<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE 2.7 patch 3 installed and log4j hot patch is applied. in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-2-7-patch-3-installed-and-log4j-hot-patch-is-applied/m-p/4544148#M572562</link>
    <description>&lt;P&gt;I'm in the same boat as &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/315922"&gt;@MAGNUS SVENSSON&lt;/a&gt;.&lt;/P&gt;&lt;P&gt;Is there some official Cisco communication that confirms this how it should be done?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 02 Feb 2022 15:30:12 GMT</pubDate>
    <dc:creator>Darkmatter</dc:creator>
    <dc:date>2022-02-02T15:30:12Z</dc:date>
    <item>
      <title>ISE 2.7 patch 3 installed and log4j hot patch is applied.</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-7-patch-3-installed-and-log4j-hot-patch-is-applied/m-p/4529312#M572123</link>
      <description>&lt;P&gt;ISE 2.7 patch 3 installed and log4j hot patch is applied. If I install patch 6 , do I have to apply the log4j hot patch after that ?&lt;/P&gt;</description>
      <pubDate>Tue, 11 Jan 2022 08:47:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-7-patch-3-installed-and-log4j-hot-patch-is-applied/m-p/4529312#M572123</guid>
      <dc:creator>MAGNUS SVENSSON</dc:creator>
      <dc:date>2022-01-11T08:47:47Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.7 patch 3 installed and log4j hot patch is applied.</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-7-patch-3-installed-and-log4j-hot-patch-is-applied/m-p/4529370#M572124</link>
      <description>&lt;P&gt;yes as per i remember if any upgrade take place, the patch need to applied as per my understanding.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Jan 2022 09:39:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-7-patch-3-installed-and-log4j-hot-patch-is-applied/m-p/4529370#M572124</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2022-01-11T09:39:27Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.7 patch 3 installed and log4j hot patch is applied.</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-7-patch-3-installed-and-log4j-hot-patch-is-applied/m-p/4529438#M572129</link>
      <description>&lt;P class="lia-align-justify"&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/315922"&gt;@MAGNUS SVENSSON&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P class="lia-align-justify"&gt;&amp;nbsp;as &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/286878"&gt;@balaji.bandi&lt;/a&gt;&amp;nbsp;said, the answer is &lt;STRONG&gt;Yes&lt;/STRONG&gt;, but remember that usually it is recommended to rollback a &lt;STRONG&gt;Hot Patch&lt;/STRONG&gt; before applying a regular&lt;STRONG&gt; ISE Patch&lt;/STRONG&gt; release !!!&lt;/P&gt;&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="lia-align-justify"&gt;Hope this helps !!!&lt;/P&gt;</description>
      <pubDate>Tue, 11 Jan 2022 12:09:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-7-patch-3-installed-and-log4j-hot-patch-is-applied/m-p/4529438#M572129</guid>
      <dc:creator>Marcelo Morais</dc:creator>
      <dc:date>2022-01-11T12:09:22Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.7 patch 3 installed and log4j hot patch is applied.</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-7-patch-3-installed-and-log4j-hot-patch-is-applied/m-p/4544148#M572562</link>
      <description>&lt;P&gt;I'm in the same boat as &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/315922"&gt;@MAGNUS SVENSSON&lt;/a&gt;.&lt;/P&gt;&lt;P&gt;Is there some official Cisco communication that confirms this how it should be done?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 02 Feb 2022 15:30:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-7-patch-3-installed-and-log4j-hot-patch-is-applied/m-p/4544148#M572562</guid>
      <dc:creator>Darkmatter</dc:creator>
      <dc:date>2022-02-02T15:30:12Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.7 patch 3 installed and log4j hot patch is applied.</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-7-patch-3-installed-and-log4j-hot-patch-is-applied/m-p/4544349#M572565</link>
      <description>&lt;P class="lia-align-justify"&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/103764"&gt;@Darkmatter&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;please take a look at: &lt;A href="https://www.cisco.com/c/en/us/solutions/security/secure-alert.html" target="_blank" rel="noopener"&gt;Cisco Secure Alert&lt;/A&gt;. and&amp;nbsp;&lt;A href="https://www.zerodayinitiative.com/blog/2021/12/14/the-december-2021-security-update-review" target="_blank" rel="noopener"&gt;December Security Update Review&lt;/A&gt;.&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;Hope this helps !!!&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 02 Feb 2022 18:37:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-7-patch-3-installed-and-log4j-hot-patch-is-applied/m-p/4544349#M572565</guid>
      <dc:creator>Marcelo Morais</dc:creator>
      <dc:date>2022-02-02T18:37:16Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.7 patch 3 installed and log4j hot patch is applied.</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-7-patch-3-installed-and-log4j-hot-patch-is-applied/m-p/4544599#M572572</link>
      <description>&lt;P&gt;Thank you &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/17232"&gt;@Marcelo Morais&lt;/a&gt; , i'm well aware about Log4J. With all due respect, but the links you posted have nothing do with the procedure of how to properly patch your ISE if you had the Log4J Hotpatch installed.&lt;/P&gt;&lt;P&gt;So my question remains, where to find the official and exact Cisco procedure that clearly states which steps to take in order to correctly install my 2.7 patch 6.&lt;/P&gt;</description>
      <pubDate>Thu, 03 Feb 2022 07:57:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-7-patch-3-installed-and-log4j-hot-patch-is-applied/m-p/4544599#M572572</guid>
      <dc:creator>Darkmatter</dc:creator>
      <dc:date>2022-02-03T07:57:59Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.7 patch 3 installed and log4j hot patch is applied.</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-7-patch-3-installed-and-log4j-hot-patch-is-applied/m-p/4545093#M572581</link>
      <description>&lt;P class="lia-align-justify"&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/103764"&gt;@Darkmatter&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;no worries .&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;If you are talking about the step to step process to install &lt;STRONG&gt;log4j&lt;/STRONG&gt; ... at &lt;A href="https://cs.co/ise-software" target="_blank" rel="noopener"&gt;ISE Software&lt;/A&gt;, search for &lt;STRONG&gt;Log4j2021&lt;/STRONG&gt;, select you version, put you mouse at the &lt;EM&gt;filename&lt;/EM&gt; and click the &lt;STRONG&gt;Release Notes&lt;/STRONG&gt; (for ex.:&amp;nbsp;&lt;A href="https://www.cisco.com/web/software/283802505/159582/README_Hotpatch_CSCwa47133_Log4j2-fix-2.4-3.0.txt" target="_blank" rel="noopener"&gt;README for installing Hot Patch to fix CSCwa47133&lt;/A&gt;).&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;If you are talking about &lt;STRONG&gt;ISE Patch&lt;/STRONG&gt; installation, please take a look at:&amp;nbsp;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/215406-patch-installation-on-ise-and-faq-durin.html" target="_blank" rel="noopener"&gt;Patch Installation on ISE and FAQ during Installation&lt;/A&gt;.&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;Hope this helps !!!&lt;/P&gt;</description>
      <pubDate>Thu, 03 Feb 2022 20:15:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-7-patch-3-installed-and-log4j-hot-patch-is-applied/m-p/4545093#M572581</guid>
      <dc:creator>Marcelo Morais</dc:creator>
      <dc:date>2022-02-03T20:15:33Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.7 patch 3 installed and log4j hot patch is applied.</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-7-patch-3-installed-and-log4j-hot-patch-is-applied/m-p/4545658#M572594</link>
      <description>&lt;P&gt;Hello &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/17232"&gt;@Marcelo Morais&lt;/a&gt; ,&lt;/P&gt;&lt;P&gt;I finally found an answer myself by Googling and ... landing back on the forum here, a post provided by a Cisco employee, but regarding an older hotpatch and ISE 2.2&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.cisco.com/t5/network-access-control/ise-2-2-patch-12-apache-struts-vulnerability/td-p/3774554" target="_blank" rel="noopener"&gt;https://community.cisco.com/t5/network-access-control/ise-2-2-patch-12-apache-struts-vulnerability/td-p/3774554&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Don't know if this way of working is still valid or that this changed in the mean time.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So to be absolutely sure, i'm going to create a TAC case for this to get a definitive answer from Cisco.&lt;/P&gt;&lt;P&gt;Because if it's no clearly documented, you'll never be sure about this is the right or wrong way (with the possibility of breaking things if your are unlucky)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'll revert back as soon as an answer on my TAC case is received!&lt;/P&gt;</description>
      <pubDate>Fri, 04 Feb 2022 15:20:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-7-patch-3-installed-and-log4j-hot-patch-is-applied/m-p/4545658#M572594</guid>
      <dc:creator>Darkmatter</dc:creator>
      <dc:date>2022-02-04T15:20:50Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.7 patch 3 installed and log4j hot patch is applied.</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-7-patch-3-installed-and-log4j-hot-patch-is-applied/m-p/4545815#M572595</link>
      <description>&lt;P class="lia-align-justify"&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/103764"&gt;@Darkmatter&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;glad to hear that.&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;Note: if you are looking for the &lt;STRONG&gt;HotPatch Rollback&lt;/STRONG&gt; process, it is described on the link I provided before:&lt;/P&gt;
&lt;PRE&gt;===============
How to Rollback 
===============

(Note: This is only required if you need to remove the hot patch)

Login to ISE CLI
Invoke the following command to rollback the hot patch:

"application install ise-&lt;STRONG&gt;rollback&lt;/STRONG&gt;-CSCwa47133_Ver_24_30_allpatches-SPA.tar.gz  &amp;lt;REPOSITORY_NAME&amp;gt;"&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;Regards&lt;/P&gt;</description>
      <pubDate>Fri, 04 Feb 2022 21:10:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-7-patch-3-installed-and-log4j-hot-patch-is-applied/m-p/4545815#M572595</guid>
      <dc:creator>Marcelo Morais</dc:creator>
      <dc:date>2022-02-04T21:10:13Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.7 patch 3 installed and log4j hot patch is applied.</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-7-patch-3-installed-and-log4j-hot-patch-is-applied/m-p/4552881#M572790</link>
      <description>&lt;P&gt;As per Cisco TAC where we had a case open to ask and confirm, log4j patch does not need to be uninstalled and you can patch directly.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope this helps!&lt;/P&gt;</description>
      <pubDate>Tue, 15 Feb 2022 16:32:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-7-patch-3-installed-and-log4j-hot-patch-is-applied/m-p/4552881#M572790</guid>
      <dc:creator>Darkmatter</dc:creator>
      <dc:date>2022-02-15T16:32:13Z</dc:date>
    </item>
  </channel>
</rss>

