This section describes four scenarios to upgrade ISA Server 2004 Enterprise Edition to ISA Server 2006 Enterprise Edition, while maintaining existing settings and configuration for each scenario:
Scenario One: Single Configuration Storage Server with One Array
Contoso Corporation, a small to medium size organization, wants to upgrade their existing ISA Server 2004 Enterprise Edition deployment to ISA Server 2006 Enterprise Edition. Contoso has deployed ISA Server 2004 Enterprise Edition in the following configuration:
-
There is one Configuration Storage server in the main office.
-
There is one array in the main office, which is named HQ.
-
The HQ array has one array member, which is named ISA_FW01.
The following table provides information about the ISA Server 2004 computers before the upgrade.
|
Computer name
|
Operating system
|
Member of domain
|
Fully Qualified Domain Name (FQDN)
|
Feature or services
|
|---|
|
ISA_CSS
|
Microsoft Windows Server 2003 with SP1
|
Yes
|
isa_css.contoso.com
|
ISA Server 2004 Configuration Storage server
|
|
ISA_FW01
|
Microsoft Windows Server 2003 with SP1
|
Yes
|
isa_fw01.contoso.com
|
ISA Server 2004 services
|
Contoso wants to upgrade to ISA Server 2006 with minimal interruption to the ISA Server 2004 services, while providing a method to revert to ISA Server 2004 if problems arise during the upgrade. For this reason, Contoso has selected the following upgrade path to ISA Server 2006 Enterprise Edition. The ISA Server array member will only be offline during the in-place upgrade process:
-
Configuration Storage server Migration to new equipment
-
ISA Server services In-place upgrade
The following table provides information about the ISA Server 2006 computers after the upgrade is complete.
|
Computer name
|
Operating system
|
Member of domain
|
FQDN
|
Feature or services
|
|---|
|
ISA_CSS06
|
Microsoft Windows Server 2003 with SP1
|
Yes
|
isa_css06.contoso.com
|
ISA Server 2006 Configuration Storage server
|
|
ISA_FW01
|
Microsoft Windows Server 2003 with SP1
|
Yes
|
isa_fw01.contoso.com
|
ISA Server 2006 services
|
|
ISA_CSS
(After the upgrade, this server is no longer needed and can be removed from service.)
|
Microsoft Windows Server 2003 with SP1
|
Yes
|
isa_css.contoso.com
|
ISA Server 2004 Configuration Storage server
|
This upgrade path enables Contoso to:
-
Make and apply firewall policy changes, even when they are preparing for the upgrade and during the upgrade process.
Note: |
|---|
|
Any changes made after the ISA Server 2004 configuration has been exported will need to be duplicated on the ISA Server 2006 Configuration Storage server after the configuration has been imported. If there are a large number of changes, the export and import process can be repeated.
|
-
Move the Configuration Storage server to new equipment.
-
Evaluate how the ISA Server 2004 configuration imports to ISA Server 2006, without affecting the production computers.
Upgrade Process for Single Configuration Storage Server with One Array
This section describes the process for upgrading a single Configuration Storage server with one array:
Install the new ISA Server 2006 Configuration Storage server
Perform the following procedure on the ISA_CSS06 computer.
To install the new Configuration Storage server
-
Install Windows Server 2003 with SP1 or Windows Server 2003 R2 on the computer that will be the ISA Server 2006 Configuration Storage server.
-
Install ISA Server 2006 Configuration Storage server. For more information, see the ISA Server 2006 Enterprise Edition Installation Guide.
-
Export the new ISA Server 2006 configuration to a file. This will enable you to restore to a new ISA Server 2006 state, if any issues arise during the import. Follow these steps:
-
In the console tree of ISA Server Management, select Microsoft Internet Security and Acceleration Server 2006.
-
On the Tasks tab, click Export (Back Up) Configuration to start the Export Wizard.
-
Follow the on-screen instructions.
Important: |
|---|
|
Select the following Export Preferences: Export confidential information and Export user permission settings.
|
Note: |
|---|
|
If ISA Server 2006 will be installed in a workgroup environment, a server certificate needs to be installed on the Configuration Storage server. For more information about installing ISA Server 2006 in a workgroup environment, see "ISA Server Enterprise Edition in a Workgroup" at the Microsoft TechNet Web site.
|
Export (back up) the configuration of the existing ISA Server 2004 Configuration Storage server
Perform the following procedure on the ISA_CSS computer.
To export the ISA Server 2004 configuration to a file
-
In the console tree of ISA Server Management, select Microsoft Internet Security and Acceleration Server 2004.
-
On the Tasks tab, click Export (Back Up) Configuration to start the Export Wizard.
-
Follow the on-screen instructions.
Important: |
|---|
|
Select the following Export Preferences: Export confidential information and Export user permission settings.
|
Import the exported configuration to the ISA Server 2006 Configuration Storage server
Perform the following procedure on ISA_CSS06.
To import the configuration to the ISA Server 2006 Configuration Storage server
-
Copy the export file from ISA_CSS computer to ISA_CSS06.
-
In the console tree of ISA Server Management, select Microsoft Internet Security and Acceleration Server 2006.
-
On the Tasks tab, click Import (Restore) Configuration to start the Import Wizard.
-
Follow the on-screen instructions.
Important: |
|---|
|
Select the following Import Preferences: Import server-specific information and Import user permission settings.
|
-
Click the Apply button in the details pane to save the changes and update the configuration.
Upgrade the array member
Perform the following procedure on ISA_FW01.
Important: |
|---|
|
If SMTP Message Screener or Firewall Client Share is currently installed, it must be uninstalled before upgrading, because these components are no longer supported in ISA Server 2006.
|
Note the following:
-
During the upgrade process, existing log and cache files are erased. ISA Server 2004 log files are not compatible with ISA Server 2006. However, ISA Server 2004 cache files are compatible with ISA Server 2006. For more information, see Appendix B: Backup Log and Cache Files.
-
Confirm that you can resolve the FQDN for ISA_CSS06, isa_css06.contoso.com, before beginning the upgrade progress.
-
During the upgrade, ISA Server services are not operational. We therefore recommend that you disconnect the ISA Server computer from the External network until the upgrade is complete.
-
During the upgrade, ISA Server services are not operational and users will experience an interruption of services until the upgrade is complete. We recommend that you notify users before the upgrade that ISA Server services will be unavailable during the upgrade process.
-
If you installed a replica Configuration Storage server on an array member, you must uninstall the replica Configuration Storage server before proceeding with the array member upgrade. After the upgrade is complete, you can add the replica Configuration Storage server. For more information about uninstalling a replica Configuration Storage server, see Uninstall Configuration Storage server feature from ISA02 in the Two Single Server Deployment Servers in the Same Enterprise scenario.
-
Monitoring applications, such as Microsoft Operations Manager (MOM) agent, use ISA Server files and may interfere with ISA Server setup and removal. To avoid issues, stop these applications before running Setup. For specific instructions about how to stop these applications, refer to the monitoring application vendor documentation.
To upgrade an array member
-
Run ISA Server 2006 Setup. The Setup program detects an existing valid version of ISA Server 2004 Enterprise Edition and performs the upgrade. To run ISA Server 2006 Setup, follow these steps:
-
Insert the ISA Server 2006 Enterprise Edition CD into the CD drive, or run ISAAutorun.exe from the shared network drive.
-
In Microsoft ISA Server Setup, click Install ISA Server 2006 and use the wizard to upgrade to ISA Server 2006 as outlined in the following table.
|
Page
|
Field or property
|
Setting
|
|---|
|
Welcome
|
None
|
Click Next.
|
|
License Agreement
|
License Agreement
|
Select I accept the terms in the license agreement, and click Next.
|
|
Customer Information
|
User Name
Organization
Product Serial Number
|
Enter user name.
Enter organization name.
Enter product serial number.
|
|
Upgrade Checklist
|
Review the upgrade checklist.
|
Click Next.
|
|
Locate Configuration Storage server
|
Configuration Storage Server
|
Enter the FQDN of the Configuration Storage server: isa_css06.contoso.com.
|
|
Services Warning
|
Review services that will be stopped and services that will be disabled if you continue.
|
Click Next.
|
|
Ready to Install the Program
|
None
|
Click Install.
|
-
After the upgrade is complete, click Finished.
-
Check that functions and connectivity in ISA Server 2006 are working properly.
Note: |
|---|
|
After the ISA Server 2006 upgrade is complete, ISA_CSS, the ISA Server 2004 Configuration Storage server, can be taken offline.
|
Scenario Two: Two Single Server Deployment Servers in the Same Enterprise
Contoso Corporation, a small to medium size organization, wants to upgrade their existing ISA Server 2004 Enterprise Edition deployment to ISA Server 2006 Enterprise Edition. Contoso has deployed ISA Server 2004 Enterprise Edition in the following configuration:
-
There are two single server deployments in the same enterprise. In a single server deployment, both the Configuration Storage server and the ISA Server services are installed on the same computer.
Note the following:
-
In a single server deployment, the default enterprise name is Enterprise and the default array name is the name of the computer. If you modified the name of the array, record the name of the ISA Server 2004 array.
-
If you have enabled Network Load Balancing (NLB) between the array members, for more information about upgrading an NLB-enabled array, see Scenario Four: Load Balanced Array.
The following table provides information about the ISA Server 2004 computers before the upgrade.
|
Computer name
|
Operating system
|
Member of domain
|
FDQN
|
Feature or services
|
|---|
|
ISA01
|
Microsoft Windows Server 2003 with SP1
|
Yes
|
isa01.contoso.com
|
ISA Server 2004 Configuration Storage server (main)
ISA Server 2004 services
|
|
ISA02
|
Microsoft Windows Server 2003 with SP1
|
Yes
|
isa02.contoso.com
|
ISA Server 2004 Configuration Storage server (replica)
ISA Server 2004 services
|
Array name: ISA01
Array properties:
-
Configuration Storage server: isa01.contoso.com
-
Alternate Configuration Storage server: isa02.contoso.com
Upgrade Process for Two Single Server Deployment Servers in the Same Enterprise
This section describes the process for upgrading two single server deployment servers in the same enterprise:
The following table provides information about the ISA Server 2006 computers after the upgrade.
|
Computer name
|
Operating system
|
Member of domain
|
FDQN
|
Feature or services
|
|---|
|
ISA01
|
Microsoft Windows Server 2003 with SP1
|
Yes
|
isa01.contoso.com
|
ISA Server 2006 Configuration Storage server (main)
ISA Server 2006 services
|
|
ISA02
|
Microsoft Windows Server 2003 with SP1
|
Yes
|
isa02.contoso.com
|
ISA Server 2006 Configuration Storage server (replica)
ISA Server 2006 services
|
Export (back up) the configuration of the existing ISA Server 2004 Configuration Storage server
Perform the following procedure on the ISA01 computer.
To export the ISA Server 2004 configuration to a file
-
In the console tree of ISA Server Management, select Microsoft Internet Security and Acceleration Server 2004.
-
On the Tasks tab, click Export (Back Up) Configuration to start the Export Wizard.
-
Follow the on-screen instructions.
Important: |
|---|
|
Select the following Export Preferences: Export confidential information and Export user permission settings.
|
Uninstall ISA Server 2004 from ISA01
Because an in-place upgrade on the Configuration Storage server cannot be performed, you must uninstall ISA Server from ISA01. ISA02 will fail over to the alternate Configuration Storage server, ISA02. If an alternate Configuration Storage server has not been defined, ISA02 uses the last known configuration it received from the Configuration Storage server.
Perform the following procedure on the ISA01 computer.
Note the following:
-
Monitoring applications, such as MOM agent, use ISA Server files and may interfere with ISA Server removal. To avoid issues, stop these applications before uninstalling ISA Server. For specific instructions about how to stop these applications, refer to the monitoring application vendor documentation.
-
Before removing ISA Server, be sure to close ISA Server Management and ISA Server Performance Monitor.
-
Before removing an ISA Server computer configured as the Configuration Storage server, you must ensure that all changes have replicated to the replica Configuration Storage server, or the configuration changes will be lost.
To uninstall ISA Server
-
Click Start, click Control Panel, and then double-click Add or Remove Programs.
-
In Microsoft ISA Server 2004, click Change/Remove.
-
On the Welcome page, click Next.
-
On the Program Maintenance page, select Remove, and click Next.
-
Confirm the settings on the Locate Configuration Storage Server page and click Next.
-
On the Generated Files Removal page:
-
Select Do not remove Microsoft ISA Server 2004 log files, to save log files.
-
Select Do not remove Microsoft ISA Server 2004 cache files, to save cache files.
-
Click Remove, to uninstall ISA Server 2004 from the computer.
-
Click OK in the following warning dialog box.
-
Click Retry in the following warning dialog box.
-
Click Finish to exit the wizard, when the removal process is complete.
Install ISA Server 2006 Enterprise Edition on ISA01
Perform the following procedure on the ISA01 computer.
To install both ISA Server services and the Configuration Storage server
-
Confirm that the computer meets the minimum requirements. For information, see Upgrade Requirements.
-
Install ISA Server 2006 Enterprise Edition. For more information, see the ISA Server 2006 Enterprise Edition Installation Guide. Select these options:
-
On the Setup Scenarios page, choose Install both ISA Server services and Configuration Storage server.
-
On the Enterprise Installation Options page, choose Create a new ISA Server enterprise.
-
Export the new ISA Server 2006 configuration to a file. This will enable you to restore to a new ISA Server 2006 state, if any issues arise during the import. Follow these steps:
-
In the console tree of ISA Server Management, select Microsoft Internet Security and Acceleration Server 2006.
-
On the Tasks tab, click Export (Back Up) Configuration to start the Export Wizard.
-
Follow the on-screen instructions.
Important: |
|---|
|
Select the following Export Preferences: Export confidential information and Export user permission settings.
|
Import configuration to ISA01 running ISA Server 2006
Note: |
|---|
|
Confirm that the name of the ISA Server 2006 array is the same as the ISA Server 2004 array name. If the ISA Server 2004 array name is different, you need to change the ISA Server 2006 array name before continuing.
|
Perform the following procedure on the ISA01 computer.
To import the configuration to the new ISA Server 2006 Configuration Storage server
-
In the console tree of ISA Server Management, select Microsoft Internet Security and Acceleration Server 2006.
-
On the Tasks tab, click Import (Restore) Configuration to start the Import Wizard.
-
Follow the on-screen instructions.
Important: |
|---|
|
Select the following Import Preferences: Import server-specific information and Import user permission settings.
|
-
Click the Apply button in the details pane to save the changes and update the configuration.
Uninstall Configuration Storage server feature from ISA02
In this procedure, you modify the installation of ISA02 to uninstall the Configuration Storage server feature. The ISA Server services remain installed. In the next procedure, you perform an in-place upgrade of the ISA02 computer.
Note the following:
-
Monitoring applications, such as MOM agent, use ISA Server files and may interfere with ISA Server removal. To avoid issues, stop these applications before uninstalling ISA Server. For specific instructions about how to stop these applications, refer to the monitoring application vendor documentation.
-
Before removing ISA Server, be sure to close ISA Server Management and ISA Server Performance Monitor.
Perform the following procedure on the ISA02 computer.
To uninstall the Configuration Storage server feature
-
Click Start, click Control Panel, and then double-click Add or Remove Programs.
-
In Microsoft ISA Server 2004, click Change/Remove.
-
On the Welcome page, click Next.
-
On the Program Maintenance page, select Modify, and click Next.
-
On the Component Selection page, select Configuration Storage server, select This feature will not be available, and click Next.
-
Click Install, to modify ISA Server 2004 on the computer.
-
Click OK in the following warning dialog box.
-
Click Retry in the following warning dialog box.
-
Click Finish to exit the wizard, when the setup process is complete.
In-place upgrade on ISA02
In this procedure, you perform an in-place upgrade on the ISA02 computer, from ISA Server 2004 to ISA Server 2006.
Important: |
|---|
|
If SMTP Message Screener or Firewall Client Share is currently installed, it must be uninstalled before upgrading, because these components are no longer supported in ISA Server 2006.
|
Note the following:
-
During the upgrade process, existing log and cache files are erased. ISA Server 2004 log files are not compatible with ISA Server 2006. However, ISA Server 2004 cache files are compatible with ISA Server 2006. For more information, see Appendix B: Backup Log and Cache Files.
-
During the upgrade, ISA Server services are not operational. We therefore recommend that you disconnect the ISA Server 2006 computer from the External network until the upgrade is complete.
-
During the upgrade, ISA Server services are not operational and users will experience an interruption of services until the upgrade is complete. We recommend that you notify users before the upgrade that ISA Server services will be unavailable during the upgrade process.
-
Monitoring applications, such as MOM agent, use ISA Server files and may interfere with ISA Server setup and removal. To avoid issues, stop these applications before running Setup. For specific instructions about how to stop these applications, refer to the monitoring application vendor documentation.
Perform the following procedure on ISA02.
To upgrade an array member
-
Run ISA Server 2006 Setup. The Setup program detects an existing valid version of ISA Server 2004 Enterprise Edition and performs the upgrade. To run ISA Server 2006 Setup, follow these steps:
-
Insert the ISA Server 2006 Enterprise Edition CD into the CD drive, or run ISAAutorun.exe from the shared network drive.
-
In Microsoft ISA Server Setup, click Install ISA Server 2006 and use the wizard to upgrade to ISA Server 2006 as outlined in the following table.
|
Page
|
Field or property
|
Setting
|
|---|
|
Welcome
|
None
|
Click Next.
|
|
License Agreement
|
License Agreement
|
Select I accept the terms in the license agreement, and click Next.
|
|
Customer Information
|
User Name
Organization
Product Serial Number
|
Enter user name.
Enter organization name.
Enter product serial number.
|
|
Upgrade Checklist
|
Review the upgrade checklist.
|
Click Next.
|
|
Locate Configuration Storage server
|
Configuration Storage Server
|
Enter the FQDN of the Configuration Storage server: isa02.contoso.com.
|
|
Services Warning
|
Review services that will be stopped and services that will be disabled if you continue.
|
Click Next.
|
|
Ready to Install the Program
|
None
|
Click Install.
|
-
After the upgrade is complete, click Finished.
Reinstall Configuration Storage server feature to ISA02 as replica of ISA01
This procedure will reinstall the Configuration Storage server feature to ISA02, as a replica Configuration Storage server of ISA01.
Note: |
|---|
|
Monitoring applications, such as MOM agent, use ISA Server files and may interfere with ISA Server setup and removal. To avoid issues, stop these applications before running Setup. For specific instructions about how to stop these applications, refer to the monitoring application vendor documentation.
|
Perform the following procedure on ISA02.
To install the Configuration Storage server feature
-
Click Start, click Control Panel, and then double-click Add or Remove Programs.
-
In Microsoft ISA Server 2006, click Change/Remove.
-
On the Welcome page, click Next.
-
On the Program Maintenance page, select Modify, and click Next.
-
On the Component Selection page, select Configuration Storage server, select This feature will be installed on local hard drive, and click Next.
-
On the Enterprise Installation page, select Create a replica of the enterprise configuration, and click Next.
-
On the Locate Configuration Storage server page, confirm that the proper FQDN has been entered, isa01.contoso.com, and click Next.
-
On the ISA Server Configure Replicate Server page, select Replicate over the network, and click Next.
Note: |
|---|
|
If replication will take place over a slow link (10 megabits per second (Mbps) or less), select Copy from the restored backup files. For more information, see "Replicating a Large Enterprise Configuration Over Slow Links" at the Microsoft TechNet Web site.
|
-
On the Enterprise Environment page, select I am deploying in a single domain or in domains with trust relationships, and click Next.
-
Click Install to modify ISA Server 2006 on the computer.
-
Click Finish to exit the wizard, when the setup process is complete.
After successfully upgrading both ISA01 and ISA02 to ISA Server 2006 Enterprise Edition, check that functions and connectivity for both ISA01 and ISA02 are working properly.
Scenario Three: Single Configuration Storage Server with Multiple Arrays
Contoso Corporation, a medium to enterprise size organization, wants to upgrade their existing ISA Server 2004 Enterprise Edition deployment to ISA Server 2006 Enterprise Edition. Contoso has three regional offices that are connected using leased lines. Contoso deployed ISA Server 2004 Enterprise Edition for its ability to centrally manage their entire ISA Server deployment from their main office.
Contoso has deployed ISA Server 2004 Enterprise Edition in the following configuration:
-
There is a single Configuration Storage server located in the New York office.
-
There is one array each in New York, Hong Kong, and London. These arrays are named NY, HKG, and LON.
-
Each array has a single array member.
Contoso wants to upgrade to ISA Server 2006 but cannot upgrade all of the arrays at the same time. Because ISA Server 2006 can only manage ISA Server 2006 arrays, Contoso needs to manage both ISA Server 2004 and ISA Server 2006 deployments until all of the arrays are upgraded to ISA Server 2006. Contoso will upgrade the Configuration Storage server along with the array in New York first. Then the London array will be upgraded, followed by the Hong Kong array. After the last array is upgraded, the ISA Server 2004 computer can be taken out of service.
The following table provides information about the ISA Server 2004 computers before the upgrade.
|
Computer name
|
Operating system
|
Member of domain
|
Array
|
FQDN
|
Feature or services
|
|---|
|
NY_CSS
|
Microsoft Windows Server 2003 with SP1
|
Yes
|
Not applicable
|
ny_css.contoso.com
|
ISA Server 2004 Configuration Storage server
|
|
NY_ISA01
|
Microsoft Windows Server 2003 with SP1
|
Yes
|
NY
|
ny_isa01.contoso.com
|
ISA Server 2004 services
|
|
LON_ISA01
|
Microsoft Windows Server 2003 with SP1
|
Yes
|
LON
|
lon_isa01.contoso.com
|
ISA Server 2004 services
|
|
HKG_ISA01
|
Microsoft Windows Server 2003 with SP1
|
Yes
|
HKG
|
hkg_isa01.contoso.com
|
ISA Server 2004 services
|
Upgrade Process for Single Configuration Storage Server with Multiple Arrays
This section describes the process for upgrading a single Configuration Storage server with multiple arrays:
The following table provides information about the ISA Server 2006 computers after the upgrade.
|
Computer name
|
Operating system
|
Member of domain
|
Array
|
FQDN
|
Feature or services
|
|---|
|
NY_CSS06
|
Microsoft Windows Server 2003 with SP1
|
Yes
|
Not applicable
|
ny_css06.contoso.com
|
ISA Server 2006 Configuration Storage server
|
|
NY_ISA01
|
Microsoft Windows Server 2003 with SP1
|
Yes
|
NY
|
ny_isa01.contoso.com
|
ISA Server 2006 services
|
|
LON_ISA01
|
Microsoft Windows Server 2003 with SP1
|
Yes
|
LON
|
lon_isa01.contoso.com
|
ISA Server 2006 services
|
|
HKG_ISA01
|
Microsoft Windows Server 2003 with SP1
|
Yes
|
HKG
|
hkg_isa01.contoso.com
|
ISA Server 2006 services
|
|
NY_CSS
(After the upgrade, this server is no longer needed and can be removed from service.)
|
Microsoft Windows Server 2003 with SP1
|
Yes
|
Not applicable
|
ny_css.contoso.com
|
ISA Server 2004 Configuration Storage server
|
|
NY_CSS_Temp
(After the upgrade, this server is no longer needed and can be removed from service.)
|
Microsoft Windows Server 2003 with SP1
|
Yes
|
Not applicable
|
ny_css_temp.contoso.com
|
ISA Server 2006 Configuration Storage server (temporary)
|
Export (back up) the configuration of the existing ISA Server 2004 Configuration Storage server
Perform the following procedure on the NY_CSS computer.
To export the ISA Server 2004 configuration to a file
-
In the console tree of ISA Server Management, select Microsoft Internet Security and Acceleration Server 2004.
-
On the Tasks tab, click Export (Back Up) Configuration to start the Export Wizard.
-
Follow the on-screen instructions.
Important: |
|---|
|
Select the following Export Preferences: Export confidential information and Export user permission settings.
|
Install the new ISA Server 2006 Configuration Storage server
Perform the following procedure on the NY_CSS06 computer.
To install the new Configuration Storage server
-
Install Windows Server 2003 with SP1 or Windows Server 2003 R2 on the computer that will be the ISA Server 2006 Configuration Storage server.
-
Install the ISA Server 2006 Configuration Storage server. For more information, see the ISA Server 2006 Enterprise Edition Installation Guide.
-
Export the new ISA Server 2006 configuration to a file. This will enable you to restore to a new ISA Server 2006 state, if any issues arise during the import. Follow these steps:
-
In the console tree of ISA Server Management, select Microsoft Internet Security and Acceleration Server 2006.
-
On the Tasks tab, click Export (Back Up) Configuration to start the Export Wizard.
-
Follow the on-screen instructions.
Important: |
|---|
|
Select the following Export Preferences: Export confidential information and Export user permission settings.
|
Note: |
|---|
|
If ISA Server 2006 will be installed in a workgroup environment, a server certificate needs to be installed on the Configuration Storage server. For more information about installing ISA Server 2006 in a workgroup environment, see "ISA Server Enterprise Edition in a Workgroup" at the Microsoft TechNet Web site.
|
Import configuration to NY_CSS06 running ISA Server 2006
Perform the following procedure on the ISA01 computer.
To import the configuration to the new ISA Server 2006 Configuration Storage server
-
Copy the export file from NY_CSS computer to NY_CSS06.
-
In the console tree of ISA Server Management, select Microsoft Internet Security and Acceleration Server 2006.
-
On the Tasks tab, click Import (Restore) Configuration to start the Import Wizard.
-
Follow the on-screen instructions.
Important: |
|---|
|
Select the following Import Preferences: Import server-specific information and Import user permission settings.
|
-
Click the Apply button in the details pane to save the changes and update the configuration.
Upgrade NY array member
In this procedure, you will perform an in-place upgrade from ISA Server 2004 to ISA Server 2006, on the first array.
Important: |
|---|
|
If SMTP Message Screener or Firewall Client Share is currently installed, it must be uninstalled before upgrading, because these components are no longer supported in ISA Server 2006.
|
Note the following:
-
During the upgrade process, existing log and cache files are erased. ISA Server 2004 log files are not compatible with ISA Server 2006. However, ISA Server 2004 cache files are compatible with ISA Server 2006. For more information, see Appendix B: Backup Log and Cache Files.
-
During the upgrade, ISA Server services are not operational. We therefore recommend that you disconnect the ISA Server 2006 computer from the External network until the upgrade is complete.
-
During the upgrade, ISA Server services are not operational and users will experience an interruption of services until the upgrade is complete. We recommend that you notify users before the upgrade that ISA Server services will be unavailable during the upgrade process.
-
Monitoring applications, such as MOM agent, use ISA Server files and may interfere with ISA Server setup and removal. To avoid issues, stop these applications before running Setup.
Perform the following procedure on NY_ISA01.
To upgrade an array member
-
Run ISA Server 2006 Setup. The Setup program detects an existing valid version of ISA Server 2004 Enterprise Edition and performs the upgrade. To run ISA Server 2006 Setup, follow these steps:
-
Insert the ISA Server 2006 Enterprise Edition CD into the CD drive, or run ISAAutorun.exe from the shared network drive.
-
In Microsoft ISA Server Setup, click Install ISA Server 2006 and use the wizard to upgrade to ISA Server 2006 as outlined in the following table.
-
|
Page
|
Field or property
|
Setting
|
|---|
|
Welcome
|
None
|
Click Next.
|
|
License Agreement
|
License Agreement
|
Select I accept the terms in the license agreement, and click Next.
|
|
Customer Information
|
User Name
Organization
Product Serial Number
|
Enter user name.
Enter organization name.
Enter product serial number.
|
|
Upgrade Checklist
|
Review the upgrade checklist.
|
Click Next.
|
|
Locate Configuration Storage server
|
Configuration Storage Server
|
Enter the FQDN of the Configuration Storage server:
NY_CSS06.contoso.com.
|
|
Services Warning
|
Review services that will be stopped and services that will be disabled if you continue.
|
Click Next.
|
|
Ready to Install the Program
|
None
|
Click Install.
|
-
After the upgrade is complete, click Finished.
-
Check that functions and connectivity in ISA Server 2006 are working properly.
Delete London and Hong Kong arrays
We recommend that any arrays that are not upgraded are deleted from the ISA Server 2006 Configuration Storage server.
In the following procedure, you will delete the LON and HKG arrays from the ISA Server 2006 Configuration Storage server.
Perform the following procedure on NY_CSS06.
To delete arrays that will not be upgraded now
-
In the console tree of ISA Server Management, select Microsoft Internet Security and Acceleration Server 2006.
-
Expand Arrays, select LON, and on the Tasks tab, click Delete Selected Arrays.
-
Click Yes in the Delete Arrays warning message dialog box.
-
Repeat step 2 and step 3 for the HKG array.
-
Click the Apply button in the details pane to save the changes and update the configuration.
Important: |
|---|
|
Until all arrays are upgraded to ISA Server 2006, you need to manage both ISA Server 2004 and ISA Server 2006 enterprises.
|
Import a single array configuration
ISA Server 2006 cannot import an exported configuration of an individual ISA Server 2004 array. ISA Server 2006 can only import an exported configuration from ISA Server 2004 when the export was done at the root of the enterprise, which shows Microsoft Internet and Acceleration Server 2004. However, you can import an individual array configuration from one ISA Server 2006 deployment to another ISA Server 2006 deployment. In this procedure, you create a temporary ISA Server 2006 Configuration Storage server and import a single array configuration. After the procedure is complete, the temporary ISA Server 2006 Configuration Storage server is no longer needed.
To enable you to import an individual array configuration from an ISA Server 2004 deployment, the following procedures need to be followed:
Create a temporary ISA Server 2006 Configuration Storage server
Perform the following on the NY_CSS_Temp computer.
For the procedures to install an ISA Server 2006 Configuration Storage server, see Install the new ISA Server 2006 Configuration Storage server in the Single Configuration Storage Server with Multiple Arrays scenario.
Import the exported configuration to NY_CSS_Temp
Perform the following on the NY_CSS_Temp computer.
For the procedures to import the exported ISA Server 2004 configuration, see Import configuration to NY_CSS06 running ISA Server 2006 in the Single Configuration Storage Server with Multiple Arrays scenario. Replace NY_CSS06 with NY_CSS_Temp.
Export LON array configuration
With the latest configuration imported to NY_CSS_Temp, you are ready to export the LON array configuration.
In the following procedure, you will export the LON array configuration.
Perform the following procedure on NY_CSS_Temp.
To export array configuration
-
In the console tree of ISA Server Management, select Microsoft Internet Security and Acceleration Server 2006.
-
Expand Arrays, select LON, and on the Tasks tab, click Export (Back Up) Array Configuration.
-
Follow the on-screen instructions.
Important: |
|---|
|
Select the following Export Preferences: Export confidential information and Export user permission settings.
|
Import the exported array configuration to NY_CSS06
Perform the following procedure on NY_CSS06.
To import the exported array configuration
-
Copy the exported file from the NY_CSS_Temp computer to NY_CSS06.
-
In the console tree of ISA Server Management, select Microsoft Internet Security and Acceleration Server 2006.
-
Select Arrays, and on the Tasks tab, click Create New Array, and use the following settings:
-
Array name: LON
-
Array DNS Name: lon_isa01.contoso.com
-
Array Policy Rule Types: Deny, Allow, and Publishing rules
-
Select the newly created array.
-
On the Tasks tab, click Import (Restore) Array Configuration and use the wizard to import the array configuration as outlined in the following table.
|
Page
|
Field or property
|
Setting
|
|---|
|
Welcome
|
None
|
Click Next.
|
|
Select the Import File
|
File Name
|
Specify the file you want to import (full path).
|
|
Import Action
|
Select if the file will be imported or used to restore the configuration.
|
Select Overwrite (restore).
|
|
Import Preferences
|
Choose the optional data that you want to import from the file.
|
Select Import server-specific information and Import user permission settings.
|
|
Enter Password
|
Password
|
Enter the password required for opening and importing the file.
|
|
Completing the Import Wizard
|
None
|
Click Finish.
|
-
Click OK in the following warning dialog box.
-
Click OK, when the import has completed successfully.
-
Click the Apply button in the details pane to save the changes and update the configuration.
Upgrade LON array member
In this procedure, you will perform an in-place upgrade from ISA Server 2004 to ISA Server 2006, on the LON array.
Important: |
|---|
|
If SMTP Message Screener or Firewall Client Share is currently installed, it must be uninstalled before upgrading, because these components are no longer supported in ISA Server 2006.
|
Note the following:
-
During the upgrade process, existing log and cache files will be erased. ISA Server 2004 log files are not compatible with ISA Server 2006. However, ISA Server 2004 cache files are compatible with ISA Server 2006. For more information, see Appendix B: Backup Log and Cache Files.
-
During the upgrade, ISA Server services are not operational. We therefore recommend that you disconnect the ISA Server computer from the External network until the upgrade is complete.
-
During the upgrade, ISA Server services are not operational and users will experience an interruption of services until the upgrade is complete. We recommend that you notify users before the upgrade that ISA Server services will be unavailable during the upgrade process.
-
Monitoring applications, such as MOM agent, use ISA Server files and may interfere with ISA Server setup and removal. To avoid issues, stop these applications before running Setup.
Perform the following procedure on NY_ISA01.
To upgrade an array member
-
Run ISA Server 2006 Setup. The Setup program detects an existing valid version of ISA Server 2004 Enterprise Edition and performs the upgrade.
-
Insert the ISA Server 2006 Enterprise Edition CD into the CD drive, or run ISAAutorun.exe from the shared network drive.
-
In Microsoft ISA Server Setup, click Install ISA Server 2006 and use the wizard to upgrade to ISA Server 2006 as outlined in the following table.
|
Page
|
Field or property
|
Setting
|
|---|
|
Welcome
|
None
|
Click Next.
|
|
License Agreement
|
License Agreement
|
Select I accept the terms in the license agreement, and click Next.
|
|
Customer Information
|
User Name
Organization
Product Serial Number
|
Enter user name.
Enter organization name.
Enter product serial number.
|
|
Upgrade Checklist
|
Review the upgrade checklist.
|
Click Next.
|
|
Locate Configuration Storage server
|
Configuration Storage Server
|
Enter the FQDN of the Configuration Storage server: ny_css06.contoso.com.
|
|
Services Warning
|
Review services that will be stopped and services that will be disabled if you continue.
|
Click Next.
|
|
Ready to Install the Program
|
None
|
Click Install.
|
Complete these steps for the HKG array when you are ready to upgrade the HKG array.
After the last array is successfully upgraded, you can remove NY_CSS_TEMP from service.
Scenario Four: Load Balanced Array
There are two mechanisms for load balancing array traffic between array members:
-
DNS round robin For each array member's IP address, there is a unique Domain Name System (DNS) entry for the array. When providing an IP address lookup for the array's DNS name, the DNS server cycles between the different array members' IP addresses.
-
Network Load Balancing (NLB) The array is configured with a virtual IP address to which all array members receive requests and determine which array member will answer the request.
This section explains how to properly upgrade an array with DNS round robin or NLB.
Note the following:
-
In ISA Server 2004, you can configure only one virtual IP address for each network that is configured for Network Load Balancing (NLB) through ISA Server Management. Additional virtual IP addresses can be defined. However, these additional virtual IP addresses are configured manually on the network adapters of each array member. The ISA Server 2006 upgrade process will only upgrade the virtual IP address for a network that is configured in ISA Server Management in ISA Server 2004, and will delete the additional virtual IP addresses that have been configured on the network adapters. ISA Server 2006 allows you to define multiple virtual IP addresses for a network though ISA Server Management. If more than one virtual IP address has been configured for an ISA Server 2004 NLB-enabled network, you need to reconfigure the additional virtual IP addresses in ISA Server Management, after the upgrade is complete.
-
If you have configured both DNS round robin and NLB for an array, you need to disable one method before upgrading, perform the upgrade, and then reinstitute the disabled load balancing method.
DNS Round Robin
Perform the following procedure to upgrade an array that is load balanced with DNS round robin. This procedure enables the array to continue to provide services to your users during the upgrade process.
Note: |
|---|
|
The assumption is that the Configuration Storage server has already been successfully upgraded.
|
Perform the following procedure on each array member.
To upgrade an array that is load balanced using DNS round robin
-
Remove the array member's IP address from the array's DNS entry. This will stop new requests from being forwarded to this array member, but does not have any effect on existing connections to the array member.
Note: |
|---|
|
Depending on the Time to Live (TTL) of the entry on the DNS server, clients and other DNS servers will cache the existing array member's IP address until the defined TTL has expired, which might result in new connections that will be sent to that IP address. You can reduce the TTL value for the array's DNS entries to reduce the client cache delay.
|
-
Perform an in-place upgrade from ISA Server 2004 to ISA Server 2006. For the procedures to perform an in-place upgrade, see Upgrade the array member in the Single Configuration Storage Server with One Array scenario.
-
Return the array member's IP address to the array's DNS entry.
-
Perform steps 1 through 3 for each of the remaining array members.
Network Load Balancing
Perform the following procedure to upgrade an array that is load balanced through NLB. This procedure enables the array to continue to provide services to your users during the upgrade process.
Note the following:
-
The assumption is that the Configuration Storage server has already been successfully upgraded.
Important: |
|---|
|
After you complete the upgrade of the Configuration Storage server, you need to disable NLB integration for the ISA Server 2006 array.
|
-
To avoid disruptions in virtual private network (VPN) site-to-site tunnels, we recommend that VPN tunnel owners be upgraded last in the arrays.
Drain and stop NLB services on the specific array member
To remove the array member from the NLB algorithm, we recommend that you drain and stop the NLB services for the specific array member. This ensures that for all future connections, the array member will no longer be included in the NLB algorithm. Existing connections are not affected by this procedure.
Perform the following procedure on the Configuration Storage server.
To drain and stop NLB services
-
In the console tree of ISA Server Management, select Microsoft Internet Security and Acceleration Server 2004.
-
Expand Arrays, and expand the selected array.
-
Select Monitoring, and in the details pane, click the Services tab.
-
Select Network Load Balancing for the specific array member.
-
On the Tasks tab, click Drain and Stop Selected Service to stop the selected service.
Suspend the NLB service on the specific array member
When the NLB services are suspended, existing connections are disconnected. Users can reconnect using the virtual IP address and connect to another array member. When the NLB service on a specific array member is suspended, NLB will not start, even after the server has been restarted.
Perform the following procedure on the Configuration Storage server.
To suspend the NLB service
-
In the console tree of ISA Server Management, select Microsoft Internet Security and Acceleration Server 2004.
-
Expand Arrays, and expand the selected array.
-
Select Monitoring and in the details pane, click the Services tab.
-
Select Network Load Balancing for the specific array member.
-
On the Tasks tab, click Suspend Selected Service.
Perform in-place upgrade on the specific array member
Perform an in-place upgrade from ISA Server 2004 to ISA Server 2006. For the procedures to perform an in-place upgrade, see Upgrade the array member in the Single Configuration Storage Server with One Array scenario.
Note: |
|---|
|
Because NLB is disabled for the ISA Server 2006 array, the array member will not receive any NLB traffic after the in-place upgrade is complete.
|
Repeat until half of the array members have been upgraded
Repeat the following until half of the array members have been upgraded:
-
Drain and stop NLB services on the specific array member.
-
Suspend the NLB service on the specific array member.
-
Perform an in-place upgrade on the specific array member.
Suspend the NLB service on the remaining ISA Server 2004 array members
After half of the array members have been upgraded to ISA Server 2006, suspend the NLB service on the remaining ISA Server 2004 array members.
Note: |
|---|
|
At this point, NLB service is suspended on both the ISA Server 2004 and ISA Server 2006 array members.
|
Start the NLB service on the ISA Server 2006 array members
Start the NLB service on the ISA Server 2006 array members. At this point, new connections will be handled by the ISA Server 2006 array members.
Perform an in-place upgrade on the remaining ISA Server 2004 array members
Perform the following procedure on the remaining ISA Server 2004 array members.
To perform an in-place upgrade on the remaining array members
-
Perform an in-place upgrade from ISA Server 2004 to ISA Server 2006. For the procedures to perform an in-place upgrade, see Upgrade the array member in the Single Configuration Storage Server with One Array scenario.
-
Enable NLB on the upgraded array member.