<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Ended up reimaging. It was in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-2-0-patch-3-issue/m-p/2962562#M38343</link>
    <description>&lt;P&gt;Ended up reimaging. It was actually pretty easy.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks for your help.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 21 Sep 2016 15:41:17 GMT</pubDate>
    <dc:creator>dporod</dc:creator>
    <dc:date>2016-09-21T15:41:17Z</dc:date>
    <item>
      <title>iSE 2.0 Patch 3 issue</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-0-patch-3-issue/m-p/2962554#M38319</link>
      <description>&lt;P&gt;Hi, I am patching our&amp;nbsp;2.0.0.306 patch 2 ISE deployment to patch 3 using the GUI. Yesterday I kicked off the process and have been unable to access the primary admin node via the web page since then. I can access the CLI. I think the patch process &amp;nbsp;is hung up some how. The rest of the deployment has not been affected.&lt;/P&gt;
&lt;P&gt;I tried stopping the ISE application but cannot:&lt;/P&gt;
&lt;P&gt;apppdiseadmin01/admin# app stop ise&lt;/P&gt;
&lt;P&gt;Waiting up to 20 seconds for lock: APP_PATCH to complete&lt;BR /&gt;Database is still locked by lock: APP_PATCH. Aborting. Please try it later&lt;BR /&gt;% Error: Another ISE DB process (APP_PATCH) is in progress, cannot perform Application Stop at this time&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I'd really like to cancel the patch process if possible.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;apppdiseadmin01/admin# sh ver&lt;/P&gt;
&lt;P&gt;Cisco Application Deployment Engine OS Release: 2.3&lt;BR /&gt;ADE-OS Build Version: 2.3.0.187&lt;BR /&gt;ADE-OS System Architecture: x86_64&lt;/P&gt;
&lt;P&gt;Copyright (c) 2005-2014 by Cisco Systems, Inc.&lt;BR /&gt;All rights reserved.&lt;BR /&gt;Hostname: apppdiseadmin01&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Version information of installed applications&lt;BR /&gt;---------------------------------------------&lt;/P&gt;
&lt;P&gt;Cisco Identity Services Engine&lt;BR /&gt;---------------------------------------------&lt;BR /&gt;Version : 2.0.0.306&lt;BR /&gt;Build Date : Thu Oct 8 02:55:23 2015&lt;BR /&gt;Install Date : Wed Jan 20 11:37:02 2016&lt;/P&gt;
&lt;P&gt;Cisco Identity Services Engine Patch&lt;BR /&gt;---------------------------------------------&lt;BR /&gt;Version : 2&lt;BR /&gt;Install Date : Thu Jan 21 07:38:01 2016&lt;/P&gt;
&lt;P&gt;apppdiseadmin01/admin# sh app sta ise&lt;/P&gt;
&lt;P&gt;ISE PROCESS NAME STATE PROCESS ID&lt;BR /&gt;--------------------------------------------------------------------&lt;BR /&gt;Database Listener running 3560&lt;BR /&gt;Database Server running 31 PROCESSES&lt;BR /&gt;Application Server not running&lt;BR /&gt;Profiler Database running&lt;BR /&gt;AD Connector running 6771&lt;BR /&gt;M&amp;amp;T Session Database running 3104&lt;BR /&gt;M&amp;amp;T Log Collector not running&lt;BR /&gt;M&amp;amp;T Log Processor not running&lt;BR /&gt;Certificate Authority Service disabled&lt;BR /&gt;SXP Engine Service disabled&lt;BR /&gt;pxGrid Infrastructure Service disabled&lt;BR /&gt;pxGrid Publisher Subscriber Service disabled&lt;BR /&gt;pxGrid Connection Manager disabled&lt;BR /&gt;pxGrid Controller disabled&lt;BR /&gt;Identity Mapping Service disabled&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 07:04:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-0-patch-3-issue/m-p/2962554#M38319</guid>
      <dc:creator>dporod</dc:creator>
      <dc:date>2019-03-11T07:04:39Z</dc:date>
    </item>
    <item>
      <title>Hi,</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-0-patch-3-issue/m-p/2962555#M38325</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;You have to reload the node instead on restarting of services.&lt;/P&gt;
&lt;P&gt;If still it doesn't help then probably need to take root access in to the node. Remove the installing patch file which got hung. Need to contact TAC for root access.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;Gagan&lt;/P&gt;
&lt;P&gt;PS: rate if it helps!!!&lt;/P&gt;</description>
      <pubDate>Thu, 15 Sep 2016 12:20:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-0-patch-3-issue/m-p/2962555#M38325</guid>
      <dc:creator>Gagandeep Singh</dc:creator>
      <dc:date>2016-09-15T12:20:50Z</dc:date>
    </item>
    <item>
      <title>I just ran into this exact</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-0-patch-3-issue/m-p/2962556#M38328</link>
      <description>&lt;P&gt;I just ran into this exact same issue. ISE 2.0 with patch 2 trying to upgrade to patch 3. I let it run for over an hour and it was stuck with only the Database Listener, Database Server, AD Connector, and M&amp;amp;T Session Database&amp;nbsp;services running.&lt;/P&gt;
&lt;P&gt;I reloaded the node (primary admin in two node deployment) and the Application Server service wouldn't start. Instead, it went back through the patch install process and finished successfully. The secondary node&amp;nbsp;never installed the patch automatically. So I did the following:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;&lt;SPAN style="line-height: normal;"&gt;I used the CLI to remove patch 3 from the primary node.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN style="line-height: normal;"&gt;Rolled back Patch 2 from the deployment using the Primary Admin GUI.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN style="line-height: normal;"&gt;Installed Patch 3 using the Primary Admin GUI.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&lt;SPAN style="line-height: normal;"&gt;Everything appears to be working okay for now.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 19 Sep 2016 01:32:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-0-patch-3-issue/m-p/2962556#M38328</guid>
      <dc:creator>Joseph Johnson</dc:creator>
      <dc:date>2016-09-19T01:32:01Z</dc:date>
    </item>
    <item>
      <title>I have tried a reload but end</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-0-patch-3-issue/m-p/2962557#M38332</link>
      <description>&lt;P&gt;I have tried a reload but end up in the same status.&lt;/P&gt;</description>
      <pubDate>Mon, 19 Sep 2016 11:30:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-0-patch-3-issue/m-p/2962557#M38332</guid>
      <dc:creator>dporod</dc:creator>
      <dc:date>2016-09-19T11:30:42Z</dc:date>
    </item>
    <item>
      <title>That will require a TAC call</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-0-patch-3-issue/m-p/2962558#M38335</link>
      <description>&lt;P&gt;That will require a TAC call because, like gagsing said, you will need root access in order to delete the offending patch. Once that's deleted, you should be able to boot the system and start back in the previous state. I would rollback patch 2 and install patch 3 once it's all up and running.&lt;/P&gt;</description>
      <pubDate>Mon, 19 Sep 2016 12:03:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-0-patch-3-issue/m-p/2962558#M38335</guid>
      <dc:creator>Joseph Johnson</dc:creator>
      <dc:date>2016-09-19T12:03:08Z</dc:date>
    </item>
    <item>
      <title>If I have to reimage would</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-0-patch-3-issue/m-p/2962559#M38337</link>
      <description>&lt;P&gt;If I have to reimage would the process be: ?&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;build a new VM&lt;/LI&gt;
&lt;LI&gt;deploy the&amp;nbsp;ise-2.0.0.306.SPA.x86_64.iso&lt;/LI&gt;
&lt;LI&gt;run setup with the same IP and hostname&lt;/LI&gt;
&lt;LI&gt;install patch 2&lt;/LI&gt;
&lt;LI&gt;rejoin deployment&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Couple of licensing questions. Will the UDI be the same on the new server if the IP and hostname are the same? Will the license files need to be installed on the new server manually or will they be installed as part of joining the deployment?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 19 Sep 2016 12:53:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-0-patch-3-issue/m-p/2962559#M38337</guid>
      <dc:creator>dporod</dc:creator>
      <dc:date>2016-09-19T12:53:37Z</dc:date>
    </item>
    <item>
      <title>You shouldn't have to build a</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-0-patch-3-issue/m-p/2962560#M38339</link>
      <description>&lt;P&gt;You shouldn't have to build a new VM. You should have the option to install when booting from the ISO and that will overwrite the existing installation because one of the steps is provisioning/formatting the drives. If you don't get that option, then you will need to delete the VM and recreate it.&lt;/P&gt;
&lt;P&gt;Yes, use the same set up information. If you have another node in the deployment as a secondary admin, go ahead promote it to primary admin while recreating the failed node. Once the failed node is recreated and patched to the same level, join it to the deployment.&lt;/P&gt;
&lt;P&gt;Yes, the UDI information will change so you will need to rehost the license(s). The licenses do not need to be reinstalled if you have a secondary admin node in place because they are already replicated to it from the primary admin when you added a secondary admin to the deployment originally.&lt;/P&gt;</description>
      <pubDate>Mon, 19 Sep 2016 13:11:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-0-patch-3-issue/m-p/2962560#M38339</guid>
      <dc:creator>Joseph Johnson</dc:creator>
      <dc:date>2016-09-19T13:11:36Z</dc:date>
    </item>
    <item>
      <title>Hi,</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-0-patch-3-issue/m-p/2962561#M38341</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;In order to proceed further on this issue, potentially&amp;nbsp;need root access and get that patch removed.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;Gagan&lt;/P&gt;
&lt;P&gt;PS: rate if it helps!!!&lt;/P&gt;</description>
      <pubDate>Mon, 19 Sep 2016 14:42:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-0-patch-3-issue/m-p/2962561#M38341</guid>
      <dc:creator>Gagandeep Singh</dc:creator>
      <dc:date>2016-09-19T14:42:06Z</dc:date>
    </item>
    <item>
      <title>Ended up reimaging. It was</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-0-patch-3-issue/m-p/2962562#M38343</link>
      <description>&lt;P&gt;Ended up reimaging. It was actually pretty easy.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks for your help.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 21 Sep 2016 15:41:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-0-patch-3-issue/m-p/2962562#M38343</guid>
      <dc:creator>dporod</dc:creator>
      <dc:date>2016-09-21T15:41:17Z</dc:date>
    </item>
  </channel>
</rss>

