<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE patch installation in Distributed Deployment in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-patch-installation-in-distributed-deployment/m-p/3504031#M537681</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;how about the backup ? is there any backup plan if the update failed ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 05 Sep 2016 01:48:41 GMT</pubDate>
    <dc:creator>riferdiy</dc:creator>
    <dc:date>2016-09-05T01:48:41Z</dc:date>
    <item>
      <title>ISE patch installation in Distributed Deployment</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-patch-installation-in-distributed-deployment/m-p/3504027#M537670</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; &lt;SPAN style="color: black;"&gt;Dear Team,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: black;"&gt;Kindly need info regarding patch installation Cisco ISE in Distributed. I have 2 Administration &amp;amp; Monitoring node (as primary &amp;amp; backup) and 10 PSN node. Based on documentation, we install in primary first and then secondary Admin node.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: black;"&gt;- When I install in primary Admin, what happen with feature in Cisco ISE ? Is Cisco ISE still work using secondary Admin ? &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: black;"&gt;- Do I need install patch in PSN also ?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best Regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 04 Sep 2016 14:41:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-patch-installation-in-distributed-deployment/m-p/3504027#M537670</guid>
      <dc:creator>riferdiy</dc:creator>
      <dc:date>2016-09-04T14:41:33Z</dc:date>
    </item>
    <item>
      <title>Re: ISE patch installation in Distributed Deployment</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-patch-installation-in-distributed-deployment/m-p/3504028#M537673</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Start patching on primary PAN. Use CLI to monitor the status. Depending on the patch, you will be logged out or even the primary pan will get rebooted. Once the patching in primary pan is done, you can log back into it and use it to monitor the patching status across the ISE cluster via its web UI. Go to patch management and find the patch, then "show now status". The patching is done via primary PAN, then automagically, &lt;IMG src="https://community.cisco.com/legacyfs/online/emoticons/happy.png" /&gt; gets executed to secondary PAN, then across all PSN. ISE patches on each node in the cluster in alphabetical order. You don't need to do patch on PSN node directly. Reminder: always have a good remote backup of your ISE deployment. Good luck.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;During the patching, PSN will be functioning properly until it gets the patching executed. And be aware that which NADs are using which PSNs.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 04 Sep 2016 14:56:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-patch-installation-in-distributed-deployment/m-p/3504028#M537673</guid>
      <dc:creator>Ping Zhou</dc:creator>
      <dc:date>2016-09-04T14:56:03Z</dc:date>
    </item>
    <item>
      <title>Re: ISE patch installation in Distributed Deployment</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-patch-installation-in-distributed-deployment/m-p/3504029#M537676</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Alzhou,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Based on your comment, "PSN will be functioning properly" --&amp;gt; will the PSN also restart when patching done ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How long it will take to install patch to one node ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you have complete guide (documentation) for patching, i try to search but just get overview info, &lt;A href="http://www.cisco.com/c/en/us/td/docs/security/ise/1-2/user_guide/ise_user_guide/ise_admin.html#71861" title="http://www.cisco.com/c/en/us/td/docs/security/ise/1-2/user_guide/ise_user_guide/ise_admin.html#71861"&gt;Cisco Identity Services Engine User Guide, Release 1.2 - Administering Cisco ISE [Cisco Identity Services Engine] - Cisc…&lt;/A&gt; my Cisco ISE is version 1.2.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best Regards.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 04 Sep 2016 16:07:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-patch-installation-in-distributed-deployment/m-p/3504029#M537676</guid>
      <dc:creator>riferdiy</dc:creator>
      <dc:date>2016-09-04T16:07:29Z</dc:date>
    </item>
    <item>
      <title>Re: ISE patch installation in Distributed Deployment</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-patch-installation-in-distributed-deployment/m-p/3504030#M537680</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;For PSN patching, depiendikng on the patch, its&amp;nbsp; services&amp;nbsp; get restarted or the appliance gets rebooted. For each node, depending on the processing power of th appliance and the patch, The estimated time for it is ranging from 10 minutes to 45 minutes or so. We don't know what's exactly a particular patch would do. So planing for the worst. Cisco constantly improves ISE, I would suggest you to open a TAC case and prepare, validate the procedure, then execute it on your production network.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 04 Sep 2016 16:15:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-patch-installation-in-distributed-deployment/m-p/3504030#M537680</guid>
      <dc:creator>Ping Zhou</dc:creator>
      <dc:date>2016-09-04T16:15:41Z</dc:date>
    </item>
    <item>
      <title>Re: ISE patch installation in Distributed Deployment</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-patch-installation-in-distributed-deployment/m-p/3504031#M537681</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;how about the backup ? is there any backup plan if the update failed ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 05 Sep 2016 01:48:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-patch-installation-in-distributed-deployment/m-p/3504031#M537681</guid>
      <dc:creator>riferdiy</dc:creator>
      <dc:date>2016-09-05T01:48:41Z</dc:date>
    </item>
    <item>
      <title>Re: ISE patch installation in Distributed Deployment</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-patch-installation-in-distributed-deployment/m-p/3504032#M537682</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Remember that configuration data are in PANs. So backing up configuration data from primary PAN to a SFTP server is highly recommended for restoring if necessary, let say, when or if PAN crashes; If PSN crashes, you can spin up a ISE node, and join the cluster, and it gets the configuration from PAN. If operation data is important to your deployment, you will also need to back them up via backup and restore menu.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 05 Sep 2016 02:19:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-patch-installation-in-distributed-deployment/m-p/3504032#M537682</guid>
      <dc:creator>Ping Zhou</dc:creator>
      <dc:date>2016-09-05T02:19:14Z</dc:date>
    </item>
    <item>
      <title>Re: ISE patch installation in Distributed Deployment</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-patch-installation-in-distributed-deployment/m-p/3504033#M537683</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;By the way, don't forget export your system certificate and private key for the ISE nodes, in case you need to recover it later.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 05 Sep 2016 02:33:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-patch-installation-in-distributed-deployment/m-p/3504033#M537683</guid>
      <dc:creator>Ping Zhou</dc:creator>
      <dc:date>2016-09-05T02:33:58Z</dc:date>
    </item>
  </channel>
</rss>

