<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Upgrading 2.2 to 2.7 in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/upgrading-2-2-to-2-7/m-p/4417836#M567849</link>
    <description>&lt;P class="lia-align-justify"&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/347992"&gt;@craiglebutt&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P class="lia-align-justify"&gt;&amp;nbsp;If you are using a &lt;STRONG&gt;Load Balancer&lt;/STRONG&gt;, you are able to block the &lt;STRONG&gt;WLC&lt;/STRONG&gt; access to the &lt;STRONG&gt;PSN&lt;/STRONG&gt; (by blocking the &lt;STRONG&gt;Authentication Port - 1812&lt;/STRONG&gt;) until the upgrade process completes.&lt;/P&gt;&lt;P class="lia-align-justify"&gt;&amp;nbsp;If you are not using a &lt;STRONG&gt;Load Balancer&lt;/STRONG&gt;, you can do the same with an &lt;STRONG&gt;ACL&lt;/STRONG&gt; at the &lt;STRONG&gt;PSN's Default GW&lt;/STRONG&gt;.&lt;/P&gt;&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="lia-align-justify"&gt;Hope this helps !!!&lt;/P&gt;</description>
    <pubDate>Mon, 14 Jun 2021 12:57:41 GMT</pubDate>
    <dc:creator>Marcelo Morais</dc:creator>
    <dc:date>2021-06-14T12:57:41Z</dc:date>
    <item>
      <title>Upgrading 2.2 to 2.7</title>
      <link>https://community.cisco.com/t5/network-access-control/upgrading-2-2-to-2-7/m-p/4417758#M567845</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Upgrading the deployment, by building new Node and restoring the backup.&lt;/P&gt;&lt;P&gt;My WLAN has all my PSNs in for resilience for Radius,&lt;/P&gt;&lt;P&gt;The first PSN go to update is the first one in radius settings.&lt;/P&gt;&lt;P&gt;Unfortunately devices are trying to auth before completing the upgrade, I can't take the&amp;nbsp; IP out of the WLAN as will drop the WLAN for a split second.&lt;/P&gt;&lt;P&gt;If a device fails to auth against the first node, should it in theory try the 2nd node, or does that only come in to play if the Node is not responding?&lt;/P&gt;&lt;P&gt;I've changed the shared secret on the WLC so doesn't match the PSN, hoping this will force the devices to try another PSN.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 14 Jun 2021 11:01:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/upgrading-2-2-to-2-7/m-p/4417758#M567845</guid>
      <dc:creator>craiglebutt</dc:creator>
      <dc:date>2021-06-14T11:01:48Z</dc:date>
    </item>
    <item>
      <title>Re: Upgrading 2.2 to 2.7</title>
      <link>https://community.cisco.com/t5/network-access-control/upgrading-2-2-to-2-7/m-p/4417836#M567849</link>
      <description>&lt;P class="lia-align-justify"&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/347992"&gt;@craiglebutt&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P class="lia-align-justify"&gt;&amp;nbsp;If you are using a &lt;STRONG&gt;Load Balancer&lt;/STRONG&gt;, you are able to block the &lt;STRONG&gt;WLC&lt;/STRONG&gt; access to the &lt;STRONG&gt;PSN&lt;/STRONG&gt; (by blocking the &lt;STRONG&gt;Authentication Port - 1812&lt;/STRONG&gt;) until the upgrade process completes.&lt;/P&gt;&lt;P class="lia-align-justify"&gt;&amp;nbsp;If you are not using a &lt;STRONG&gt;Load Balancer&lt;/STRONG&gt;, you can do the same with an &lt;STRONG&gt;ACL&lt;/STRONG&gt; at the &lt;STRONG&gt;PSN's Default GW&lt;/STRONG&gt;.&lt;/P&gt;&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="lia-align-justify"&gt;Hope this helps !!!&lt;/P&gt;</description>
      <pubDate>Mon, 14 Jun 2021 12:57:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/upgrading-2-2-to-2-7/m-p/4417836#M567849</guid>
      <dc:creator>Marcelo Morais</dc:creator>
      <dc:date>2021-06-14T12:57:41Z</dc:date>
    </item>
    <item>
      <title>Re: Upgrading 2.2 to 2.7</title>
      <link>https://community.cisco.com/t5/network-access-control/upgrading-2-2-to-2-7/m-p/4417847#M567850</link>
      <description>&lt;P&gt;Hi, Craigle.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I think changing the shared secret is a good idea, I encountered a similar case on my migration, where I was wondering why the network device is authenticating on the secondary PSN while we already set the network device to authenticate to the primary PSN.&lt;BR /&gt;&lt;BR /&gt;We later then found out from the logs that there were attempts to authenticate on the primary PSN but the shared secret was incorrect thus authenticating to the secondary PSN.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;</description>
      <pubDate>Mon, 14 Jun 2021 13:18:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/upgrading-2-2-to-2-7/m-p/4417847#M567850</guid>
      <dc:creator>jj2048</dc:creator>
      <dc:date>2021-06-14T13:18:36Z</dc:date>
    </item>
  </channel>
</rss>

