Hi phoneboy,
thank you for your reply.
Yes you are right. Normally we should avoid to break the ICA. But the old management server is still online and used. What we have done, we splitted the manager into two. Means we now have two management server each of it serves some of the gateways/cluster, which were managed before by only one server.
I know, we could use all the old stuff (ICA and SIC certificates) on both servers, but we don‘t want to get into future trouble with that. That was the reason for the sic_reset on the new server.
Example: We use QRadar as SIEM system. When not creating a new ICA on the new server we will have two lea connection from our QRadar. One to each management server, but with the same credentials (hostname is the same, only IP is different). That works for now, but who knows if that is a recommended configuration. So we decided to create on one server the new ICA.
We figured out, to reconnect a vsx cluster from the old to the new management server, we have to do a fresh install on each of the both cluster gateways and then do a vsx_util reconfigure - that works. But that means we have an Outage.
Do you have a more comfortable idea, maybe without outage? Or only short outage?
Thank you in adavance,
Markus