<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Patching nodes in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/patching-nodes/m-p/3802488#M541732</link>
    <description>This is the expected behavior.  While registering a node there is a check done to ensure the version and patch level matches.  If the same check was done following registration, you would end up with nodes that are paper weights during patching.  When you patch from the CLI it warns you that the patch will only be installed on the node you are logged in to.  They can run with mismatched patch levels but I would suggest limiting the exposure and finish patching in one change window if possible.&lt;BR /&gt;&lt;BR /&gt;Another note, patching should begin with the primary admin node, then progress to the other nodes.  &lt;BR /&gt;&lt;BR /&gt;Other than that, patching from the CLI is very straight forward as you found out.  A single command and you can run multiple nodes in parallel, I find it far superior to using the GUI when dealing with large environments because of this.</description>
    <pubDate>Fri, 15 Feb 2019 05:56:28 GMT</pubDate>
    <dc:creator>Damien Miller</dc:creator>
    <dc:date>2019-02-15T05:56:28Z</dc:date>
    <item>
      <title>Patching nodes</title>
      <link>https://community.cisco.com/t5/network-access-control/patching-nodes/m-p/3802482#M541731</link>
      <description>&lt;P&gt;&lt;FONT size="2" face="helvetica"&gt;Recently I was testing the application of patch 5 to 2.4. I chose to do the patching using CLI.&lt;/FONT&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;FONT size="2" face="helvetica"&gt;I applied patch 5 to the secondary PAN first, the patch got applied without any issues, and the node is &lt;/FONT&gt;still&lt;FONT size="2" face="helvetica"&gt; connected to the cluster there has been no &lt;/FONT&gt;error&lt;FONT size="2" face="helvetica"&gt; reported.&lt;/FONT&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;FONT size="2" face="helvetica"&gt;The questions it that, when I am creating a cluster ISE asks for every node to be on &lt;/FONT&gt;same&lt;FONT size="2" face="helvetica"&gt; version and patch level. But, when I chose to apply the patch to a node in &lt;/FONT&gt;a cluster&lt;FONT size="2" face="helvetica"&gt; there was no check made! Is this an acceptable behaviour or am I missing a crucial step here?&lt;/FONT&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;FONT size="2" face="helvetica"&gt;Any pointers?&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 08:55:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/patching-nodes/m-p/3802482#M541731</guid>
      <dc:creator>dgaikwad</dc:creator>
      <dc:date>2019-03-11T08:55:48Z</dc:date>
    </item>
    <item>
      <title>Re: Patching nodes</title>
      <link>https://community.cisco.com/t5/network-access-control/patching-nodes/m-p/3802488#M541732</link>
      <description>This is the expected behavior.  While registering a node there is a check done to ensure the version and patch level matches.  If the same check was done following registration, you would end up with nodes that are paper weights during patching.  When you patch from the CLI it warns you that the patch will only be installed on the node you are logged in to.  They can run with mismatched patch levels but I would suggest limiting the exposure and finish patching in one change window if possible.&lt;BR /&gt;&lt;BR /&gt;Another note, patching should begin with the primary admin node, then progress to the other nodes.  &lt;BR /&gt;&lt;BR /&gt;Other than that, patching from the CLI is very straight forward as you found out.  A single command and you can run multiple nodes in parallel, I find it far superior to using the GUI when dealing with large environments because of this.</description>
      <pubDate>Fri, 15 Feb 2019 05:56:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/patching-nodes/m-p/3802488#M541732</guid>
      <dc:creator>Damien Miller</dc:creator>
      <dc:date>2019-02-15T05:56:28Z</dc:date>
    </item>
  </channel>
</rss>

