<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ISE upgrade in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-upgrade/m-p/3388072#M548641</link>
    <description>&lt;P&gt;Hi Techies,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am planning to upgrade my huge deployment 24 PSN's + 2 MNT + 2 AN from 2.0.0.306 to probably 2.4 , these are all physical appliances. Last time about year ago when i tried to upgrade to 2.1 i failed miserably with range of issues like Replication error, Oracle SGA value error etc.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Has anyone attempted upgrade of this nature/ please advise me how to go ahead with successfull upgrade , what should be my strategy without affecting my major services like VPN, TACACS etc&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 18:56:51 GMT</pubDate>
    <dc:creator>atif.mohamed</dc:creator>
    <dc:date>2020-02-21T18:56:51Z</dc:date>
    <item>
      <title>ISE upgrade</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-upgrade/m-p/3388072#M548641</link>
      <description>&lt;P&gt;Hi Techies,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am planning to upgrade my huge deployment 24 PSN's + 2 MNT + 2 AN from 2.0.0.306 to probably 2.4 , these are all physical appliances. Last time about year ago when i tried to upgrade to 2.1 i failed miserably with range of issues like Replication error, Oracle SGA value error etc.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Has anyone attempted upgrade of this nature/ please advise me how to go ahead with successfull upgrade , what should be my strategy without affecting my major services like VPN, TACACS etc&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 18:56:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-upgrade/m-p/3388072#M548641</guid>
      <dc:creator>atif.mohamed</dc:creator>
      <dc:date>2020-02-21T18:56:51Z</dc:date>
    </item>
    <item>
      <title>Re: ISE upgrade</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-upgrade/m-p/3388081#M548642</link>
      <description>&lt;P&gt;I feel your pain!&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I would start by installing the ISE 2.4 URT (Upgrade Readiness Tool) on your Secondary PAN node and then seeing what it thinks.&amp;nbsp; It analyses the state of your deployment and also gives predictions of how much time it will take to perform upgrade per node.&lt;/P&gt;
&lt;P&gt;The URT is a good start as a sanity check of the database.&amp;nbsp; Highly recommended, no matter which steps you follow next.&amp;nbsp; You could either&lt;/P&gt;
&lt;P&gt;1) Follow the upgrade path ... or&lt;/P&gt;
&lt;P&gt;2) Rebuild each server from the .iso&lt;/P&gt;
&lt;P&gt;I think the only clean approach is method 2.&amp;nbsp; We do it all the time because of the misery of an upgrade procedure.&amp;nbsp; In the VM world this is quite simple.&amp;nbsp; In your case, it might require some work via the CIMC and vKVM etc - but ultimately it's possible.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Here are the high level steps&lt;/P&gt;
&lt;P&gt;1) Make a config backup on your repository&lt;/P&gt;
&lt;P&gt;2) Reboot your Secondary PAN using ISE 2.4 .iso - perform a fresh install of ISE 2.4&lt;/P&gt;
&lt;P&gt;3) Restore the config backup onto this STANDALONE node&lt;/P&gt;
&lt;P&gt;4) Make that node Primary, thus creating the foundation of your new ISE deployment.&lt;/P&gt;
&lt;P&gt;5) &amp;nbsp;Reboot your Secondary&amp;nbsp;MnT using ISE 2.4 .iso - perform a fresh install of ISE 2.4&lt;/P&gt;
&lt;P&gt;6) Register that MnT to your new PAN&lt;/P&gt;
&lt;P&gt;7) Reboot a chosen PSN using ISE 2.4 .iso - perform a fresh install of ISE 2.4&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":smiling_face_with_sunglasses:"&gt;😎&lt;/span&gt; Register that PSN to new 2.4 deployment.&lt;/P&gt;
&lt;P&gt;9) Stop and test with a few NAS's to see if that PSN works as expected&lt;/P&gt;
&lt;P&gt;10) Continue with rest of PSN's&lt;/P&gt;
&lt;P&gt;11) Finally convert the last MnT node, and then if you are REALLY happy to proceed, then rebuild the remaining PAN node.&amp;nbsp; Then all will be freshly built and registered to ISE 2.4 deployment&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Keep in mind that patch 1 is not out yet.&amp;nbsp; I suspect that ISE 2.4 is riddled with bugs - but as they say, "it depends" on what you're doing with ISE.&amp;nbsp;&amp;nbsp; Cisco message these days is that ISE 2.2 is the "stable release" - and they are aiming that ISE 2.4 will be the next stable release.&amp;nbsp; They don't justify their comments.&amp;nbsp; You have to read between the lines.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am on 2.3 so I guess I pulled the short straw...&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 24 May 2018 01:20:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-upgrade/m-p/3388081#M548642</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2018-05-24T01:20:05Z</dc:date>
    </item>
    <item>
      <title>Re: ISE upgrade</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-upgrade/m-p/3388118#M548643</link>
      <description>&lt;P&gt;Whie there are no "show stopper" bugs identified in ISE 2.4 at this time, customer deployments are limited. I'd wait until 2.4 Patch 1. We should see it released in the next couple of weeks.&lt;/P&gt;</description>
      <pubDate>Thu, 24 May 2018 03:03:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-upgrade/m-p/3388118#M548643</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2018-05-24T03:03:38Z</dc:date>
    </item>
    <item>
      <title>Re: ISE upgrade</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-upgrade/m-p/3388346#M548644</link>
      <description>&lt;P&gt;I would suggest to go for 2.3 Patch 3, instead of 2.4, for now at least.&lt;/P&gt;</description>
      <pubDate>Thu, 24 May 2018 10:24:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-upgrade/m-p/3388346#M548644</guid>
      <dc:creator>AlexPi</dc:creator>
      <dc:date>2018-05-24T10:24:00Z</dc:date>
    </item>
    <item>
      <title>Re: ISE upgrade</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-upgrade/m-p/3388647#M548645</link>
      <description>&lt;P&gt;My 2 cents.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have a 14 appliances deployment (highly recommended to use 3595 as PRIM/SEC PAN-MNT)&amp;nbsp;and I would do exactly what Arne said about reimaging the boxes (like a&amp;nbsp;fresh install)&amp;nbsp;using CIMC/ISO (Daemon Tools Lite is the app that I have been using for the Virtual DVD Disk creation running the mapped&amp;nbsp;ISO file) so there is no issue regarding the upgrade process.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am not going to provide details BUT I would not go with 2.2 version at all.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 24 May 2018 16:27:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-upgrade/m-p/3388647#M548645</guid>
      <dc:creator>ajc</dc:creator>
      <dc:date>2018-05-24T16:27:38Z</dc:date>
    </item>
  </channel>
</rss>

