Skip to main content

Install, Configure, and Upgrade Guide for 26.x

Objects Not Migrated

Warning

Access restrictions, permissions, and users can be migrated during the initial replication. However, changes to these policy objects or configuration settings are not synchronized by pcemigrate sync.

Pairing profiles can also be migrated. The following options must be specified respectively:

--import-rbac-settings, --import-users,

  • Container clusters

    Container clusters and container workload profiles are migrated if the option --import-container-clusters is specified with the pcemigrate migrate command during the initial replication. However, changes to these objects are not synced by the pcemigrate sync command.

    The objects owned by container clusters, such as workloads, virtual services, and service bindings, are ignored, as well as changes to these objects. This can cause some rules to be dropped during the migration.

  • Load Balancers, NENs

    You must configure the relevant settings in the SaaS post-migration, if needed.

  • Virtual Servers, Virtual Services

    Rules containing Virtual Servers are dropped only if the virtual service is owned by a container cluster.

  • Traffic Data

    The existing traffic data will not be migrated; it will be rebuilt as VENs report to the SaaS.

  • Label dimensions, labels, label groups, services, IP lists, User Groups (AD Groups)

    Supported for migration in initial replication to the Illumio SaaS and the synchronization of changes to policy objects on the on-premises PCE to the Illumio SaaS.

  • RBAC

    (local users, roles, authorization security principals, permissions, and access restrictions):

    Supported for migration in initial replication to the Illumio SaaS only if appropriate options are specified.

  • Pairing profiles, container cluster, container cluster workload profiles

    Supported for migration in initial replication to the Illumio SaaS only. Synchronization is not supported.

  • Workloads

    Supported for initial migration and synchronization

  • Rules, rulesets, enforcement boundaries/deny rules

    Supported for migration in initial replication to the Illumio SaaS and synchronization of changes to policies from the on-premises PCE to the Illumio SaaS.

  • Other unsupported objects

    Trusted Policies, Report Templates, Firewall Settings, Secure Connect Gateways, and Flowlink.