<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE upgrade timed out in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-upgrade-timed-out/m-p/4647410#M576055</link>
    <description>&lt;P&gt;If you are not sure what to do, please call TAC when you have a production system down!&lt;/P&gt;
&lt;P&gt;As &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/326026"&gt;@Leo Laohoo&lt;/a&gt; said, you may create a pre-emptive TAC case just in case.&lt;/P&gt;</description>
    <pubDate>Fri, 08 Jul 2022 22:06:06 GMT</pubDate>
    <dc:creator>thomas</dc:creator>
    <dc:date>2022-07-08T22:06:06Z</dc:date>
    <item>
      <title>ISE upgrade timed out</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-upgrade-timed-out/m-p/4638924#M575980</link>
      <description>&lt;P&gt;Hi, I wonder if someone can help me. I will appreciate it very much.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I started the process to upgrade our ISE deployment consisting of 2 SNS-3615-K9 servers. These have AD-OS version 3.0 (with no patches) and I wanted to upgrade it to AD-OS 3.1.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I read I had to install patch 2 of version 3.0 first, which after a few issues I managed to do but that was because an issue with smart accounts.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I went through the Checklist OK twice, once before the download and installation of patch 2 and another after I installed it. The URT tool indicated no problems and every test it did was successful. On the day of the upgrade the health checks (from the Administration à System menu) were also OK apart from DNS resolvability and the Trust Store Certificate Validation which were highlighted yellow. The Trust Store Certificate Validation had been highlighted yellow before and after I installed patch 2 but DNS resolvability&lt;/P&gt;&lt;P&gt;had been green before the installation of patch 2 and then yellow. It remined yellow even after I ran health checks again. I decide to go ahead with it since there had not been network changes that could have impacted this connectivity.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The system calculated 600 mins to upgrade both servers so I left it and monitored it from time to time. The first server to be upgraded was the Secondary (Secondary PAN and MnT) The progress bar indicated 80% of the process had been completed of this Secondary and that is where I left it. The day after I logged on to see if the servers had been upgraded and found the message Upgrade timed out in the status column of the secondary server, and the Primary server displayed Upgrade cancelled in the status column. I understand the system didn’t go ahead with upgrading the Primary server because the Secondary was not completed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please note that the servers subnet and the ftp server (where the repositories are) are both connected via Gigabit interfaces using different SVI interfaces of the same core switch, hence I do not believe bandwidth is an issue here. But I am happy to consider your thoughts.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The situation now is, I still have service form the Primary server but there is no backup as I have no connectivity with the Secondary server (cannot even ping it) and I cannot do anything in the Upgrade section in the GUI as everything is greyed out, I cannot deselect the nodes or click Continue or Download the upgrade file to the servers, etc.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can someone suggest the best way to recover from this? I would like the option of reimaging the secondary server to be the last resort. I saved all the logs (bundles) and backed up the Operational and Configuration data.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can someone suggest what I the best thing to do in these circumstances?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you in advance.&lt;/P&gt;</description>
      <pubDate>Sun, 26 Jun 2022 06:24:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-upgrade-timed-out/m-p/4638924#M575980</guid>
      <dc:creator>a.maldonado</dc:creator>
      <dc:date>2022-06-26T06:24:49Z</dc:date>
    </item>
    <item>
      <title>Re: ISE upgrade timed out</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-upgrade-timed-out/m-p/4638942#M575981</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/177536"&gt;@a.maldonado&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;
&lt;P&gt;&lt;SPAN&gt;Can someone suggest the best way to recover from this?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Can someone suggest what I the best thing to do in these circumstances?&lt;/SPAN&gt;&lt;/P&gt;
&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;Always raise a TAC Case before every upgrade.&lt;/P&gt;</description>
      <pubDate>Sun, 26 Jun 2022 07:40:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-upgrade-timed-out/m-p/4638942#M575981</guid>
      <dc:creator>Leo Laohoo</dc:creator>
      <dc:date>2022-06-26T07:40:34Z</dc:date>
    </item>
    <item>
      <title>Re: ISE upgrade timed out</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-upgrade-timed-out/m-p/4645214#M575985</link>
      <description>&lt;P&gt;Personally I always use the CLI to do ISE upgrades to remove any dependency on the browsers that would cause the sessions to timeout. What do you see on the stuck node's screen? does it show anything?&lt;/P&gt;</description>
      <pubDate>Wed, 06 Jul 2022 17:33:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-upgrade-timed-out/m-p/4645214#M575985</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2022-07-06T17:33:50Z</dc:date>
    </item>
    <item>
      <title>Re: ISE upgrade timed out</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-upgrade-timed-out/m-p/4645310#M575989</link>
      <description>&lt;P&gt;What do you mean by "&lt;SPAN&gt;These have AD-OS version 3.0 (with no patches) and I wanted to upgrade it to AD-OS 3.1."&amp;nbsp; Do you mean an ISE 3.0 to ISE 3.1 upgrade?&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;At this point I would just rebuild the secondary server from scratch and just re-add to the deployment.&amp;nbsp; All of the configuration is stored on the PAN anyways.&amp;nbsp; You will need certificates re-generated and the secondary node joined back to the AD domain (if there is an AD join point).&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 06 Jul 2022 18:51:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-upgrade-timed-out/m-p/4645310#M575989</guid>
      <dc:creator>ahollifield</dc:creator>
      <dc:date>2022-07-06T18:51:38Z</dc:date>
    </item>
    <item>
      <title>Re: ISE upgrade timed out</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-upgrade-timed-out/m-p/4645498#M575996</link>
      <description>&lt;P class="lia-align-justify"&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/177536"&gt;@a.maldonado&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&lt;STRONG&gt;1st&amp;nbsp;ISE 3.1.0&lt;/STRONG&gt; parity with &lt;STRONG&gt;3.0 P2&lt;/STRONG&gt;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&lt;STRONG&gt;2nd&amp;nbsp;ISE 3.1&lt;/STRONG&gt; supports &lt;U&gt;restore from backups&lt;/U&gt; obtained from &lt;STRONG&gt;ISE 2.6+&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&lt;STRONG&gt;3rd&amp;nbsp;&lt;/STRONG&gt;upgrade &lt;STRONG&gt;ISE&lt;/STRONG&gt; using &lt;STRONG&gt;BACKUP &amp;amp; RESTORE&lt;/STRONG&gt; is &lt;U&gt;RECOMMENDED&lt;/U&gt;, because it helps to reinstate the &lt;STRONG&gt;ISE Deployment&lt;/STRONG&gt; settings and prevent data loss in case of any breakage during the upgrade process.&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&lt;STRONG&gt;4th&amp;nbsp;&lt;/STRONG&gt;when upgrading &lt;STRONG&gt;ISE&lt;/STRONG&gt; using the &lt;STRONG&gt;GUI&lt;/STRONG&gt;, note that the &lt;U&gt;timeout for the process&lt;/U&gt; is &lt;STRONG&gt;4 hours&lt;/STRONG&gt;. If the process takes &lt;U&gt;more than&lt;/U&gt; &lt;STRONG&gt;4 hours&lt;/STRONG&gt;, the &lt;U&gt;UPGRADE FAILS&lt;/U&gt; !!!&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&lt;STRONG&gt;5th&lt;/STRONG&gt; you have the option to &lt;STRONG&gt;Purge M&amp;amp;T Operation Data&lt;/STRONG&gt; to &lt;U&gt;speed up the process&lt;/U&gt; (your case &lt;STRONG&gt;&amp;lt; 600 min&lt;/STRONG&gt;) via the following command:&lt;/P&gt;
&lt;PRE class="lia-align-justify"&gt;ise/admin# application configure ise&lt;BR /&gt;Selection configuration option&lt;BR /&gt;...&lt;BR /&gt;[3]Purge M&amp;amp;T Operational Data&lt;BR /&gt;...&lt;/PRE&gt;
&lt;P class="lia-align-justify"&gt;Putting ALL together&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&lt;STRONG&gt;Node A&lt;/STRONG&gt;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;1. &lt;U&gt;Install&lt;/U&gt; &lt;STRONG&gt;ISE 3.1&lt;/STRONG&gt; &lt;U&gt;from scratch&lt;/U&gt;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;2. &lt;U&gt;Update&lt;/U&gt; to &lt;STRONG&gt;ISE 3.1 P3&lt;/STRONG&gt;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;3. Use the &lt;STRONG&gt;Backup&lt;/STRONG&gt; from &lt;STRONG&gt;3.0&lt;/STRONG&gt; and &lt;STRONG&gt;Restore&lt;/STRONG&gt; (with &lt;STRONG&gt;ADE 0S&lt;/STRONG&gt;) to &lt;STRONG&gt;ISE 3.1 P3&lt;/STRONG&gt;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&lt;STRONG&gt;Node B&lt;/STRONG&gt;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;1. &lt;U&gt;Install&lt;/U&gt; &lt;STRONG&gt;ISE 3.1&lt;/STRONG&gt; &lt;U&gt;from scratch&lt;/U&gt;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;2. &lt;U&gt;Update&lt;/U&gt; to &lt;STRONG&gt;ISE 3.1 P3&lt;/STRONG&gt;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;3. Register to &lt;STRONG&gt;Node A Cluster&lt;/STRONG&gt;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;Hope this helps !!!&lt;/P&gt;</description>
      <pubDate>Wed, 06 Jul 2022 23:56:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-upgrade-timed-out/m-p/4645498#M575996</guid>
      <dc:creator>Marcelo Morais</dc:creator>
      <dc:date>2022-07-06T23:56:57Z</dc:date>
    </item>
    <item>
      <title>Re: ISE upgrade timed out</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-upgrade-timed-out/m-p/4647410#M576055</link>
      <description>&lt;P&gt;If you are not sure what to do, please call TAC when you have a production system down!&lt;/P&gt;
&lt;P&gt;As &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/326026"&gt;@Leo Laohoo&lt;/a&gt; said, you may create a pre-emptive TAC case just in case.&lt;/P&gt;</description>
      <pubDate>Fri, 08 Jul 2022 22:06:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-upgrade-timed-out/m-p/4647410#M576055</guid>
      <dc:creator>thomas</dc:creator>
      <dc:date>2022-07-08T22:06:06Z</dc:date>
    </item>
  </channel>
</rss>

