Skip to main content

Install, Configure, and Upgrade Guide for 26.x

Before You Begin the Migration

Review the prerequisites before you start the migration.

Important

Before you begin the migration, verify that your SaaS tenant is provisioned.

Supported Releases for Migration

PCE and VEN

OS

Release/Version

Illumio PCE on-premises releases

RHEL/CentOS

The migration-ready version: 26.2.10

Illumio VEN

The migration-ready version: 23.2 and later

Important

If you're running on any older versions of the PCE, you must upgrade to 26.2.10. To find your upgrade path, go to the Illumio Support portal.

Prerequisites for the system running the pcemigrate tool

  • The machine running pcemigrate must have a minimum of 16 GB of memory and 1-2 TB of available disk space for large configurations of workloads over 100,000.

  • Illumio recommends that you use at least 4 CPU cores for minimal performance.

    Note

    More memory and cores will improve performance.

Prerequisites for the VEN Software

  • Make sure you are on a supported version of the VEN (23.2 and later) for Windows, Linux, macOS, and AIX.

  • Supported Endpoints: Endpoints must run a supported OS (Windows, Linux, macOS, AIX).

  • Connectivity between VEN and SaaS is a prerequisite.

    An essential rule is required to allow traffic between VEN and the SaaS PCE or to put the VEN in visibility mode.

    You may need to add a proxy configuration on the VEN.

Prerequisites for the SaaS Target

  • Basic Organization Setup: The organization's setup must be complete in the Illumio SaaS.

  • Access Configuration: Configure Illumio SaaS access settings (Local users, OIDC, IdP).

  • Owners/Administrators: Configure the organization owners on the Illumio SaaS.

  • AWS S3 Buckets: Configure AWS S3 buckets if applicable.

    If you are exporting any logs from your PCE to a SIEM, configure an S3 bucket.

    See the KB article.

  • API Keys: Generate API keys for the migration tools. API keys must have the organization owner's credentials.

  • Certificate Trust: Adjust end-to-end certificates so the Illumio SaaS can be accessed from the workstation running pcemigrate.

  • Pairing Profiles: Set up pairing profiles.