<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE patch while upgrading in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-patch-while-upgrading/m-p/3875265#M472159</link>
    <description>&lt;P&gt;I see that you can apply patches prior to registering PSNs to the upgraded deployment per this document: &lt;A href="https://community.cisco.com/t5/security-documents/ise-upgrades-best-practices/ta-p/3656934#toc-hId--718381845" target="_blank"&gt;https://community.cisco.com/t5/security-documents/ise-upgrades-best-practices/ta-p/3656934#toc-hId--718381845&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 18 Jun 2019 17:22:43 GMT</pubDate>
    <dc:creator>matthen</dc:creator>
    <dc:date>2019-06-18T17:22:43Z</dc:date>
    <item>
      <title>ISE patch while upgrading</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-patch-while-upgrading/m-p/3875259#M472156</link>
      <description>&lt;P&gt;Is there a way to apply a patch while you're upgrading an ISE environment?&amp;nbsp; My use case is, if a customer is upgrading from ISE 2.2 to 2.4, they start with their Secondary Admin, Primary Monitoring, then they start upgrading their PSNs.&amp;nbsp; However, during this process the newly upgraded PSNs will be vulnerable to any bugs in the base 2.4 code, and users being migrated to the upgraded PSNs will be exposed to those bugs.&amp;nbsp; Is there a way to apply a patch to each node as they're being upgraded to avoid unnecessary issues?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Matt&lt;/P&gt;</description>
      <pubDate>Tue, 18 Jun 2019 17:17:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-patch-while-upgrading/m-p/3875259#M472156</guid>
      <dc:creator>matthen</dc:creator>
      <dc:date>2019-06-18T17:17:09Z</dc:date>
    </item>
    <item>
      <title>Re: ISE patch while upgrading</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-patch-while-upgrading/m-p/3875265#M472159</link>
      <description>&lt;P&gt;I see that you can apply patches prior to registering PSNs to the upgraded deployment per this document: &lt;A href="https://community.cisco.com/t5/security-documents/ise-upgrades-best-practices/ta-p/3656934#toc-hId--718381845" target="_blank"&gt;https://community.cisco.com/t5/security-documents/ise-upgrades-best-practices/ta-p/3656934#toc-hId--718381845&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 18 Jun 2019 17:22:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-patch-while-upgrading/m-p/3875265#M472159</guid>
      <dc:creator>matthen</dc:creator>
      <dc:date>2019-06-18T17:22:43Z</dc:date>
    </item>
    <item>
      <title>Re: ISE patch while upgrading</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-patch-while-upgrading/m-p/3875275#M472162</link>
      <description>Unfortunately, you will not be able to upgrade to rest of the deployment if you do so. The nodes will be upgraded for a brief moment before they fail to join the upgraded deployment and are rolled back. What you can test is though is to apply patches, test the user authentications, see if they are working, roll back the patches and then upgrade the rest of the deployment. This is not a tested path as such but going by the logic, this should work and you will be doing it at your own risk.&lt;BR /&gt;</description>
      <pubDate>Tue, 18 Jun 2019 17:35:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-patch-while-upgrading/m-p/3875275#M472162</guid>
      <dc:creator>Surendra</dc:creator>
      <dc:date>2019-06-18T17:35:06Z</dc:date>
    </item>
    <item>
      <title>Re: ISE patch while upgrading</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-patch-while-upgrading/m-p/3875300#M472167</link>
      <description>Short answer no. During the upgrade process the databases will be tweaked&lt;BR /&gt;by starting with secondary PAN then making it ready to accept PSNs until&lt;BR /&gt;primary PAN is upgraded and rejoined the upgraded deployment. If you alter&lt;BR /&gt;the database with patches you mightnot be able to recover.&lt;BR /&gt;</description>
      <pubDate>Tue, 18 Jun 2019 18:01:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-patch-while-upgrading/m-p/3875300#M472167</guid>
      <dc:creator>Mohammed al Baqari</dc:creator>
      <dc:date>2019-06-18T18:01:06Z</dc:date>
    </item>
    <item>
      <title>Re: ISE patch while upgrading</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-patch-while-upgrading/m-p/3875634#M472170</link>
      <description>&lt;P&gt;To recap our discussion offline on this,&amp;nbsp;&lt;SPAN&gt;&lt;A href="https://community.cisco.com/t5/user/viewprofilepage/user-id/361506" target="_blank"&gt;Surendra&lt;/A&gt;&lt;/SPAN&gt;&lt;SPAN&gt; and &lt;A href="https://community.cisco.com/t5/user/viewprofilepage/user-id/292493" target="_blank"&gt;Mohammed al Baqari&lt;/A&gt;&lt;/SPAN&gt;&amp;nbsp;are both correct in case of using the guided upgrade in ISE admin web UI.&amp;nbsp;Whereas&amp;nbsp;&lt;SPAN&gt;&lt;A href="https://community.cisco.com/t5/security-documents/ise-upgrades-best-practices/ta-p/3656934" target="_blank"&gt;ISE Upgrades - Best Practices&lt;/A&gt;&lt;/SPAN&gt; describes additional options, besides the UI guided upgrade. The other options could be preferable, for sizable ISE deployments, for those ISE Releases unable to upgrade directly to ISE 2.4 or 2.6, or other considerations.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 19 Jun 2019 01:38:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-patch-while-upgrading/m-p/3875634#M472170</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2019-06-19T01:38:54Z</dc:date>
    </item>
  </channel>
</rss>

