Skip navigation
McAfee Secure sites help keep you safe from identity theft, credit card fraud, spyware, spam, viruses and online scams
6659 Views 12 Replies Latest reply: Jun 3, 2013 10:43 AM by alexn RSS 1 2 Previous Next
netik Newcomer 17 posts since
Jan 22, 2013
Currently Being Moderated

May 1, 2013 4:07 AM

4.6 to 5.0 upgrade and migration to a new server

Dear Community

We are using McAfee ePO 4.6, build 1029 and would like to
a) move ePO from the current (old, x86) server to a new, virtual one (x64, 2008 rc2). This is the more important step than...

b) As ePO 5.0 has been release, it would be good to upgrade to 5.0 aswell, as our version is outdated.

 

My prefered way go would be to leave the old server as it is (and have it as a backup) and install and configure the new server with epo 5.0 in parallel (4.6, build 1029 cannot be upgrade to 5.0 directly anyway)

What I know is that I have to exchange the security keys and register the new server in the old one and then transfer the systems to the new server.

 

My questions:

a) On the new server, I don't have the structure ...the "folders" where the clients are pushed in, yet. On the old system, the clients are grouped by the subnetmask. So, how can I export and import all the policies and tasks, when the structure is missing? I can't transfer the systems first because then (I believe, and that's question b) the clients will already use the new server which will not be fully configured at this time.

b) Are the clients connecting to the new server, as soon as I transfer them to the new server?

c) Does epo 5.0 require the agent 4.8?

 

Is there anything else I have to keep in mind, so that this migration and update will succeed?

 

Thanks a lot

 

Nachricht geändert durch netik on 01.05.13 03:46:44 CDT

 

Nachricht geändert durch netik on 01.05.13 03:48:31 CDT

 

Nachricht geändert durch netik on 01.05.13 04:07:59 CDT
  • Mike_H Newcomer 7 posts since
    Sep 24, 2010
    Currently Being Moderated
    1. May 1, 2013 8:39 AM (in response to netik)
    Re: 4.6 to 5.0 upgrade and migration to a new server

    Hi Netik

     

    Take a look at this McAfee Knowledgebase article.  I think it is what you are looking for. 

    Please post back if it helps.

     

    https://kc.mcafee.com/corporate/index?page=content&id=KB71078&actp=search&viewlo cale=en_US&searchid=1365091354810

  • Mike_H Newcomer 7 posts since
    Sep 24, 2010
    Currently Being Moderated
    3. May 1, 2013 9:14 AM (in response to netik)
    Re: 4.6 to 5.0 upgrade and migration to a new server

    Hi Netik

     

    Are you wanting to keep your existing agents then?

     

    If you bring up a new server it, by its nature, will have a new IP address so the agents will not know about it.  If you change the DNS record to point to the new server and it has the correct Agent to Server key then it will connect and download a new Sitelist.xml with the new server details in it, then you should be able to do away with the domain name redirect and the agents will still talk to the new server via IP or NetBIOS at first then it will, I think receive a new sitelist.xml with the correct DNS entry, if it has not already got it in the previous one, which I believe it should have, either way it will be able to communicater. 

     

    As far as the transfering of the agents, I do believe this is possible also, as long as your two ePO servers can see each other, as, as you say when you transfer them over to the new ePO Server they will get the new Sitelist.xml telling them the info of the new server, then on the next ASCI they will start talking to that one instead.  I believe thats how it works.  Hopefully someone else will post correcting me if i'm wrong.

     

    The third option, if feesable is to have both servers running and slowly deploy the new agent via the new server via the $ share credentials if you have them.

     

    Let me know if thast answers your question.

  • alexn Veteran 722 posts since
    Aug 9, 2012
    Currently Being Moderated
    4. May 1, 2013 10:11 AM (in response to Mike_H)
    Re: 4.6 to 5.0 upgrade and migration to a new server


    Netik,

     

    I have serveral recommendations for this migration but I would make it simple and easy for you as I have tested it bymyself.

     

    ePo 5.0 bundled with a Compatibility tool.This tool does the trick of this whole KB article.

     

    Run this tool on 32 bit machine where you have your old ePO server.

    It will creat a zip file on C:\root. This is the file that includes everything you need .

    Copy this file on your new 64 bit machine.

    Run Compatibility tool again and browse to this file, after it finishes

    Run epo 5.0 setup wizard and follow on screen prompts.

     

    Please let me know if this suits to you???

     

    Alexn


    Post Timings: 6.00 AM to 3.00PM PDT
  • Laszlo G Veteran 1,213 posts since
    May 23, 2007
    Currently Being Moderated
    6. May 2, 2013 7:17 AM (in response to netik)
    Re: 4.6 to 5.0 upgrade and migration to a new server

    Hi netik, if you still want to transfer computers from the old epo server to the new one I would suggest to de the folowwing:

     

    - From the old ePO server go to system tree->my organization and click on system tree actions->export systems (this group and all subgroups)

    - From the new ePO server go to system tree->my organization and click on system tree actions->new systems->

     

    so you'll have all your computers (unmanaged) in your new ePO server using the same tree structure as the old one.

     

    Now you'll have to export/import all your policies to the new ePO server:

     

    - Check all product extensions on the new ePO server as you have in the old server

    - From the old ePO server go to system tree->assigned policies->export all assignments

    - From the new ePO server go to system tree->assigned policies->import assignments

     

    so you'll have all policies applied to groups/computers on the new ePO server.

     

    Now you'll have to register the olfd ePO server to the new server so you can transfer systems:

     

    - From the old ePO server go to menu->configuration->server settings->security keys and export the master key (the one that usually does not have a 0 next to it)

    - From the new ePO server go to menu->configuration->server settings->security keys and import the key

    - From the old ePO server go to menu->configuration->registered servers and set a new ePO server (this will be the new ePO server).

     

    Finally you can try to transfer some computers from the old ePO to the new one and see if they are transferred as they should (action->agent->transfer systems).

     

    This worked for me on different servers so it should also work for you.

  • alexn Veteran 722 posts since
    Aug 9, 2012
    Currently Being Moderated
    7. May 2, 2013 8:55 AM (in response to Laszlo G)
    Re: 4.6 to 5.0 upgrade and migration to a new server

    netik,

    Agent attempts to connect ePO via

    IP

    DNS Netbios

    if any one of them is similliar to the previous old epo server then agent will surely make a connection and will download sitelist.xml file.

     

    and Yes Agent 4.6 is compatible with ePO 5.0

     

    migrated zip file will have all the info required by server to locate its Agents.

     

    Above all and it is best practice as well

     

    in ePO under server settings you will find Agent to server communication keys and Repository keys.

    Export them and save them.If after upgrade communication fails import these keys into your new epo and it will establish communication with all agents.

    There are many options, just dive into the sea and you will learn how to swim


    Post Timings: 6.00 AM to 3.00PM PDT
  • alexn Veteran 722 posts since
    Aug 9, 2012
    Currently Being Moderated
    9. May 3, 2013 9:45 AM (in response to netik)
    Re: 4.6 to 5.0 upgrade and migration to a new server

    Correct. Its easy task. Click start >Run and type ncpa.cpl>right click network connection properties and give the ip settings as previous server was


    Post Timings: 6.00 AM to 3.00PM PDT
1 2 Previous Next

More Like This

  • Retrieving data ...

Bookmarked By (0)

Legend

  • Correct Answers - 5 points
  • Helpful Answers - 3 points