<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: patch ISE server from 3.3 patch-4 to patch-6 via CLI in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/patch-ise-server-from-3-3-patch-4-to-patch-6-via-cli/m-p/5309786#M597288</link>
    <description>&lt;P class="lia-align-justify"&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1191533"&gt;@adamscottmaster2013&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;I prefer to &lt;STRONG&gt;Deregister&lt;/STRONG&gt; some &lt;STRONG&gt;Nodes&lt;/STRONG&gt; from the &lt;STRONG&gt;Cluster&lt;/STRONG&gt; before an update.&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;This way I can test the &lt;U&gt;new patch&lt;/U&gt;, where all the &lt;STRONG&gt;Nodes&lt;/STRONG&gt; are patched, and also have a &lt;U&gt;rollback plan&lt;/U&gt; using the &lt;U&gt;deregistered&lt;/U&gt; &lt;STRONG&gt;Nodes&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;Note: I'm doing this for a recently update from &lt;STRONG&gt;3.3 P4&lt;/STRONG&gt; to &lt;STRONG&gt;3.3 P6&lt;/STRONG&gt;, so far &lt;STRONG&gt;P6&lt;/STRONG&gt; is OK.&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;Hope this helps !!!&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 15 Jul 2025 23:04:12 GMT</pubDate>
    <dc:creator>Marcelo Morais</dc:creator>
    <dc:date>2025-07-15T23:04:12Z</dc:date>
    <item>
      <title>patch ISE server from 3.3 patch-4 to patch-6 via CLI</title>
      <link>https://community.cisco.com/t5/network-access-control/patch-ise-server-from-3-3-patch-4-to-patch-6-via-cli/m-p/5309050#M597248</link>
      <description>&lt;P&gt;I do not have a test environment to test so I am asking here.&amp;nbsp; I have a five nodes cluster environment 3.3 patch-4 and I need to get them to patch-6, in a safe way.&amp;nbsp; My environment:&lt;/P&gt;&lt;P&gt;node1:&amp;nbsp; Primary Admin, Secondary MnT&lt;/P&gt;&lt;P&gt;node2:&amp;nbsp; Secondary Admin, Primary MnT&lt;/P&gt;&lt;P&gt;node3:&amp;nbsp; PSN&lt;/P&gt;&lt;P&gt;node4:&amp;nbsp; PSN&lt;/P&gt;&lt;P&gt;node5:&amp;nbsp; PSN&lt;/P&gt;&lt;P&gt;My plan is to patch these ISE servers through the CLI, in this order:&lt;/P&gt;&lt;P&gt;A- patch node2 (Secondary Admin, Primary MnT) first,&lt;/P&gt;&lt;P&gt;B- patch node3 (PSN) after that,&lt;/P&gt;&lt;P&gt;&lt;U&gt;&lt;EM&gt;&lt;STRONG&gt;C- wait for one week to confirm that everything is still working,&lt;/STRONG&gt;&lt;/EM&gt;&lt;/U&gt;&lt;/P&gt;&lt;P&gt;D- patch node4 (PSN) and node5 (PSN),&lt;/P&gt;&lt;P&gt;E- patch node1 (Primary Admin, Secondary MnT)&lt;/P&gt;&lt;P&gt;I just don't want to patch all the systems and if they have issues, have to roll everything back, which might involve downtime.&amp;nbsp; I talked to Cisco TAC in the past, and I think they told me this method would be ok too, but I can't recall.&lt;/P&gt;&lt;P&gt;Anyone seeing issues with this?&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;TIA&lt;/P&gt;</description>
      <pubDate>Mon, 14 Jul 2025 12:16:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/patch-ise-server-from-3-3-patch-4-to-patch-6-via-cli/m-p/5309050#M597248</guid>
      <dc:creator>adamscottmaster2013</dc:creator>
      <dc:date>2025-07-14T12:16:00Z</dc:date>
    </item>
    <item>
      <title>Re: patch ISE server from 3.3 patch-4 to patch-6 via CLI</title>
      <link>https://community.cisco.com/t5/network-access-control/patch-ise-server-from-3-3-patch-4-to-patch-6-via-cli/m-p/5309055#M597249</link>
      <description>&lt;P&gt;It is pretty unorthodox to do it this way, but it should work fine. Ideally you would upgrade your deployment in one go - ISE patching is pretty safe. It is very rare for it to cause issues in my experience.&lt;/P&gt;
&lt;P&gt;I would also alter the procedure somewhat if you go down this route.&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Upgrade &lt;EM&gt;both&lt;/EM&gt; PAN nodes, these won't cause network downtime for authentication and this is where I would guess any patch-version differences to cause issues if any should occur.&lt;/LI&gt;
&lt;LI&gt;Upgrade 1 PSN, wait and verify.&lt;/LI&gt;
&lt;LI&gt;Upgrade the remaining PSN nodes.&lt;/LI&gt;
&lt;/OL&gt;</description>
      <pubDate>Mon, 14 Jul 2025 12:49:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/patch-ise-server-from-3-3-patch-4-to-patch-6-via-cli/m-p/5309055#M597249</guid>
      <dc:creator>Torbjørn</dc:creator>
      <dc:date>2025-07-14T12:49:56Z</dc:date>
    </item>
    <item>
      <title>Re: patch ISE server from 3.3 patch-4 to patch-6 via CLI</title>
      <link>https://community.cisco.com/t5/network-access-control/patch-ise-server-from-3-3-patch-4-to-patch-6-via-cli/m-p/5309088#M597251</link>
      <description>&lt;P&gt;Thank you&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/964504"&gt;@Torbjørn&lt;/a&gt;.&amp;nbsp; I would rather avoid upgrading both PAN nodes at the same time, because if things don't work and I have to rollback, nobody can log into ISE and make configuration changes. I've done enough ISE patching upgrades to know that it works well 95% of the time but I was part of the 5% that had issues.&amp;nbsp; Better safe than sorry, but your point is well taken.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 14 Jul 2025 13:57:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/patch-ise-server-from-3-3-patch-4-to-patch-6-via-cli/m-p/5309088#M597251</guid>
      <dc:creator>adamscottmaster2013</dc:creator>
      <dc:date>2025-07-14T13:57:40Z</dc:date>
    </item>
    <item>
      <title>Re: patch ISE server from 3.3 patch-4 to patch-6 via CLI</title>
      <link>https://community.cisco.com/t5/network-access-control/patch-ise-server-from-3-3-patch-4-to-patch-6-via-cli/m-p/5309786#M597288</link>
      <description>&lt;P class="lia-align-justify"&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1191533"&gt;@adamscottmaster2013&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;I prefer to &lt;STRONG&gt;Deregister&lt;/STRONG&gt; some &lt;STRONG&gt;Nodes&lt;/STRONG&gt; from the &lt;STRONG&gt;Cluster&lt;/STRONG&gt; before an update.&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;This way I can test the &lt;U&gt;new patch&lt;/U&gt;, where all the &lt;STRONG&gt;Nodes&lt;/STRONG&gt; are patched, and also have a &lt;U&gt;rollback plan&lt;/U&gt; using the &lt;U&gt;deregistered&lt;/U&gt; &lt;STRONG&gt;Nodes&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;Note: I'm doing this for a recently update from &lt;STRONG&gt;3.3 P4&lt;/STRONG&gt; to &lt;STRONG&gt;3.3 P6&lt;/STRONG&gt;, so far &lt;STRONG&gt;P6&lt;/STRONG&gt; is OK.&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;Hope this helps !!!&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 15 Jul 2025 23:04:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/patch-ise-server-from-3-3-patch-4-to-patch-6-via-cli/m-p/5309786#M597288</guid>
      <dc:creator>Marcelo Morais</dc:creator>
      <dc:date>2025-07-15T23:04:12Z</dc:date>
    </item>
    <item>
      <title>Re: patch ISE server from 3.3 patch-4 to patch-6 via CLI</title>
      <link>https://community.cisco.com/t5/network-access-control/patch-ise-server-from-3-3-patch-4-to-patch-6-via-cli/m-p/5310733#M597344</link>
      <description>&lt;P class="lia-align-justify"&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1191533"&gt;@adamscottmaster2013&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;please pay special attention to the new &lt;STRONG&gt;ISE 3.3 P7 - Resolved Caveats&lt;/STRONG&gt;:&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&lt;A id="link_7" class="page-link lia-link-navigation lia-custom-event" href="https://community.cisco.com/t5/security-knowledge-base/cisco-ise-related-vulnerability-cve-2025-20281-amp-20282-amp/ta-p/5302518" target="_blank"&gt;Cisco ISE related Vulnerability (CVE-2025-20281 &amp;amp; 20282 &amp;amp; 20337)&lt;/A&gt;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&lt;A id="link_7" class="page-link lia-link-navigation lia-custom-event" href="https://community.cisco.com/t5/security-knowledge-base/cisco-ise-related-vulnerability-cve-2025-20283-amp-20284-amp/ta-p/5310696" target="_blank"&gt;Cisco ISE related Vulnerability (CVE-2025-20283 &amp;amp; 20284 &amp;amp; 20285)&lt;/A&gt;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;Hope this helps !!!&lt;/P&gt;
&lt;P class="lia-align-justify"&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 17 Jul 2025 18:09:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/patch-ise-server-from-3-3-patch-4-to-patch-6-via-cli/m-p/5310733#M597344</guid>
      <dc:creator>Marcelo Morais</dc:creator>
      <dc:date>2025-07-17T18:09:39Z</dc:date>
    </item>
  </channel>
</rss>

