Objects Not Migrated
Warning
Access restrictions, permissions, and users can be migrated during the initial replication. However, changes to these policy objects or configuration settings are not synchronized by pcemigrate sync.
Container clusters
The on-prem PCE can contain containers and container workload profiles. However, these objects cannot be migrated and must remain static for the duration of the migration.
The objects owned by container clusters cannot be changed during the migration process, as this can cause
pcemigrate syncto fail.Load Balancers, NENs
You must perform the related settings in SaaS if needed.
Virtual Servers, Virtual Services
Rules containing Virtual Servers will be dropped and must be recreated manually in the SaaS.
Traffic Data
The existing traffic data will not be migrated and will be rebuilt as VENs report to the SaaS.
Label dimensions, labels, label groups, services, IP lists, User Groups (AD Groups)
Supported for migration in initial replication to the Illumio SaaS and the synchronization of changes to policy objects on the on-premise PCE to the Illumio SaaS.
RBAC
(local users, roles, authorization security principals, permissions, and access restrictions):
Supported for migration in initial replication to the Illumio SaaS only if appropriate options are specified.
Pairing profiles, container cluster, container cluster workload profiles
Supported for migration in initial replication to the Illumio SaaS only. Synchronization is not supported.
Workloads
Supported for initial migration and synchronization
Rules, rulesets, enforcement boundaries/deny rules
Supported for migration in initial replication to the Illumio SaaS and synchronization of changes to policies from the on-premises PCE to the Illumio SaaS.
Other unsupported objects
Trusted Policies, Report Templates, Firewall Settings, Secure Connect Gateways, and Flowlink.