Skip to main content

Install, Configure, and Upgrade Guide for 26.x

Changes During the VEN Migration

During the VEN migration process, you can continue making necessary changes to policy objects and sync them to ensure consistency.

Synchronization Limitations
  • Policy object changes should be made on the on-prem PCE to account for potential version differences between on-prem and SaaS releases.

  • Changes to managed workloads on either PCE are mirrored on the other.

  • New unmanaged workloads on the on-prem PCE are being replicated to the Illumio SaaS.

    New unmanaged workloads in Illumio SaaS are not replicated to the on-prem PCE.

  • Manual invocation of pcemigrate sync is required to synchronize policy object changes. It does not trigger automatically.

  • Specific settings, such as pairing profiles, local users, and RBAC settings, are not replicated after the initial replication.

  • Skipping workload syncing is possible if workloads are not linked to rulesets, which can expedite the completion of pcemigrate sync.

    Note

    Skipping is recommended only if no changes are made to the workload (interface, label, and so forth).

For more information about available options, see pcemigrate sync --help.

Here's an example command for pcemigrate sync with the confirmation prompt disabled that replicates changes to policy objects.

pcemigrate sync --from on-prem --to-pce saas --no-prompt

Warning

The pcemigrate sync might fail to provision policy objects in the SaaS PCE if their content has not changed.

The update can be triggered by the object being provisioned on-prem, by the absence of a map file, or by an empty map file when objects are on-prem.