
    I'd really like to avoid the last idea since this is my working computer and I'd like to setup the new one as quickly as possible.
    Any other suggestion is more than welcome!
    Gab

    Thanks for the guide. This part in particular seems really helpful:
    "You cannot transfer "backwards" from a newer "major" version of OSX to an earlier one (such as Mountain Lion 10.8.x to Lion 10.7.x).  However, you can transfer "backwards" from a newer "minor" version to an earlier one (such as 10.8.2 to 10.8.1), but before using any Apple apps, you should upgrade to at least the same version as the original, as the older versions of the apps may not work properly with newer versions of data."
    That being said, do you think it would actually apply for transferring a clone running on 10.7.5 (Lion) to the new iMac running 10.8 (Mountain Lion)? Or should I rely on the second paragraph that seems to indicate I'd be better off updating my clone (buying Mountain Lion on the macbook pro) then use the Setup Assistant to transfer my older settings.
    I don't think there's only one good way to to do this. Which would you recommend?

  • Preparing new PC.  Best way to migrate over Creative Cloud on new PC and decomission/uninstall on the old PC?

    Hello.
    I'm prepping a new motherboard, memory, SSD's and GPU.  I subscribe to Creative Cloud and want to install the apps on my new PC, while removing them from my older PC.
    I dont plan on running both systems with Creative Cloud concurrently as I am also migrating the CPU from one to the other.  I have a spare I can pop into the old one to do any cleanup if need be.
    Do I need to uninstall Creative Cloud on the existing PC and then reinstall it on the new one?
    Regards
    Frank

    You need to install on the new one (migration will not work).  What you do with the old one is your choice.  You are allowed to have two working installations, so if you would like to have a backup installation available just leave it as is.  Otherwise, the minimum you need to do is to sign out of the Cloud on the old machine.

  • Best way to migrate Mailboxes with all permissions Exchange 2010 to Exchange 2010--cross forest

    Hi,
    Due to some Exchange and Active Directory issues (with remnants of old Ex 2003 server), we are going to migrate Exchange 2010 Mailboxes and public folders to a new Exchange 2010 Sp3 server, which is created in a new AD forest.
    I would really appreciate if someone can direct us to the best way to migrate mailboxes and PFs with their permissions, to new Ex 2010 SP3 server. We have around 30 mailboxes, and 300 GB of mailboxes data, and 200 GB of PFdata.
    Thanks in anticipation.
    Regards, David Johnson

    Hello,
    Firstly, you need to creat forest trust between two forests.
    If you want to move AD user account and mailboxes, please use ADMT and PrepareMoveRequest script.
    If you want to migrate public folder, please export data to PST file and then import pst file to new server. 
    Additional article for your reference.
    http://blogs.technet.com/b/exchange/archive/2010/08/10/3410619.aspx
    Cara Chen
    TechNet Community Support

  • Best way to migrate iTunes, iPhoto, iCal, Address Book to Mac?

    I have been a user of Macs since 1985, but my wife has always used Windows (and before that, MSDOS).
    I have now gotten for her a new MacBookPro and would like suggestions on the best way to migrate the data needed to sync her iPhone with the new Mac.
    Currently, her contacts and calendar are in Microsoft Outlook for Windows, her photos are in some kind of Windows program and her music is in iTunes for Windows.
    What is the smoothest, easiest way to migrate these Windows files into a Mac format so she can use iCal on the Mac for her calendar, Address Book for contacts, iPhoto for pix and transfer her music from iTunes/Windows to iTunes for Mac?
    Is there any way to just sync the new MacBookPro with the iPhone and have it upload the data from the iPhone to the Mac????
    Just lookin' for the easiest way to do this....

    Have the Apple Store do this for you or call Apple support and they will help you do it.

  • Best Way To Migrate Local Accounts to new OD Server?

    Hello everybody, I'll keep this simple:
    I've got about 20 macs that have just joined themselves to my shiny new Open Directory (i.e. I bound each machine through the Directory Utility).
    What is the best way to migrate their local accounts to network accounts? Note that almost all of these macs are laptops that will be taken home from time to time. And of course, the less 'interruption' of normalcy, the better.
    Thanks for any suggestions,
    Evan

    I did something similar last year, migrating local accounts to network accounts after binding the machines to AD. I'm not sure how much what I did will differ for your particular case, but maybe this will point you in the right direction. Bear in mind, this sort of laborious, but it works well enough.
    In my particular case, the local accounts were named the same as the network accounts so I had to do some sleight of hand with the home folders to make sure nothing got deleted on accident.
    Log in as root (you could do this with an admin account, but root makes it much easier.)
    Move the local account home folder out of the /Users folder and to the root desktop for safekeeping.
    Go to User Account control panel and delete the user account.
    Log out of root and log back in as the network user.
    Log out of network user and log back in as root.
    Delete the new, default home folder in /Users and move the old one back.
    Use chown -R username /Users/username/ on the command line to give the new network account ownership of the old home folder.

  • Best way to migrate to replaced machine?

    If Apple insist on picking up my defective MBP C2D before my new one arrives, what is the best way to migrate my files, etc?
    I was thinking of using Carbon Copy Cloner and a spare firewire 800 drive. Should I create a disk image of my current setup? Or a bootable clone? Or a non-bootable clone?
    Too many options. Hope someone can help!

    Plug your external drive into your new MBP, hold your 'Option' key down and boot from the external backup. Then clone that to your new MBP's drive. That way, when your done, everything is going to be exactly as it is now on your current MBP.
    -Bmer
    Mac Owners Support Group
    Join Us @ MacOSG.com
    ITMS: MacOSG Podcast
     An Apple User Group 

  • What are the best practices to migrate VPN users for Inter forest mgration?

    What are the best practices to migrate VPN users for Inter forest mgration?

    It depends on a various factors. There is no "generic" solution or best practice recommendation. Which migration tool are you planning to use?
    Quest (QMM) has a VPN migration solution/tool.
    ADMT - you can develop your own service based solution if required. I believe it was mentioned in my blog post.
    Santhosh Sivarajan | Houston, TX | www.sivarajan.com
    ITIL,MCITP,MCTS,MCSE (W2K3/W2K/NT4),MCSA(W2K3/W2K/MSG),Network+,CCNA
    Windows Server 2012 Book - Migrating from 2008 to Windows Server 2012
    Blogs: Blogs
    Twitter: Twitter
    LinkedIn: LinkedIn
    Facebook: Facebook
    Microsoft Virtual Academy:
    Microsoft Virtual Academy
    This posting is provided AS IS with no warranties, and confers no rights.

  • What is the best way to migrate my MacBook Pro to my new Imac desk top, both seem to be running OS X version 10.9.5

    What is the best way to migrate my MacBook Pro to my new Imac desk top, both seem to be running OS X version 10.9.5

    OS X: How to migrate data from another Mac using Mavericks

  • WHat is the best way for other iphone users to share pictures with me?  I am doing a project which req. people to send me 100 pictures at a time that I'll be putting in my iphoto?

    WHat is the best way for other iphone users to share pictures with me?  I am doing a project which req. people to send me 100 pictures at a time that I'll be putting in my iphoto? thank you.

    ingridlisa,
    I'd suggest to ask them to create Shared PhotoStreams and to invite you to view the streams, see:
    iCloud: Using and troubleshooting Shared Photo Streams
    Regards
    Léonie
    Added:
    that I'll be putting in my iphoto?
    Will you be collecting the photos in iPhoto on your iPhone or on a Mac? On a Mac a Shared PhotoStream requires Mac OS X 10.8.2.

  • What is the best way to manage 5 users and 6 devices? We dont all want the same merged contacts, we dont all want the same calendar notes, music, pics etc etc.

    What is the best way to manage 5 users and 6 devices? We dont all want the same merged contacts, we dont all want the same calendar notes, music, pics etc etc.

    As long as it is pointed to iTunes it will be accessible via home sharing on Apple TV.
    http://support.apple.com/kb/HT1751?viewlocale=en_US&locale=en_US
    If these are commercial DVD's we can't comment on any conversion process.

  • Best Way to Migrate a configuration from one sun webserver to another

    Hi,
    What is the best way to migrate a configuration from one Sun Webserver to another? I am using Webserver 7 Update 5 on Linux. If I just copy the configuration directory, the administration server doesn't know it. Thanks!

    I found my answer.. I found this link - http://forums.sun.com/thread.jspa?threadID=5317534

Maybe you are looking for