Objects Not Migrated
Warning
Access restrictions, permissions, and users can be migrated during the initial replication. However, changes to these policy objects or configuration settings are not synchronized by pcemigrate sync.
Pairing profiles can also be migrated. The following options must be specified respectively:
--import-rbac-settings, --import-users,
Container clusters
Container clusters and container workload profiles are migrated if the option
--import-container-clustersis specified with thepcemigrate migratecommand during the initial replication. However, changes to these objects are not synced by thepcemigrate synccommand.The objects owned by container clusters, such as workloads, virtual services, and service bindings, are ignored, as well as changes to these objects. This can cause some rules to be dropped during the migration.
Load Balancers, NENs
You must configure the relevant settings in the SaaS post-migration, if needed.
Virtual Servers, Virtual Services
Rules containing Virtual Servers are dropped only if the virtual service is owned by a container cluster.
Traffic Data
The existing traffic data will not be migrated; it will be rebuilt as VENs report to the SaaS.
Label dimensions, labels, label groups, services, IP lists, User Groups (AD Groups)
Supported for migration in initial replication to the Illumio SaaS and the synchronization of changes to policy objects on the on-premises PCE to the Illumio SaaS.
RBAC
(local users, roles, authorization security principals, permissions, and access restrictions):
Supported for migration in initial replication to the Illumio SaaS only if appropriate options are specified.
Pairing profiles, container cluster, container cluster workload profiles
Supported for migration in initial replication to the Illumio SaaS only. Synchronization is not supported.
Workloads
Supported for initial migration and synchronization
Rules, rulesets, enforcement boundaries/deny rules
Supported for migration in initial replication to the Illumio SaaS and synchronization of changes to policies from the on-premises PCE to the Illumio SaaS.
Other unsupported objects
Trusted Policies, Report Templates, Firewall Settings, Secure Connect Gateways, and Flowlink.