<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE 2.6 FULL / PIC - Patching nightmare. in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-2-6-full-pic-patching-nightmare/m-p/4406048#M567433</link>
    <description>&lt;P&gt;A bit of follow up:&lt;/P&gt;&lt;P&gt;I did install Patch9 on my ISE PIC VM and of course it works.&lt;/P&gt;&lt;P&gt;I'm quite sure now that TAC was wrong. There's a lot of security bugfixes in Patch 6-9 and I can't find any reason to stay at patch5.&lt;/P&gt;&lt;P&gt;I also found on top of this that, according to compatibility matrix, only ISE PIC V2.6Patch6+ is allowed when using FMC 6.7&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Cisco FMC-ISE-Matrix.png" style="width: 704px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/120829i83AA8117D9FF2FD4/image-size/large?v=v2&amp;amp;px=999" role="button" title="Cisco FMC-ISE-Matrix.png" alt="Cisco FMC-ISE-Matrix.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Source:&amp;nbsp;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/firepower/compatibility/firepower-compatibility.html" target="_blank"&gt;Cisco Firepower Compatibility Guide - Cisco&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 20 May 2021 14:03:31 GMT</pubDate>
    <dc:creator>Erwan LE BIHAN</dc:creator>
    <dc:date>2021-05-20T14:03:31Z</dc:date>
    <item>
      <title>ISE 2.6 FULL / PIC - Patching nightmare.</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-6-full-pic-patching-nightmare/m-p/4400156#M567214</link>
      <description>&lt;P&gt;hi all.&lt;/P&gt;&lt;P&gt;Let's say you need to install ISE PIC 2.6 or ISE PIC 2.7.&lt;/P&gt;&lt;P&gt;If you look at cisco Support, the latest patch version for ISE PIC 2.6 is Patch5.&lt;/P&gt;&lt;P&gt;And if you have a look at ISE PIC 2.7, there's no patch available at all.&lt;/P&gt;&lt;P&gt;&lt;A href="https://software.cisco.com/download/home/286313041/type/286314948/release/2.7.0" target="_blank" rel="noopener"&gt;https://software.cisco.com/download/home/286313041/type/286314948/release/2.7.0&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We all know there's patch3 for 2.7, and latest for 2.6 is Patch9.&lt;/P&gt;&lt;P&gt;When I asked TAC about this, their answer is:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;My&amp;nbsp;name&amp;nbsp;is&amp;nbsp;Ahmed from&amp;nbsp;AAA&amp;nbsp;team. I am sending this&amp;nbsp;email to let you know that I took ownership of the case.&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;The ISE-PIC is a subset of the functionality offered with the Cisco Identity Services Engine. The Cisco ISE-PIC only support the passive ID functionality contained in the ISE.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;So you can only upgrade to ISE-PIC patch 5, Not ISE patch 9.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But, according to ISE PIC Administrator manual, software patch Installation Guidelines, p111&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/2-6/pic_admin_guide/PIC_admin26.pdf" target="_blank" rel="noopener"&gt;https://www.cisco.com/c/en/us/td/docs/security/ise/2-6/pic_admin_guide/PIC_admin26.pdf&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Cisco ISE patches can be installed on ISE-PIC as well.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So:&lt;/P&gt;&lt;P&gt;* Should I follow the manual, disregard TAC, and install the latest Patch for ISE (Patch9)&lt;/P&gt;&lt;P&gt;* Should I disregard the manual, follow TAC, and install only Patch5 ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;</description>
      <pubDate>Mon, 10 May 2021 10:09:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-6-full-pic-patching-nightmare/m-p/4400156#M567214</guid>
      <dc:creator>Erwan LE BIHAN</dc:creator>
      <dc:date>2021-05-10T10:09:51Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.6 FULL / PIC - Patching nightmare.</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-6-full-pic-patching-nightmare/m-p/4400341#M567224</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/167360"&gt;@Erwan LE BIHAN&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P class="lia-align-justify"&gt;&amp;nbsp;excellent point ...&lt;/P&gt;&lt;P class="lia-align-justify"&gt;&amp;nbsp;First of all ... &lt;STRONG&gt;ISE PIC&lt;/STRONG&gt; is a &lt;U&gt;subset&lt;/U&gt; of &lt;STRONG&gt;ISE&lt;/STRONG&gt;, in other words, you must install the &lt;STRONG&gt;ISE PIC ISO&lt;/STRONG&gt; and not the &lt;STRONG&gt;ISE ISO&lt;/STRONG&gt;:&lt;/P&gt;&lt;P class="lia-align-justify"&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="ISEPIC.png" style="width: 526px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/119895i3EB1BE0D8A891464/image-dimensions/526x135?v=v2" width="526" height="135" role="button" title="ISEPIC.png" alt="ISEPIC.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="lia-align-justify"&gt;&amp;nbsp;Second ... although &lt;STRONG&gt;ISE PIC&lt;/STRONG&gt; software download has up to &lt;STRONG&gt;P5&lt;/STRONG&gt; (for &lt;STRONG&gt;2.6&lt;/STRONG&gt;&lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="ISEPIC2.png" style="width: 525px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/119896i024F5BD4F57AF4FA/image-dimensions/525x342?v=v2" width="525" height="342" role="button" title="ISEPIC2.png" alt="ISEPIC2.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P class="lia-align-justify"&gt;if you take a look at &lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/2-6/pic_install_upgrade/b_pic_installUpgradeConfig_26/pic_upgrade.html" target="_blank" rel="noopener"&gt;Upgrade Cisco ISE-PIC&lt;/A&gt;, search for&amp;nbsp;&lt;STRONG&gt;Validate Data to Prevent Upgrade Failures&lt;/STRONG&gt;, you should use the &lt;STRONG&gt;URT&lt;/STRONG&gt; for that, but there is no &lt;STRONG&gt;URT&lt;/STRONG&gt; software download on &lt;STRONG&gt;ISE PIC&lt;/STRONG&gt; only on &lt;STRONG&gt;ISE&lt;/STRONG&gt; ... the same for &lt;STRONG&gt;ISE Upgrade Bundle&lt;/STRONG&gt; (search for &lt;STRONG&gt;Cisco ISE-PIC Upgrade Overview&lt;/STRONG&gt;).&lt;/P&gt;&lt;P class="lia-align-justify"&gt;&amp;nbsp;IMO, I agree with the documentation "&lt;EM&gt;Cisco ISE Patches can be installed on ISE-PIC as well"&lt;/EM&gt;.&lt;/P&gt;&lt;P class="lia-align-justify"&gt;Note: if the documentation is incorrect, &lt;STRONG&gt;TAC&lt;/STRONG&gt; could request the change.&lt;/P&gt;&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="lia-align-justify"&gt;Hope this helps !!!&lt;/P&gt;</description>
      <pubDate>Mon, 10 May 2021 15:31:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-6-full-pic-patching-nightmare/m-p/4400341#M567224</guid>
      <dc:creator>Marcelo Morais</dc:creator>
      <dc:date>2021-05-10T15:31:13Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.6 FULL / PIC - Patching nightmare.</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-6-full-pic-patching-nightmare/m-p/4406048#M567433</link>
      <description>&lt;P&gt;A bit of follow up:&lt;/P&gt;&lt;P&gt;I did install Patch9 on my ISE PIC VM and of course it works.&lt;/P&gt;&lt;P&gt;I'm quite sure now that TAC was wrong. There's a lot of security bugfixes in Patch 6-9 and I can't find any reason to stay at patch5.&lt;/P&gt;&lt;P&gt;I also found on top of this that, according to compatibility matrix, only ISE PIC V2.6Patch6+ is allowed when using FMC 6.7&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Cisco FMC-ISE-Matrix.png" style="width: 704px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/120829i83AA8117D9FF2FD4/image-size/large?v=v2&amp;amp;px=999" role="button" title="Cisco FMC-ISE-Matrix.png" alt="Cisco FMC-ISE-Matrix.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Source:&amp;nbsp;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/firepower/compatibility/firepower-compatibility.html" target="_blank"&gt;Cisco Firepower Compatibility Guide - Cisco&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 20 May 2021 14:03:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-6-full-pic-patching-nightmare/m-p/4406048#M567433</guid>
      <dc:creator>Erwan LE BIHAN</dc:creator>
      <dc:date>2021-05-20T14:03:31Z</dc:date>
    </item>
  </channel>
</rss>

