<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: log4j hotfix CSCwa47133 - ISE distributed environment in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/log4j-hotfix-cscwa47133-ise-distributed-environment/m-p/4521703#M571849</link>
    <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;- I don't think it really matters , because for this patch , no&lt;EM&gt; ise (internal) communications dependencies&lt;/EM&gt; are involved.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;M.&lt;/P&gt;</description>
    <pubDate>Mon, 20 Dec 2021 17:10:50 GMT</pubDate>
    <dc:creator>Mark Elsen</dc:creator>
    <dc:date>2021-12-20T17:10:50Z</dc:date>
    <item>
      <title>log4j hotfix CSCwa47133 - ISE distributed environment</title>
      <link>https://community.cisco.com/t5/network-access-control/log4j-hotfix-cscwa47133-ise-distributed-environment/m-p/4521609#M571847</link>
      <description>&lt;P&gt;Hello guys,&lt;/P&gt;&lt;P&gt;In a distributed environment is there a specific order in which the hot fix needs to be done? I'm having an 11 node setup, with 2 PAN. I assume the patch should start with the primary PAN, secondary PAN and then all the other PSN nodes. Is this correct?&lt;/P&gt;&lt;P&gt;Have someone already did it?&lt;/P&gt;&lt;P&gt;Thank you!&lt;/P&gt;</description>
      <pubDate>Mon, 20 Dec 2021 14:18:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/log4j-hotfix-cscwa47133-ise-distributed-environment/m-p/4521609#M571847</guid>
      <dc:creator>ValentinPuiu91087</dc:creator>
      <dc:date>2021-12-20T14:18:39Z</dc:date>
    </item>
    <item>
      <title>Re: log4j hotfix CSCwa47133 - ISE distributed environment</title>
      <link>https://community.cisco.com/t5/network-access-control/log4j-hotfix-cscwa47133-ise-distributed-environment/m-p/4521703#M571849</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;- I don't think it really matters , because for this patch , no&lt;EM&gt; ise (internal) communications dependencies&lt;/EM&gt; are involved.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;M.&lt;/P&gt;</description>
      <pubDate>Mon, 20 Dec 2021 17:10:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/log4j-hotfix-cscwa47133-ise-distributed-environment/m-p/4521703#M571849</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2021-12-20T17:10:50Z</dc:date>
    </item>
    <item>
      <title>Re: log4j hotfix CSCwa47133 - ISE distributed environment</title>
      <link>https://community.cisco.com/t5/network-access-control/log4j-hotfix-cscwa47133-ise-distributed-environment/m-p/4521705#M571850</link>
      <description>&lt;P&gt;I can confirm that the order it is applied in does not matter. You just need to apply the hotfix to each node in the order of your choosing keeping in mind that the services will restart when you run it on that specific node, so most would do it one node at a time.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 20 Dec 2021 17:17:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/log4j-hotfix-cscwa47133-ise-distributed-environment/m-p/4521705#M571850</guid>
      <dc:creator>Damien Miller</dc:creator>
      <dc:date>2021-12-20T17:17:40Z</dc:date>
    </item>
    <item>
      <title>Re: log4j hotfix CSCwa47133 - ISE distributed environment</title>
      <link>https://community.cisco.com/t5/network-access-control/log4j-hotfix-cscwa47133-ise-distributed-environment/m-p/4521708#M571851</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/320219"&gt;@Damien Miller&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Do you know what the recommendations are with the log4j hotfix if you have PAN failover enabled? Should this be disabled before applying the hotfix or does it not matter?&lt;/P&gt;</description>
      <pubDate>Mon, 20 Dec 2021 17:29:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/log4j-hotfix-cscwa47133-ise-distributed-environment/m-p/4521708#M571851</guid>
      <dc:creator>dm2020</dc:creator>
      <dc:date>2021-12-20T17:29:04Z</dc:date>
    </item>
    <item>
      <title>Re: log4j hotfix CSCwa47133 - ISE distributed environment</title>
      <link>https://community.cisco.com/t5/network-access-control/log4j-hotfix-cscwa47133-ise-distributed-environment/m-p/4521714#M571854</link>
      <description>&lt;P&gt;I would disable it before applying this hotfix, you don't want to take the extended outage for both PANs switching around on you while you're doing this work.&lt;/P&gt;</description>
      <pubDate>Mon, 20 Dec 2021 17:37:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/log4j-hotfix-cscwa47133-ise-distributed-environment/m-p/4521714#M571854</guid>
      <dc:creator>Damien Miller</dc:creator>
      <dc:date>2021-12-20T17:37:57Z</dc:date>
    </item>
    <item>
      <title>Re: log4j hotfix CSCwa47133 - ISE distributed environment</title>
      <link>https://community.cisco.com/t5/network-access-control/log4j-hotfix-cscwa47133-ise-distributed-environment/m-p/4521963#M571868</link>
      <description>&lt;P&gt;Thank you! Really helpful.&lt;/P&gt;&lt;P&gt;Yesterday evening I patched our 11 virtual nodes environment. Started with the far PSNs and ending with the 2 PAN nodes, for which I did manual failover - PA PM and upgrade the SA SM.&lt;/P&gt;&lt;P&gt;Downtime per application restart ~ 10 minutes.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Merry Christmas and a Happy new Year!&lt;BR /&gt;Vali Puiu&lt;/P&gt;</description>
      <pubDate>Tue, 21 Dec 2021 07:36:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/log4j-hotfix-cscwa47133-ise-distributed-environment/m-p/4521963#M571868</guid>
      <dc:creator>ValentinPuiu91087</dc:creator>
      <dc:date>2021-12-21T07:36:36Z</dc:date>
    </item>
    <item>
      <title>Re: log4j hotfix CSCwa47133 - ISE distributed environment</title>
      <link>https://community.cisco.com/t5/network-access-control/log4j-hotfix-cscwa47133-ise-distributed-environment/m-p/4527822#M572069</link>
      <description>&lt;P&gt;Could you please provide a link to guide which explains the procedure step by step?. I am doing it for very first time and we have total 6 PSN nodes and 2 PAN nodes in HA mode.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 07 Jan 2022 08:11:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/log4j-hotfix-cscwa47133-ise-distributed-environment/m-p/4527822#M572069</guid>
      <dc:creator>nikhil_shinde</dc:creator>
      <dc:date>2022-01-07T08:11:41Z</dc:date>
    </item>
    <item>
      <title>Re: log4j hotfix CSCwa47133 - ISE distributed environment</title>
      <link>https://community.cisco.com/t5/network-access-control/log4j-hotfix-cscwa47133-ise-distributed-environment/m-p/4527905#M572071</link>
      <description>&lt;P&gt;Everything what you need to do is specified in the release notes of the patch. See description below.&lt;/P&gt;&lt;P&gt;1.copy the patch to a repository which is reachable from ISE&lt;/P&gt;&lt;P&gt;2.connect CLI to each node, copy the patch from repo and update the application&lt;/P&gt;&lt;P&gt;It doesn't matter the order, the cluster will not brake as this is a hotfix. The downtime is around 10-15 minutes per node. Do them 1 by 1.&lt;/P&gt;&lt;P&gt;"&lt;/P&gt;&lt;PRE&gt;=================================================
README for installing Hot Patch to fix CSCwa47133 
=================================================

This hot patch is to address CSCwa47133 (related to Apache Log4j2)

Download the following files from CCO.
                                                               
ise-apply-CSCwa47133_3.1.0.518_patch1-SPA.tar.gz 
ise-rollback-CSCwa47133_3.1.0.518_patch1-SPA.tar.gz


Confirm that the hash of the downloaded files matches the ones listed on CCO.
Copy the files to repository which is reachable from ISE.
Configure the repository in ISE to start the installation process.

===================
Few important notes
===================

This hot patch is only for Patch 1 of ISE 3.1 release.

This needs to be installed on every ISE node in a deployment.

===============
How to install 
===============

Login to ISE CLI
Invoke the following command to install the bundle which will apply the hot patch:

"application install ise-apply-CSCwa47133_3.1.0.518_patch1-SPA.tar.gz &amp;lt;REPOSITORY_NAME&amp;gt;" 

=======================================================
How to Verify whether patch has installed successfully
=======================================================

Login to ISE CLI
Execute the command "show logging application hotpatch.log"
It should show that 'CSCwa47133_3.1.0.518_patch1' is installed, this will confirm that the hot patch was successfully installed.

===============
How to Rollback 
===============

(Note: This is only required if you need to remove the hot patch)

Login to ISE CLI
Invoke the following command to rollback the hot patch:

"application install ise-rollback-CSCwa47133_3.1.0.518_patch1-SPA.tar.gz  &amp;lt;REPOSITORY_NAME&amp;gt;""&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 07 Jan 2022 12:00:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/log4j-hotfix-cscwa47133-ise-distributed-environment/m-p/4527905#M572071</guid>
      <dc:creator>ValentinPuiu91087</dc:creator>
      <dc:date>2022-01-07T12:00:43Z</dc:date>
    </item>
  </channel>
</rss>

