Migrating PAM from VMware to KVM, AWS, or Azure
search cancel

Migrating PAM from VMware to KVM, AWS, or Azure

book

Article ID: 100106

calendar_today

Updated On:

Products

CA Privileged Access Manager (PAM)

Issue/Introduction

This article describes the supported methods for migrating Symantec Privileged Access Manager (PAM) instances from a VMware environment to alternative platforms including physical KVM hosts, Amazon Web Services (AMI), or Microsoft Azure (VHD).

Environment

CA Privileged Access Manager 4.x

KVM Physical Hardware

AWS / Azure Cloud

Resolution

Symantec PAM does not support the direct physical conversion of VMware .vmdk files to other formats. The recommended migration path is to use PAM's built-in clustering capabilities to sync data to new appliances.

Migration Steps

  1. Deploy New Appliances: Deploy new PAM appliances on your target platform following the specific deployment guides:
  2. Configure Network Connectivity: Ensure firewall rules allow communication between your existing VMware appliances and the new site (Ports 443, 8443, and 3307 are required for clustering).
  3. Add Cluster Site: Join the newly created appliances as a secondary site to your existing PAM cluster.
  4. Data Replication: Allow the cluster to fully synchronize all database and configuration data.
  5. Decommission Old Site: Once the new site is verified, remove the older VMware appliances from the cluster configuration and decommission them.

Alternative Methods

If clustering is not feasible, you may use manual export/import methods for provisioning data: