<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Insert a new PAN node during upgrade in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/insert-a-new-pan-node-during-upgrade/m-p/3433969#M521309</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This is covered in the admin guide and will work&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Just remove unneeded nodes&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We don’t discuss roadmap on public forum please get your feature request to our pm team through the sales channel&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a concern however&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ISE 1.2 is significantly different around how Guest access works, if you’re doing any guest you should test it out and make sure it works as needed&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also moving them to 1.3 is a bad idea as it’s end of life and support, it’s also really old and missing lots of key functionality&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;https://www.cisco.com/c/en/us/products/collateral/security/identity-services-engine/bulletin-c25-737392.html&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You need to look at moving them to ISE 2.2&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 27 Sep 2017 11:58:14 GMT</pubDate>
    <dc:creator>Jason Kunst</dc:creator>
    <dc:date>2017-09-27T11:58:14Z</dc:date>
    <item>
      <title>Insert a new PAN node during upgrade</title>
      <link>https://community.cisco.com/t5/network-access-control/insert-a-new-pan-node-during-upgrade/m-p/3433968#M521308</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Team,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Customer is upgrading ISE cluster from 1.2 to 1.3. Under distribution deployment, upgrade step as below.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;SecPAN(1.2) upgrade to PriPAN(1.3)&lt;/P&gt;&lt;P&gt;PriMNT(1.2) upgrade to PriMNT(1.3)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So now we have two cluster, new 1.3 cluster and old 1.2 cluster, without any HA. All PSN still register to old 1.2 PAN&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;At this juncture, customer like to insert HA into new 1.3 cluster. He bring up a new 1.3 node and join 1.3 PAN as secPAN. Question is, will this work? Our argument is 1.3 PAN still hold DB that has record of 1.2 PAN being peer and is expecting this peer to join back. But instead we are joining 1.3 PAN with a new node as SecPAN. This mean it will not work. Is our understanding correct?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also, customer is asking why can't we have different ISE version in same cluster. This will make the upgrading work easier and customer don't need to rush to upgrade the entire cluster of 14 nodes in 8 hours of MW. Do we have such support in roadmap?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your advise&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards &amp;amp;&lt;/P&gt;&lt;P&gt;Have a nice day&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 27 Sep 2017 09:25:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/insert-a-new-pan-node-during-upgrade/m-p/3433968#M521308</guid>
      <dc:creator>jpoh</dc:creator>
      <dc:date>2017-09-27T09:25:33Z</dc:date>
    </item>
    <item>
      <title>Re: Insert a new PAN node during upgrade</title>
      <link>https://community.cisco.com/t5/network-access-control/insert-a-new-pan-node-during-upgrade/m-p/3433969#M521309</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This is covered in the admin guide and will work&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Just remove unneeded nodes&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We don’t discuss roadmap on public forum please get your feature request to our pm team through the sales channel&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a concern however&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ISE 1.2 is significantly different around how Guest access works, if you’re doing any guest you should test it out and make sure it works as needed&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also moving them to 1.3 is a bad idea as it’s end of life and support, it’s also really old and missing lots of key functionality&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;https://www.cisco.com/c/en/us/products/collateral/security/identity-services-engine/bulletin-c25-737392.html&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You need to look at moving them to ISE 2.2&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 27 Sep 2017 11:58:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/insert-a-new-pan-node-during-upgrade/m-p/3433969#M521309</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2017-09-27T11:58:14Z</dc:date>
    </item>
    <item>
      <title>Re: Insert a new PAN node during upgrade</title>
      <link>https://community.cisco.com/t5/network-access-control/insert-a-new-pan-node-during-upgrade/m-p/3433970#M521310</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Recommendation is to build ISE 2.2 from scratch and start new &lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 27 Sep 2017 12:11:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/insert-a-new-pan-node-during-upgrade/m-p/3433970#M521310</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2017-09-27T12:11:41Z</dc:date>
    </item>
    <item>
      <title>Re: Insert a new PAN node during upgrade</title>
      <link>https://community.cisco.com/t5/network-access-control/insert-a-new-pan-node-during-upgrade/m-p/3433971#M521311</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Jason,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;after upgrade from SecPAN(1.2) to PriPAN(1.3), I will need to login to PriPAN(1.3) and remove the PriPAN(1.2) node from the DB. I will then add the new node as SecPAN(1.3). &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I believed PriPAN(1.3) will have the same license as PriPAN(1.2) right?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is a 14 nodes (2 x PAN, 2 x MNT, 10 x PSN) distributed deployment across 5 countries. Main purpose is to authenticate wireless user and do posture validation. No guest access. Hardware is 33XX series. So the supported version is till 1.4. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ISE 2.0 onwards cannot support 33xx series hardware. You are right on the EOS of 1.3. My best bet now is to upgrade to 1.4.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards &amp;amp;&lt;/P&gt;&lt;P&gt;Have a nice day&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 27 Sep 2017 12:51:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/insert-a-new-pan-node-during-upgrade/m-p/3433971#M521311</guid>
      <dc:creator>jpoh</dc:creator>
      <dc:date>2017-09-27T12:51:35Z</dc:date>
    </item>
    <item>
      <title>Re: Insert a new PAN node during upgrade</title>
      <link>https://community.cisco.com/t5/network-access-control/insert-a-new-pan-node-during-upgrade/m-p/3433972#M521312</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you are using the upgrade process you shouldn't have to worry about licensing as it should carry through the upgrade process.&amp;nbsp; I don't do the upgrade process normally.&amp;nbsp; I would have rebuilt the nodes fresh as 1.3, restored the 1.2 backup, rehosted licenses and gone from there.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;If you do have any issues with licensing you can simply contact &lt;/SPAN&gt;&lt;A class="jive-link-email-small" href="mailto:licensing@cisco.com"&gt;licensing@cisco.com&lt;/A&gt;&lt;SPAN&gt; and do a rehost.&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 27 Sep 2017 14:29:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/insert-a-new-pan-node-during-upgrade/m-p/3433972#M521312</guid>
      <dc:creator>paul</dc:creator>
      <dc:date>2017-09-27T14:29:39Z</dc:date>
    </item>
  </channel>
</rss>

