Skip to main content

Illumio Core 25.2.10 Install, Configure, Upgrade

VEN Migration Scenarios

VEN Migration steps can be performed in two scenarios, depending on whether the PCE's front-end management ports are opened to the VEN host system.

VEN migration can be performed in one or multiple batches, with multiple batches taking longer.

Front-end Management Ports (443 tcp) and the VEN Host System

Note

Typically, PCE on-prem default ports are 8443

Scenario 1: Front-end management ports of the PCE are closed to the VEN host systems
  1. Create unmanaged workloads on the on-prem PCE.

  2. Export metadata for managed workloads.

  3. Migrate VENs using the venmigrate command on the VEN host systems.

  4. Apply custom labels after pairing VENs with SaaS.

  5. Delete unnecessary unmanaged workloads post-pairing.

Scenario 2: Front-end management ports of the PCE are opened to the VEN host systems

In this case, the same steps 1-5 can be performed automatically by the venmigrate tool.

Specify the API key information for both PCEs in the VEN migration parameter file, which must be encrypted before deployment on the VEN hosts.

Syncing Policy Object Changes During the VEN Migration

The migration of VENs from on-premises to Illumio SaaS may take an extended period of time and will be done in batches.

Sync Limitations

Review these sync limitations before migrating the VEN.

  • Policy object changes must occur on the on-prem PCE.

  • Managed workload changes sync between on-prem PCE and SaaS.

  • New unmanaged workloads on the on-prem PCE are replicated on SaaS.

  • Pairing profiles, users, and cluster containers changes are not synced after initial replication.

Sync Actions

For VEN migration, sync policy changes.

VEN Migration in Short or Extended Time

This overview outlines the migration of VENs, whether it occurs over a short or extended period.

Migration of VENs in one batch

In this case, policy objects are not modified until all VENs have been migrated to the SaaS platform.

Migration of VENS must be carried out one on-premises PCE at a time and include the following steps:

  1. Replicate on-premise policy objects to SaaS using the pcemigrate migrate command, affecting only new objects without altering existing ones on SaaS.

  2. Migrate all VENs from on-premise PCE to SaaS with the venmigrate command on each VEN host.

  3. Clean up unnecessary unmanaged workloads and retire the on-premise PCE.

Migration of VENs in multiple batches

VENs are migrated in batches over an extended period.

Important

If you have more than 1,000 VENs, Illumio recommends that you do multiple batches of migration.

Policy objects may change on the on-premise PCE during VEN migration and must be synchronized with Illumio SaaS.

For details on migrating VENs in batches, see VEN Migration in Batches.