<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Cisco ISE Upgrade from 2.2 P9 to 2.4 p6 (Distributed Deployment  ) in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cisco-ise-upgrade-from-2-2-p9-to-2-4-p6-distributed-deployment/m-p/3814252#M541676</link>
    <description>&lt;P&gt;Hi All ,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;i have cisco ISE 2.2 P9 and because of lots of bugs we need to upgrade it .&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Deployment Scenario :&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Site A&lt;/P&gt;
&lt;P&gt;Primary PAN&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Primary MnT&lt;/P&gt;
&lt;P&gt;Primary PSN&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;DR Site B (Connected Over WAN)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Secondary PAN&lt;/P&gt;
&lt;P&gt;Secondary MnT&lt;/P&gt;
&lt;P&gt;Secondary PSN&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Note : all nodes are on Different VMs&lt;/P&gt;
&lt;P&gt;after reading the cisco DOC , my understanding is to Start Upgrade with :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;First Secondary Admin Node&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2nd Secondary Monitoring node&amp;nbsp;&lt;/P&gt;
&lt;P&gt;3rd Secondary&amp;nbsp; PSN&amp;nbsp;&lt;/P&gt;
&lt;P&gt;4th Primary PSN&amp;nbsp;&lt;/P&gt;
&lt;P&gt;5th Primary Monitoring&amp;nbsp;&lt;/P&gt;
&lt;P&gt;6th Primary Admin Node&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;***my question is if i am doing GUI - based upgrade , i have to download Ise-Upgradebundle on all nodes or&lt;/P&gt;
&lt;P&gt;or only one node ?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;*** if admin node is in ver 2.4 and Policy node is in ver 2.2 , there will be communication between them ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;*** is there any change in Licensing ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please Advise&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 05 Mar 2019 13:37:02 GMT</pubDate>
    <dc:creator>aslam.bajwa</dc:creator>
    <dc:date>2019-03-05T13:37:02Z</dc:date>
    <item>
      <title>Cisco ISE Upgrade from 2.2 P9 to 2.4 p6 (Distributed Deployment  )</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-upgrade-from-2-2-p9-to-2-4-p6-distributed-deployment/m-p/3814252#M541676</link>
      <description>&lt;P&gt;Hi All ,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;i have cisco ISE 2.2 P9 and because of lots of bugs we need to upgrade it .&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Deployment Scenario :&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Site A&lt;/P&gt;
&lt;P&gt;Primary PAN&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Primary MnT&lt;/P&gt;
&lt;P&gt;Primary PSN&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;DR Site B (Connected Over WAN)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Secondary PAN&lt;/P&gt;
&lt;P&gt;Secondary MnT&lt;/P&gt;
&lt;P&gt;Secondary PSN&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Note : all nodes are on Different VMs&lt;/P&gt;
&lt;P&gt;after reading the cisco DOC , my understanding is to Start Upgrade with :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;First Secondary Admin Node&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2nd Secondary Monitoring node&amp;nbsp;&lt;/P&gt;
&lt;P&gt;3rd Secondary&amp;nbsp; PSN&amp;nbsp;&lt;/P&gt;
&lt;P&gt;4th Primary PSN&amp;nbsp;&lt;/P&gt;
&lt;P&gt;5th Primary Monitoring&amp;nbsp;&lt;/P&gt;
&lt;P&gt;6th Primary Admin Node&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;***my question is if i am doing GUI - based upgrade , i have to download Ise-Upgradebundle on all nodes or&lt;/P&gt;
&lt;P&gt;or only one node ?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;*** if admin node is in ver 2.4 and Policy node is in ver 2.2 , there will be communication between them ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;*** is there any change in Licensing ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please Advise&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Mar 2019 13:37:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-upgrade-from-2-2-p9-to-2-4-p6-distributed-deployment/m-p/3814252#M541676</guid>
      <dc:creator>aslam.bajwa</dc:creator>
      <dc:date>2019-03-05T13:37:02Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ISE Upgrade from 2.2 P9 to 2.4 p6 (Distributed Deployment  )</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-ise-upgrade-from-2-2-p9-to-2-4-p6-distributed-deployment/m-p/3814576#M541678</link>
      <description>Your server upgrade order looks good, no issue there.  As for your other questions.&lt;BR /&gt;&lt;BR /&gt;The ISE upgrade package has to be downloaded to every node, if using the GUI to upgrade the deployment this is done during the pre upgrade tasks and often times out if there is a slow wan link.  For most upgrades we create a repository for disk:/ and manually copy the upgrade bundle to each servers disk:/ before starting.  &lt;BR /&gt;&lt;BR /&gt;During the upgrade, the secondary PAN that upgrades from 2.2 to 2.4 first, will then become the primary admin node in the 2.4 deployment.  While upgrading you have two separate ISE deployments, one running 2.2 and a new one running 2.4, there is no communication between these two.  When the secondary MNT and PSN upgrade, they will register with the 2.4 PAN.  &lt;BR /&gt;&lt;BR /&gt;2.2 to 2.4 includes VM license changes.  You will have to email Cisco your Cisco sales order number where you originally purchased the RTU ISE vm's.  The BU will issue new medium VM licenses for you to install on the 2.4 deployment.  You can do this before or after the upgrade with no impact other than a nag message on the dashboard. Read about it here.&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine-24/213171-ise-2-4-upgrade-alarms-fewer-vm-license.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine-24/213171-ise-2-4-upgrade-alarms-fewer-vm-license.html&lt;/A&gt;&lt;BR /&gt;"If you are planning to upgrade to Release 2.4, contact ise-vm-license@cisco.com with sales order numbers that include VM purchase to procure one medium VM license for each VM previously purchased. You should also include your CCOID along with the sales order number."&lt;BR /&gt;&lt;BR /&gt;One additional side note, I tend to prefer upgrading via the CLI because you have control over the process.  When you upgrade from the GUI, I find that nodes will start too soon after the previous, and you have no way to pause and test.  If you do this manually you will be able to upgrade the PAN/MNT/first PSN, test, then continue or roll back.  Also, make sure you have run the URT bundle to rule out any major issues upgrading.</description>
      <pubDate>Tue, 05 Mar 2019 22:38:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-ise-upgrade-from-2-2-p9-to-2-4-p6-distributed-deployment/m-p/3814576#M541678</guid>
      <dc:creator>Damien Miller</dc:creator>
      <dc:date>2019-03-05T22:38:21Z</dc:date>
    </item>
  </channel>
</rss>

