Objects Not Migrated
Warning
Access restrictions, permissions, and users are migrated during the initial replication. However, changes to these policy objects or configuration settings are not synchronized by pcemigrate sync.
Pairing profiles can also be migrated. Specify the following options:
--import-rbac-settings, --import-users
Container clusters
Container clusters and container workload profiles are migrated if the options
--import-container-clustersand--extended-migrationare specified with thepcemigrate migratecommand during the initial replication. However, thepcemigrate synccommand does not sync changes to these objects.The objects owned by container clusters, such as workloads, virtual services, and service bindings, are ignored, along with changes to these objects. This can cause some rules to be dropped during the migration.
Load Balancers, NENs
You must configure the relevant settings in the SaaS post-migration, if needed.
Virtual Servers
Virtual Services
Virtual services are not migrated unless you specify the option
--extended-migration. If a rule contains the virtual service associated with CVENs, the rule may be dropped.Traffic Data
The existing traffic data is not migrated; it will be rebuilt as VENs report to the SaaS.
Label dimensions, labels, label groups, services, IP lists, User Groups (AD Groups)
Supported for migration in initial replication to the Illumio SaaS and the synchronization of changes to policy objects on the on-premises PCE to the Illumio SaaS.
RBAC
(Local users, roles, authorization security principals, permissions, and access restrictions):
Supported for migration in initial replication if these options are specified:
--skip-export-users
--skip-export-rbac-settings
--import-users
--import-rbac-settings
Note
If you have rules that reference the authorization security principals, then specify --import-rbac-settings.
Pairing profiles, container cluster, container cluster workload profiles
Supported for migration in initial replication to the Illumio SaaS only. Synchronization is not supported.
Workloads
Supported for initial migration and synchronization. Workloads associated with CVENs are ignored.
Rules, rulesets, enforcement boundaries/deny rules
Supported for migration in initial replication to the Illumio SaaS and synchronization of changes to policies from the on-prem PCE to the Illumio SaaS.
Other unsupported objects
Trusted Policies
Report Templates
Firewall Settings
Secure Connect Gateways
Flowlink