<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE distributed deployment upgrade - 1.3 to 2.1 in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-distributed-deployment-upgrade-1-3-to-2-1/m-p/3552316#M519238</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It won’t retain the license.  You just need to rehost the licenses.  I usually must email licensing@cisco.com&amp;lt;mailto:licensing@cisco.com&amp;gt;.  They are very responsive.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 11 Dec 2017 21:49:41 GMT</pubDate>
    <dc:creator>paul</dc:creator>
    <dc:date>2017-12-11T21:49:41Z</dc:date>
    <item>
      <title>ISE distributed deployment upgrade - 1.3 to 2.1</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-distributed-deployment-upgrade-1-3-to-2-1/m-p/3552311#M519222</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="color: #58585b; font-family: CiscoSans, 'Helvetica Neue', Helvetica, Arial, sans-serif; font-size: 16px;"&gt;My customer has an ISE deployment with 5 nodes: Admin/Monitor Primary and Secondary plus 3 Policy Server. The Admin Nodes and 2 Policty Nodes are VMs. The last Policy node is 3415 appliance.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #58585b; font-family: CiscoSans, 'Helvetica Neue', Helvetica, Arial, sans-serif; font-size: 16px;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #58585b; font-family: CiscoSans, 'Helvetica Neue', Helvetica, Arial, sans-serif; font-size: 16px;"&gt;I checked the release notes, it says that we can directly upgrade from 1.3 to 2.1.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #58585b; font-family: CiscoSans, 'Helvetica Neue', Helvetica, Arial, sans-serif; font-size: 16px;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #58585b; font-family: CiscoSans, 'Helvetica Neue', Helvetica, Arial, sans-serif; font-size: 16px;"&gt;Could someone share their experience or a step-by-step document to upgrade this distributed environment ISE deployment?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #58585b; font-family: CiscoSans, 'Helvetica Neue', Helvetica, Arial, sans-serif; font-size: 16px;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #58585b; font-family: CiscoSans, 'Helvetica Neue', Helvetica, Arial, sans-serif; font-size: 16px;"&gt;Thanks.&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 11 Dec 2017 03:00:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-distributed-deployment-upgrade-1-3-to-2-1/m-p/3552311#M519222</guid>
      <dc:creator>dot1x</dc:creator>
      <dc:date>2017-12-11T03:00:49Z</dc:date>
    </item>
    <item>
      <title>Re: ISE distributed deployment upgrade - 1.3 to 2.1</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-distributed-deployment-upgrade-1-3-to-2-1/m-p/3552312#M519224</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Moin, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;you can directly upgrade to 2.1 from 1.3 &lt;/P&gt;&lt;P&gt;couple of guidelines and steps are mentioned in the links below - &lt;/P&gt;&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/2-1/upgrade_guide/b_ise_upgrade_guide_21/b_ise_upgrade_guide_21_chapter_00.html" title="https://www.cisco.com/c/en/us/td/docs/security/ise/2-1/upgrade_guide/b_ise_upgrade_guide_21/b_ise_upgrade_guide_21_chapter_00.html"&gt;Cisco Identity Services Engine Upgrade Guide, Release 2.1 - Cisco ISE Upgrade Overview [Cisco Identity Services Engine…&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/1-3/upgrade_guide/b_ise_upgrade_guide_13/b_ise_upgrade_guide_chapter_01.html#ID20" title="https://www.cisco.com/c/en/us/td/docs/security/ise/1-3/upgrade_guide/b_ise_upgrade_guide_13/b_ise_upgrade_guide_chapter_01.html#ID20"&gt;Cisco Identity Services Engine Upgrade Guide, Release 1.3 - Upgrade Methods for Different Types of Deployments [Cisco …&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 11 Dec 2017 03:45:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-distributed-deployment-upgrade-1-3-to-2-1/m-p/3552312#M519224</guid>
      <dc:creator>Nidhi</dc:creator>
      <dc:date>2017-12-11T03:45:32Z</dc:date>
    </item>
    <item>
      <title>Re: ISE distributed deployment upgrade - 1.3 to 2.1</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-distributed-deployment-upgrade-1-3-to-2-1/m-p/3552313#M519228</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;As I have posted previously, I would recommend not using any of the Cisco documented GUI/CLI methods for upgrading.&amp;nbsp; The method I have found to work the best over the years is:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Kick out secondary admin node from the old deployment.&lt;/LI&gt;&lt;LI&gt;Fresh build it to the desired version&lt;/LI&gt;&lt;LI&gt;Restore data from old version&lt;/LI&gt;&lt;LI&gt;Verify restored data.&amp;nbsp; This node now becomes the anchor point of the new version deployment.&lt;/LI&gt;&lt;LI&gt;One at a time rebuild each PSN by installing a fresh build of the new version&lt;/LI&gt;&lt;LI&gt;Join the PSNs to the new deployment&lt;/LI&gt;&lt;LI&gt;Finally rebuild what was the primary admin node of the old deployment and join it to the new deployment&lt;/LI&gt;&lt;LI&gt;Move personas around as needed&lt;/LI&gt;&lt;/OL&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 11 Dec 2017 20:42:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-distributed-deployment-upgrade-1-3-to-2-1/m-p/3552313#M519228</guid>
      <dc:creator>paul</dc:creator>
      <dc:date>2017-12-11T20:42:50Z</dc:date>
    </item>
    <item>
      <title>Re: ISE distributed deployment upgrade - 1.3 to 2.1</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-distributed-deployment-upgrade-1-3-to-2-1/m-p/3552314#M519232</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Agree with paul!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 11 Dec 2017 20:44:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-distributed-deployment-upgrade-1-3-to-2-1/m-p/3552314#M519232</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2017-12-11T20:44:31Z</dc:date>
    </item>
    <item>
      <title>Re: ISE distributed deployment upgrade - 1.3 to 2.1</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-distributed-deployment-upgrade-1-3-to-2-1/m-p/3552315#M519235</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Paul.&lt;/P&gt;&lt;P&gt;What happens to the license when we use this approach?&lt;/P&gt;&lt;P&gt;Would it retain the licenses?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 11 Dec 2017 21:47:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-distributed-deployment-upgrade-1-3-to-2-1/m-p/3552315#M519235</guid>
      <dc:creator>dot1x</dc:creator>
      <dc:date>2017-12-11T21:47:17Z</dc:date>
    </item>
    <item>
      <title>Re: ISE distributed deployment upgrade - 1.3 to 2.1</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-distributed-deployment-upgrade-1-3-to-2-1/m-p/3552316#M519238</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It won’t retain the license.  You just need to rehost the licenses.  I usually must email licensing@cisco.com&amp;lt;mailto:licensing@cisco.com&amp;gt;.  They are very responsive.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 11 Dec 2017 21:49:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-distributed-deployment-upgrade-1-3-to-2-1/m-p/3552316#M519238</guid>
      <dc:creator>paul</dc:creator>
      <dc:date>2017-12-11T21:49:41Z</dc:date>
    </item>
    <item>
      <title>Re: ISE distributed deployment upgrade - 1.3 to 2.1</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-distributed-deployment-upgrade-1-3-to-2-1/m-p/3552317#M519240</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;My experience is the device ID doesn’t change if you are using the same VM so you should be able to reuse the same license files if you still have them.  Otherwise, rehosting certainly works.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;George&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 11 Dec 2017 22:00:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-distributed-deployment-upgrade-1-3-to-2-1/m-p/3552317#M519240</guid>
      <dc:creator>gbekmezi-DD</dc:creator>
      <dc:date>2017-12-11T22:00:30Z</dc:date>
    </item>
    <item>
      <title>Re: ISE distributed deployment upgrade - 1.3 to 2.1</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-distributed-deployment-upgrade-1-3-to-2-1/m-p/3552318#M519241</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm fairly new to this, could you pelase have a look and advise if my understanding is correct?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kick out secondary admin node from the old deployment.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Manually de-register Secondary Admin Node and take back up of this secondary admin node?&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Fresh build it to the desired version&lt;/P&gt;&lt;P&gt;Using this?&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;A class="jive-link-external-small" href="https://www.cisco.com/c/en/us/td/docs/security/ise/2-1/install_guide/b_ise_InstallationGuide21/b_ise_InstallationGuide21_chapter_010.html#task_C60EBD3F53714C7BA83DC2E691E4FC1B" rel="nofollow" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/ise/2-1/install_guide/b_ise_InstallationGuide21/b_ise_InstallationGuide21_chapter_010.html#task_C60EBD3F53714C7BA83DC2E691E4FC1B&lt;/A&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Restore data from old version&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Restoring the back up taken in Step 1 for Secondary Admin Node?&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Verify restored data.&amp;nbsp; This node now becomes the anchor point of the new version deployment.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;One at a time rebuild each PSN by installing a fresh build of the new version&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;At this point of time, do I de-register old PSNs one by one?&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Join the PSNs to the new deployment&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Finally rebuild what was the primary admin node of the old deployment and join it to the new deployment&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Should I take backup of Primary Admin node and then restore to new deployment? At this point of time, this will become secondary admin node in new deployment?&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Move personas around as needed&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 11 Dec 2017 22:15:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-distributed-deployment-upgrade-1-3-to-2-1/m-p/3552318#M519241</guid>
      <dc:creator>dot1x</dc:creator>
      <dc:date>2017-12-11T22:15:29Z</dc:date>
    </item>
  </channel>
</rss>

